Compliance • education • education tips • •

FTC Safeguards Rule Requirements: Compliance Guide

From risk assessments to employee training, see what the FTC Safeguards Rule expects businesses to have in place for protecting customer information.

FTC Safeguards Rule requirements for protecting customer financial information

Protecting customer financial information is no longer simply an IT responsibility. For businesses covered by the Federal Trade Commission's Safeguards Rule, it is an organization-wide compliance obligation involving security controls, risk assessment, employee awareness, service providers, incident response, governance, and regulatory reporting.

The FTC Safeguards Rule requirements apply to financial institutions under FTC jurisdiction and require them to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards designed to protect customer information. The current Rule also requires covered institutions to notify the FTC about certain security events involving at least 500 consumers.

That sounds straightforward until an organization starts asking practical questions. Who counts as a financial institution? What customer information is covered? Is encryption mandatory? Who can serve as the Qualified Individual? Does a small business have to meet every requirement? What happens when a service provider handles customer data?

This guide answers those questions by breaking down the current federal requirements, explaining what they mean in practice, and showing where state-specific obligations may also need attention.

What Is the FTC Safeguards Rule?

The Safeguards Rule is a federal regulation issued by the Federal Trade Commission under the Gramm-Leach-Bliley Act (GLBA). Its purpose is to ensure that financial institutions within FTC jurisdiction protect the security and confidentiality of customer information.

The Rule is found in 16 CFR Part 314. Under the FTC Safeguards Rule, covered financial institutions must establish an information security program appropriate to their size and complexity, the nature and scope of their activities, and the sensitivity of the customer information involved.

The Rule is not new. It originally took effect in 2003. However, the FTC amended it substantially in 2021 to introduce more specific information security requirements. A further amendment added a requirement to notify the FTC about certain data breaches and security incidents. That notification requirement took effect in May 2024.

The result is a framework that goes considerably beyond telling businesses simply to "keep data secure." Covered institutions must address defined areas such as risk assessment, access controls, encryption, multi-factor authentication, security testing, workforce training, service-provider oversight, incident response, and governance reporting.

How the Safeguards Rule Fits Within GLBA

The Safeguards Rule should not be confused with the whole Gramm-Leach-Bliley Act.

GLBA addresses several aspects of how financial institutions handle consumers' financial information. As the FTC's Gramm-Leach-Bliley Act guidance explains, financial institutions have obligations concerning both their information-sharing practices and the safeguarding of sensitive data.

The Safeguards Rule specifically focuses on protecting customer information through an information security program. Other GLBA requirements, including privacy obligations, address different questions.

For compliance purposes, that distinction matters. An organization should not assume that satisfying one GLBA-related obligation automatically satisfies every other applicable requirement.

Who Must Comply With the FTC Safeguards Rule?

One of the easiest mistakes to make is assuming that "financial institution" means only a bank.

Under the Safeguards Rule, the term is broader. What matters is primarily the nature of the activities an organization performs, rather than the label it uses to describe itself.

According to the FTC's business guidance on the Safeguards Rule, the Rule applies to financial institutions subject to FTC jurisdiction that are not subject to the enforcement authority of another regulator under the relevant GLBA provision. For a closer look at coverage, see who must comply with the FTC Safeguards Rule, including how financial activities and regulatory jurisdiction affect applicability. 

What Counts as a Financial Institution?

Depending on their activities and the applicable regulatory framework, businesses potentially within the FTC's definition can include:

  • Mortgage lenders and brokers

  • Finance companies

  • Account servicers

  • Payday lenders

  • Check-cashing businesses

  • Wire transferors

  • Collection agencies

  • Credit counselors

  • Certain financial advisors

  • Tax preparation firms

  • Certain non-federally insured credit unions

  • Certain investment advisors

Tax professionals can review the FTC Safeguards Rule for tax preparers for a more focused explanation of how these requirements relate to tax preparation businesses. 

This is not an exhaustive list.

