Who Must Comply with the FTC Safeguards Rule? (You May Be Surprised)

The list of businesses that must comply with FTC Safeguards reaches well beyond Wall Street. The Gramm-Leach-Bliley Act (GLBA) is a 1999 US federal law. It requires financial institutions to explain how they share and protect customers’ nonpublic personal information.
For non-bank businesses, the FTC Safeguards Rule (16 CFR Part 314) implements GLBA’s data security requirements. The Privacy Rule handles the notice piece separately.
Traditional banks and credit unions are carved out. They answer to equivalent rules from the OCC, Federal Reserve, or FDIC. The FTC amended the Safeguards Rule in 2021; the key provisions became mandatory on June 9, 2023.
Does the FTC Safeguards Rule Apply to Banks? No — Here’s Why
Banks and credit unions are not covered by the FTC Safeguards Rule. They fall under equivalent data-security safeguards enforced by their own federal regulators:
- National banks — Office of the Comptroller of the Currency (OCC)
- Member banks — Federal Reserve
- State-chartered banks — FDIC
The FTC’s jurisdiction specifically covers non-bank financial institutions. If you searched “are banks subject to FTC safeguards rule,” the answer is no. The businesses that must comply are the ones listed below.
Who Must Comply With FTC Safeguards: The Full List of Covered Entities
The FTC Safeguards Rule (16 CFR Part 314) requires non-bank financial institutions under FTC jurisdiction to develop, implement, and maintain a comprehensive written information security program.
Here is the full list of FTC safeguards rule covered entities:
| Entity Type | Why They’re Covered |
|---|---|
| Auto dealers | Dealerships that arrange financing or leasing for consumers |
| Mortgage brokers and lenders | Non-bank lenders and brokers handling home loans |
| Tax preparers | Tax preparation firms handling sensitive income data |
| CPAs and accountants | Accountants and CPA firms providing financial or tax services |
| Payday and consumer lenders | Businesses offering short-term or personal loans |
| Finance companies | Organizations financing retail purchases or providing consumer credit |
| Debt collectors | Agencies collecting past due consumer debts |
| Check cashers | Storefronts cashing checks for a fee |
| Wire transferors | Services moving money electronically for consumers |
| Investment advisers | Advisers not required to register with the SEC |
| Real estate settlement | Services handling escrow or title closing processes |
| Higher education | Colleges and universities participating in federal student aid, specifically to protect that financial aid data |
The Significantly Engaged Test
Regulators use a “significantly engaged” standard to decide who qualifies as a financial institution under GLBA. If your business is significantly engaged in providing financial products or services to consumers, assume you are covered until proven otherwise.
| Scenario | Significantly Engaged? | Why |
|---|---|---|
| A local shop that occasionally lets a regular customer pay later | No | Incidental credit; financing is not a primary business activity |
| A retailer that routinely finances purchases or issues store credit | Yes | Financing is a major portion of revenue and a core part of the customer relationship |
The test captures many standard retail and service businesses. You cannot claim you are simply a retail store if a major portion of your revenue comes from arranging customer financing.
Small Business Applicability and Exemptions
Many owners look for FTC Safeguards Rule exemptions based on size. The requirements for small businesses are close to those for large corporations, with one narrow exception.
16 CFR 314.6 provides a narrow exemption. If your business holds customer information on fewer than 5,000 consumers, you are excused from four obligations:
- Written risk-assessment documentation
- The continuous-monitoring and annual-penetration-testing schedule
- The written incident response plan
- The annual board report
Outside that carve-out, headcount and revenue do not exempt you. You must still build a security program.
Breach notification threshold: report to the FTC within 30 days of discovery if a security event involves the unencrypted information of 500 or more consumers, effective May 13, 2024.

What changes at each threshold:
| Consumer Records Held | Your Obligations |
|---|---|
| Under 500 | Build the security program with encryption and access controls. The 30-day breach-reporting mandate does not apply. |
| 500-4,999 | Must report qualifying breaches to the FTC within 30 days. The four Section 314.6 exemptions (risk assessment docs, pen-testing schedule, incident response plan, board report) still apply. |
| 5,000+ | Full program required: written risk assessment, continuous monitoring or annual penetration testing, written incident response plan, annual board report — plus all baseline obligations. |
If you are wondering who is exempt from FTC Safeguards Rule compliance entirely, the answer is almost no one who meets the definition of a covered financial institution.
What Compliance Requires Once You Are Covered
If you are on the covered-entity list, Section 314.4 requires nine elements:
- Designate a single Qualified Individual to implement and supervise the program.
- Base the program on a written risk assessment.
