FTC Safeguards • GLBACompliance • Information Security • •

Who Must Comply With the FTC Safeguards Rule?

Who must comply with the FTC Safeguards Rule? Check covered activities, customer information, small-business exceptions, and staff training needs.

A tax preparation manager and employee reviewing customer records in a small US office

A tax preparation business may never call itself a financial institution. Under the FTC Safeguards Rule, it may still be one.

Who must comply with the FTC Safeguards Rule? Generally, a business under FTC jurisdiction must comply if it is significantly engaged in a covered financial activity. Tax preparation, consumer lending, mortgage brokering, and arranging certain auto financing are examples. The answer depends on what the business does, who regulates it, and the customer information it handles. A business name alone cannot settle the question.

This guide helps you make that first coverage check and spot the cases that need a closer look. It reflects the current rule in 16 CFR Part 314 and the FTC’s business guidance. 

What Makes a Business a Financial Institution Under the Rule?

The rule looks at financial activities, not just familiar labels such as “bank” or “lender.” A business can be a financial institution for this purpose when it is significantly engaged in an activity that the rule treats as financial in nature or incidental to a financial activity. The FTC’s rule also has to be the rule that governs that institution.

Coverage test showing financial activity, significant engagement, FTC jurisdiction, and customer information

What Does “Significantly Engaged” Mean?

Think about what your business offers as part of its normal work. The rule gives two useful retail examples. A store that issues its own credit card to customers is engaged in a financial activity. A store that merely accepts credit cards issued by others is not a financial institution on that basis alone. The difference is the store’s own activity, not whether a customer happens to use credit.

This is why a short industry checklist can mislead you. Two businesses with the same storefront may handle financing differently. Review the services you actually provide, including any activity that is less visible to customers, before deciding the rule does or does not apply.

Why Does FTC Jurisdiction Matter?

The Gramm-Leach-Bliley Act, or GLBA, sets a broader framework for protecting financial information. More than one federal regulator has a role under that framework. The FTC Safeguards Rule applies to financial institutions within the FTC’s jurisdiction; an institution overseen under another regulator’s safeguards rules needs to check those rules instead.

For example, “banks are covered by the FTC Safeguards Rule” is too broad. So is “credit unions are never covered.” Identify the institution and its regulator before applying either statement. If your business offers several services, check the activity at issue as well as the name on its license.

Which Businesses Commonly Have to Comply?

The FTC’s examples reach beyond banks. Businesses that may be covered, depending on their activities and regulators, include:

  • Consumer lenders, payday lenders, and mortgage brokers.

  • Tax preparation businesses.

  • Debt collection agencies, check-cashing businesses, and wire transferors.

  • Certain investment advisers and credit counseling services.

  • Auto dealers that arrange financing or offer qualifying leases.

  • Businesses that act as finders by bringing buyers and sellers of financial products or services together.

Suppose a small business prepares tax returns and keeps client files in a cloud system. Its size and office setup do not decide coverage. Tax preparation is listed in the rule’s financial-institution examples, so its owner should examine the rule and the information the business holds. For a separate look at protecting business records, see our guide to information security compliance training.

Examples of covered financial activities, including lending, tax preparation, auto financing, payments, advising, and finder servicesDo Auto Dealers Have to Comply?

Many do, but the answer turns on what the dealership does. An auto dealer that arranges financing for customers or enters into certain leases can fall within the rule. A dealer that only sells cars for cash should not assume the same result from the word “dealer” alone.

The FTC’s auto dealer Safeguards Rule FAQ explains how financing, leases, customer relationships, and information received from other financial institutions affect the analysis. A dealer should check the transactions it offers and how it receives and keeps application data. 

Do Tax Preparers Have to Comply?

Tax preparation is specifically listed in the rule’s examples of financial activity. A tax preparer should therefore check its Safeguards Rule duties even if it does not lend money or arrange financing. Tax files can hold information that needs careful handling, whether employees use paper folders, laptops, or a service provider’s system.

The IRS also provides a Written Information Security Plan guide for tax professionals. That guide can help a tax practice plan how it protects client data. The FTC rule and the business’s own circumstances still determine its duties.