A business, therefore, should not decide that the Rule is irrelevant merely because financial services are not its primary brand identity. The more useful question is whether it is significantly engaged in financial activities that bring it within the Rule's definition.

Organizations with uncertain status may need qualified legal or compliance advice based on their specific activities and regulatory relationships.

Examples of financial institutions potentially covered by the FTC Safeguards Rule

Does the Safeguards Rule Apply to Auto Dealerships?

It can.

Many automobile dealers engage in financing or leasing activities that bring them within the definition of a financial institution. The FTC has issued dedicated Safeguards Rule FAQs for automobile dealers explaining how the Rule applies to common dealership situations.

The important point is that selling vehicles by itself is not the entire analysis. The dealer's financial activities and handling of customer information matter.

Are Small Businesses Exempt?

There is no blanket rule saying that every small business is exempt from the Safeguards Rule.

There is a narrower exception under 16 CFR § 314.6. Financial institutions maintaining customer information for fewer than 5,000 consumers are exempt from certain requirements, including the detailed written risk assessment, specified penetration-testing and vulnerability-assessment provisions, written incident response plan, and the qualified individual's written reporting requirement.

However, this does not mean smaller institutions are exempt from the Safeguards Rule. They should identify which requirements apply to their circumstances rather than treating the 5,000-consumer threshold as a complete exemption.

What Information Does the Safeguards Rule Protect?

Understanding the rule starts with understanding what it protects.

The FTC defines customer information as records containing nonpublic personal information about a financial institution's customer, whether in paper, electronic, or other forms, when handled or maintained by or for the institution or its affiliates.

The concept goes beyond a single customer database. Customer information can move across employees, systems, applications, devices, service providers, and physical records, so the security program should protect it throughout the relevant environment.

Customer Information and Nonpublic Personal Information

Nonpublic personal information can include personally identifiable financial information and certain information derived from it.

The practical compliance question is not simply, "Do we store customer names?"

An institution needs to understand what protected information it holds, where it is located, who can access it, how it moves, and which systems or third parties interact with it.

Information Systems Matter Too

The Safeguards Rule also defines an "information system" broadly enough to encompass electronic resources containing customer information or connected to systems containing customer information.

That is why asset and data awareness are fundamental to compliance. An organization cannot reliably protect information if it does not know where that information is stored, transmitted, processed, or accessible.

The FTC's Safeguards Rule business guidance provides further definitions and examples organizations can use when evaluating their own information environments.


Customer information moving through employees systems devices and service providers

FTC Safeguards Rule Requirements: What Covered Financial Institutions Must Do

The core FTC Safeguards Rule requirements revolve around a written information security program.

Under 16 CFR § 314.3, that program must contain administrative, technical, and physical safeguards appropriate to the institution's circumstances. Section 314.4 then establishes specific program elements.

Here is the framework at a glance:

Requirement

What It Means in Practice

Typical Organizational Responsibility

Qualified Individual

Someone oversees and implements the security program

Security/compliance leadership

Risk Assessment

Identify foreseeable risks to customer information

Security/risk/compliance

Safeguards

Implement controls addressing identified risks

IT/security

Testing and Monitoring

Check whether key safeguards remain effective

IT/security

Personnel and Training

Prepare employees and security personnel

Security/HR/L&D

Service Providers

Address third-party handling of customer information

Procurement/security/compliance

Program Updates

Adapt the program as risks and operations change

Qualified Individual/management

Incident Response

Prepare for security events

Security/legal/compliance

Governance Reporting

Report program status and material issues

Qualified Individual/governing body

FTC Notification

Report qualifying notification events

Legal/compliance/security

The functions shown in the third column are practical examples, not roles prescribed by the Rule. Organizations structure responsibilities differently.

FTC Safeguards Rule requirements including risk assessment safeguards training and incident response

1. Designate a Qualified Individual

A covered financial institution must designate a Qualified Individual to oversee, implement, and enforce its information security program.

