Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

FTC Safeguards Rule penalties explained

FTC Safeguards Rule Penalties: The Complete WISP Enforcement Guide

FTC Safeguards Rule penalties are misunderstood in both directions: the Rule itself, 16 CFR Part 314, contains no penalty provision, and the Gramm-Leach-Bliley Act sections it implements — 501 and 505(b)(2) — give the Federal Trade Commission enforcement authority rather than a fine schedule.

Yet the consequences of failing to keep a written information security plan are real, because the FTC enforces the Rule under section 5 of the FTC Act, and the path runs from an investigation to a consent order with years of compliance obligations, and from there to civil penalties of up to $53,088 per violation — the amount set by 16 CFR 1.98 for penalties assessed after 17 January 2025 — for every violation of that order, with each day of a continuing violation a separate violation.

Around the federal route sit the others: the IRS’s authority over tax professionals who must have a WISP, state attorneys general enforcing state safeguards laws and breach statutes, and private litigation after a breach. This guide sets out how enforcement actually works, what a consent order contains, when civil penalties arise and how they are calculated, the state and IRS layers, what a breach adds, and the compliance failures that have drawn FTC action.

FTC Safeguards Rule penalties: how enforcement actually works
No fine in the Rule → FTC Act section 5 investigation → complaint and consent order (20-year obligations, assessments, reporting) → civil penalties for order violations: up to $53,088 per violation (16 CFR 1.98, from 17 Jan 2025), each day a separate violation → plus IRS action on tax professionals, state AG enforcement, private litigation after a breach.

FTC Safeguards Rule penalties: what the Rule and the Act actually say

Instrument What it provides Penalty content
16 CFR Part 314, the Safeguards Rule Standards for safeguarding customer information: the information security program and its elements in 314.4 None. The Rule sets requirements; it contains no penalty section
GLBA sections 501 and 505(b)(2) Section 501 states the policy of protecting consumers’ nonpublic personal information and directs agencies to establish safeguards standards; section 505 assigns enforcement, giving the FTC jurisdiction over financial institutions not regulated by another agency Enforcement authority; no fixed fines for Safeguards Rule violations
FTC Act section 5 Prohibits unfair or deceptive acts or practices; the FTC’s general enforcement tool Administrative complaints and orders; civil penalties for violating an order or a rule with penalty authority
16 CFR 1.98 Inflation-adjusted civil penalty amounts $53,088 per violation under FTC Act sections 5(l) and 5(m)(1)(A)–(B), for penalties assessed after 17 January 2025

The consequence for planning is that FTC Safeguards Rule penalties start with an order, not a fine: a first Safeguards Rule failure rarely produces a fine; it produces an order. The fine follows a failure to comply with the order. Our guide to who the FTC Safeguards Rule applies to covers the institutions within the FTC’s jurisdiction.

How an FTC Safeguards Rule enforcement action runs

  1. Trigger. A reported breach, a notification under 314.4(j), a consumer complaint, a referral from a state or the IRS, or a sweep of a sector.
  2. Investigation. A civil investigative demand for the written program, the risk assessment, the Qualified Individual’s designation and reports, testing results, service-provider contracts, training records and incident records — the ten elements of 314.4, in documents.
  3. Complaint. Alleging violations of the Safeguards Rule and, usually, unfair or deceptive practices under section 5 — for example, privacy statements that promised safeguards the company did not have.
  4. Consent order. The typical outcome: an order lasting twenty years requiring a comprehensive information security program, biennial independent assessments by a qualified assessor for ten or twenty years, annual certifications by a senior officer, breach reporting to the FTC, record-keeping and compliance reporting.
  5. Civil penalties. Only where an order or a penalty-bearing rule is violated: up to $53,088 per violation, each day of a continuing violation counted separately, sought in federal court.
  6. Monetary relief in the complaint. Where deception is alleged, the FTC may seek redress; some settlements have included payments to consumers or the Treasury.

FTC Safeguards Rule penalties beyond the fine: what an order costs

Order obligation Typical duration Practical cost
Comprehensive information security program 20 years Everything the Rule requires, documented to the order’s standard, with the FTC entitled to inspect
Independent assessments Every two years for 10–20 years A qualified third-party assessor’s engagement each cycle
Annual certification Annually for the order’s term A senior officer certifies compliance personally
Incident reporting For the order’s term Report specified security events to the FTC within days
Compliance reports and record-keeping For the order’s term Reports on demand; records retained for years
Order violations Civil penalties up to $53,088 per violation per day

The assessments and certifications are where a small institution feels the order most: a practice that could have kept a written program for a few thousand dollars a year pays for an external assessor every two years for a decade or two.

