The Safeguards Rule Notification Amendment: How 16 CFR 314.4(j) Defines a Reportable Event
Key Takeaways
- Section 314.4(j) has been effective since May 13, 2024 and requires notice to the FTC no later than 30 days after discovery of a notification event involving at least 500 consumers.
- A notification event is defined in 314.2(m) as acquisition of unencrypted customer information without the individual's authorization; unauthorized access is presumed to be acquisition unless the institution has reliable evidence otherwise.
- The Commission dropped the proposed requirement that an institution assess whether misuse was likely, and lowered the proposed threshold from 1,000 consumers to 500.
- The 5,000-consumer exception in 314.6 lists 314.4(b)(1), (d)(2), (h) and (i); paragraph (j) is not among them.
- The reporting form states that a submitted report may be made public, and the adopting release says the Commission intends to enter reports into a publicly available database.
The Amendment to the Safeguards Rule
On November 13, 2023 the Federal Trade Commission published a final rule amending 16 CFR Part 314, the Safeguards Rule, to add a reporting obligation at § 314.4(j). The rest of Part 314 tells a covered financial institution what its information security program has to contain. Paragraph (j) is different in kind: it is the only provision in the part that requires the institution to tell the Commission something after an incident.
The final rule was published at 88 FR 77499 and, by the terms of the amended § 314.5, paragraph (j) took effect on May 13, 2024 — six months after publication, which the Commission had proposed as a deliberate runway. The FTC confirmed the date in a business blog post dated May 14, 2024.
The version adopted differs from the version proposed in two respects that change who has to file and when. The supplemental notice would have required an institution to determine, after becoming aware of a security event, whether misuse of customer information had occurred or was reasonably likely, and to report only if it had — and only above a 1,000-consumer floor. Neither survived.
What Counts as a Notification Event
The trigger sits in a definition rather than in the operative paragraph. Section 314.2(m) defines a notification event as the "acquisition of unencrypted customer information without the authorization of the individual to which the information pertains." Two clauses follow, and both do work:
- Information is treated as unencrypted "if the encryption key was accessed by an unauthorized person" — encryption is not a safe harbor where the key travelled with the data.
- "Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information." Access is presumed to be acquisition, and rebutting the presumption takes affirmative evidence.
The Commission explained in the adopting release why it moved the trigger off the misuse standard it had proposed. The term "misuse" was ambiguous — it was unclear whether acquisition alone counted, or whether alteration of data did — and the release states that the ambiguity "could have been used as an opportunity to circumvent the reporting requirement," because an institution assessing its own likelihood of misuse could underestimate it. The release also notes that the rebuttable presumption is borrowed from the Health Breach Notification Rule at 16 CFR 318.2(a), where the same sentence appears about personal health record information.
The consequence is that the determination an institution makes under the final rule is narrower than the one the proposal contemplated: whether unencrypted customer information was acquired, not whether anyone is likely to be hurt by it. "Customer information" is itself defined in § 314.2(d) as any record containing nonpublic personal information about a customer, in paper, electronic or other form, handled or maintained by the institution or on its behalf.
The Consumer Threshold
Paragraph (j)(1) applies where "the notification event involves the information of at least 500 consumers." The proposal had set that figure at 1,000. The Commission lowered it, reasoning in the adopting release that an event involving acquisition of unencrypted customer information affecting at least 500 consumers "is significant enough to warrant notification of the Commission, regardless of the size of the financial institution," and observing that several state breach-notification statutes use the same 500-person figure for regulator notice.
Section 314.6 is where the Safeguards Rule relieves small institutions of some obligations, and it is worth reading against paragraph (j). It provides that "§ 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." Paragraph (j) is not on that list. In the regulatory flexibility analysis the Commission stated it did not propose a small-entity exemption because the burden was minimal, and pointed to the 500-consumer floor itself as the mechanism that keeps the smallest institutions out of scope.
The Reporting Clock
Paragraph (j)(1) requires notice "as soon as possible, and no later than 30 days after discovery of the event." Paragraph (j)(2) then defines discovery, and the definition is broad: "A notification event shall be treated as discovered as of the first day on which such event is known to you," and an institution is "deemed to have knowledge of a notification event if such event is known to any person, other than the person committing the breach, who is your employee, officer, or other agent."