The rule does not require a specific degree, job title, or government-issued certification. The qualified individual may be an employee, affiliate, or service provider.

However, the institution remains responsible for compliance and must meet applicable oversight requirements when using an outside provider or affiliate.

The key consideration is whether the person has the knowledge and capability appropriate to the organization's circumstances. The qualified individual oversees the program, but effective implementation requires cooperation across the organization.

2. Conduct and Document a Risk Assessment

An effective information security program has to reflect the risks the organization actually faces. The Safeguards Rule therefore requires covered institutions, subject to the applicable small-institution exception, to base their program on a written risk assessment.

  1. Identify and categorize risks: The assessment must address reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information. It should include criteria for evaluating and categorizing those identified risks or threats.

  2. Assess systems and customer information: The organization must evaluate its information systems and the customer information they handle, including whether existing safeguards are sufficient to control identified risks.

  3. Define risk treatment: The written assessment should establish requirements for how identified risks will be mitigated or, where appropriate, accepted. This helps connect the assessment directly to the organization's security decisions.

This is important because the rule does not treat risk assessment as a document that can be written once and forgotten. Risks change as systems, personnel, business activities, service providers, and threats change. Periodic reassessment allows the information security program to evolve with them.

A risk assessment should therefore inform security decisions rather than merely document them after the fact.

3. Design and Implement Safeguards to Control Identified Risks

Once risks are understood, the organization must implement safeguards to address them.

This is where several of the Rule's best-known technical requirements appear.

Access Controls

Institutions must implement and periodically review access controls.

Access should be limited to authorized users, and authorized personnel should have access only to customer information they need to perform their duties and functions.

This makes access management an ongoing process. Changes in jobs, responsibilities, employment status, systems, and business needs can all affect whether existing access remains appropriate.

Understand the Information Environment

The rule requires institutions to identify and manage relevant data, personnel, devices, systems, and facilities.

In practical terms, an organization needs sufficient visibility into its information environment to protect it effectively.

That may involve identifying systems containing customer information, understanding where information is transmitted, and recognizing the employees and third parties that interact with those systems.

Encryption

The Rule requires customer information to be protected by encryption when held by the institution and when transmitted over external networks.

Where encryption is infeasible, the regulation allows effective alternative compensating controls reviewed and approved by the Qualified Individual.

That qualification is important. "Encryption is inconvenient" is not the same as establishing that encryption is infeasible and using an approved effective alternative.

Secure Applications

Organizations that develop applications used to transmit, access, or store customer information must adopt secure development practices.

Institutions using externally developed applications also need procedures for evaluating, assessing, or testing their security.

The Rule therefore requires attention not only to networks and databases but also to the applications through which protected information is handled.

Multi-Factor Authentication

Multi-factor authentication (MFA) is another prominent requirement.

The rule generally requires MFA for individuals accessing information systems. Under the regulatory definition, MFA involves verifying at least two different categories of authentication factors, such as something the person knows, possesses, or inherently is.

An alternative can be used where the qualified individual has approved in writing reasonably equivalent or more secure access controls.

This is a legal requirement with a defined alternative, not merely a general recommendation to use stronger passwords.

Secure Disposal and Data Retention

Covered institutions must establish procedures for secure disposal of customer information.

The Rule generally provides for disposal no later than two years after the last use of the information in connection with providing a product or service to the customer, subject to exceptions such as legitimate business needs, legal retention requirements, or circumstances in which targeted disposal is not reasonably feasible.

Institutions must also periodically review their data-retention policies to minimize unnecessary retention.

Change Management and User Activity

The program must address change management and include controls designed to monitor and log authorized-user activity and detect unauthorized access, use, or tampering involving customer information.

Together, these measures reinforce an important principle: safeguards must address both outside threats and risks arising within authorized environments.

The FTC's detailed explanation of Safeguards Rule requirements provides further context for applying these controls.

