Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

The FTC Safeguards Rule Explained: What It Is and Whether It Applies to You

July 14, 2026

The FTC Safeguards Rule (16 CFR Part 314) requires non-bank financial institutions under FTC jurisdiction to develop, implement, and maintain a comprehensive written information security program to protect customer information. If you run a Chicagoland business that handles consumer financial data, this regulation dictates exactly how your IT systems must be secured. It is a strict federal mandate, not a set of optional best practices.

Historically, many business owners ignored federal cybersecurity regulations because they assumed the rules only applied to massive banks. That is no longer true. Today, you are likely hearing about these requirements from your auto dealer association, your tax software vendor, or your cyber insurance provider. They are asking for proof of compliance because the regulatory environment has shifted.

At the center of the regulation is the requirement to build a customer information security program. You cannot rely on basic antivirus software anymore. The core deliverable is your written information security program (WISP), the blueprint for your compliance that details risk assessments, technical controls, and incident response strategies. This guide translates the standards for safeguarding customer information into plain English so you know exactly what to do next.

Key Takeaways

  • The FTC Safeguards Rule (16 CFR Part 314) requires non-bank financial institutions under FTC jurisdiction to build, implement, and maintain a written information security program (WISP) that protects customer information.
  • It grew out of the 1999 Gramm-Leach-Bliley Act (GLBA) and is enforced directly by the FTC. There is no official certification for this regulation, only ongoing compliance.
  • Coverage is broader than most owners assume: auto dealers, mortgage brokers, non-bank lenders, tax preparers, accountants, debt collectors, and several other non-bank business types are all covered.
  • The 2021 amendments added specific technical requirements, including encryption and multi-factor authentication, and those key provisions became mandatory on June 9, 2023.
  • A breach notification requirement took effect May 13, 2024: businesses must report breaches involving 500 or more consumers’ unencrypted information to the FTC within 30 days of discovery.

Where it Comes From and Who Enforces it

To understand your obligations, start with the law itself. The Gramm-Leach-Bliley Act (GLBA), a 1999 US federal law, requires financial institutions to explain how they share and protect customers’ nonpublic personal information. The GLBA’s privacy notice requirements fall under the Privacy Rule; its data security piece is implemented for non-bank businesses by the FTC directly. (If you need a refresher, we explain the GLBA in plain English.)

Unlike voluntary frameworks such as PCI DSS, which the U.S. government has no involvement in enforcing, the Safeguards Rule is enforced directly by the federal government. The FTC has direct jurisdiction over your business. If you ignore the mandate or suffer a breach because you failed to implement the required controls, you face severe penalties.

The FTC can investigate your operations and seek civil penalties or impose consent orders that subject your business to years of mandatory federal oversight.

It is also important to understand that compliance is an operational reality. LeadingIT helps you become and stay compliant, but we do not certify your business. You are either actively maintaining the required technical controls or you are operating out of compliance and carrying the legal risk.

Who Must Comply

The regulation covers non-bank financial institutions as the FTC defines them. This specific definition surprises many business owners because it includes companies that never consider themselves part of the financial sector. If your business is significantly engaged in providing financial products or services to consumers, assume you are covered until proven otherwise.

The list of covered entities is broad. The table below breaks it down by category, why each one is covered, and the specific business types named in the rule.

Business TypeWhy it’s CoveredExamples
Auto and vehicle financingArranges financing or leasing for customersAuto dealers
Lenders and finance companiesProvide consumer financing, credit, or lending servicesMortgage brokers, non-bank lenders, payday lenders, consumer lenders, general finance companies
Tax and accounting firmsHandle sensitive taxpayer data. The FTC Safeguards Rule for tax preparers mandates the same strict technical controls as it does for large finance companies.Tax preparation firms, accountants, CPA firms
Financial transaction and advisory servicesHandle consumer financial transactions or provide advisory services outside SEC oversightDebt collectors, check cashers, wire transferors, investment advisers not required to register with the SEC
Real estate settlement servicesHandle consumer financial data in real estate transactionsReal estate settlement providers
Higher education (aid data only)Participate in federal student aid programs, specifically regarding that aid dataColleges and universities

If you operate in any of these spaces, non-banking financial institution data security is your legal responsibility. If you are unsure whether your specific operations trigger the requirements, review our complete breakdown of who must comply.

FTC Safeguards Rule Changes: 2021 Amendments and 2024 Breach Notification

The regulatory landscape shifted dramatically a few years ago. The FTC amended the Safeguards Rule in 2021 to remove outdated language and replace general suggestions with highly specific it requirements. The 2021 amendments made it clear exactly what technical controls a business must deploy, and those prescriptive provisions became mandatory on June 9, 2023.

The GLBA safeguards rule update forced thousands of businesses to overhaul their IT environments. You can no longer claim that a simple firewall constitutes reasonable security. The amendments mandate modern cybersecurity architecture.

More recently, the FTC added a strict breach notification requirement. Effective May 13, 2024, covered businesses must report security events directly to the FTC. If your business discovers an event involving unencrypted information of 500 or more consumers, you must report it within 30 days of discovery. Missing this window drastically increases your legal liability.

