Payments Glossary · Law & Regulation
FTC Safeguards Rule
Also called Safeguards Rule, GLBA Safeguards
A federal data security rule requiring a written information security program at businesses that are financial institutions under FTC jurisdiction.
What it is
The FTC Safeguards Rule requires covered financial institutions to develop, implement and maintain a written information security program. The term financial institution is defined broadly to cover activities that are financial in nature, and the FTC's own guidance lists examples including mortgage brokers, finance companies, wire transferors, collection agencies and tax preparers. The rule specifies program elements rather than leaving security to judgment: a designated qualified individual responsible for the program, written risk assessments, safeguards including encryption, multi-factor authentication and access controls, monitoring and testing, staff training, service provider vetting, keeping the program current, a written incident response plan, and annual reporting to the board or governing body. Customer information is defined broadly, covering any record containing nonpublic personal information about a customer, whether in paper, electronic or other form. Institutions maintaining information on fewer than 5,000 consumers receive some exemptions from specific requirements. Whether a particular payments participant is covered is a genuine legal question that depends on its activities, and it is a question for counsel rather than for a compliance blog. What is not in doubt is that the elements above constitute a defensible baseline for any business handling merchant or customer financial data.
Why it matters to your business
Even if you conclude you are not covered, the elements of this rule are the standard a customer, a partner or a plaintiff's lawyer will measure you against after an incident. Multi-factor authentication on email and financial systems, encryption of stored customer data, a documented list of who has access to what, and a written plan for who does what in the first hour of an incident are worth building regardless of your legal classification. If you handle other people's financial data in any volume, get a real answer on coverage from counsel rather than assuming. This is education, not legal advice; coverage determinations under the Safeguards Rule are legal questions.
Where it gets contested
The scope question is where the argument sits. Financial in nature is a broad phrase, and businesses that do not think of themselves as financial institutions, including some payments intermediaries, marketing firms serving lenders, and businesses offering financing at the point of sale, may fall inside it. Many have never analyzed the question. The rule also produced a real compliance market. Vendors sell Safeguards programs as packaged deliverables, and the quality varies from genuine risk assessment to a template with a company name inserted. Because the rule requires the program to be current and tested, a template purchased once and never revisited fails on its own terms. What remains unresolved for small operators is proportionality. The rule scales somewhat through the under-5,000-consumer exemptions, but the core obligations, a named responsible individual, a written risk assessment, MFA, encryption, an incident response plan, do not have a small business version, and most small firms are not meeting them.
How to check it yourself
Ask yourself who at your company is named as responsible for information security, and where the written incident response plan is stored. If neither has an answer, you do not have a program, whatever documents you may have purchased.
Receipts
Claims above that are checkable, with where to check them. Published so you do not have to take anyone's word for it.
-
The FTC Safeguards Rule requires a written program with a designated qualified individual, risk assessments, encryption and MFA, monitoring, training, service provider vetting, an incident response plan and annual reporting, with some exemptions below 5,000 consumers
ftc.gov ↗