222 views 2 mins 0 comments

FTC announces new Safeguards Rule provision: Is your company up on what’s required?

In News, Legal News
October 27, 2023
FTC announces new Safeguards Rule provision: Is your company up on what’s required?

October 2023 marks the 20th anniversary of the effective date of the Gramm-Leach-Bliley Safeguards Rule. Its purpose then – and its purpose now – is to protect consumers by requiring entities covered by the Rule to “develop, implement, and maintain reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer information.” The FTC just announced an amendment to the Rule that will require non-banking financial institutions within the FTC’s jurisdiction to report data breaches affecting 500 or more people.

Threats to the security of financial data have materialized and morphed in recent years. After considering public comments and hosting a national workshop, the FTC revised the Safeguards Rule in October 2021 to strengthen protections for consumers’ information maintained by non-banking financial institutions – for example, mortgage brokers and payday lenders. Also announced was a proposed supplemental amendment to the Safeguards Rule that would require financial institutions to report certain data breaches and other security events to the FTC. The agency just approved an amendment that will require notification.

You’ll want to read the revised Rule for the specifics, but the focus is on “notification events” – defined as the “acquisition of unencrypted customer information without the authorization of the individual to which the information pertains.” If a notification event “involves the information of at least 500 consumers,” the covered entity must contact the FTC “as soon as possible, and no later than 30 days after discovery of the event” using a form on the FTC’s website. 

Here are some of the things the notice must include:

  1. the name and contact information of the financial institution;
  2. a description of the types of information involved;
  3. the date or date range of the notification event, if it’s possible to determine;
  4. the number of consumers affected; and
  5. a general description of the notification event.

The amendment to the Rule will take effect 180 days after it’s published in the Federal Register. Looking for more information about Safeguards Rule compliance? The FTC has a special page with Gramm-Leach-Bliley Act resources.

Source: Federal Trade Commission