The FTC Safeguards Rule applies to far more businesses than the words “financial institution” suggest, and that mismatch is why many owners find out they are covered during a breach investigation instead of before one. If your company handles customer financial data — even as a by-product of what you actually sell — the answer comes from the regulation’s definition, not from your instinct about what industry you are in.
The rule is formally the Federal Trade Commission’s Standards for Safeguarding Customer Information, codified at 16 CFR Part 314 and issued under the Gramm-Leach-Bliley Act (GLBA). It took effect in 2003, was substantially rewritten in 2021, and was amended again in 2023 to add breach reporting, which took effect in May 2024. This guide walks through the coverage test, the business types the FTC names, the businesses it excludes, and the partial exemption that changes what smaller firms actually have to do.
Who does the FTC Safeguards Rule apply to?
Coverage comes down to a two-part test, and you have to fail both parts to stay outside the rule.
Part one: are you a “financial institution”? Section 314.1(b) says an entity is a financial institution if it is engaged in an activity that is “financial in nature” or incidental to such financial activities, as described in section 4(k) of the Bank Holding Company Act of 1956 (12 U.S.C. § 1843(k)). The definition adds that an institution significantly engaged in those activities is a financial institution. Notice what is absent: any reference to industry labels, licensing, or how you describe yourself on your own website. What matters is the activity.
Part two: is another regulator already responsible for you? The FTC Safeguards Rule reaches only financial institutions that are subject to the FTC’s jurisdiction and that are not subject to another regulator’s enforcement authority under section 505 of the GLBA (15 U.S.C. § 6805). That second condition is what removes banks, federally insured credit unions, SEC-registered investment advisers and state-regulated insurers from the FTC’s list — not because they are unregulated, but because someone else has them.
The practical result is that the FTC Safeguards Rule is the data security regulation for the non-bank financial sector: the auto dealer, the mortgage broker, the collection agency, the CPA firm. These are exactly the businesses least likely to employ a security team.
The 13 business types the FTC Safeguards Rule names
Section 314.2(h) works by example, and the FTC’s own compliance guide highlights 13 kinds of entity that qualify as financial institutions. If your business appears on this list, the analysis is effectively over.
| Business type | Why it is covered |
|---|---|
| Mortgage lenders | Extending credit is a listed financial activity |
| Mortgage brokers | Arranging credit on behalf of others |
| Payday lenders | Short-term consumer lending |
| Finance companies | Consumer and commercial lending |
| Account servicers | Servicing loans for lenders |
| Check cashers | Cashing checks for a fee |
| Wire transferors | Transmitting money |
| Collection agencies | Collecting consumer debts |
| Credit counselors and other financial advisors | Advising consumers on their finances |
| Tax preparation firms | Handling financial records to prepare returns |
| Non-federally insured credit unions | Outside NCUA enforcement, so inside the FTC’s |
| Investment advisers not required to register with the SEC | State-registered and exempt advisers |
| Finders | Added in 2021: firms that bring buyers and sellers together and let the parties negotiate |
The regulation itself goes further with worked examples. An automobile dealership that leases cars on a non-operating basis for an initial term of at least 90 days is a financial institution with respect to its leasing business. A personal property or real estate appraiser is covered because appraisal is a listed financial activity. A career counselor is covered when it specializes in serving people employed by or seeking work with financial organizations. And a retailer that issues its own credit card directly to consumers is covered, because extending credit that way shows it is significantly engaged in lending.
Businesses the FTC Safeguards Rule does not cover
Section 314.2(h) also gives four examples of entities that are not significantly engaged in financial activities:
- A retailer whose only means of extending credit are occasional “lay away” and deferred payment plans, or accepting credit cards issued by others.
- A retailer that merely accepts payment in cash, checks, or credit cards it did not issue.
- A merchant that merely allows an individual to “run a tab”.
- A grocery store that merely lets customers cash a check, or write a check for more than the purchase and take the difference in cash.
The dividing line in every one of those examples is whether the credit or money-movement function is a real part of the business or an incidental convenience. Accepting Visa does not make you a lender. Issuing your own card does.
The second exclusion is jurisdictional rather than definitional. Banks, savings associations, federally insured credit unions, SEC-registered broker-dealers and investment advisers, and insurers supervised by state insurance authorities sit outside this rule because GLBA section 505 assigns them to other enforcers. They face equivalent obligations under their own regimes.
The 5,000-consumer exemption in the FTC Safeguards Rule
This is the most misread provision in the regulation. Section 314.6 reads, in full: “Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.”