That is knowledge imputed from anyone in the organization other than the perpetrator, which places the start of the clock earlier than an escalation-based reading would. It is the same construction the FTC uses elsewhere in its breach rules, and it is the reason the 30 days is measured from awareness rather than from confirmation, containment or completion of an investigation.
What the Notice Must Contain
The notice is made electronically on a form on the FTC's website, and paragraph (j)(1) enumerates six items it must include:
- The name and contact information of the reporting financial institution;
- A description of the types of information involved in the notification event;
- The date or date range of the event, if it is possible to determine;
- The number of consumers affected or potentially affected;
- A general description of the notification event; and
- Whether a law enforcement official has provided a written determination that notifying the public would impede a criminal investigation or cause damage to national security, plus a means for the Commission to contact that official.
The Safeguards Rule Security Event Reporting Form tracks those items. It carries OMB control number 3084-0171, estimates five hours to complete, and permits third parties such as outside counsel or service providers to submit on an affected institution's behalf, including a single report covering multiple institutions.
The last of the six items is the delay mechanism. Under paragraph (j)(1)(vi), a law enforcement official may request an initial delay of up to 30 days from the date notice was given to the Commission, extendable by up to 60 further days on a written request, with anything beyond that available only if Commission staff determines that public disclosure continues to impede an investigation or damage national security. What is delayed is publication, not the report: the notice to the FTC is still filed on the 30-day clock.
Public Posting of Reported Events
The reporting form states plainly, twice, that "Your report may be made public," and gives a "Law Enforcement Delay Requested" checkbox for the case covered by paragraph (j)(1)(vi). The adopting release explains the design. Commenters had asked for a confidential reporting channel; the Commission declined, writing that reporting "provides a broader value to the general public," that the general level of detail required "will not compromise a financial institution's security posture going forward" and "cannot provide a meaningful roadmap for attackers," and that it "intends to enter notification event reports into a publicly available database."
That is the Commission's stated intent as recorded in the November 2023 release, and the form's language is consistent with it. This post does not report on the contents of any such database; nothing published by the Commission and retrievable at the time of writing sets out the reports filed to date.
Who the Rule Reaches
Paragraph (j) reaches exactly the institutions the rest of Part 314 reaches, which is a wider set than the phrase "financial institution" suggests. Section 314.2(h)(1) defines the term by reference to activities "financial in nature or incidental to such financial activities as described in section 4(k) of the Bank Holding Company Act of 1956," and covers any institution significantly engaged in them.
The definition then gives worked examples, and they are the useful part: a retailer that issues its own credit card, an automobile dealership that leases cars on a non-operating basis for more than 90 days, a personal property or real estate appraiser, a career counselor serving the finance industry, and a business that prints and sells checks are each identified in the rule text as financial institutions. The FTC's blog post lists thirteen categories named in the rule — among them mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions and investment advisers not required to register with the SEC — and states that even that list "isn't exhaustive."
Banks, federally insured credit unions and SEC-registered entities are outside the FTC's Safeguards Rule; the Gramm-Leach-Bliley Act allocates them to their own prudential regulators. The FTC's part is the residual category, and the reporting duty in paragraph (j) runs to that residual category alone.
Background
For the underlying law rather than this development: Financial Services privacy law.
Frequently Asked Questions
Does the Safeguards Rule notification requirement depend on whether consumers were harmed?
Are small financial institutions exempt from reporting to the FTC?
When does the 30-day clock start under 16 CFR 314.4(j)?
Is encrypted data covered by the reporting requirement?
Does a report filed with the FTC become public?
Sources
Everything above is reported from these documents. Follow them to verify.
- 16 CFR 314.4 — Elements, including the notification requirement at paragraph (j) (September 1, 2026) regulation
- 16 CFR 314.2 — Definitions, including "notification event" at paragraph (m) (September 1, 2026) regulation
- 16 CFR 314.6 — Exceptions for institutions under 5,000 consumers (September 1, 2026) regulation
- FTC final rule, Standards for Safeguarding Customer Information, 88 FR 77499 (November 13, 2023) regulation
- FTC Safeguards Rule Security Event Reporting Form (September 1, 2026) agency guidance
- FTC business blog, Safeguards Rule notification requirement now in effect (May 14, 2024) agency guidance
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.