FTC Safeguards Rule breach notification became a federal obligation on 13 May 2024, when 16 CFR 314.4(j) took effect: a financial institution that discovers a notification event involving the information of at least 500 consumers must notify the Federal Trade Commission as soon as possible and no later than 30 days after discovery, electronically, on the FTC’s form, with six specified items.
The definitions decide everything. A notification event is the acquisition of unencrypted customer information without the authorisation of the individual it pertains to — information counts as unencrypted if the key was accessed by an unauthorised person, and unauthorised acquisition is presumed from unauthorised access unless the institution has reliable evidence that acquisition did not and could not reasonably have occurred.
Discovery is deemed on the first day the event is known to any employee, officer or agent other than the person who committed the breach, so the 30-day clock starts when a receptionist notices, not when the Qualified Individual is told. The 500-consumer threshold decides whether the FTC is notified, not whether the incident is a breach — state breach statutes and the institution’s own incident response plan apply from the first consumer. This guide sets out the definitions, the 500 and 30-day rules with the law-enforcement delay, the six content items, how consumers are counted, the state and IRS layers that run alongside, and the procedure a practice needs before the first event.

FTC Safeguards Rule breach notification: the definitions that decide it
| Term (16 CFR 314.2 and 314.4(j)(2)) | Definition | Consequence |
|---|---|---|
| Notification event | Acquisition of unencrypted customer information without the authorisation of the individual to which the information pertains | Acquisition, not mere exposure, is the trigger — but see the presumption |
| Unencrypted | Customer information is considered unencrypted if the encryption key was accessed by an unauthorised person | Encryption at rest is a defence only while the key is safe |
| Presumption of acquisition | Unauthorised acquisition is presumed to include unauthorised access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorised acquisition | Access is treated as acquisition unless the institution can prove otherwise — logs, forensics |
| Discovery | The event is treated as discovered on the first day it is known to you; you are deemed to know if it is known to any person, other than the person committing the breach, who is your employee, officer or other agent | The clock starts on the first staff member’s knowledge |
| Customer information | Nonpublic personal information about a customer, in any form, handled or maintained by or on behalf of the institution | Includes information held by service providers |
| Consumer | An individual who obtains a financial product or service for personal, family or household purposes, or that individual’s legal representative | Each individual counts; applicants count even if declined |
Our guide to who the FTC Safeguards Rule applies to covers which institutions carry the obligation.
FTC Safeguards Rule breach notification: the 500-consumer rule and the 30-day clock
| Element | Rule | Practice |
|---|---|---|
| Threshold | The notification event involves the information of at least 500 consumers | Count individuals whose information was acquired; below 500 there is no FTC notice, but the incident is still a security event under 314.4(h) and state law |
| Deadline | As soon as possible, and no later than 30 days after discovery | The 30 days is an outer limit; ‘as soon as possible’ is the standard |
| Method | Electronically, on a form located on the FTC’s website | The FTC’s online notification form |
| Law-enforcement delay | A law enforcement official may request an initial delay of up to 30 days from the date notice was provided to the FTC, extendable for up to 60 more days if sought in writing; further delay only if Commission staff determine disclosure would still impede an investigation or damage national security | The delay concerns public disclosure by the FTC of the notice, requested through the law-enforcement item in the form; the institution’s notice to the FTC is still made |
The six content items of an FTC Safeguards Rule breach notification
| Item | Content | Where it comes from |
|---|---|---|
| (i) | The name and contact information of the reporting financial institution | The institution’s record |
| (ii) | A description of the types of information involved in the notification event | The data inventory and the forensic scope |
| (iii) | If possible to determine, the date or date range of the notification event | Logs and forensics |
| (iv) | The number of consumers affected or potentially affected | The consumer count — see below |
| (v) | A general description of the notification event | The incident record |
| (vi) | Whether any law enforcement official has provided a written determination that notifying the public would impede a criminal investigation or cause damage to national security, and a means for the FTC to contact the official | The law-enforcement liaison |
Counting consumers
The 500 threshold is reached faster than most practices expect. Spouses and dependants on a joint return are separate individuals; prior-year clients whose records are retained still count; applicants who were declined count; and records held by a service provider on the institution’s behalf count. A tax practice filing 900 returns can hold information on 2,500 or more consumers, so a compromise of its client files is a 314.4(j) event by a wide margin. The count for item (iv) is affected or potentially affected — an institution that cannot bound the intrusion reports the population that could have been acquired. Our guide to the FTC Safeguards Rule for tax preparers covers the counting for a practice.