That is a partial exemption from four specific requirements. It is not an exemption from the rule. Here is what it does and does not release you from.
| Requirement | Under 5,000 consumers | 5,000 or more |
|---|---|---|
| Written risk assessment — 314.4(b)(1) | Not required in writing | Required |
| Continuous monitoring, or annual penetration testing plus six-monthly vulnerability scans — 314.4(d)(2) | Not required | Required |
| Written incident response plan — 314.4(h) | Not required | Required |
| Annual written report to the board — 314.4(i) | Not required | Required |
| Designated Qualified Individual — 314.4(a) | Required | Required |
| Written information security program — 314.3 | Required | Required |
| Access controls, encryption, MFA, secure disposal — 314.4(c) | Required | Required |
| Security awareness training — 314.4(e) | Required | Required |
| Service provider oversight — 314.4(f) | Required | Required |
| Breach reporting to the FTC — 314.4(j) | Required | Required |
Count consumers rather than active customers, and count every record you maintain — including information held on your behalf by a service provider. Firms that outsource document storage routinely undercount.
What the FTC Safeguards Rule requires once you are covered
Section 314.4 sets out nine elements. In sequence: designate a Qualified Individual to run the program; conduct a risk assessment; implement safeguards to control the risks you found; monitor and test those safeguards; train your staff; oversee your service providers; keep the program current; write an incident response plan; and have the Qualified Individual report to your board or a senior officer at least annually.
The safeguards in element three are the concrete ones: periodic access reviews, a data inventory, encryption of customer information at rest and in transit, assessment of the apps you build or buy, multi-factor authentication for anyone accessing customer information, secure disposal no later than two years after last use, change management, and logging of authorized user activity. Where encryption or MFA is not feasible, the Qualified Individual can approve equivalent controls — but the approval has to be in writing.
All of it has to be documented in a written information security program that is appropriate to your size, your activities and the sensitivity of the data. Our written information security plan template maps each documented element to the section of the rule it satisfies.
Breach reporting under the FTC Safeguards Rule
Section 314.4(j) requires you to notify the FTC as soon as possible, and no later than 30 days after discovery, of a “notification event” — a security breach involving the unauthorized acquisition of at least 500 consumers’ unencrypted information. Encrypted data counts as unencrypted if the encryption key was also accessed. Unauthorized access is treated as unauthorized acquisition unless reliable evidence shows acquisition did not and could not reasonably have occurred.
Reports go through the FTC’s online form, which asks for the company name, the start and end dates of the event, the number of consumers affected, the types of information involved, and a short summary. Two things catch people out: your report may be made public, and you are expected to file with what you know and update later rather than wait for a complete picture. If law enforcement has asked you to hold the details back, there is a box to request delay.
This obligation applies whether or not you qualify for the 5,000-consumer exemption.
How to settle the question this week
- List your revenue-generating activities, not your industry. For each one, ask whether it involves extending credit, moving money, servicing accounts, appraising property, preparing returns, or advising consumers on their finances.
- Check for another regulator. If a federal banking agency, the SEC, the NCUA or a state insurance authority already supervises you under GLBA section 505, this is not your rule.
- Count the consumers whose information you maintain, including at service providers, to decide whether section 314.6 applies to you.
- Name a Qualified Individual and start the written program. That is required at every size, and it is the first thing anyone will ask you for.
If step four is where you are stuck, our WISP Toolkit gives you 74 editable FTC Safeguards Rule templates for $99 — the written program, risk assessment, incident response plan, Qualified Individual appointment and board report included. Firms that prepare returns should also read our breakdown of the 10 requirements for tax preparers, and one-person practices will want the WISP for a sole practitioner.
FTC Safeguards Rule FAQ
Does the FTC Safeguards Rule apply to CPA and accounting firms?
Yes, where the firm prepares tax returns or provides financial advisory services. Tax preparation firms are one of the 13 examples the FTC lists, and accounting firms that collect financial information in order to provide financial services are covered non-bank financial institutions.
Are car dealerships covered by the FTC Safeguards Rule?
Generally yes. The regulation gives the explicit example of a dealership that leases vehicles on a non-operating basis for an initial term of at least 90 days, and dealerships that arrange consumer financing are extending or brokering credit. Most franchise dealers are covered on both counts.
Does it apply to businesses outside the United States?
It reaches financial institutions subject to the FTC’s jurisdiction. A non-US firm offering covered financial products or services to US consumers can fall within that jurisdiction, so location alone is not a defense. Take legal advice on your specific facts.
What happens if you ignore the FTC Safeguards Rule?
The FTC enforces the rule directly. Enforcement has historically produced consent orders imposing mandated security programs, independent third-party assessments running for years, and monetary relief. Because the available penalties depend on the statute invoked and are adjusted for inflation annually, check current FTC guidance or ask counsel rather than relying on a headline figure.
Is a written program required below 5,000 consumers?
Yes. Section 314.6 exempts smaller firms from the written risk assessment, the monitoring and penetration testing requirement, the written incident response plan and the annual board report — but not from maintaining a written information security program, a Qualified Individual, encryption, MFA, training or service provider oversight.
Where is the official text?
The regulation sits at 16 CFR Part 314. The FTC also publishes a plain-language small entity compliance guide, FTC Safeguards Rule: What Your Business Needs to Know, which is the best starting point if you are not a lawyer.
This article is general information about the FTC Safeguards Rule, not legal advice. Confirm your coverage and obligations with qualified counsel.