The GLBA Safeguards Rule: What 16 CFR Part 314 Requires, and of Whom
Key Takeaways
- The FTC's Safeguards Rule reaches entities that are “significantly engaged” in an activity financial in nature under section 4(k) of the Bank Holding Company Act. The rule text names tax preparation firms, travel agencies operated in connection with financial services, collection agencies, check cashers and career counselors among them.
- Section 314.4 enumerates nine lettered elements, from (a) through (j). Encryption of customer information in transit and at rest, multi-factor authentication and annual penetration testing are written into the text rather than left to a reasonableness standard.
- Section 314.6 exempts institutions holding customer information on fewer than 5,000 consumers from four specific obligations — the written risk assessment, continuous monitoring or periodic testing, the written incident response plan and the annual report — and from nothing else.
- Since May 13, 2024, section 314.4(j) has required notice to the FTC no later than 30 days after discovering a notification event involving at least 500 consumers.
- State comprehensive privacy statutes exempt GLBA in two incompatible ways: Virginia exempts the institution, California exempts only the regulated data.
Who Is a Financial Institution
The Gramm-Leach-Bliley Act directs financial regulators to set standards for safeguarding customer records, and 15 U.S.C. 6805 divides the job among them: the federal banking agencies for banks and savings associations, the National Credit Union Administration for federally insured credit unions, the Securities and Exchange Commission for brokers, dealers and registered investment advisers, state insurance authorities for insurers, and the Federal Trade Commission for everyone else. The FTC's rule, at 16 CFR Part 314, is the residual category, and it is the one that catches businesses that do not think of themselves as financial at all.
The coverage test in 314.1(b) borrows its definition from banking law rather than writing a new one. An entity is a financial institution if its business is engaging in an activity financial in nature or incidental to such activity, as described in section 4(k) of the Bank Holding Company Act of 1956, which in turn incorporates the activities the Federal Reserve Board enumerated at 12 CFR 225.28 and 225.86. Section 314.2(h)(1) adds a threshold: an institution significantly engaged in those activities is a financial institution.
The rule then does something unusual for a regulation of this kind and lists examples. Section 314.1(b) names mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, travel agencies operated in connection with financial services, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, investment advisers not required to register with the SEC, and entities acting as finders. Section 314.2(h)(2) works through more: a retailer that issues its own proprietary credit card, a dealership that leases automobiles on a non-operating basis for longer than 90 days, a property appraiser, a business that prints and sells checks.
The negative examples in 314.2(h)(4) draw the line from the other side. A retailer whose only credit arrangements are occasional layaway and deferred payment plans is not a financial institution. Neither is a merchant that lets a customer run a tab, nor a grocery store that cashes checks for the people it sells groceries to. The distinction the rule is drawing is between entities significantly engaged in a financial activity and entities that merely brush against one.
One provision in 314.1(b) extends the reach further than the coverage test alone would suggest: the part applies to all customer information in an institution's possession, whether or not it pertains to that institution's own customers, and expressly including the customers of other financial institutions that provided the information.
The Privacy Rule and Annual Notices
The Safeguards Rule is often discussed as though it were the whole of GLBA's obligations on a non-bank business. It is not, and the division between the security rule and the privacy rule has moved since the statute was enacted.
The statute at 15 U.S.C. 6803 requires a financial institution to disclose its privacy policy at the time a customer relationship is established and not less than annually while it continues, and 15 U.S.C. 6802(a) conditions disclosure of nonpublic personal information to a nonaffiliated third party on notice and an opportunity to direct that the sharing not occur. The Dodd-Frank Act moved most of the rulewriting for those duties to the Consumer Financial Protection Bureau, which codified them at 12 CFR Part 1016 as Regulation P.
What remains of the FTC's privacy rule at 16 CFR Part 313 is now narrow. Section 313.1(b) states that the part applies to persons described in 12 U.S.C. 5519 that are predominantly engaged in the sale and servicing, or the leasing and servicing, of motor vehicles. The result is a split worth stating plainly: for most non-bank financial institutions the security obligations sit with the FTC under Part 314 while the privacy notice obligations sit with the CFPB under Regulation P.
Regulation P at 12 CFR 1016.5(a)(1) states the annual notice rule and defines annually as at least once in any period of 12 consecutive months during the relationship. Section 1016.5(e), added after the FAST Act, removes the annual notice obligation for an institution that shares nonpublic personal information only within the statutory exceptions at 1016.13, 1016.14 and 1016.15 and has not changed the practices described in its most recent notice. Section 1016.5(e)(2)(ii) sets a 100-day deadline for resuming annual notices where a change in practice ends the exception without triggering a revised notice.
The Safeguards Rule Elements
Section 314.3(a) states the general obligation: a comprehensive written information security program containing administrative, technical and physical safeguards appropriate to the institution's size and complexity, the nature and scope of its activities, and the sensitivity of the customer information at issue. Section 314.3(b) restates the three statutory objectives from section 501(b) — insuring security and confidentiality, protecting against anticipated threats, and protecting against unauthorized access or use that could result in substantial harm or inconvenience.