The obligations that run alongside FTC Safeguards Rule breach notification
| Obligation | Trigger and clock | Relationship to 314.4(j) |
|---|---|---|
| Incident response plan — 314.4(h) | Any security event materially affecting confidentiality, integrity or availability; no threshold | The plan is where the notification-event determination and the FTC notice are made; exempt as a written document below 5,000 consumers, but the response is still required |
| State breach notification statutes | All fifty states; triggers, definitions of personal information, deadlines (from 30 to 60 days or ‘without unreasonable delay’) and attorney-general notices vary; some have their own thresholds | Independent of the federal notice; a 300-consumer event may require state notices and no FTC notice |
| Notice to affected consumers | Not required by 314.4(j); required by most state statutes | The federal form asks whether it was given |
| IRS — tax professionals | Report data theft to the IRS Stakeholder Liaison; the IRS states federal law requires a WISP | Parallel reporting for preparers |
| Service-provider incidents | Contracts under 314.4(f) should require the provider to notify the institution promptly | The institution’s discovery is deemed when its agent knows — a provider that is an agent starts the clock |
| Consent orders | Institutions under FTC orders have their own reporting terms | Usually shorter than 30 days |
Our guide to FTC Safeguards Rule penalties covers what a missed notice adds to an enforcement case.
The FTC Safeguards Rule breach notification procedure to have before the first event
- Write the notification-event test into the incident response plan. Was customer information accessed; was it unencrypted or was the key accessed; can we show reliable evidence that acquisition did not occur; how many consumers — with the presumption applied honestly.
- Define discovery and log it. The first day any employee, officer or agent knew, recorded by the Qualified Individual, because the 30 days runs from that date and not from escalation.
- Make reporting internally blame-free. The deemed-discovery rule punishes delayed escalation, so staff must report suspected events immediately; a no-blame policy is a compliance control.
- Keep a live consumer count. The data inventory under 314.4(c) should be able to produce the number of consumers whose information sits in each system.
- Pre-draft the six items. A form with items (i) and (vi) filled in advance and fields for the others.
- Map the state statutes. For every state where consumers reside: definition, deadline, attorney-general notice, consumer notice content.
- Put the clock in provider contracts. Hours, not days, for a provider to notify the institution.
- Rehearse. One tabletop a year that runs the count, the discovery date, the form and the state notices.
Frequently asked questions
When must a financial institution notify the FTC of a breach?
Under 16 CFR 314.4(j), effective 13 May 2024: when a notification event — unauthorised acquisition of unencrypted customer information — involves the information of at least 500 consumers, as soon as possible and no later than 30 days after discovery, electronically on the FTC’s form.
What is a notification event?
The acquisition of unencrypted customer information without the authorisation of the individual it pertains to. Information is unencrypted if the key was accessed; unauthorised access is presumed to be acquisition unless the institution has reliable evidence that acquisition did not and could not reasonably have occurred.
When does the 30-day clock start?
On the first day the event is known to any employee, officer or agent of the institution other than the person committing the breach — not when the Qualified Individual or management is told.
Do breaches under 500 consumers have to be reported?
Not to the FTC under 314.4(j). They remain security events under the incident response plan and may require state breach notices, consumer notices and, for tax preparers, IRS reporting.
Must consumers be notified under the Safeguards Rule?
314.4(j) requires notice to the FTC only; it asks whether consumers were notified. Consumer and attorney-general notices come from state breach statutes, which apply alongside.
Where this leaves you
Build FTC Safeguards Rule breach notification into the incident response plan as a test, a date and a form: apply the acquisition presumption honestly, log discovery from the first employee’s knowledge, keep a consumer count that can answer item (iv), pre-draft the six items, map the state statutes that apply from the first consumer, and rehearse — because the 30 days runs from a date the institution does not control and the 500 threshold arrives sooner than a practice’s client list suggests.
References
- 16 CFR Part 314 — Standards for Safeguarding Customer Information (eCFR) — Sections 314.2 (definitions), 314.4(j) and 314.5 (effective date).
- FTC — Gramm-Leach-Bliley Act business guidance — The FTC’s Safeguards Rule guidance and notification form.
More on WISP and the Safeguards Rule
- FTC Safeguards Rule breach notification — you are here
- The written information security plan: 10 elements
- Who the FTC Safeguards Rule applies to
- The Qualified Individual
- FTC Safeguards Rule penalties
- The FTC Safeguards Rule for tax preparers
The incident response plan with the notification-event test, the discovery log, the consumer-count worksheet, the FTC notification form template with the six items and the state breach-law matrix are in the WISP Toolkit, or start with the free templates.