4. Regularly Test and Monitor Safeguards

Putting a security control in place does not mean it will continue to work effectively.

  • Test security controls: Regularly test or monitor key safeguards, systems, and procedures.

  • Detect attacks: Include controls that can identify actual or attempted attacks.

  • Conduct penetration testing: Where continuous monitoring is not effective, conduct annual penetration testing based on identified risks.

  • Perform vulnerability assessments: Conduct assessments at least every six months when required by the Rule.

  • Use qualified personnel: Testing should be performed by appropriately qualified individuals.

  • Act on findings: Use results to improve risk assessment, remediation, security programs, and management oversight.

5. Train Employees and Maintain Qualified Security Personnel

Technology cannot implement an information security program by itself.

The Safeguards Rule requires policies and procedures designed to ensure that personnel can enact the organization's program. This includes security awareness training that is updated as necessary to reflect risks identified through the risk assessment. Organizations can explore the FTC Safeguards Rule training requirements in more detail to understand how workforce awareness fits within the Rule’s personnel requirements. 

Covered institutions must also use qualified information-security personnel sufficient to manage their security risks and perform or oversee the program. Those personnel need security updates and training appropriate to relevant risks, while key information-security personnel must maintain current knowledge of changing threats and countermeasures.

For employees outside specialist security roles, awareness matters because everyday activities can involve protected information: accessing records, using applications, handling credentials, sharing information, responding to suspicious communications, or reporting potential security events.

Employees completing FTC Safeguards Rule security awareness training in a US workplace

More broadly, security awareness training for financial institutions can help employees understand how their everyday actions support the organization's information-security program.

Organizations that want structured learning to support workforce awareness can use FTC Safeguards Rule Awareness Training  as one component of a broader training and information-security program.

USCI training provides a certificate of completion. Completing a course does not constitute FTC certification, government approval, or proof that an organization as a whole complies with the Safeguards Rule.

Organizations looking at their wider workforce learning strategy may also find USCI's Information Security Compliance Training 101 useful for understanding how security training fits into broader organizational compliance.

6. Oversee Service Providers

Outsourcing a business process does not automatically outsource the associated information-security responsibility.

The Safeguards Rule requires covered institutions to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards for the customer information at issue.

Contracts must require relevant service providers to implement and maintain appropriate safeguards.

Institutions must also periodically assess service providers based on the risk they present and the continued adequacy of their safeguards.

This makes third-party oversight part of the compliance program rather than merely a procurement issue.

An institution should know which service providers can receive, maintain, process, or otherwise access customer information and ensure that relevant contractual and oversight arrangements reflect that exposure.

7. Keep the Information Security Program Current

Compliance is not a one-time implementation project.

The Rule requires financial institutions to evaluate and adjust their information security programs in light of risk-assessment results, testing and monitoring, material changes to operations or business arrangements, and other circumstances that may materially affect the program.

That means a security program that was appropriate several years ago may no longer be sufficient.

A new platform, acquisition, service provider, customer-information flow, remote-working arrangement, emerging threat, or organizational restructure can change the risk picture.

Legal requirement: Maintain and adjust the program in response to relevant changes.

Good implementation practice: Build review points into normal governance processes so changes affecting customer information trigger security and compliance consideration rather than waiting for the next major review.

8. Establish a Written Incident Response Plan

For institutions subject to this provision, the Rule requires a written incident response plan designed to respond promptly to and recover from security events materially affecting the confidentiality, integrity, or availability of customer information.

The plan must address areas including:

  • The goals of the incident response plan

  • Internal response processes

  • Roles, responsibilities, and decision-making authority

  • Internal and external communications

  • Remediation of identified weaknesses

  • Documentation and reporting

  • Evaluation and revision after an event

An incident response plan should not be confused with the overall information security program. The security program is the broader framework for safeguarding customer information; the incident response plan addresses what the organization will do when a relevant security event occurs.

Likewise, having an incident response plan does not by itself satisfy the FTC's separate notification requirement for qualifying events.

