GLBA Safeguards Rule
Amended United States (Federal) · In force May 23, 2003 · no upcoming deadlines
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Requires non-bank financial institutions under FTC jurisdiction to maintain a written information security program with a qualified individual, risk assessments, access controls, encryption, MFA, monitoring and board reporting. Since May 13, 2024, institutions must notify the FTC within 30 days of discovering a 'notification event' (unauthorized acquisition of unencrypted customer information) affecting at least 500 consumers.
- Who it applies to
- Financial institutions subject to FTC jurisdiction (e.g. mortgage brokers, lenders, auto dealers, tax preparers, payment and fintech companies, and other non-bank entities significantly engaged in financial activities). Certain program elements (written risk assessment, continuous monitoring/pen testing, incident response plan, annual board report) do not apply to institutions holding customer information on fewer than 5,000 consumers.
- Penalties
- The Rule itself carries no civil penalty; the FTC enforces through Section 5 of the FTC Act (injunctive orders), with civil penalties for violating resulting orders.
- Enforced by
- Federal Trade Commission
- Official name
- FTC Standards for Safeguarding Customer Information (Safeguards Rule), 16 CFR Part 314, under the Gramm-Leach-Bliley Act
- Citation
- 15 U.S.C. 6801(b), 6805(b)(2); 16 CFR Part 314; amendments at 86 FR 70272 (2021) and 88 FR 77499 (2023)
- Topics
- financial, cybersecurity, breach-notification, privacy
Research notes
Banks and credit unions follow the parallel Interagency Guidelines, not this Rule. FTC notices of notification events may be made public.
Related
Questions about GLBA Safeguards Rule
- What are the GLBA Safeguards Rule compliance deadlines?
- Jan 10, 2022: 2021 Safeguards Rule amendments effective. Jun 9, 2023: Compliance with expanded security program elements. May 13, 2024: FTC breach notification requirement effective.
- When does GLBA Safeguards Rule take effect?
- GLBA Safeguards Rule took effect on May 23, 2003.
- Who does GLBA Safeguards Rule apply to?
- Financial institutions subject to FTC jurisdiction (e.g. mortgage brokers, lenders, auto dealers, tax preparers, payment and fintech companies, and other non-bank entities significantly engaged in financial activities). Certain program elements (written risk assessment, continuous monitoring/pen testing, incident response plan, annual board report) do not apply to institutions holding customer information on fewer than 5,000 consumers.
- What are the penalties under GLBA Safeguards Rule?
- The Rule itself carries no civil penalty; the FTC enforces through Section 5 of the FTC Act (injunctive orders), with civil penalties for violating resulting orders.