Which Businesses May Fall Outside the FTC Safeguards Rule?

Some ordinary payment practices do not, by themselves, make a merchant a financial institution under this rule. The rule gives examples: a retailer that only takes cards issued by someone else, a merchant that occasionally offers layaway or deferred payment, and a business that lets a customer run a tab. 

Look beyond that one practice before reaching a final answer. The same retailer might also run its own lending program. A company might provide a covered financial service alongside its main business. The activities need to be reviewed together.

Three other situations deserve care:

A bank has a different regulator. That can mean the FTC’s Safeguards Rule is not its governing rule. It does not mean the bank has no information security duties.

A vendor works with a covered institution. Handling that institution’s data does not automatically make the vendor a financial institution under the FTC rule. Its own activities must be checked separately.

A business handles business accounts. The rule’s consumer and customer definitions focus on financial products or services for personal, family, or household use. A business account alone does not answer whether the company is covered for other activities or records. 

What Customer Information Does a Covered Business Protect?

The rule uses three related terms, and each does a different job:

  • A consumer is an individual who obtains, or has obtained, a financial product or service mainly for personal, family, or household use.

  • A customer is a consumer with a continuing relationship with the financial institution.

  • Customer information is a record containing nonpublic personal information about a customer, whether the record is on paper, on a computer, or held on the institution’s behalf.

Definitions of consumer, customer, and customer information under the FTC Safeguards RulePicture an auto dealer arranging a loan for a buyer’s personal car. Financing documents and information about a person with an ongoing financing relationship may bring customer-information duties into view. If an applicant is turned down and no continuing relationship starts, that person is not automatically a customer under that definition. The dealer must still check what information it received and whether it has other duties, including duties tied to information from another financial institution. The FTC dealer FAQ walks through these distinctions. 

Do not limit the review to a database. Ask where paper files go, which employees can open them, what is stored in email, and whether outside providers keep copies. If your team needs a starting point for everyday handling of sensitive records, our article on data privacy compliance covers the broader topic.

Does the FTC Safeguards Rule Apply to Small Businesses?

Yes, if a small business meets the rule’s coverage test. There is no general exemption just because a firm has a few employees, one location, or a small budget. The rule does provide limited relief from four specific provisions for institutions that maintain customer information concerning fewer than 5,000 consumers. That is different from being outside the rule. 

What Does the Fewer Than 5,000 Consumers Exception Change?

A qualifying institution is exempted from the rule’s provisions on:

  1. Certain written risk-assessment requirements in § 314.4(b)(1).

  2. The prescribed testing schedule in § 314.4(d)(2).

  3. A written incident response plan under § 314.4(h).

  4. An annual written report from the Qualified Individual under § 314.4(i). 

The exception does not erase the rest of the rule. Covered businesses still need an information security program suited to their operations. They still need to assess risks under the remaining provisions, monitor or test safeguards as required, oversee relevant service providers, and provide suitable security training. If you think the exception applies, record how you counted the consumers whose customer information you maintain, then check the exact provisions rather than treating “under 5,000” as a pass on compliance.

Is the 500-Consumer Breach Threshold the Same Thing?

No. The fewer-than-5,000 exception concerns four program requirements. The 500-consumer threshold concerns when a covered institution must notify the FTC after a qualifying event involving the unauthorized acquisition of unencrypted customer information. If notification is required, the rule says to notify the FTC as soon as possible and no later than 30 days after discovering the event. Neither number decides, on its own, whether the business is covered. 

Does Using an IT Vendor Change Who Must Comply?

Outsourcing IT does not transfer a covered business’s responsibility under the rule. A financial institution must take reasonable steps to select and retain service providers capable of protecting customer information, require appropriate safeguards by contract, and periodically assess those providers based on the risk they present.

For example, a tax practice may use a company to host its client files. The host may control the servers, but the tax practice still needs to know what access the host has, what the agreement requires, and how the practice checks on that arrangement. Whether the host is itself a financial institution is a separate question about the host’s own activities. 

What Should You Do Once You Know Your Business Is Covered?