9. Report to the Board or Governing Body

Information-security governance does not end with the security team.

For institutions subject to the requirement, the Qualified Individual must report in writing, regularly and at least annually, to the board of directors or equivalent governing body. If there is no board or equivalent, the report goes to a senior officer responsible for the information security program.

The report must address the overall status of the program and compliance with the Rule, along with material matters.

Depending on the circumstances, those matters can include risk assessments, risk-management and control decisions, service-provider arrangements, testing results, security events, management responses, and recommendations for changes.

The purpose is not simply to generate another compliance document. It creates a formal route for relevant leadership to understand the condition of the information security program and material issues affecting it.

FTC Safeguards Rule Breach Notification Requirements

A significant change to the Rule took effect in May 2024: covered financial institutions now have a direct FTC notification obligation for certain security events.

This requirement should be considered alongside—but not confused with—the written incident response plan or separate state breach-notification laws.

What Is a Notification Event?

Under the Rule, a notification event involves the unauthorized acquisition of unencrypted customer information concerning at least 500 consumers.

For this purpose, encrypted customer information is treated as unencrypted if an unauthorized person accessed the relevant encryption key.

The Rule also establishes an important presumption. Unauthorized access to unencrypted customer information is treated as unauthorized acquisition unless the institution has reliable evidence showing that unauthorized acquisition has not occurred and could not reasonably have occurred.

Organizations therefore need a process for investigating security events carefully enough to determine whether the federal reporting threshold has been reached.

When Must the FTC Be Notified?

If a notification event occurs, the institution must notify the FTC as soon as possible and no later than 30 days after discovery.

The FTC provides an electronic reporting mechanism for these notifications.

The deadline makes incident escalation particularly important. Employees who discover suspicious activity need to know where and how to report it internally so the appropriate security, legal, and compliance personnel can evaluate the event without unnecessary delay.

The current FTC Safeguards Rule notification requirements should be checked when an organization is determining its reporting obligations.
FTC Safeguards Rule breach notification process for events affecting 500 or more consumers
What Must the Notification Include?

Under the Rule, the FTC notice includes specified information about the event. This includes the institution's name and contact information, a description of the types of information involved, the date or date range of the event if known, the number of affected or potentially affected consumers, a general description of what happened, and—where applicable—whether law enforcement has made the required determination supporting a delay in public disclosure.

Organizations should work from the current regulatory requirements and FTC reporting process when preparing an actual notification rather than relying solely on a generic breach-response checklist.

Just as importantly, reporting to the FTC does not necessarily resolve every notification obligation. State and other federal laws may create separate duties.

Federal FTC Compliance vs. State Data Security Requirements

The Safeguards Rule is a federal requirement. For covered institutions, however, federal compliance may be only one part of the legal picture.

An organization can potentially be subject to the FTC Safeguards Rule while also having obligations under state cybersecurity, privacy, financial-services, or data-breach laws.

For example, financial-services organizations regulated by the New York Department of Financial Services may separately need to consider 23 NYCRR Part 500, New York's Cybersecurity Regulation. Its requirements arise from a different regulatory framework and should not be treated as interchangeable with FTC compliance.

State breach-notification rules can also differ from the FTC framework.

California provides a useful example. California law requires notification to affected California residents in specified circumstances involving unauthorized acquisition of covered personal information. It also requires a business that must notify more than 500 California residents as a result of a single breach to submit a sample notification to the California Attorney General. Organizations can review the California Attorney General's data security breach reporting guidance for the state-specific requirements.

The practical lesson is straightforward:

Do not treat FTC Safeguards Rule compliance as automatic compliance with every other data-security or breach-notification law.

Organizations operating across states should identify the laws applicable to their business activities, regulatory status, information, and affected individuals.

How to Approach FTC Safeguards Rule Compliance

The Rule contains specific obligations, but implementation becomes more manageable when those requirements are treated as parts of one connected program. An FTC Safeguards Rule compliance checklist can help organizations work through these obligations systematically and identify areas requiring further attention. 