The operative detail is at 314.4, which enumerates the elements in lettered paragraphs (a) through (j). The 2021 amendment, at 86 FR 70307, is what converted this section from a short statement of objectives into a specified list, and several of its entries name a technology or a cadence rather than a standard of care:
- 314.4(c)(3) — encryption of all customer information held or transmitted, both in transit over external networks and at rest, with alternative compensating controls permitted only where encryption is infeasible and the alternative is reviewed and approved in writing by the Qualified Individual.
- 314.4(c)(5) — multi-factor authentication for any individual accessing any information system, unless the Qualified Individual has approved in writing reasonably equivalent or more secure access controls. Section 314.2(k) defines the factors as knowledge, possession and inherence.
- 314.4(c)(6)(i) — secure disposal procedures for customer information no later than two years after its last use in connection with providing a product or service, subject to exceptions for business necessity and legal retention.
- 314.4(d)(2) — continuous monitoring, or in its absence annual penetration testing and vulnerability assessments at least every six months and after material changes.
- 314.4(e) — security awareness training updated to reflect the risks the risk assessment identifies, and verification that key security personnel maintain current knowledge of changing threats.
Section 314.6 then withdraws four of these from institutions that maintain customer information concerning fewer than 5,000 consumers: the written risk assessment at 314.4(b)(1), the monitoring and testing regime at 314.4(d)(2), the written incident response plan at 314.4(h) and the annual report at 314.4(i). The exemption is drawn to those four paragraphs. Encryption, multi-factor authentication, access controls, vendor oversight and the notification duty carry no headcount threshold.
Qualified Individual and Written Program
Section 314.4(a) requires the designation of a single qualified individual responsible for overseeing, implementing and enforcing the information security program, a role the rule capitalizes as the Qualified Individual. The paragraph permits that person to be employed by the institution, an affiliate or a service provider.
Where the role is filled from outside, 314.4(a)(1) through (3) attach three conditions: the institution retains responsibility for compliance, designates a senior member of its own personnel responsible for direction and oversight of the Qualified Individual, and requires the service provider or affiliate to maintain an information security program that protects the institution in accordance with the part. The structure allows the function to be outsourced while keeping accountability for it in place.
Section 314.4(i) gives the role a reporting line. The Qualified Individual reports in writing, regularly and at least annually, to the board of directors or equivalent governing body, or where none exists to a senior officer responsible for the program. The paragraph specifies the contents: the overall status of the program and compliance with the part, and material matters including risk assessment, risk management and control decisions, service provider arrangements, testing results, security events or violations and management's responses, and recommendations for changes.
Risk Assessment and Access Controls
Section 314.4(b) requires the program to be based on a risk assessment identifying reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information, and assessing the sufficiency of the safeguards in place to control them.
Paragraph (b)(1) requires that the assessment be written and specifies three contents: criteria for evaluating and categorizing identified risks or threats, criteria for assessing the confidentiality, integrity and availability of information systems and customer information including the adequacy of existing controls, and requirements describing how identified risks will be mitigated or accepted and how the program will address them. Paragraph (b)(2) requires periodic reassessment.
The safeguards that follow are tied back to that assessment by 314.4(c), which requires designing and implementing safeguards to control the risks identified through it. Access controls under (c)(1) carry two distinct requirements: authenticating and permitting access only to authorized users, and limiting authorized users to the customer information they need to perform their duties. Paragraph (c)(8) adds logging and monitoring of authorized user activity to detect unauthorized access, use or tampering — a control aimed at the authorized insider rather than the external intruder.
Vendor Oversight
Section 314.2(r) defines a service provider as any person or entity that receives, maintains, processes or is otherwise permitted access to customer information through providing services directly to a covered financial institution. Section 314.4(f) sets three obligations toward them: taking reasonable steps to select and retain providers capable of maintaining appropriate safeguards, requiring those safeguards by contract, and periodically assessing providers based on the risk they present and the continued adequacy of their safeguards.
The FTC's most fully documented Safeguards Rule enforcement action turns on precisely this paragraph. In its December 2020 complaint against Ascension Data & Analytics, LLC, a mortgage industry data analytics firm, the Commission alleged that a vendor engaged to perform text recognition scanning on mortgage documents stored their contents on a cloud-based server in plain text, without a password or encryption, and that the server was accessed dozens of times. The documents were alleged to contain names, dates of birth, Social Security numbers, loan information, credit and debit account numbers, driver's license numbers and credit files.
