Skip to content
Wednesday, August 26, 2026
3G TIMESFINTECH LAW · LEGAL TECH · COMPLIANCE
Home / Compliance
Compliance

Who the FTC Safeguards Rule Covers, and When Its Incident-Notification Requirement Triggers

The Gramm-Leach-Bliley security rule reached its full modern shape in June 2023, and since May 2024 certain breaches go straight to the Commission within thirty days.

Petra Vogel, · April 4, 2026 · 7 min read
ShareXFacebookLinkedInTelegramEmail
Infographic of incident clocks running from discovery to day thirty

The FTC's Standards for Safeguarding Customer Information, 16 CFR Part 314, requires non-bank financial institutions to run a written information-security program — risk assessment, designated qualified individual, encryption, multi-factor access controls, monitoring, and vendor oversight — with the amended rule's program obligations fully in force since June 5, 2023, and its breach-notification overlay effective May 13, 2024: discovery of a breach involving at least 500 consumers' unencrypted information triggers a report to the Commission within thirty days, and the FTC publishes what it receives. For fintechs outside the banking agencies' perimeter, this is the federal security regime that actually names them.

3G Times publishes information, not legal advice. Coverage and notification questions turn on an entity's GLBA status and the specific facts of an incident, and belong with counsel.

Who counts as a non-bank financial institution here?

The rule reaches the financial activities the Commission has identified as substantially engaged in lending, brokering, or servicing consumer loans; transferring or safeguarding money; preparing individual tax returns; providing credit advice; collecting debts; and kindred activities — in practice: mortgage brokers and non-bank lenders, loan servicers, payday and auto-title lenders, debt collectors, tax preparers, credit counselors, courier services moving money or checks, finders, and real-estate appraisers, among others. The definitional trap runs both ways: some fintechs assume GLBA applies to them and over-build against the wrong rule, while others that plainly service consumer loans assume it does not. The two exclusions to know: entities already subject to a functional regulator's equivalent regime are out, and purely incidental financial activity is out. A consumer-facing lending app's servicing operations are in; the same company's venture-backer relations are irrelevant to the analysis.

What must the written program contain?

The amended rule is unusually concrete for a program-level standard. A designated qualified individual owns the program, reporting to the board or equivalent at least annually. The risk assessment drives controls across nine elements, including access controls, inventory of systems and data, encryption at rest and in transit for customer information, secure development practices, multi-factor authentication for systems accessing it, logging and monitoring, and incident-response planning. Vendor selection with due diligence and contractual oversight is its own element — the rule names the provider relationship explicitly. Testing is annual at minimum, with penetration testing and vulnerability assessments on stated cadences for higher-risk footprints. The flexibilities are real but narrow: smaller institutions scale documentation, not duties.

How does the notification requirement work?

Since May 13, 2024, discovery of an event involving the unauthorized acquisition of unencrypted customer information of at least 500 consumers requires notice to the FTC through the Commission's designated form within 30 days of discovery. The report travels regardless of whether consumers themselves must be notified under state law — it is an independent federal duty, not a coordination step. The FTC posts reported events publicly, which converts the submission into a disclosure event with its own communications calculus. Below 500 consumers, or encrypted-but-key-compromised data, the federal duty does not trigger, though state breach statutes and contract duties may. "Discovery" is read as when the event was or reasonably should have been determined to be a breach — the same clock discipline incident-response teams know from state regimes, now with a federal counterparty.

Program elementAmended rule expectationCommon audit finding
Qualified individualNamed owner; annual board reportingTitle without authority or reporting path
Risk assessmentDocumented, current, driving controlsOne-time artifact, never refreshed
EncryptionCustomer info at rest and in transitExceptions undocumented
MFAFor systems accessing customer infoBreak-glass paths without MFA
Vendor oversightDiligence plus contractual termsDiligence filed, contracts silent
NotificationFTC form within 30 days at 500+ consumersState-law clock mistaken for the federal one

How does the rule interact with the state-law stack?

The Safeguards Rule is a security-program rule with a federal reporting tip; the state stack is a consumer-notification lattice plus, increasingly, its own program duties. The operational discipline is one incident, several clocks: the FTC's 30-day counter from discovery at the 500-consumer threshold; each state's timing and content rules where residents are affected; contractual notification duties to bank partners and vendors, which frequently run fastest of all. Programs that maintain a single incident-classification step — determining what data, how many consumers, encrypted or not, which residents — produce every clock's inputs at once. The classification artifact is also the exam answer when a partner bank asks why an event did or did not trigger their contract's notice.

The audit calendar deserves its own mention: the rule's annual testing expectation is where programs drift, because the first year's evidence is fresh and the third year's is folklore. A standing testing calendar — penetration test scope decisions, vulnerability-scan cadence, the qualified individual's report dates — keeps the program's age invisible to the file, which is the only place audit findings read age from.

How do bank partners enforce the rule?

Through flow-downs: partner banks read their own vendor guidance into fintech contracts, so the Safeguards program arrives as a contractual artifact — the qualified individual's role acknowledged, the annual report deliverable, the notification duty extended to the partner on a faster clock than the FTC's thirty days. Programs built to the federal floor usually clear partner diligence; programs built to partner clocks clear both.

What does this mean in practice?

The Safeguards Rule spent two decades as the quietest federal security regime; the 2023 program teeth and the 2024 reporting duty ended the quiet. For the non-bank financial sector it is now the floor — modest, named, and enforced by an agency that publishes what it learns.

What does an examiner ask for first under this rule?

The program document with its named qualified individual, the most recent risk assessment, testing evidence with dates, and the vendor-oversight file. Programs that produce the four without assembly time describe the rest of the conversation as substantive; the ones that begin by scheduling a document review have already written the finding's tone.

Frequently asked questions

Do crypto companies fall under the rule?

Only where their activities are financial in the GLBA sense — money transmission has drawn coverage arguments — and the analysis is activity-by-activity, not entity-level. A crypto exchange's custody of consumer assets raises different regimes; its money-transmission rails raise this one's questions.

Does encryption cure the notification duty?

Properly implemented encryption, with keys uncompromised, keeps an event outside the 500-consumer federal trigger. The rule's text and FAQs read acquisition of unreadable data as not the triggering event — which makes key-management documentation part of the notification defense.

Who is the qualified individual allowed to be?

An employee or a service provider, provided the designation and reporting path are real. What fails audit is the title without program authority — the named individual who learns of incidents last.

Frequently Asked Questions

Do crypto companies fall under the rule?
Only where their activities are financial in the GLBA sense, analyzed activity-by-activity. Custody of consumer assets raises different regimes; money-transmission rails raise this one's questions.
Does encryption cure the notification duty?
Properly implemented encryption with uncompromised keys keeps an event outside the 500-consumer federal trigger — which makes key-management documentation part of the notification defense.
Who is the qualified individual allowed to be?
An employee or a service provider, provided the designation and reporting path are real. What fails is the title without program authority — the named individual who learns of incidents last.