A practical compliance sequence looks like this:

  1. Determine whether the organization is covered. Review the financial activities the business performs and the regulator with enforcement authority.

  2. Identify customer information and relevant information systems. Understand what protected information exists, where it resides, how it moves, and who can access it.

  3. Designate the Qualified Individual. Establish clear responsibility for overseeing and implementing the information security program.

  4. Conduct the required risk assessment. Identify foreseeable internal and external risks and evaluate existing safeguards, subject to the applicable provisions and exceptions.

  5. Evaluate administrative, technical, and physical safeguards. Compare existing controls with the Rule's requirements and identified risks.

  6. Address gaps systematically. Prioritize deficiencies based on regulatory requirements and risk rather than treating every security improvement as equally urgent.

  7. Prepare personnel. Implement and update security awareness training and ensure information-security personnel have appropriate expertise.

  8. Review service providers. Identify providers with access to customer information and evaluate contractual and oversight arrangements.

  9. Prepare for security events. Establish applicable incident-response procedures and understand the FTC notification threshold and deadline.

  10. Monitor, document, report, and improve. Testing, governance reporting, risk reassessment, and program adjustments keep compliance active as circumstances change.

There is an important distinction throughout this process.

Rule requirement: Something the Safeguards Rule expressly requires covered institutions to do.

Implementation consideration: A practical method an organization may choose to help satisfy or manage that requirement.

Not every sensible cybersecurity practice is specifically mandated by the Safeguards Rule. Conversely, implementing a collection of generally accepted cybersecurity measures does not necessarily establish compliance with every element of the Rule.

Common FTC Safeguards Rule Compliance Mistakes

Even a well-intentioned compliance program can begin with the wrong assumptions. Several issues deserve particular attention.

Assuming only banks are covered. The FTC's definition of financial institution is broader than ordinary usage. Organizations should assess their activities rather than relying on their industry label.

Treating the 5,000-consumer threshold as a complete exemption. Institutions below that threshold receive exceptions from specified provisions. The threshold does not automatically remove every Safeguards Rule obligation.

Treating compliance as an IT-only project. Technical controls matter, but the Rule also addresses governance, risk assessment, personnel, training, service providers, incident response, and reporting.

Writing a risk assessment and never revisiting it. The Rule requires periodic reassessment as risks and circumstances evolve.

Overlooking service providers. Customer information can remain exposed even when an institution's internal controls are strong if third parties handling that information are not appropriately managed.

Treating training as a once-a-year checkbox. The Rule calls for security awareness training that is updated as necessary to reflect risks identified through the risk assessment.

Failing to adjust the program after change. New technology, business arrangements, threats, systems, and operations can all affect the adequacy of existing safeguards.

Confusing incident response with breach notification. An organization may have an incident response plan and still need a separate process for determining whether an event must be reported to the FTC or under applicable state law.

Building an Ongoing Safeguards Rule Compliance Program

The most useful way to think about the FTC Safeguards Rule is not as a list of isolated cybersecurity tasks. It is an ongoing information-security framework.

Risk assessment informs safeguards. Safeguards need testing. Employees need the knowledge to follow the program. Service providers require oversight. Security events require an organized response. Material issues need governance attention. Changes in threats, technology, personnel, and operations may require the program to change as well.

For covered institutions, that cycle should continue as the organization evolves.

It is equally important to keep regulatory boundaries clear. The Safeguards Rule establishes federal requirements for financial institutions within FTC jurisdiction, but an organization may have additional obligations under state privacy, cybersecurity, financial-services, or breach-notification laws.

Workforce awareness is one part of maintaining that wider program. Organizations that need structured education can incorporate FTC Safeguards Rule Awareness Training alongside their policies, technical safeguards, risk-management processes, and role-specific procedures.

The course provides a certificate of completion only. It does not constitute FTC certification, government approval, or proof of compliance with the Rule.