The Commission's allegations were that Ascension failed to adequately vet that vendor and others, that its vendor contracts did not require safeguarding the information, and that it failed to conduct risk assessments of all its third-party vendors. The settlement, finalized in December 2021, required a comprehensive data security program, biennial assessments by an independent organization, annual certification by a senior executive, and reporting of future breaches to the Commission within 10 days of notifying other federal or state agencies. The action was brought under the Safeguards Rule as it stood before the 2021 amendment; the vendor oversight paragraph it turned on survives at 314.4(f).
Incident Response and the Reporting Requirement
Section 314.4(h) requires a written incident response plan designed to promptly respond to and recover from a security event materially affecting the confidentiality, integrity or availability of customer information. The paragraph enumerates seven areas the plan addresses: its goals, internal response processes, clear roles and decision-making authority, external and internal communications, requirements for remediating identified weaknesses, documentation and reporting of security events, and evaluation and revision of the plan after an event.
The reporting duty is separate, and it is newer. Section 314.4(j), added by the 2023 amendment at 88 FR 77508, requires notice to the Federal Trade Commission upon discovery of a notification event involving the information of at least 500 consumers, as soon as possible and no later than 30 days after discovery, on an electronic form on the FTC's website. Section 314.5 makes that paragraph effective as of May 13, 2024.
Two definitions do most of the work. Section 314.2(m) defines a notification event as acquisition of unencrypted customer information without the authorization of the individual it pertains to, treats information as unencrypted where the encryption key was accessed by an unauthorized person, and — the provision that widens the trigger — presumes unauthorized acquisition from unauthorized access unless there is reliable evidence that acquisition has not occurred and could not reasonably have occurred. Section 314.4(j)(2) treats an event as discovered on the first day it is known to any employee, officer or agent other than the person committing the breach.
The notice content is specified at 314.4(j)(1)(i) through (vi): the reporting institution's name and contact information, the types of information involved, the date or date range if determinable, the number of consumers affected or potentially affected, a general description of the event, and whether a law enforcement official has provided a written determination that public notice would impede a criminal investigation or damage national security. That last item carries its own timetable — an initial delay of up to 30 days at law enforcement request, extendable in writing by up to 60 more, with further delay only if Commission staff determines disclosure continues to impede an investigation.
Overlap With State Privacy Laws
State comprehensive privacy statutes almost all carve out GLBA, but they do not carve it out the same way, and the difference decides how much of a financial institution's data the state law still reaches.
Virginia's Consumer Data Protection Act takes the entity-level approach. Section 59.1-576(B) states that the chapter does not apply to any financial institution or data subject to Title V of the Gramm-Leach-Bliley Act. A business that qualifies as a financial institution is outside the statute as an institution, whatever data is at issue.
California takes the data-level approach. Civil Code section 1798.145(e) provides that the title does not apply to personal information collected, processed, sold or disclosed subject to GLBA and its implementing regulations, or to the California Financial Information Privacy Act — and then adds that the subdivision does not apply to section 1798.150, the private right of action for breaches. Personal information a covered institution holds that falls outside GLBA's scope, such as information about job applicants or website visitors who never became consumers of a financial product, is not exempted by that subdivision, and the breach cause of action is preserved regardless.
The two approaches produce different answers for the same company on the same facts, which is why the exemption's wording rather than its existence is the operative detail. This guide does not chart the exemption style of every state comprehensive statute; only Virginia and California are described here, from the statutory text of each, and the pattern in the remaining states is not inferred from those two.
Background
For the underlying law rather than this development: Financial Services privacy law.
Frequently Asked Questions
Does the FTC Safeguards Rule apply to a company that is not a bank?
What does the 5,000-consumer exemption in section 314.6 actually remove?
When does the 30-day clock for notifying the FTC start?
Can the Qualified Individual be someone outside the company?
Is a privacy notice still an FTC obligation under GLBA?
Sources
Everything above is reported from these documents. Follow them to verify.
- 16 CFR Part 314 — Standards for Safeguarding Customer Information regulation
- 16 CFR Part 313 — Privacy of Consumer Financial Information regulation
- 12 CFR Part 1016 — Privacy of Consumer Financial Information (Regulation P) regulation
- 15 U.S.C. §§ 6801–6809 — Gramm-Leach-Bliley Act, Title V, Subchapter I statute
- Standards for Safeguarding Customer Information — final rule amending 16 CFR Part 314, 88 FR 77499 (November 13, 2023) regulation
- FTC — Safeguards Rule: What Your Business Needs to Know agency guidance
- FTC — Safeguards Rule notification requirement now in effect (May 13, 2024) agency guidance
- FTC — Mortgage Analytics Company Settles FTC Allegations It Failed to Ensure Vendor Was Adequately Protecting Consumer Data (December 15, 2020) agency release
- FTC — In the Matter of Ascension Data & Analytics, LLC (Docket No. 192-3126) docket
- Va. Code § 59.1-576 — Consumer Data Protection Act, scope and exemptions statute
- Cal. Civ. Code § 1798.145 — CCPA exemptions, including the GLBA exemption at subdivision (e) statute
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.