FTC Safeguards Rule Changes: 2021 Amendments and 2024 Breach Notification,  GLBA 1999 timeline

The Nine Required Elements at a Glance

If you are looking for an FTC Safeguards Rule checklist, Section 314.4 of the regulation outlines exactly what your business must do to achieve compliance. These are the nine requirements you must implement and maintain.

  1. Designate a Qualified Individual. You must name a specific person to implement and supervise your information security program. This person can be an internal employee, or someone at an affiliate or service provider. Many covered businesses designate a role supported by their managed IT provider to ensure technical accuracy. However, your business always retains ultimate legal responsibility for compliance.
  2. Base the program on a written risk assessment. You cannot build a security program on assumptions. Your defenses must be based on a formal risk assessment. This written document must identify the specific internal and external threats to your customer data and evaluate how effectively your current technical controls mitigate those threats.
  3. Implement specific technical safeguards. The regulation lists exact controls you must deploy: strict access controls, a detailed data inventory, and secure development practices. The amended rule specifically requires encryption for all customer information both at rest and in transit. It also mandates multi-factor authentication for anyone accessing any system that holds customer information. You must also implement secure disposal procedures, enforce change management policies, and actively monitor authorized user activity.
  4. Regularly test your safeguards. You must prove that your technical defenses actually work. The regulation requires continuous monitoring of your systems. If you do not use continuous monitoring, you must perform annual penetration testing along with vulnerability assessments at least every six months.
  5. Train your staff on security awareness. Human error is a massive vulnerability. You must provide ongoing security awareness training to your employees so they understand how to handle sensitive financial data and how to identify phishing attempts or social engineering attacks.
  6. Oversee your service providers. You cannot outsource your compliance risk. You must oversee your service providers by contract and assessment. Your vendor agreements must explicitly require them to maintain appropriate security measures, and you must periodically assess their security posture to confirm they are actually protecting your data.
  7. Keep the program current. Your written information security program is a living document. As your business operations change or as new cyber threats emerge, you must update your security program. (If you need help structuring this documentation, read the WISP guide.)
  8. Maintain a written incident response plan. You must have a formal documented plan that details exactly how your business will respond to a security event. This plan must outline internal roles, communication strategies, and the exact steps you will take to meet the 30-day breach reporting window.
  9. Report to leadership annually. The Qualified Individual must report in writing to your board of directors or senior leadership at least once a year. This report must detail the overall status of the information security program and highlight any material matters related to your compliance efforts.

Nine required elements, one written program. Score yourself against each one before you talk to anyone about compliance.

See Where You Stand

Free 2-minute Safeguards Rule self-check: 8 plain-English questions, your risk level and the gaps to fix. No sign-up to see your result. free Safeguards Rule compliance self-assessment

Frequently Asked Questions

What is the FTC safeguards rule for auto dealers?

Auto dealers that arrange financing or leasing for customers are classified as financial institutions under FTC jurisdiction. This means dealerships must implement a comprehensive written information security program to protect consumer financial data. Dealerships must deploy specific controls like multi-factor authentication, encrypt customer data, and appoint a Qualified Individual to oversee their IT security.

What does the FTC safeguards rule require all tax preparers to do?

Tax preparation firms handle massive amounts of nonpublic personal information, making them covered entities under the regulation. Tax preparers must write and maintain a formal information security program based on a written risk assessment. They are required to encrypt taxpayer data, enforce multi-factor authentication for system access, and train their staff on security awareness.

Does the FTC safeguards rule apply to banks?

No, the FTC Safeguards Rule specifically applies to non-bank financial institutions under the jurisdiction of the Federal Trade Commission. Traditional banks are governed by federal banking regulators such as the FDIC or the OCC, while credit unions are regulated by the National Credit Union Administration. However, the underlying Gramm-Leach-Bliley Act applies to both banks and non-bank financial institutions.

What is the major requirement of the safeguards rule?

The primary requirement is that covered businesses must develop, implement, and maintain a comprehensive written information security program. This program must be built on a formal risk assessment and must include specific technical controls like encryption and multi-factor authentication. It also requires businesses to actively test their defenses and oversee their service providers.

What is the goal of the FTC safeguards rule?

The goal of the regulation is to ensure that non-bank financial institutions keep consumer financial data secure and confidential. It forces businesses to move away from reactive it practices and adopt modern, proactive cybersecurity measures. By mandating specific technical controls and breach reporting, the FTC aims to protect consumers from identity theft and financial fraud.

Next Steps for Your Business

LeadingIT is a Chicagoland managed it and cybersecurity provider. We have helped Illinois businesses since 2010 and currently serve roughly 200 organizations and over 2,500 users from our offices in Woodstock and Manteno.

We implement and operate every technical safeguard the rule requires: MFA, encryption, continuous monitoring, security testing, and incident response. We can also serve as or support your Qualified Individual role to ensure your technical controls meet federal standards.

If you need an experienced partner to manage these strict requirements, explore LeadingIT’s FTC Safeguards compliance services (done-for-you path). You can book a call to discuss your current it setup, or contact us at 815-788-6041 to get started.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.