Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Who Must Comply with the FTC Safeguards Rule? (You May Be Surprised)

July 14, 2026

The list of businesses that must comply with FTC Safeguards reaches well beyond Wall Street. The Gramm-Leach-Bliley Act (GLBA) is a 1999 US federal law. It requires financial institutions to explain how they share and protect customers’ nonpublic personal information.

For non-bank businesses, the FTC Safeguards Rule (16 CFR Part 314) implements GLBA’s data security requirements. The Privacy Rule handles the notice piece separately.

Traditional banks and credit unions are carved out. They answer to equivalent rules from the OCC, Federal Reserve, or FDIC. The FTC amended the Safeguards Rule in 2021; the key provisions became mandatory on June 9, 2023.

Does the FTC Safeguards Rule Apply to Banks? No — Here’s Why

Banks and credit unions are not covered by the FTC Safeguards Rule. They fall under equivalent data-security safeguards enforced by their own federal regulators:

  • National banks — Office of the Comptroller of the Currency (OCC)
  • Member banks — Federal Reserve
  • State-chartered banks — FDIC

The FTC’s jurisdiction specifically covers non-bank financial institutions. If you searched “are banks subject to FTC safeguards rule,” the answer is no. The businesses that must comply are the ones listed below.

Who Must Comply With FTC Safeguards: The Full List of Covered Entities

The FTC Safeguards Rule (16 CFR Part 314) requires non-bank financial institutions under FTC jurisdiction to develop, implement, and maintain a comprehensive written information security program.

Here is the full list of FTC safeguards rule covered entities:

Entity TypeWhy They’re Covered
Auto dealersDealerships that arrange financing or leasing for consumers
Mortgage brokers and lendersNon-bank lenders and brokers handling home loans
Tax preparersTax preparation firms handling sensitive income data
CPAs and accountantsAccountants and CPA firms providing financial or tax services
Payday and consumer lendersBusinesses offering short-term or personal loans
Finance companiesOrganizations financing retail purchases or providing consumer credit
Debt collectorsAgencies collecting past due consumer debts
Check cashersStorefronts cashing checks for a fee
Wire transferorsServices moving money electronically for consumers
Investment advisersAdvisers not required to register with the SEC
Real estate settlementServices handling escrow or title closing processes
Higher educationColleges and universities participating in federal student aid, specifically to protect that financial aid data

The Significantly Engaged Test

Regulators use a “significantly engaged” standard to decide who qualifies as a financial institution under GLBA. If your business is significantly engaged in providing financial products or services to consumers, assume you are covered until proven otherwise.

ScenarioSignificantly Engaged?Why
A local shop that occasionally lets a regular customer pay laterNoIncidental credit; financing is not a primary business activity
A retailer that routinely finances purchases or issues store creditYesFinancing is a major portion of revenue and a core part of the customer relationship

The test captures many standard retail and service businesses. You cannot claim you are simply a retail store if a major portion of your revenue comes from arranging customer financing.

Small Business Applicability and Exemptions

Many owners look for FTC Safeguards Rule exemptions based on size. The requirements for small businesses are close to those for large corporations, with one narrow exception.

16 CFR 314.6 provides a narrow exemption. If your business holds customer information on fewer than 5,000 consumers, you are excused from four obligations:

  • Written risk-assessment documentation
  • The continuous-monitoring and annual-penetration-testing schedule
  • The written incident response plan
  • The annual board report

Outside that carve-out, headcount and revenue do not exempt you. You must still build a security program.

Breach notification threshold: report to the FTC within 30 days of discovery if a security event involves the unencrypted information of 500 or more consumers, effective May 13, 2024.

What changes at each threshold:

Consumer Records HeldYour Obligations
Under 500Build the security program with encryption and access controls. The 30-day breach-reporting mandate does not apply.
500-4,999Must report qualifying breaches to the FTC within 30 days. The four Section 314.6 exemptions (risk assessment docs, pen-testing schedule, incident response plan, board report) still apply.
5,000+Full program required: written risk assessment, continuous monitoring or annual penetration testing, written incident response plan, annual board report — plus all baseline obligations.

If you are wondering who is exempt from FTC Safeguards Rule compliance entirely, the answer is almost no one who meets the definition of a covered financial institution.