Effective Safeguards Rule compliance requires organizations to connect the key elements: understanding the information they hold, identifying risks, implementing safeguards, training personnel, overseeing third parties, responding to incidents, and updating the program as circumstances change.

Frequently Asked Questions

01 What Are the FTC Safeguards Rule Requirements? +

Covered financial institutions must maintain a written information security program with administrative, technical, and physical safeguards appropriate to their circumstances. Key requirements include a Qualified Individual, risk assessment, safeguards, testing and monitoring, personnel training, service-provider oversight, program updates, incident response, governance reporting, and FTC notification for qualifying events. Some requirements have exceptions for institutions maintaining customer information on fewer than 5,000 consumers.

02 Who Must Comply With the FTC Safeguards Rule? +

The Rule applies to financial institutions under FTC jurisdiction that are not subject to another regulator's enforcement authority under the relevant GLBA provision. "Financial institution" can include lenders, finance companies, mortgage brokers, certain financial advisors, tax preparation firms, and automobile dealers engaged in qualifying financial activities.

03 Does the FTC Safeguards Rule Apply to Small Businesses? +

Potentially, yes. Small size does not create a general exemption. Financial institutions maintaining customer information concerning fewer than 5,000 consumers are exempt from certain specified provisions under 16 CFR § 314.6, but other applicable Safeguards Rule requirements remain. Businesses should therefore determine their actual coverage and applicable exceptions rather than assuming the Rule does not apply.

04 Does the FTC Safeguards Rule Require Employee Training? +

Yes. The Rule requires covered institutions to provide personnel with security awareness training, updated as necessary based on risks identified through the risk assessment. It also requires qualified information-security personnel to maintain knowledge of changing security threats and countermeasures.

Training is only one part of the information security program and does not replace required technical, administrative, physical, governance, or incident-response measures.

05 Does the FTC Safeguards Rule Require Multi-Factor Authentication? +

Yes. The Rule requires multi-factor authentication for individuals accessing information systems, subject to its specified alternative. A Qualified Individual may approve in writing reasonably equivalent or more secure access controls.

Organizations should therefore treat MFA as a regulatory requirement rather than optional cybersecurity guidance.

06 Does the FTC Safeguards Rule Require Encryption? +

Yes. The Rule requires covered institutions to encrypt customer information when held by the institution and when transmitted over external networks. If encryption is infeasible, effective alternative compensating controls may be used if reviewed and approved by the Qualified Individual.This alternative should not be treated as a general option to avoid encryption for convenience.

07 What Is a Qualified Individual? +

A Qualified Individual is the person designated to oversee, implement, and enforce the financial institution's information security program. They may work for the institution, an affiliate, or a service provider and do not need a specific degree or job title.

Using an outside person does not transfer the institution's underlying compliance responsibility.

08 When Must a Data Breach Be Reported to the FTC? +

A covered institution must notify the FTC as soon as possible and no later than 30 days after discovering a notification event involving unauthorized acquisition of unencrypted customer information concerning at least 500 consumers. The Rule contains additional provisions concerning encrypted information, unauthorized access, and the contents of the notice. Separate state or other federal notification requirements may also apply.

09 Is FTC Safeguards Rule Training a Certification? +

Awareness training can support the personnel-training component of an organization's information security program, but completing a training course does not make an individual or organization "FTC certified."

USCI's FTC Safeguards Rule Awareness Training  provides a certificate of completion. It should be used as an educational component within a broader compliance program, not as a substitute for satisfying the organization's regulatory obligations.

Precision Compliance Training Built for Your Business.
We’re constantly expanding our U.S. compliance courses to fit your exact needs. Whether that’s state-specific mandates, niche industry standards, or scalable training for your workforce. Reach out today to build your custom plan.
Request Custom Training
Ready to Write Your Success Story?
Join thousands of students who have already transformed their careers. Start your learning journey today and become our next success story.