✳ US · FTC Safeguards Rule

FTC Safeguards Rule: customer information program (not every bank's rule, not PCI)

An educational overview of the FTC Standards for Safeguarding Customer Information (16 CFR Part 314): a written customer-information program for financial institutions under FTC jurisdiction. Not every bank's rule, and not PCI DSS.

US · FTC Safeguards RuleProgram explainerLast reviewed

What category of obligation this is

The official name is the Standards for Safeguarding Customer Information, the Safeguards Rule for short. It is codified at 16 CFR Part 314. The eCFR purpose statement says this part implements sections 501 and 505(b)(2) of the Gramm-Leach-Bliley Act and sets standards to protect the security, confidentiality, and integrity of customer information.

That is an FTC rule about customer information. It is not a payment-industry standard, and it is not the examination handbook for every bank.

Identify the regulator first

Part 314 applies to financial institutions over which the FTC has jurisdiction, and that are not otherwise subject to another regulator's enforcement authority under section 505 of the Gramm-Leach-Bliley Act. FTC guidance says the Rule's "financial institution" definition is broader than everyday speech, and that what matters are the activities, not the label the company uses for itself.

Examples named in the FTC guidance and in § 314.1(b) include mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, investment advisors that are not required to register with the SEC, and finders. Federally supervised banks, and many credit unions, often answer first to other regulators (the OCC, the Federal Reserve, the FDIC, the NCUA, and others). The Finance path already says to identify the responsible regulator first. This page does not quiz you into a coverage answer. Escalate that question.

A written program, not a product

Covered financial institutions must develop, implement, and maintain a written information security program. § 314.3 says the program contains administrative, technical, and physical safeguards appropriate to size and complexity, the nature and scope of activities, and the sensitivity of customer information. The objectives are the security and confidentiality of customer information, protection against anticipated threats or hazards to the security or integrity of that information, and protection against unauthorized access or use that could result in substantial harm or inconvenience to a customer.

Customer information, in the Rule's definition, is any record containing nonpublic personal information about a customer of a financial institution, in paper, electronic, or other form, handled or maintained by or on behalf of you or your affiliates. That customer-information lane is not the same sentence as payment account data under PCI DSS.

Program elements as categories

§ 314.4 names elements of that written program. Read them as categories, then open the FTC guidance and the eCFR text for the detail. The themes are Qualified Individual oversight, a written risk assessment, safeguards to control the risks you identify, testing and monitoring, training, service-provider oversight, evaluation of the program, a written incident response plan, and a written Qualified Individual report to the board or governing body (or, if there is none, to a senior officer) at least annually.

Safeguard themes inside that risk-based design include access controls, knowing which data and systems you have, encryption or an alternative the Qualified Individual approves, multi-factor authentication themes, secure disposal, change management, and logging and monitoring of authorized users. Naming the themes is literacy. It is not a checklist you complete in Atlas, and it does not score each element for you. § 314.6 excepts some of those elements for financial institutions that maintain customer information concerning fewer than five thousand consumers. This page does not count consumers or decide that exception.

Notification, at literacy depth

§ 314.5 says section 314.4(j) is effective as of 13 May 2024. Under § 314.4(j), if a notification event involves the information of at least 500 consumers, the financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery. The notice is electronic, on a form on ftc.gov.

That is the existence of a timing category. This page does not supply a breach-report template, and it does not decide whether a real event is a notification event.

FFIEC guidance is related, not this rule

The Finance path also cites FFIEC Authentication and Access to Financial Institution Services and Systems. The press release is dated 11 August 2021. It is interagency examination guidance on risk assessment and layered authentication and access for covered financial institutions. It is not 16 CFR Part 314, and it is not a freestanding universal law.

One outbound link is enough. This page is not an FFIEC explainer, and it does not merge OCC or NCUA handbooks into the Safeguards Rule.

Rewrite the one-line claim

Replace "every U.S. bank follows FTC Safeguards as their one cyber law" with a regulator-first sentence: the Safeguards Rule is an FTC customer-information program rule for financial institutions under FTC jurisdiction. Payment card data is a PCI DSS question. FFIEC authentication guidance is related examination guidance, a different instrument.

At work, privately ask counsel or compliance which regulator owns customer-information security for one product line. Do not paste customer nonpublic personal information into Atlas.

Phrases people collapse

Teaching table only. It does not assign FTC jurisdiction, and it does not find that a written program meets Part 314.

Four phrases people fold into one finance cyber rule. Not a Safeguards determination.
Phrase people sayLiteracy correction
Finance cyber = SafeguardsOnly if the entity is an FTC-jurisdiction financial institution under Part 314. Many banks and credit unions answer to other regulators first.
Safeguards = FFIECSafeguards is the FTC rule (16 CFR Part 314). FFIEC authentication guidance is interagency examination guidance. Related theme (authentication and access), different instrument.
Safeguards = PCIPCI DSS is a payment-industry standard for payment account data, run through brands and acquirers. Different category.
We bought a tool, so Safeguards is doneThe Rule frames a written program and risk-based safeguards, not a single product.

Claims to retire

Every bank and credit union is primarily an FTC Safeguards story.

Part 314 frames financial institutions under FTC jurisdiction that are not under another GLBA section 505 enforcer. Many banks and credit unions answer to other regulators first. Identify the regulator before you name the rule.

Safeguards, FFIEC, and PCI are the same finance cyber rule.

The Safeguards Rule is 16 CFR Part 314. FFIEC authentication guidance is interagency examination guidance. PCI DSS is a payment-industry standard for payment account data. Related themes are not the same instrument.

An encryption checkbox, or an MFA checkbox, means Safeguards is done.

Encryption and multi-factor authentication are safeguard themes inside a written, risk-based program. One control setting is not the program, and buying a tool is not the program.

A vendor badge that says GLBA compliant replaces the jurisdiction question.

A homepage badge does not decide whether the entity is a financial institution under FTC jurisdiction. That question belongs to counsel or compliance, using the activities and the regulator, not a slogan.

Finishing this lesson is a Safeguards determination.

Atlas does not issue Safeguards determinations. Completing the lesson is not a finding that a program meets Part 314.

Sort three finance sentences

Teaching sort only. It does not decide that a real institution is in FTC jurisdiction, and it does not approve a control.

Three lanes people fold into one badge. Not a determination.
SentenceLaneWhat this page is teaching
FTC customer-information program rule for covered financial institutions under FTC jurisdiction.Safeguards RuleStandards for Safeguarding Customer Information, 16 CFR Part 314. Regulator first. Not every bank.
Payment card data security standard, validated through brands and acquirers.PCI DSSA different regime for payment account data. The PCI DSS explainer is the place for that standard.
Interagency examination guidance on authentication and access.FFIEC, relatedThe 11 August 2021 press release is examination guidance. It is not Part 314, and this page is not that explainer.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.