HomeFrameworksInformation Security & PrivacyFTC Safeguards/GLBA

Framework  Information Security & Privacy

FTC Safeguards/GLBA

The FTC Safeguards Rule (16 CFR Part 314) implements the Gramm-Leach-Bliley Act for financial institutions that are not supervised by a banking regulator: mortgage brokers and lenders, auto dealers that finance, payday and finance companies, tax preparers, collection agencies, check cashers, wire transfer services, credit counselors, investment advisers not registered with the SEC, and similar businesses.

The 2021 amendments, in force since June 9, 2023, turned the rule into a prescriptive program, and a further amendment effective May 13, 2024 added a requirement to notify the FTC within 30 days of discovering unauthorized access to unencrypted information of 500 or more consumers.

The rule is written-program heavy. A covered institution must designate a Qualified Individual, keep a written risk assessment, implement listed safeguards (access controls, encryption in transit and at rest, MFA, secure disposal, change management, activity logging), test and monitor them, train staff, oversee service providers by contract, keep a written incident response plan, and have the Qualified Individual report in writing to the board at least annually.

Institutions holding information on fewer than 5,000 consumers are exempt from some of the written elements.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedSafeguards program v2by name, on record
Qualified Individual Approvedwith AllyMatter
Safeguard the Modern WayYour written information security program, acknowledged by every employee
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every employee on record
Who read which version, and when
03
Report to the board with the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Financial institutions under FTC jurisdiction that hold customer information, meaning businesses significantly engaged in financial activities that are not banks, credit unions, SEC-registered advisers or other agency-supervised entities.

Institutions with information on fewer than 5,000 consumers are exempt from the written risk assessment, continuous monitoring or annual penetration testing, written incident response plan and annual board report requirements.

What the assessor asks to see

Designation of the Qualified Individual; written risk assessment; written information security program and policies; access control and MFA configuration; encryption evidence; data inventory and disposal schedule; change management records; logging and monitoring evidence; penetration test and vulnerability assessment reports; training records; service provider contracts and oversight records; written incident response plan; annual board report; notification event records.

Where the requirement sits: 16 CFR 314.4(a) qualified individual; (b) written risk assessment; (c) safeguards incl. (c)(5) MFA; (d) monitoring/testing; (e) training; (h) written IR plan; (i) annual board report

What AllyMatter does here

Authors, approves, versions and proves staff acknowledgment of the WISP, and holds the annual board report and IR plan under control.

AllyMatter publishes this site.

Assessors

Who assesses FTC Safeguards/GLBA

Government enforcement only. The FTC investigates and brings enforcement actions; there is no certification or third-party audit requirement. Institutions may commission independent assessments voluntarily or under a consent order.

No firm has claimed a FTC Safeguards/GLBA assessor listing yet. Claim yours →

Consultants

Who helps with FTC Safeguards/GLBA

Yes. IT security firms and compliance consultants serving auto dealers, mortgage brokers, tax practices and lenders offer Safeguards gap assessments, written program templates, virtual Qualified Individual services, MFA and encryption rollouts, and vendor oversight programs. Engagements are usually short, with an annual review cycle.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a FTC Safeguards/GLBA consultant listing yet. Claim yours →

Software

Tools for FTC Safeguards/GLBA

Tools that name this framework in their own material.

Related reading

  1. FTC strengthens GLBA information security requirements for non-bank financial institutionsExplains who counts as a financial institution and what the written information security program, qualified individual and board reporting duties mean.Davis Wright Tremaine
  2. Updates to the Safeguards Rule will require non-banking financial institutions to report data security breaches to the FTCCovers the notification amendment, the 30-day clock and the 500-consumer threshold that now sits on top of the program requirements.WilmerHale

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for FTC Safeguards/GLBA

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of FTC Safeguards/GLBA in AllyMatter

Approve the policies FTC Safeguards/GLBA asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.