The FTC Safeguards Rule is a federal regulation under the Gramm-Leach-Bliley Act that requires non-bank financial institutions to build and maintain a written information security program protecting customer data. The Federal Trade Commission enforces it, and it reaches far beyond banks: mortgage brokers, auto dealers that arrange financing, tax preparers, collection agencies, and colleges that participate in federal student aid all fall inside it. If your business handles consumer financial information, the rule likely tells you who has to run your security program, what technical controls you must use, how to plan for an incident, and when you must notify the FTC after a breach.
Who Has to Comply
The rule applies to any business “significantly engaged” in providing financial products or services to consumers. That category is broader than most business owners assume. It covers mortgage lenders and brokers, payday lenders, finance companies, account servicers, check-cashing businesses, wire transfer services, collection agencies, credit counselors, investment advisors not registered with the SEC, and tax preparation firms.1eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information
Auto dealerships that lease vehicles for terms of 90 days or longer, or that arrange financing for buyers, count as financial institutions under the rule. So do travel agencies operating in connection with financial services and “finders” that connect buyers and sellers of financial products.2eCFR. 16 CFR 314.2 – Definitions
Colleges and universities that participate in Title IV federal student aid programs must comply as well. The FTC treats them as financial institutions because they administer federal student loans and other aid.3Knowledge Center. Updates to the Gramm-Leach-Bliley Act Cybersecurity Requirements
What Counts as Customer Information
The rule protects any record containing nonpublic personal information about a customer, whether on paper, electronic, or in any other form.2eCFR. 16 CFR 314.2 – Definitions In practice that means Social Security numbers, bank account details, credit card numbers, loan applications, income records, and credit history. The fact that a person is or has been your customer is itself protected. Data collected through cookies or web beacons during a financial interaction also counts. Information that is genuinely public, such as government records or widely distributed media, does not.
What Your Security Program Must Include
The rule sets out specific elements every covered institution has to build into its security program.
A Qualified Individual in Charge
You must designate a Qualified Individual to oversee and enforce the program. This person does not have to be an employee; the role can be filled by someone at an affiliate or a service provider.4eCFR. 16 CFR 314.4 – Elements
A Written Risk Assessment
Your program has to rest on a written risk assessment that identifies foreseeable internal and external threats to customer information, evaluates how well your current safeguards address them, and names your specific vulnerabilities, including gaps in training, network security, and data handling.4eCFR. 16 CFR 314.4 – Elements
Specific Technical Safeguards
Customer information must be encrypted both in transit over external networks and at rest. If encryption isn’t feasible in a particular situation, the Qualified Individual must approve a written alternative control. Multi-factor authentication is required for anyone accessing your information systems, again unless the Qualified Individual approves an equally secure or stronger written alternative. Access must be limited to what each authorized user needs for their job. User activity must be monitored and logged so unauthorized access, use, or tampering can be detected. And formal change management procedures must govern updates to your systems so modifications don’t introduce new vulnerabilities.4eCFR. 16 CFR 314.4 – Elements
Testing and Updating
You have to test the effectiveness of your safeguards on an ongoing basis. Continuous monitoring of your information systems satisfies that obligation. If you don’t run continuous monitoring, you must instead conduct annual penetration testing and vulnerability assessments every six months, including system-wide scans for publicly known vulnerabilities.5Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know More testing is required whenever there are material changes to operations or arrangements, and you must adjust the program based on the results, updated risk assessments, or other relevant new circumstances.4eCFR. 16 CFR 314.4 – Elements
Service Provider Oversight
You have to choose service providers capable of maintaining appropriate safeguards, write your security expectations into their contracts, build in ways to monitor their work, and periodically reassess whether they’re still suitable.5Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know
Employee Training
All staff must be trained on their role in protecting customer information, and the training has to be updated as your business, technology, or threat environment changes.4eCFR. 16 CFR 314.4 – Elements
Incident Response Plan and Board Reporting
You must maintain a written incident response plan. The plan has to spell out your response goals, the internal processes you’ll follow during a security event, who holds which decision-making authority, how you’ll communicate internally and externally, how you’ll remediate the weaknesses the event exposes, how you’ll document what happened, and how you’ll evaluate and revise the plan afterward.4eCFR. 16 CFR 314.4 – Elements
Separately, your Qualified Individual has to deliver a written report to the board of directors or equivalent governing body at least once a year. That report must cover the overall status of the program, risk assessment results, the effectiveness of your safeguards, and your service provider arrangements.4eCFR. 16 CFR 314.4 – Elements
When You Must Report a Breach
If a security event involves the unencrypted customer information of at least 500 consumers, you have to notify the FTC as soon as possible and no later than 30 days after discovery. The notice goes in through the FTC’s online Safeguards Rule Security Event Reporting Form and must include your business’s name, a contact person, the start and end dates of the event, the number of consumers affected, the types of information involved, and a summary of what happened.6Federal Trade Commission. Safeguards Rule Security Event Reporting Form
The rule defines a triggering event as the unauthorized acquisition of unencrypted customer information. If someone gained unauthorized access to unencrypted data, you have to presume unauthorized acquisition occurred unless you have reliable evidence otherwise.7Federal Trade Commission. Safeguards Rule Notification Requirement Now in Effect
The Small-Business Exemption
Institutions that maintain customer information on fewer than 5,000 consumers are exempt from four specific requirements: the written risk assessment, the penetration testing and vulnerability assessment schedule, the written incident response plan, and the annual board report.8eCFR. 16 CFR 314.6 – Exceptions
Everything else still applies. Smaller institutions still must designate a Qualified Individual, encrypt data, use multi-factor authentication, limit access, oversee service providers, and train employees. The exemption cuts documentation and formal testing, not the underlying duty to protect the data.5Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know
A Related Duty: Disposing of Consumer Data
A separate FTC regulation, the Disposal Rule, requires anyone who possesses consumer information for a business purpose to dispose of it in a way reasonable enough to prevent unauthorized access. For paper, that usually means shredding, burning, or pulverizing so records cannot be reconstructed. For electronic media, it means destroying or erasing data beyond recovery. If you hire a third-party disposal company, you should review its operations, check references, confirm certifications, and evaluate its security policies. Businesses already subject to the Safeguards Rule should fold disposal into the broader security program.9eCFR. 16 CFR 682.3 – Proper Disposal of Consumer Information
Penalties for Noncompliance
The FTC enforces the Safeguards Rule under its authority over unfair or deceptive business practices. Civil penalties are assessed per violation and adjusted for inflation annually, so the exact dollar figure shifts from year to year. Enforcement actions typically result in consent orders that impose ongoing compliance obligations, independent audits, and reporting duties on the business.
The Gramm-Leach-Bliley Act itself also carries criminal penalties for anyone who knowingly obtains customer information from a financial institution through fraud or deception. A conviction can bring up to five years in prison, or up to ten years if the conduct was part of a pattern involving more than $100,000 in a 12-month period.10Office of the Law Revision Counsel. 15 U.S. Code 6823 – Criminal Penalty