Framework Information Security & Privacy
FTC Safeguards/GLBA
The FTC Safeguards Rule (16 CFR Part 314) implements the Gramm-Leach-Bliley Act for financial institutions that are not supervised by a banking regulator: mortgage brokers and lenders, auto dealers that finance, payday and finance companies, tax preparers, collection agencies, check cashers, wire transfer services, credit counselors, investment advisers not registered with the SEC, and similar businesses.
The 2021 amendments, in force since June 9, 2023, turned the rule into a prescriptive program, and a further amendment effective May 13, 2024 added a requirement to notify the FTC within 30 days of discovering unauthorized access to unencrypted information of 500 or more consumers.
The rule is written-program heavy. A covered institution must designate a Qualified Individual, keep a written risk assessment, implement listed safeguards (access controls, encryption in transit and at rest, MFA, secure disposal, change management, activity logging), test and monitor them, train staff, oversee service providers by contract, keep a written incident response plan, and have the Qualified Individual report in writing to the board at least annually.
Institutions holding information on fewer than 5,000 consumers are exempt from some of the written elements.
Who has to comply
Financial institutions under FTC jurisdiction that hold customer information, meaning businesses significantly engaged in financial activities that are not banks, credit unions, SEC-registered advisers or other agency-supervised entities.
Institutions with information on fewer than 5,000 consumers are exempt from the written risk assessment, continuous monitoring or annual penetration testing, written incident response plan and annual board report requirements.
What the assessor asks to see
Designation of the Qualified Individual; written risk assessment; written information security program and policies; access control and MFA configuration; encryption evidence; data inventory and disposal schedule; change management records; logging and monitoring evidence; penetration test and vulnerability assessment reports; training records; service provider contracts and oversight records; written incident response plan; annual board report; notification event records.
Where the requirement sits: 16 CFR 314.4(a) qualified individual; (b) written risk assessment; (c) safeguards incl. (c)(5) MFA; (d) monitoring/testing; (e) training; (h) written IR plan; (i) annual board report
What AllyMatter does here
Authors, approves, versions and proves staff acknowledgment of the WISP, and holds the annual board report and IR plan under control.
AllyMatter publishes this site.
Assessors
Who assesses FTC Safeguards/GLBA
Government enforcement only. The FTC investigates and brings enforcement actions; there is no certification or third-party audit requirement. Institutions may commission independent assessments voluntarily or under a consent order.
No firm has claimed a FTC Safeguards/GLBA assessor listing yet. Claim yours →
Consultants
Who helps with FTC Safeguards/GLBA
Yes. IT security firms and compliance consultants serving auto dealers, mortgage brokers, tax practices and lenders offer Safeguards gap assessments, written program templates, virtual Qualified Individual services, MFA and encryption rollouts, and vendor oversight programs. Engagements are usually short, with an annual review cycle.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a FTC Safeguards/GLBA consultant listing yet. Claim yours →
Software
Tools for FTC Safeguards/GLBA
Tools that name this framework in their own material.
Related reading
- FTC strengthens GLBA information security requirements for non-bank financial institutionsExplains who counts as a financial institution and what the written information security program, qualified individual and board reporting duties mean.Davis Wright Tremaine
- Updates to the Safeguards Rule will require non-banking financial institutions to report data security breaches to the FTCCovers the notification amendment, the 30-day clock and the 500-consumer threshold that now sits on top of the program requirements.WilmerHale
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for FTC Safeguards/GLBA
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of FTC Safeguards/GLBA in AllyMatter
Approve the policies FTC Safeguards/GLBA asks for, keep every version, and record a named acknowledgment from each person who has to read them.