GLBA Safeguards Rule Update: Controls, Reporting, and Penalties

The FTC Safeguards Rule requirements obligate covered non-bank financial institutions to build a written information security program with specific technical controls, designate a Qualified Individual to run it, oversee service providers, notify the FTC of qualifying breaches within 30 days, and report annually to the board. Every element is currently in force, and civil penalties reach $53,088 per violation as of the January 2025 inflation adjustment.1Federal Trade Commission. FTC Publishes Inflation-Adjusted Civil Penalty Amounts for 2025

Which Businesses Are Covered

The rule reaches any entity the FTC treats as a “financial institution” under the Gramm-Leach-Bliley Act, which extends well past banks and credit unions. The regulation specifically names mortgage lenders, mortgage brokers, payday lenders, finance companies, check cashers, wire transferors, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, and investment advisors not required to register with the SEC.2eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information

Auto dealerships fall in when they finance vehicle purchases or lease vehicles for longer than 90 days. Colleges and trade schools that participate in federal student aid must comply as a condition of their Title IV Program Participation Agreement with the Department of Education.

The Small-Institution Carve-Out

If your business maintains customer information on fewer than 5,000 consumers, four provisions drop away: the detailed written risk assessment criteria, penetration testing and vulnerability assessments, the written incident response plan, and the annual board report.3eCFR. 16 CFR 314.6 – Exceptions Everything else still applies, including the written program, the Qualified Individual, access controls, MFA, and encryption. The 5,000 threshold counts every consumer whose data you hold, not just active customers.

The Written Information Security Program

Every covered institution must develop, implement, and maintain a written information security program tailored to its size, complexity, and the sensitivity of the data it handles.4Federal Trade Commission. Gramm-Leach-Bliley Act The program has to sit on top of a formal, written risk assessment that identifies foreseeable internal and external threats to the security, confidentiality, and integrity of customer information.5eCFR. 16 CFR 314.4 – Elements

The risk assessment is not a one-time exercise. It must document the criteria your organization uses for evaluating and categorizing risks, and it needs to be revisited when operations change or new threats emerge. Every safeguard flows from this document, so a thin risk assessment undermines the whole program. Regulators tend to start here when they investigate.

Required Technical Controls

The updated rule prescribes specific controls rather than leaving “reasonable security” to interpretation.

Access Controls

The program must authenticate and permit only authorized users to reach customer information, and it must limit each user’s access to only the data they need to do their job.5eCFR. 16 CFR 314.4 – Elements Role-based access with regular reviews is the practical answer. A customer service representative should not have the same reach into the data as a database administrator.

Multi-Factor Authentication

MFA is required for any individual accessing any information system that contains customer data. There is one exception: your Qualified Individual can approve in writing the use of a different access control that is equally secure or more secure.5eCFR. 16 CFR 314.4 – Elements The written approval must explain why the alternative is equivalent. Deciding MFA is inconvenient does not qualify.

Encryption

All customer information must be encrypted both in transit over external networks and at rest in storage.5eCFR. 16 CFR 314.4 – Elements If encryption is genuinely infeasible for a particular system, a compensating control can substitute, but the Qualified Individual must review and approve it in writing. Encryption also matters heavily on the back end: the breach notification rule treats unencrypted data far more severely, so skipping encryption where it is feasible creates outsized exposure.

Testing and Monitoring

Covered institutions must regularly test or monitor the effectiveness of their safeguards, including systems designed to detect attacks or intrusions. The rule offers two paths.5eCFR. 16 CFR 314.4 – Elements

Continuous monitoring that detects vulnerability-creating changes on an ongoing basis satisfies the requirement without any fixed testing schedule. If continuous monitoring is not in place, you must run:

  • Annual penetration testing of the information systems identified as at-risk in your risk assessment.
  • Vulnerability assessments at least every six months, plus additional assessments after material changes to operations or business arrangements, or after circumstances arise that could materially affect the security program.

Results feed back into the risk assessment and drive adjustments to the safeguards.

Operational Requirements Beyond the Headlines

Several requirements sit outside the marquee technical controls and are easy to miss during compliance planning.

Data and Asset Inventory

You must identify and manage all data, personnel, devices, systems, and facilities relevant to your business operations, organized by their importance to your objectives and risk profile.5eCFR. 16 CFR 314.4 – Elements This inventory becomes the foundation for access controls, encryption decisions, and testing priorities.