What Compliance Requires Once You Are Covered

If you are on the covered-entity list, Section 314.4 requires nine elements:

  1. Designate a single Qualified Individual to implement and supervise the program.
  2. Base the program on a written risk assessment.
  3. Implement safeguards to protect customer information:
  • Access controls
  • A data inventory
  • Encryption of customer information at rest and in transit
  • Secure development practices
  • Multi-factor authentication for anyone accessing customer information
  • Secure disposal of customer information no longer needed
  • Change management procedures
  • Monitoring and logging of authorized user activity
  1. Regularly test the safeguards through continuous monitoring or annual penetration testing, plus vulnerability assessments at least every six months.
  2. Train staff on security awareness.
  3. Oversee service providers by contract and assessment.
  4. Keep the program current as the business changes.
  5. Maintain a written incident response plan.
  6. Have the Qualified Individual report in writing to the board or senior leadership at least annually.

The written information security program (WISP) is the core Safeguards Rule deliverable. It documents how the business protects customer information. It is built on the written risk assessment and covers safeguards, testing, training, vendor oversight, and incident response.

The Qualified Individual role. The QI is the single named person responsible for implementing and supervising the information security program. It can be an employee, or a person at an affiliate or service provider. Many covered SMBs designate a role supported by their MSP, but the business retains legal responsibility for compliance.

The amended Rule specifically requires encryption of customer information both at rest and in transit. It also mandates multi-factor authentication for any individual accessing any information system that holds customer information — unless the Qualified Individual approves in writing a reasonably equivalent control. Read the full requirements checklist to see exactly what this entails.

Vertical Deep-Dives

Certain industries face unique challenges when implementing these federal controls.

Does FTC Safeguards Rule apply to auto dealers? Yes, auto dealers that arrange financing or leasing are covered. Dealerships handle consumer credit applications, SSNs, and bank account data, making them frequent targets for cybercriminals. Read the auto-dealer deep dive to see how dealerships must lock down their networks.

Does FTC Safeguards Rule apply to CPA firms and tax preparers? Yes, tax preparation firms and accountants are covered. Handling consumer financial data for tax returns triggers the rule. Read the tax-preparer / CPA deep dive to understand your specific obligations.

See Where You Stand

Free 2-minute Safeguards Rule self-check: 8 plain-English questions, your risk level and the gaps to fix. No sign-up to see your result. free FTC Safeguards Rule checklist

Frequently Asked Questions

Does the FTC safeguards rule apply to banks?

No, traditional banks and credit unions are carved out of the FTC Safeguards Rule. They fall under equivalent safeguards enforced by other agencies like the OCC, the Federal Reserve, or the FDIC. The FTC rule specifically applies to non-bank financial institutions.

Who does the FTC Act apply to?

The FTC Act broadly applies to almost any business operating in commerce to prevent unfair or deceptive acts. Under the specific Safeguards Rule, the FTC jurisdiction covers non-bank financial institutions. This includes everyday businesses that are significantly engaged in providing financial products or services to consumers.

What does the FTC safeguards rule require all tax preparers to do?

Tax preparers must develop, implement, and maintain a comprehensive written information security program to protect customer information. This includes designating a Qualified Individual, conducting written risk assessments, and implementing technical controls like multi-factor authentication and encryption. They must also oversee their service providers and maintain an incident response plan.

What is the purpose of the FTC safeguards rule?

The purpose of the rule is to ensure that non-bank financial institutions protect the security and confidentiality of customer information. It forces businesses to build a formal cybersecurity program to prevent data breaches. The rule aims to stop identity theft and keep sensitive consumer financial data secure.

What kind of cases does the FTC handle?

The FTC handles cases involving consumer protection and antitrust issues. In the context of data security, the FTC investigates companies that fail to protect consumer information or violate the Safeguards Rule. They can bring enforcement actions, impose consent orders, and seek civil penalties against businesses that ignore these regulations.

What three criteria must be met for an act to be considered unfair under the FTC Act?

An act is considered unfair if it causes or is likely to cause substantial injury to consumers. Second, the injury must not be reasonably avoidable by consumers themselves. Third, the injury must not be outweighed by countervailing benefits to consumers or to competition.

Secure Your Business and Stay Compliant

Unlike PCI DSS, a contractual industry standard with no government enforcement, the Safeguards Rule is enforced directly by the federal government. The FTC can investigate, bring enforcement actions, impose consent orders with years of oversight obligations, and seek civil penalties.

Who we are. LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses since 2010.

What we do. We implement and operate the technical safeguards the rule requires: multi-factor authentication, encryption, continuous monitoring, testing, and incident response. We can also serve as or support your Qualified Individual role.

We help you become and stay compliant, though LeadingIT does not certify FTC compliance since no such certification exists. Learn more about LeadingIT’s FTC Safeguards compliance services (done-for-you path) to see how we can protect your business.

If you are ready to secure your data, book a call or contact us today.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.