Skip to content

GLBA Safeguards Rule

Amended United States (Federal) · In force May 23, 2003 · no upcoming deadlines

Deadlines

DateWhat happens
Jan 10, 20222021 Safeguards Rule amendments effective4.7 years ago
Jun 9, 2023Compliance with expanded security program elements3.3 years ago
May 13, 2024FTC breach notification requirement effective2.4 years ago

Summaries for reference, not legal advice. Check the official text.

What it does

Requires non-bank financial institutions under FTC jurisdiction to maintain a written information security program with a qualified individual, risk assessments, access controls, encryption, MFA, monitoring and board reporting. Since May 13, 2024, institutions must notify the FTC within 30 days of discovering a 'notification event' (unauthorized acquisition of unencrypted customer information) affecting at least 500 consumers.

Who it applies to
Financial institutions subject to FTC jurisdiction (e.g. mortgage brokers, lenders, auto dealers, tax preparers, payment and fintech companies, and other non-bank entities significantly engaged in financial activities). Certain program elements (written risk assessment, continuous monitoring/pen testing, incident response plan, annual board report) do not apply to institutions holding customer information on fewer than 5,000 consumers.
Penalties
The Rule itself carries no civil penalty; the FTC enforces through Section 5 of the FTC Act (injunctive orders), with civil penalties for violating resulting orders.
Enforced by
Federal Trade Commission
Official name
FTC Standards for Safeguarding Customer Information (Safeguards Rule), 16 CFR Part 314, under the Gramm-Leach-Bliley Act
Citation
15 U.S.C. 6801(b), 6805(b)(2); 16 CFR Part 314; amendments at 86 FR 70272 (2021) and 88 FR 77499 (2023)
Topics
financial, cybersecurity, breach-notification, privacy
Research notes

Banks and credit unions follow the parallel Interagency Guidelines, not this Rule. FTC notices of notification events may be made public.

Related

Questions about GLBA Safeguards Rule
What are the GLBA Safeguards Rule compliance deadlines?
Jan 10, 2022: 2021 Safeguards Rule amendments effective. Jun 9, 2023: Compliance with expanded security program elements. May 13, 2024: FTC breach notification requirement effective.
When does GLBA Safeguards Rule take effect?
GLBA Safeguards Rule took effect on May 23, 2003.
Who does GLBA Safeguards Rule apply to?
Financial institutions subject to FTC jurisdiction (e.g. mortgage brokers, lenders, auto dealers, tax preparers, payment and fintech companies, and other non-bank entities significantly engaged in financial activities). Certain program elements (written risk assessment, continuous monitoring/pen testing, incident response plan, annual board report) do not apply to institutions holding customer information on fewer than 5,000 consumers.
What are the penalties under GLBA Safeguards Rule?
The Rule itself carries no civil penalty; the FTC enforces through Section 5 of the FTC Act (injunctive orders), with civil penalties for violating resulting orders.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.