The Safeguards Rule is what happens when the FTC writes down the security program it spent twenty years imposing through consent orders, then attaches penalties to skipping it. Since June 2023 the rule reads like a checklist because it is one: a named Qualified Individual, a written risk assessment, MFA, encryption, testing on a schedule, vendor oversight, an incident plan, and an annual report to the board. Since May 2024, large breaches of unencrypted data go to a public FTC database within 30 days. For the car dealers, tax shops, and fintechs it covers, the rule’s message is blunt: the program is no longer aspirational, and neither is the fine.
| Rule | 16 CFR Part 314 (GLBA) |
|---|---|
| Covered | Non-bank financial institutions incl. auto dealers, tax preparers, fintechs |
| Core | 9 elements: QI, risk assessment, MFA, encryption, testing, training, vendors, IR plan, board report |
| Small-entity relief | <5,000 consumers: subset of written requirements waived |
| Breach notice | FTC portal, 30 days, 500+ consumers, unencrypted data (public database) |
| Penalties | $50K+ per violation, per element, per day |
Complying element by element
Start with the QI and the risk assessment. Every other element hangs off them, and both are pure documentation wins; the GLBA program guide covers build-out.
Encrypt to shrink breach exposure. Encrypted customer data is outside the 30-day FTC report and most state notice laws, the highest-leverage single control.
Paper the vendor chain. Selection diligence, contract clauses, and periodic reassessment are element 6; align with your vendor management program.
Reconcile with the Privacy Rule. Safeguards secures the data; GLBA privacy notices govern telling customers how you share it; the FTC’s broader security expectations frame both.
Customer-facing web forms are covered customer information systems: check what yours expose with a free scan.