{"id":29609,"date":"2023-12-04T18:00:43","date_gmt":"2023-12-04T12:30:43","guid":{"rendered":"https:\/\/www.getastra.com\/blog\/?p=29609"},"modified":"2026-04-14T19:17:41","modified_gmt":"2026-04-14T13:47:41","slug":"ftc-safeguards-rule","status":"publish","type":"post","link":"https:\/\/www.getastra.com\/blog\/compliance\/ftc-safeguards-rule\/","title":{"rendered":"FTC Safeguards Rule: 2023 Amendment &#038; Strategies"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Federal Trade Commission or FTC, established in 1914, was put forth by then-president Woodrow Wilson to protect consumers, investors, and businesses from anti-competition or industry monopoly. Essentially this meant promoting competition and providing more opportunities for others to enter the market sector.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.investopedia.com\/articles\/financial-theory\/10\/the-us-federal-trade-commission.asp\" target=\"_blank\" rel=\"noopener\">Federal Trade Commission\u2019s<\/a> major role in the U.S economy is helping with its smooth running. They achieve this by enforcing various laws and regulations to prevent anti-competition, deception, and unfair business practices. One such rule for the protection of consumers is the FTC safeguards rule.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This article focuses on what the FTC safeguards rule is, what the 2023 amendment means for your business, and strategies to implement the rule seamlessly. Let\u2019s dive in without further ado!&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Action_Points\"><\/span>Action Points<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The FTC Safeguards Rule is a set of standards under the Gramm-Leach-Billey Act of 1999. Its purpose is to ensure that financial institutions protect customers&#8217;s non-public personal data.<\/li>\n\n\n\n<li>The Safeguards Rule was amended in 2023 October to state that non-banking financial institutions are required to inform the FTC within 30 days of a breach if it affects 500 or more customers. <\/li>\n\n\n\n<li>The Safeguard Rule states that organizations must design and implement an information security program that addresses the size and complexity of their organization. <\/li>\n\n\n\n<li>Organizations under FTC jurisdiction must assess risks, implement safeguards, oversee service providers, and regularly monitor security measures through penetration tests. <\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Is_the_FTC_Safeguards_Rule\"><\/span>What Is the FTC Safeguards Rule?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">FTC Safeguards Rule or Standards for Safeguarding Customer Information is a set of regulations established under the Gramm-Leach-Billey Act (GLBA) of 1999. Its primary goal is to ensure the protection of consumers&#8217; personal information held by financial institutions. They are required to secure the confidentiality and security of consumers&#8217; non-public personal data.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here, banks, credit unions, insurance companies, and other companies that engage in financial activities all come under the umbrella term \u201cfinancial institutions\u201d. While non-public personal data includes social security numbers, credit history, and account numbers.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The standard was established in 2003 but underwent modification in 2021 to apace with the current trends in technology. The revised rule provides more solid guidance for businesses in terms of protecting customer data.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Gramm-Leach-Billey Act, 1999<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Gramm-Leach-Bliley Act, established in 1999,&nbsp; is also known as the Financial Services Modernization Act of 1999. It is a US federal law that governs how financial institutions handle individuals\u2019 private information. The act mandates disclosure of information-sharing practices, and implementing safeguards for sensitive data. The rules under GLBA are the Safeguards Rule, the Financial Privacy Rule, and Pretexting provisions.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Who_Does_The_FTC_Safeguards_Rule_Apply_To\"><\/span>Who Does The FTC Safeguards Rule Apply To?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As mentioned above, the FTC Safeguards Rule mostly applies to financial institutions that come under the FTC jurisdiction. Besides this, according to the Gramm-Leach-Billey Act, the finance business should also not come under any other enforcement authority of another regulator.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re wondering whether your business falls under financial institutions subject to FTC\u2019s safeguards rule, well let\u2019s clear that right up! Section 314.2 of the rule lists some examples of entities that come under the term financial institutions. They include:&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Mortgage brokers &amp; lenders<\/li>\n\n\n\n<li>Payday lenders&nbsp;<\/li>\n\n\n\n<li>Finance companies<\/li>\n\n\n\n<li>Check cashers<\/li>\n\n\n\n<li>Collection agencies<\/li>\n\n\n\n<li>Credit counselors and other financial advisors<\/li>\n\n\n\n<li>Tax preparation firms<\/li>\n\n\n\n<li>Non-federally insured credit unions,<\/li>\n\n\n\n<li>Investment advisors who aren\u2019t required to register with the SEC<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The 2021 amendments to the Safeguards Rule add a new example of a financial institution \u2013 finders. Those are companies that bring together buyers and sellers and then the parties themselves negotiate and consummate the transaction. It is also key to note that even if your company wasn\u2019t covered in the original rule, it is important to keep checking since the rule is under constant evolution.