The Federal Trade Commission has added a breach reporting requirement to the Safeguards Rule. Starting May 13, 2024, non-bank financial institutions under the FTC's jurisdiction must notify the FTC within 30 days of discovering a "notification event" that involves the unencrypted information of at least 500 consumers. The Commission approved the amendment on October 27, 2023, and it was published in the Federal Register on November 13, 2023.
That gives covered businesses about six months to decide how they'll recognize a reportable event, count the affected consumers and file the notice. This post explains who is covered, what triggers a report, what goes in it, and how the change fits with the 2021 amendments that took effect earlier this year.
What does the Safeguards Rule amendment require?
The amendment adds a new paragraph, 16 CFR 314.4(j), to the rule's list of required program elements. It requires a financial institution to notify the FTC "as soon as possible, and no later than 30 days after discovery" of a notification event involving the information of at least 500 consumers.
A notification event is defined as the "acquisition of unencrypted customer information without the authorization of the individual to which the information pertains."
The rule treats an event as discovered on the first day it is known to the institution. It counts as known once any employee, officer or other agent of the institution knows about it, other than the person who committed the breach.
The requirement takes effect 180 days after Federal Register publication, which puts the effective date at May 13, 2024.
Who does the FTC Safeguards Rule apply to?
The Safeguards Rule implements part of the Gramm-Leach-Bliley Act. It applies to financial institutions within the FTC's jurisdiction, which generally means businesses engaged in financial activities that aren't overseen by a banking regulator, the SEC or another agency with its own safeguards rules.
That covers a wide range of businesses that many people wouldn't think of as financial institutions. The FTC's own examples include:
- mortgage lenders and mortgage brokers
- motor vehicle dealers that arrange financing or leasing
- payday lenders and other finance companies
- account servicers, check cashers and wire transferors
- collection agencies and credit counselors
- tax preparation firms
- non-federally insured credit unions
- investment advisors that aren't required to register with the SEC
- "finders" that bring together buyers and sellers of a product or service
If your organization fits one of these descriptions and handles customer financial information, assume the rule applies and confirm the details with counsel.
What counts as a notification event?
The definition turns on unauthorized acquisition of unencrypted customer information. Three details shape how it works in practice.
Unauthorized access is presumed to be acquisition
The rule presumes that unauthorized acquisition occurred whenever there has been unauthorized access to unencrypted customer information. The institution can overcome that presumption only if it has "reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition."
In practice, that evidence usually comes from logs. If you can't show what an intruder did or didn't take, expect to treat the access as acquisition.
Encrypted data can still be reportable
Encrypted customer information falls outside the definition, with one important exception. The rule treats customer information as unencrypted if the encryption key was accessed by an unauthorized person. Keeping keys separate from the data they protect, and monitoring access to them, directly affects whether an event is reportable.
The 500-consumer threshold applies per event
The threshold is tied to the number of consumers whose information was involved in the event, not the size of your customer base. An institution with a small customer list can still have a reportable event if at least 500 consumers are affected.
What must the notice to the FTC include?
The notice is filed electronically, using a form the FTC will make available on its website. It must include:
- the name and contact information of the reporting financial institution
- a description of the types of information involved
- the date or date range of the event, if it can be determined
- the number of consumers affected or potentially affected
- a general description of the event
- whether a law enforcement official has provided a written determination that notifying the public would impede a criminal investigation or damage national security, along with a way for the FTC to contact that official
Will the notice be made public?
The FTC has said it intends to enter notification event reports into a publicly available database. That makes the content of the notice worth drafting carefully.
A law enforcement official can ask for public posting to be delayed for up to 30 days after the notice is filed with the FTC. The official may seek up to 60 more days in writing, and any further delay requires a determination by Commission staff. These delays affect only public posting. They don't change the 30-day deadline for notifying the FTC.
Does the rule require notifying consumers?
