GLBA
The US Gramm-Leach-Bliley Act, which requires financial institutions to protect customers' non-public personal financial information — including recorded calls and their transcripts — under its Safeguards Rule.
GLBA governs how banks, lenders, advisers, insurers and other financial institutions handle a customer’s non-public personal information. Its Safeguards Rule requires a written security programme with access controls, encryption, monitoring and vendor oversight — and a recorded advisory or support call, once transcribed, is exactly the kind of data it covers.
Sending those recordings to a third-party cloud transcription service pushes regulated financial data outside the institution and adds a vendor that must itself be assessed and contractually bound. On-prem transcription keeps the audio and transcripts inside the institution’s own controls, which is the simpler path to satisfying the Safeguards Rule. GLBA is a distinct framework from HIPAA and SOC 2; a financial firm typically needs to reason about it on its own terms.