Change Management

Procedures for change management have to ensure that modifications to systems, networks, or business operations do not introduce security gaps.5eCFR. 16 CFR 314.4 – Elements Deploying new software, migrating data, changing vendors, or reconfiguring the network should each pass through this process before going live.

Secure Disposal

Customer information must be securely disposed of no later than two years after the last date it was used to provide a product or service to that customer. Retention beyond that is allowed when it is necessary for legitimate business operations, required by another law or regulation, or when targeted disposal is not reasonably feasible given how the data is stored.5eCFR. 16 CFR 314.4 – Elements

Written Incident Response Plan

Institutions above the 5,000-consumer threshold must maintain a written incident response plan for security events that materially affect the confidentiality, integrity, or availability of customer information. The plan must address internal response processes, roles and decision-making authority, internal and external communications, remediation of identified weaknesses, documentation of events and responses, and post-incident evaluation of the plan itself.5eCFR. 16 CFR 314.4 – Elements A plan that has never been walked through will fail when you need it.

Service Provider Oversight

Outsourcing data handling does not outsource compliance. The rule imposes three distinct duties when service providers can access customer information.2eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information

  • Take reasonable steps to select and retain providers capable of maintaining appropriate safeguards.
  • Require by contract that providers implement and maintain safeguards consistent with the rule.
  • Periodically reassess each provider based on the risk it presents and whether its safeguards remain adequate.

If the Qualified Individual role itself is outsourced to a service provider or affiliate, that provider must maintain a security program that protects your organization in accordance with the full rule.5eCFR. 16 CFR 314.4 – Elements The FTC has emphasized that service provider contracts should build in ways to monitor the provider’s work and allow for periodic reassessment.6Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know

The Qualified Individual and Board Reporting

Every covered institution must designate a single Qualified Individual responsible for overseeing, implementing, and enforcing the information security program.5eCFR. 16 CFR 314.4 – Elements This person can be an employee or can work for an affiliate or service provider. The FTC does not require a specific degree, certification, or title; what matters is real-world knowledge suited to the organization’s circumstances.6Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know Delegating the title does not delegate the liability.

All personnel must receive security awareness training covering the risks and threats relevant to your operations. For institutions above the 5,000-consumer threshold, the Qualified Individual must report in writing at least annually to the board of directors or equivalent governing body. If your organization has no board, the report goes to the senior officer responsible for information security.5eCFR. 16 CFR 314.4 – Elements

The annual report must address the overall status of the security program and the organization’s compliance, plus material matters such as risk assessment outcomes, risk management decisions, service provider arrangements, testing results, security events, management’s responses, and recommended program changes.5eCFR. 16 CFR 314.4 – Elements It is often one of the first documents regulators request during an investigation.

Notifying the FTC of a Breach

Since May 13, 2024, covered financial institutions must notify the FTC of qualifying data breaches. Notification is required no later than 30 days after discovering a security event involving the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.7Federal Trade Commission. Safeguards Rule Notification Requirement Now in Effect

The rule presumes that unauthorized access to unencrypted customer information constitutes unauthorized acquisition unless you have reliable evidence showing that acquisition did not occur and could not reasonably have occurred. Data is considered unencrypted for this purpose if the encryption key itself was accessed by an unauthorized person. Encrypted data with properly protected keys may not trigger the notification obligation at all.

Penalties and Collateral Consequences

The FTC enforces the Safeguards Rule under its authority in the Federal Trade Commission Act. Enforcement tools include consent orders, injunctive relief, and civil monetary penalties. As of the most recent inflation adjustment in January 2025, the maximum civil penalty is $53,088 per violation, and that figure adjusts upward annually.1Federal Trade Commission. FTC Publishes Inflation-Adjusted Civil Penalty Amounts for 2025 Each day of a continuing violation can count as a separate offense, so penalties compound quickly when compliance gaps go unaddressed.

Direct FTC penalties are not the only exposure. Institutions participating in federal student aid risk their Title IV eligibility. Businesses in regulated industries may face additional scrutiny from state attorneys general or sector-specific regulators. Reputational damage from a public enforcement action or a reported breach often costs more than the fine itself.