No. The FTC considered requiring direct notice to affected consumers and decided against it, noting that every state already has some form of consumer breach notification law. Your state-law obligations to notify consumers, and in some states a state regulator or attorney general, continue alongside the new FTC requirement.
How does this fit with the 2021 Safeguards Rule amendments?
The breach reporting requirement builds on a larger update the FTC finalized in October 2021. Most of those changes were originally due in December 2022, and the FTC extended the deadline by six months. They took effect on June 9, 2023.
Those requirements included:
- designating a Qualified Individual to oversee the information security program
- a written risk assessment
- access controls, and encryption of customer information at rest and in transit over external networks
- multi-factor authentication for anyone accessing information systems
- security awareness training
- oversight of service providers
- a written incident response plan
- continuous monitoring, or annual penetration testing and vulnerability assessments every six months
- a written annual report to the board of directors or other governing body
Institutions that maintain customer information on fewer than 5,000 consumers are exempt from a few of those requirements, including the written risk assessment, the written incident response plan and the annual board report. That exemption does not extend to the new reporting requirement. A smaller institution must still notify the FTC if an event involves at least 500 consumers.
Key Safeguards Rule dates
| Date | Milestone |
|---|---|
| June 9, 2023 | Most 2021 Safeguards Rule requirements took effect |
| October 27, 2023 | FTC approved the breach reporting amendment |
| November 13, 2023 | Amendment published in the Federal Register |
| May 13, 2024 | Breach reporting requirement takes effect |
How should covered businesses prepare?
The six months before the effective date are enough time to get ready, but only if the work starts now.
Update the incident response plan
Add an explicit step for deciding whether an event is an FTC notification event, who makes that call, and who files the notice. Record the discovery date for every incident, since the 30-day clock runs from discovery.
Know where customer information lives
You can't count affected consumers if you don't know which systems hold customer information. The data inventory work many institutions did for the 2021 amendments is the starting point. Check that it's current.
Review encryption and key management
Confirm which systems hold customer information unencrypted, and where encryption keys are stored relative to the data. Encryption only takes an event out of scope if the key wasn't accessed.
Make sure logging supports a decision
Because unauthorized access is presumed to be acquisition, your logs are what let you rebut that presumption. Check that systems holding customer information record enough detail about access and data movement, and that logs are retained long enough to be useful.
Bring service providers into the process
The rule defines customer information to include records handled or maintained on your behalf. Review contracts with providers that hold your customers' data, and make sure they require prompt notice of security events so your own 30-day clock isn't consumed waiting to hear from them.
Map overlapping obligations
Build a single view of your notification duties: the FTC, state breach laws, and any other regulators or contractual partners. Different deadlines and thresholds apply, and it's easier to work that out before an incident than during one.
Frequently asked questions
Do we have to notify the FTC if fewer than 500 consumers are affected?
No. The FTC requirement applies only when at least 500 consumers are involved. State breach notification laws may still require notice to consumers or state authorities.
Does the small business exemption apply to breach reporting?
No. The exemption for institutions with customer information on fewer than 5,000 consumers covers only certain program requirements. The notification requirement applies whenever an event involves at least 500 consumers.
What if the affected data was encrypted?
Encrypted customer information isn't part of a notification event unless the encryption key was also accessed by an unauthorized person.
Can law enforcement delay our notice to the FTC?
No. A law enforcement request can delay public posting of the notice, but the institution must still notify the FTC within 30 days of discovery.
Key takeaways
- From May 13, 2024, non-bank financial institutions must notify the FTC within 30 days of discovering an event involving unencrypted information of 500 or more consumers.
- Unauthorized access is presumed to be acquisition unless you have reliable evidence otherwise, so logging matters.
- Encryption takes data out of scope only if the key stayed secure.
- The FTC intends to publish notices in a public database.
- Fold the new requirement into your incident response plan now, rather than in May.
This post summarizes the amended rule and isn't legal advice. Confirm how it applies to your business with counsel.