- Implement safeguards to protect customer information:
- Access controls
- A data inventory
- Encryption of customer information at rest and in transit
- Secure development practices
- Multi-factor authentication for anyone accessing customer information
- Secure disposal of customer information no longer needed
- Change management procedures
- Monitoring and logging of authorized user activity
- Regularly test the safeguards through continuous monitoring or annual penetration testing, plus vulnerability assessments at least every six months.
- Train staff on security awareness.
- Oversee service providers by contract and assessment.
- Keep the program current as the business changes.
- Maintain a written incident response plan.
- Have the Qualified Individual report in writing to the board or senior leadership at least annually.
The written information security program (WISP) is the core Safeguards Rule deliverable. It documents how the business protects customer information. It is built on the written risk assessment and covers safeguards, testing, training, vendor oversight, and incident response.
The Qualified Individual role. The QI is the single named person responsible for implementing and supervising the information security program. It can be an employee, or a person at an affiliate or service provider. Many covered SMBs designate a role supported by their MSP, but the business retains legal responsibility for compliance.
The amended Rule specifically requires encryption of customer information both at rest and in transit. It also mandates multi-factor authentication for any individual accessing any information system that holds customer information — unless the Qualified Individual approves in writing a reasonably equivalent control. Read the full requirements checklist to see exactly what this entails.
Vertical Deep-Dives
Certain industries face unique challenges when implementing these federal controls.
Does FTC Safeguards Rule apply to auto dealers? Yes, auto dealers that arrange financing or leasing are covered. Dealerships handle consumer credit applications, SSNs, and bank account data, making them frequent targets for cybercriminals. Read the auto-dealer deep dive to see how dealerships must lock down their networks.
Does FTC Safeguards Rule apply to CPA firms and tax preparers? Yes, tax preparation firms and accountants are covered. Handling consumer financial data for tax returns triggers the rule. Read the tax-preparer / CPA deep dive to understand your specific obligations.
See Where You Stand
Free 2-minute Safeguards Rule self-check: 8 plain-English questions, your risk level and the gaps to fix. No sign-up to see your result. free FTC Safeguards Rule checklist
Related Guides
- What Is the Gramm-Leach-Bliley Act (GLBA)? Plain English
- FTC Safeguards Rule for Auto Dealers: What Dealerships Must Do
- FTC Safeguards Rule for Tax Preparers and CPA Firms
- GLBA / FTC Safeguards Rule Requirements: The 9 Elements
Frequently Asked Questions
Does the FTC safeguards rule apply to banks?
No, traditional banks and credit unions are carved out of the FTC Safeguards Rule. They fall under equivalent safeguards enforced by other agencies like the OCC, the Federal Reserve, or the FDIC. The FTC rule specifically applies to non-bank financial institutions.
Who does the FTC Act apply to?
The FTC Act broadly applies to almost any business operating in commerce to prevent unfair or deceptive acts. Under the specific Safeguards Rule, the FTC jurisdiction covers non-bank financial institutions. This includes everyday businesses that are significantly engaged in providing financial products or services to consumers.
What does the FTC safeguards rule require all tax preparers to do?
Tax preparers must develop, implement, and maintain a comprehensive written information security program to protect customer information. This includes designating a Qualified Individual, conducting written risk assessments, and implementing technical controls like multi-factor authentication and encryption. They must also oversee their service providers and maintain an incident response plan.
What is the purpose of the FTC safeguards rule?
The purpose of the rule is to ensure that non-bank financial institutions protect the security and confidentiality of customer information. It forces businesses to build a formal cybersecurity program to prevent data breaches. The rule aims to stop identity theft and keep sensitive consumer financial data secure.
What kind of cases does the FTC handle?
The FTC handles cases involving consumer protection and antitrust issues. In the context of data security, the FTC investigates companies that fail to protect consumer information or violate the Safeguards Rule. They can bring enforcement actions, impose consent orders, and seek civil penalties against businesses that ignore these regulations.
What three criteria must be met for an act to be considered unfair under the FTC Act?
An act is considered unfair if it causes or is likely to cause substantial injury to consumers. Second, the injury must not be reasonably avoidable by consumers themselves. Third, the injury must not be outweighed by countervailing benefits to consumers or to competition.
Secure Your Business and Stay Compliant
Unlike PCI DSS, a contractual industry standard with no government enforcement, the Safeguards Rule is enforced directly by the federal government. The FTC can investigate, bring enforcement actions, impose consent orders with years of oversight obligations, and seek civil penalties.
Who we are. LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses since 2010.
What we do. We implement and operate the technical safeguards the rule requires: multi-factor authentication, encryption, continuous monitoring, testing, and incident response. We can also serve as or support your Qualified Individual role.
We help you become and stay compliant, though LeadingIT does not certify FTC compliance since no such certification exists. Learn more about LeadingIT’s FTC Safeguards compliance services (done-for-you path) to see how we can protect your business.
If you are ready to secure your data, book a call or contact us today.
