US Federal Law United States

FTC Safeguards Rule: The Security Program GLBA Requires

The amended Safeguards Rule for non-bank financial institutions: nine required elements, the Qualified Individual, MFA and encryption mandates, and the 30-day breach notification.

Regulation

Standards for Safeguarding Customer Information, 16 CFR Part 314, under GLBA; amended 2021 (effective June 2023) and 2023 (breach notification, effective May 13, 2024)

Max Penalty

Civil penalties per violation (inflation-adjusted, over $50,000 each) plus injunctive orders; FTC v. individual defendants available for knowing violations

Enforcing Authority

Federal Trade Commission (FTC)

Official Source

www.ftc.gov

Executive Summary

  • The Safeguards Rule (16 CFR Part 314) requires non-bank financial institutions, auto dealers, mortgage brokers, payday lenders, tax preparers, collection agencies, fintechs, and 'finders', to maintain a comprehensive written information security program.
  • The 2021 amendments (fully effective June 9, 2023) converted the rule from principles to prescriptions: nine required elements including a Qualified Individual, written risk assessment, MFA, encryption, and continuous monitoring or annual penetration testing.
  • Since May 13, 2024, covered institutions must notify the FTC within 30 days of discovering a security event involving unencrypted customer information of 500 or more consumers, and the reports are published.
  • Institutions maintaining records on fewer than 5,000 consumers are exempt from a subset of written requirements but not from the program itself.
  • Banks and credit unions are outside the rule (their prudential regulators impose parallel standards); everyone else 'significantly engaged' in financial activities is in.

The Safeguards Rule is what happens when the FTC writes down the security program it spent twenty years imposing through consent orders, then attaches penalties to skipping it. Since June 2023 the rule reads like a checklist because it is one: a named Qualified Individual, a written risk assessment, MFA, encryption, testing on a schedule, vendor oversight, an incident plan, and an annual report to the board. Since May 2024, large breaches of unencrypted data go to a public FTC database within 30 days. For the car dealers, tax shops, and fintechs it covers, the rule’s message is blunt: the program is no longer aspirational, and neither is the fine.

Rule16 CFR Part 314 (GLBA)
CoveredNon-bank financial institutions incl. auto dealers, tax preparers, fintechs
Core9 elements: QI, risk assessment, MFA, encryption, testing, training, vendors, IR plan, board report
Small-entity relief<5,000 consumers: subset of written requirements waived
Breach noticeFTC portal, 30 days, 500+ consumers, unencrypted data (public database)
Penalties$50K+ per violation, per element, per day

Complying element by element

Start with the QI and the risk assessment. Every other element hangs off them, and both are pure documentation wins; the GLBA program guide covers build-out.

Encrypt to shrink breach exposure. Encrypted customer data is outside the 30-day FTC report and most state notice laws, the highest-leverage single control.

Paper the vendor chain. Selection diligence, contract clauses, and periodic reassessment are element 6; align with your vendor management program.

Reconcile with the Privacy Rule. Safeguards secures the data; GLBA privacy notices govern telling customers how you share it; the FTC’s broader security expectations frame both.

Customer-facing web forms are covered customer information systems: check what yours expose with a free scan.

Frequently Asked Questions

Who counts as a financial institution under the rule?

Any business significantly engaged in financial activities as defined under the Bank Holding Company Act, excluding banks and entities regulated by prudential regulators, the SEC, or state insurance authorities for this purpose. The list is broader than intuition: auto dealers arranging financing or leasing, mortgage lenders and brokers, payday and title lenders, check cashers, money transmitters, debt collectors, tax preparation firms, non-bank fintechs, investment advisors not SEC-registered, real estate settlement services, and, added in 2021, 'finders' who bring buyers and sellers together for financial transactions. The FTC's dealer-focused outreach reflects reality: car dealerships are the rule's largest covered population and a stated enforcement priority. If customers' nonpublic personal information flows through your financing function, assume coverage and analyze out.

What are the nine required elements?

314.4 requires: (1) designate a Qualified Individual to implement and supervise the program; (2) a written risk assessment identifying reasonably foreseeable internal and external risks; (3) safeguards addressing the assessment, including access controls, data inventory and classification, encryption of customer information at rest and in transit, secure development practices, MFA for anyone accessing customer information systems, retention and disposal limits (dispose within two years of last use absent business need), change management, and activity monitoring; (4) regular testing, continuous monitoring or annual penetration tests plus biannual vulnerability assessments; (5) workforce training; (6) service provider selection, contracts, and periodic reassessment; (7) program evaluation and adjustment; (8) a written incident response plan; (9) the Qualified Individual's written report to the board or governing body at least annually. Elements 2's written form, 4's testing schedule, 8, and 9 are relaxed for institutions under the 5,000-consumer threshold.

Who can be the Qualified Individual, and what do they sign up for?

Anyone with qualifications suitable to the institution's size and complexity, an employee, an affiliate's employee, or a service provider (a vCISO arrangement is expressly permitted, but then the institution must designate a senior internal member to direct and oversee them, retaining responsibility). The role owns implementation and supervision of the program and authors the annual written report covering program status, risk assessment results, testing outcomes, security events and responses, and recommendations. For small dealers and preparers this is typically the owner or office manager with an MSP behind them; the rule accepts that, what it does not accept is the role existing only on paper. In an FTC investigation, the QI's reports are the first documents requested, and their absence is a per-element violation.

How does the 30-day breach notification work?

The 2023 amendment, effective May 13, 2024, requires notice to the FTC (through its online portal) no later than 30 days after discovering a 'notification event': unauthorized acquisition of unencrypted customer information involving 500 or more consumers. Discovery is the first day the event is known to any person other than the perpetrator; acquisition is presumed from unauthorized access unless reliable evidence shows otherwise. The report names the institution, describes the event, data types, dates, and consumer count, and the FTC publishes the reports in a public database, a reputational lever the agency chose deliberately. Note what it is not: there is no federal consumer-notice requirement in the rule itself; state breach laws govern individual notice on their own, usually shorter, clocks. Encryption remains the practical exemption, encrypted data whose key is not compromised does not trigger the report.

What does Safeguards enforcement look like?

Penalty-eligible from the first violation, unlike bare Section 5, each day of noncompliance and each element can count separately at over $50,000 per violation, inflation-adjusted. The FTC's enforcement history includes pre-amendment actions against mortgage companies and dealers for absent programs, PayPal/Venmo's GLBA-related order, and post-amendment matters pairing Safeguards counts with Section 5 in fintech and lead-generation cases; exam-style sweeps have focused on auto dealers. Investigations track the nine elements as a checklist: produce the risk assessment, the QI designation, MFA evidence, testing reports, vendor contracts, the IR plan, and the annual board report. The rule's prescriptiveness cuts both ways, compliance is more work than 'reasonableness', but provability is mechanical, and the artifact list doubles as the audit defense.

Regulatory Crosswalk

GLBA Privacy RuleNIST CSFNYDFS Part 500State insurance data security laws

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.