Start by writing down why the rule applies. Name the covered activity, the regulator, and the customer information your business maintains. Note where that information sits, who uses it, and which service providers can reach it. This gives the person overseeing your security program something concrete to work from.

The rule calls for a Qualified Individual to oversee and carry out the information security program. That person may be an employee or work for an affiliate or service provider, subject to the rule’s conditions. Handing that role to an outside expert does not remove the institution’s responsibility. 

Once you know the rule applies, work through the full FTC Safeguards Rule requirements with the person responsible for your security program. That phrase is reserved as the link to our forthcoming pillar guide. For a look at how staff actions affect security, read what cybersecurity compliance means in daily work.

Who Needs FTC Safeguards Rule Awareness Training?

A covered institution must provide personnel with security awareness training as necessary, based on its risk assessment, and keep that training up to date as risks change. The rule also addresses the knowledge and skills of information security personnel. Training should fit the work people actually do. Someone opening customer files needs to know how to handle and report them; a manager needs to know who acts when a problem is raised; security staff need training suited to their tasks.

An auto dealership employee shows her manager a suspicious email involving customer informationConsider a dealership employee who gets an email asking her to send finance applications to a new address. She should know how to pause, check the request, and report it through her workplace process. That is a practical reason to train people before an incident occurs. Our guide to reporting phishing in Outlook covers one common way a suspicious request reaches staff.

For teams that need an introduction to the rule, our FTC Safeguards Rule Awareness Training is an approximately 80-minute, self-paced course. It includes module knowledge checks, downloadable resources, and a completion certificate. Use it to build staff awareness alongside your own policies and job-specific instruction. A course certificate does not, by itself, make an organization compliant. 

How Can You Check Whether the Rule Applies to Your Business?

Write down the financial services your business actually provides. Compare them with the rule’s definition of a financial institution, confirm which regulator has jurisdiction, and identify the customer information you maintain. Then check whether the limited fewer-than-5,000-consumers exception changes any specific duties. Keep a record of your reasoning and the next steps you assign.

If your team handles customer information and needs an introduction to its responsibilities, review the FTC Safeguards Rule Awareness Training course.

Frequently Asked Questions

01 Who Is Subject to the Gramm-Leach-Bliley Act? +

GLBA applies to financial institutions as defined under the applicable parts of the law. The FTC Safeguards Rule covers financial institutions under FTC jurisdiction that meet its activity-based definition. Check the activity and regulator rather than relying on the business’s label.

02 Which Financial Institutions Are Subject to the GLBA? +

Examples under the FTC Safeguards Rule include businesses significantly engaged in consumer lending, mortgage brokering, tax preparation, certain auto financing, check cashing, and other listed financial activities. Other financial institutions may be overseen by different regulators under GLBA.

03 What Is Not a Financial Institution Under GLBA? +

For the FTC Safeguards Rule, merely accepting another company’s credit card does not make a retailer a financial institution. The rule also gives examples involving occasional layaway and customer tabs. A business offering other financial services still needs to check those activities separately.

04 Does GLBA Apply to Business Accounts? +

The FTC rule defines a consumer in terms of an individual obtaining a financial product or service mainly for personal, family, or household use. A business account alone does not create that consumer relationship. Do not use that fact to dismiss other services the institution offers or other laws that may protect the records.

05 Who Is Considered a Customer Under GLBA? +

Under the FTC rule, a customer is a consumer with a continuing relationship with a financial institution. A person who asks about a product does not automatically become a customer. The details of the service and relationship matter.

06 Who Is Responsible for Enforcing GLBA? +

Responsibility is divided among regulators according to the institution and the applicable GLBA rules. The FTC enforces its Safeguards Rule for financial institutions under FTC jurisdiction. Check the institution’s regulator before assuming the FTC is the only authority involved.

Precision Compliance Training Built for Your Business.
We’re constantly expanding our U.S. compliance courses to fit your exact needs. Whether that’s state-specific mandates, niche industry standards, or scalable training for your workforce. Reach out today to build your custom plan.
Request Custom Training
Ready to Write Your Success Story?
Join thousands of students who have already transformed their careers. Start your learning journey today and become our next success story.