FTC Safeguards Rule penalties from the other enforcers

Enforcer Basis What it can do
IRS The IRS states that federal law requires tax and accounting professionals to create and maintain a written information security plan; a WISP is part of the PTIN and e-file provider expectations Action against a preparer’s e-file authorisation; referral to the FTC; the practical loss of the ability to file
State attorneys general State safeguards laws — Massachusetts 201 CMR 17.00 and others — and state breach notification statutes; some states enforce GLBA-type standards directly Investigations, settlements, civil penalties under state law
State insurance regulators The NAIC Insurance Data Security Model Law as adopted by states, for insurance licensees Licence action and penalties
Private plaintiffs Negligence and consumer protection claims after a breach; class actions Damages and settlements, often larger than any regulatory penalty
Contract counterparties Client agreements and professional liability policies that assume a compliant program Termination; denied claims

Our guide to Massachusetts 201 CMR 17.00 covers the state rule most often enforced alongside the federal one.

What a breach adds to FTC Safeguards Rule penalties

Since 13 May 2024, 314.4(j) requires notice to the FTC within 30 days of discovering a notification event that affects 500 or more consumers. A breach therefore does three things at once: it creates a federal notification obligation whose breach is itself a Rule violation; it triggers state breach statutes with their own deadlines and, in some states, penalties; and it produces the evidence — the risk assessment that was never written, the MFA that was never turned on — on which an FTC complaint is built. Our guide to FTC Safeguards Rule breach notification covers the 500-consumer rule.

The failures that draw FTC Safeguards Rule action

  • No written program at all. The most common allegation against small institutions.
  • No risk assessment. Safeguards chosen without the written assessment 314.4(b) requires above five thousand consumers.
  • No Qualified Individual, or one in name only. Our guide to the Qualified Individual covers the designation.
  • Missing technical safeguards. No multi-factor authentication, unencrypted customer information, no access controls, no logging — the 314.4(c) list.
  • Service providers unmanaged. No contracts requiring safeguards, no assessment of the providers holding customer data.
  • Privacy promises not kept. A privacy notice describing protections that did not exist — the section 5 deception count that accompanies most Safeguards complaints.
  • Breach notification missed. A 314.4(j) event unreported within 30 days.

Frequently asked questions

What are the penalties for violating the FTC Safeguards Rule?
The Rule contains none. The FTC enforces it under section 5 of the FTC Act: an investigation, a complaint and typically a consent order with twenty years of programme, assessment, certification and reporting obligations. Civil penalties — up to $53,088 per violation under 16 CFR 1.98 for penalties assessed after 17 January 2025, each day of a continuing violation counted separately — apply to violations of such an order.

Can the FTC fine a company for a first Safeguards Rule violation?
Generally not directly; the first action is an order. Civil penalties follow violations of an order or of a rule that carries penalty authority, and the FTC may also seek monetary relief where it alleges deception.

How much is the civil penalty per violation?
$53,088 per violation under FTC Act sections 5(l) and 5(m)(1), as adjusted for inflation in 16 CFR 1.98 for penalties assessed after 17 January 2025; the amount is adjusted periodically and each day of a continuing violation is a separate violation.

Does the IRS penalise tax preparers without a WISP?
The IRS states that federal law requires tax and accounting professionals to maintain a written information security plan and treats it as part of a preparer’s obligations; the practical consequences run through the preparer’s e-file authorisation and referral to the FTC rather than a fixed IRS fine.

What costs more, the fine or the order?
For most institutions the order: twenty years of programme obligations with independent assessments every two years and annual senior-officer certifications, plus the breach litigation that usually accompanies the case.

Where this leaves you

Read the FTC Safeguards Rule penalties as an order first and a fine second: the Rule sets requirements with no fine attached, the FTC Act turns a failure into a twenty-year consent order with assessments and certifications, and $53,088 per violation per day attaches to breaking that order — with the IRS, the states and the plaintiffs’ bar waiting behind — which is why a written program that satisfies the ten elements is cheaper than any of them.

References

More on WISP and the Safeguards Rule

The ten-element WISP, the risk assessment, the Qualified Individual designation, the service-provider oversight procedure and the incident response and FTC notification procedures are in the WISP Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.