The FTC's Standards for Safeguarding Customer Information, 16 CFR Part 314, requires non-bank financial institutions to run a written information-security program — risk assessment, designated qualified individual, encryption, multi-factor access controls, monitoring, and vendor oversight — with the amended rule's program obligations fully in force since June 5, 2023, and its breach-notification overlay effective May 13, 2024: discovery of a breach involving at least 500 consumers' unencrypted information triggers a report to the Commission within thirty days, and the FTC publishes what it receives. For fintechs outside the banking agencies' perimeter, this is the federal security regime that actually names them.
3G Times publishes information, not legal advice. Coverage and notification questions turn on an entity's GLBA status and the specific facts of an incident, and belong with counsel.
Who counts as a non-bank financial institution here?
The rule reaches the financial activities the Commission has identified as substantially engaged in lending, brokering, or servicing consumer loans; transferring or safeguarding money; preparing individual tax returns; providing credit advice; collecting debts; and kindred activities — in practice: mortgage brokers and non-bank lenders, loan servicers, payday and auto-title lenders, debt collectors, tax preparers, credit counselors, courier services moving money or checks, finders, and real-estate appraisers, among others. The definitional trap runs both ways: some fintechs assume GLBA applies to them and over-build against the wrong rule, while others that plainly service consumer loans assume it does not. The two exclusions to know: entities already subject to a functional regulator's equivalent regime are out, and purely incidental financial activity is out. A consumer-facing lending app's servicing operations are in; the same company's venture-backer relations are irrelevant to the analysis.
What must the written program contain?
The amended rule is unusually concrete for a program-level standard. A designated qualified individual owns the program, reporting to the board or equivalent at least annually. The risk assessment drives controls across nine elements, including access controls, inventory of systems and data, encryption at rest and in transit for customer information, secure development practices, multi-factor authentication for systems accessing it, logging and monitoring, and incident-response planning. Vendor selection with due diligence and contractual oversight is its own element — the rule names the provider relationship explicitly. Testing is annual at minimum, with penetration testing and vulnerability assessments on stated cadences for higher-risk footprints. The flexibilities are real but narrow: smaller institutions scale documentation, not duties.
How does the notification requirement work?
Since May 13, 2024, discovery of an event involving the unauthorized acquisition of unencrypted customer information of at least 500 consumers requires notice to the FTC through the Commission's designated form within 30 days of discovery. The report travels regardless of whether consumers themselves must be notified under state law — it is an independent federal duty, not a coordination step. The FTC posts reported events publicly, which converts the submission into a disclosure event with its own communications calculus. Below 500 consumers, or encrypted-but-key-compromised data, the federal duty does not trigger, though state breach statutes and contract duties may. "Discovery" is read as when the event was or reasonably should have been determined to be a breach — the same clock discipline incident-response teams know from state regimes, now with a federal counterparty.
| Program element | Amended rule expectation | Common audit finding |
|---|---|---|
| Qualified individual | Named owner; annual board reporting | Title without authority or reporting path |
| Risk assessment | Documented, current, driving controls | One-time artifact, never refreshed |
| Encryption | Customer info at rest and in transit | Exceptions undocumented |
| MFA | For systems accessing customer info | Break-glass paths without MFA |
| Vendor oversight | Diligence plus contractual terms | Diligence filed, contracts silent |
| Notification | FTC form within 30 days at 500+ consumers | State-law clock mistaken for the federal one |
How does the rule interact with the state-law stack?
The Safeguards Rule is a security-program rule with a federal reporting tip; the state stack is a consumer-notification lattice plus, increasingly, its own program duties. The operational discipline is one incident, several clocks: the FTC's 30-day counter from discovery at the 500-consumer threshold; each state's timing and content rules where residents are affected; contractual notification duties to bank partners and vendors, which frequently run fastest of all. Programs that maintain a single incident-classification step — determining what data, how many consumers, encrypted or not, which residents — produce every clock's inputs at once. The classification artifact is also the exam answer when a partner bank asks why an event did or did not trigger their contract's notice.
The audit calendar deserves its own mention: the rule's annual testing expectation is where programs drift, because the first year's evidence is fresh and the third year's is folklore. A standing testing calendar — penetration test scope decisions, vulnerability-scan cadence, the qualified individual's report dates — keeps the program's age invisible to the file, which is the only place audit findings read age from.
How do bank partners enforce the rule?
Through flow-downs: partner banks read their own vendor guidance into fintech contracts, so the Safeguards program arrives as a contractual artifact — the qualified individual's role acknowledged, the annual report deliverable, the notification duty extended to the partner on a faster clock than the FTC's thirty days. Programs built to the federal floor usually clear partner diligence; programs built to partner clocks clear both.
What does this mean in practice?
- Confirm GLBA status in writing, with reasoning. The coverage memo is the first document requested when an incident raises the question; deciding status during an incident is deciding it under stress.
- Rehearse the 30-day federal clock with the state clocks. The FTC form's inputs — consumer counts, data elements, encryption status — should be fields your classification template already produces.
- Treat vendor contracts as program artifacts. The rule's oversight element and your bank partners' flow-downs want the same clauses: notice, audit, cooperation.
- Watch the public-posting consequence. A filed report is a public document; the communications plan belongs in the incident-response annex, not in improvisation.
The Safeguards Rule spent two decades as the quietest federal security regime; the 2023 program teeth and the 2024 reporting duty ended the quiet. For the non-bank financial sector it is now the floor — modest, named, and enforced by an agency that publishes what it learns.
What does an examiner ask for first under this rule?
The program document with its named qualified individual, the most recent risk assessment, testing evidence with dates, and the vendor-oversight file. Programs that produce the four without assembly time describe the rest of the conversation as substantive; the ones that begin by scheduling a document review have already written the finding's tone.
Frequently asked questions
Do crypto companies fall under the rule?
Only where their activities are financial in the GLBA sense — money transmission has drawn coverage arguments — and the analysis is activity-by-activity, not entity-level. A crypto exchange's custody of consumer assets raises different regimes; its money-transmission rails raise this one's questions.
Does encryption cure the notification duty?
Properly implemented encryption, with keys uncompromised, keeps an event outside the 500-consumer federal trigger. The rule's text and FAQs read acquisition of unreadable data as not the triggering event — which makes key-management documentation part of the notification defense.
Who is the qualified individual allowed to be?
An employee or a service provider, provided the designation and reporting path are real. What fails audit is the title without program authority — the named individual who learns of incidents last.
For more context, read How to Document a Compliance Risk Assessment That Survives an OCC Examination.
For more context, read regulation e error resolution.
For more context, read ecoa adverse action notices ai.