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Latest_2023_Amendment_To_FTC_Safeguards_Rule\"><\/span>Latest 2023 Amendment To FTC Safeguards Rule<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">October 2023 marked the 20-year anniversary of the Gramm-Leach-Billey Act under which the FTC Safeguards Rule came into effect. Along with this, the <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2023\/10\/ftc-amends-safeguards-rule-require-non-banking-financial-institutions-report-data-security-breaches\" target=\"_blank\" rel=\"noopener\">FTC also announced an amendment to the rule<\/a> that states that non-banking financial institutions within the FTC\u2019s jurisdiction will have to report any data breach that affects 500 or more people.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What Is It?&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The revised rule essentially focuses on notification events which are defined as the acquisition of customer information without said customer\u2019s authorization. If at least 500 individuals&#8217; information is affected, then the company in question must contact the FTC as soon as possible and within 30 days after the discovery of the breach.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The organization must then fill out a form that includes &#8211;&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Name and contact information of the organization<\/li>\n\n\n\n<li>Description of information type<\/li>\n\n\n\n<li>Specific date or date range of the breach<\/li>\n\n\n\n<li>The number of customers affected<\/li>\n\n\n\n<li>A general description of the breach.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Who Does It Affect?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Wonder\u012bng if the latest amendment is applicable to your organization? Well if your company comes under a non-banking financial institution under the jurisdiction of FTC such as mortgage brokers, payday lenders or motor vehicle dealers, then the answer is yes.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why Was It Enforced?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The amendment was placed to ensure that companies that handle such sensitive financial information are more transparent in case of a data compromise. This disclosure agreement was established in hopes of giving non-banking financial companies an added incentive to safeguard their customer data.&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"FTC_Safeguards_Rule_Requirements_For_Your_Company\"><\/span>FTC Safeguards Rule Requirements For Your Company<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If your company falls under any of the above-mentioned businesses under financial institution, the FTC requires you to maintain an information security program. The information security program must be developed, implemented, and maintained with administrative, physical, and technical safeguards to ensure that customer\u2019s non-public information is protected.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The information security program developed by your business must be par with its size and complexity. It should address the nature and scope of your business activities and ensure customer data confidentiality and security accordingly. The program should also protect against potential risks, threats, or hazards to the security of the information and protect against unauthorized access to the same.&nbsp;<\/p>\n\n\n<style>\n.newctaWrapper{\n  background-color: #f8f2e4;\n  padding: 40px;\n  border-radius: 10px;\n  margin: 20px 0px;\n}\n.ctaHead{\n  display: flex;\n  align-items: center;\n  grid-gap: 1rem;\n}\n.newctaHeading{\n  font-size: 36px;\n  font-weight: 600;\n  line-height: 1.1;\n  margin-bottom: 0px;\n  color: #403F3E;\n}\n.spanBold{\n  color: #164DB3;\n  font-weight: 700;\n}\n.ctaOne{\n  text-decoration: none;\n  background-color: #2F76F8;\n  color: #ffffff!important;\n  padding: 10px 25px;\n  border-radius: 6px;\n  font-weight: 600;\n}\n.ctaOne:hover{\n  color:#fff;\n}\n.ctaTwo{\n  text-decoration: none;\n  background-color: #24BC94;\n  color: #ffffff!important;\n  padding: 10px 25px;\n  border-radius: 6px;\n  font-weight: 600;\n}\n.ctaTwo:hover{\n  color:#fff;\n}\n.ctaBody{\n  padding-top: 40px;\n  display: flex;\n  align-items: flex-end;\n  grid-gap: 1rem;\n}\n.ctoImg{\n  height: 310px;\n  width: 300px;\n}\n@media(max-width: 768px){\n}\n@media(max-width: 576px){\n  .ctaBody{\n    flex-direction: column;\n  }\n  .ctoImg{\n     display: none;\n  }\n}\n<\/style>\n<div class=\"newctaWrapper\">\n<div class=\"ctaHead\"><img loading=\"lazy\" decoding=\"async\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2024\/08\/ceb80994-shield.png\" alt=\"shield\" width=\"58\" height=\"62\" \/>\n<p class=\"newctaHeading\">Why Astra is the best in pentesting?<\/p>\n\n<\/div>\n<div class=\"ctaBody\">\n<div>\n<ul style=\"margin: 0px 25px 25px;\">\n \t<li>We\u2019re the only company that\u00a0<span class=\"spanBold\">combines automated &amp; manual pentest<\/span>\u00a0to create a one-of-a-kind pentest platform.<\/li>\n \t<li>Vetted scans ensure<span class=\"spanBold\">\u00a0zero false positives.<\/span><\/li>\n \t<li>Our intelligent <span class=\"spanBold\">vulnerability scanner emulates hacker behavior<\/span>\u00a0&amp; evolves with every pentest.<\/li>\n \t<li>Astra\u2019s scanner helps you shift left by integrating with your CI\/CD.<\/li>\n \t<li>Our platform helps you\u00a0<span class=\"spanBold\">uncover, manage &amp; fix<\/span>\u00a0vulnerabilities in one place.<\/li>\n \t<li>Trusted by the brands\u00a0<span class=\"spanBold\">you trust<\/span>\u00a0like Agora, Spicejet, Muthoot, Dream11, etc.<\/li>\n<\/ul>\n<div class=\"ctaHead\"><a class=\"ctaOne\" href=\"https:\/\/rcl.ink\/5BDjS\" target=\"_blank\" rel=\"noopener\">Let\u2019s Talk<\/a>\n<a class=\"ctaTwo\" href=\"https:\/\/astra.sh\/pentest-service\" target=\"_blank\" rel=\"noopener\">Get Started<\/a><\/div>\n<\/div>\n<div><img decoding=\"async\" class=\"ctoImg\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2024\/08\/b262d665-cto.png\" alt=\"cto\" width=\"\" \/><\/div>\n<\/div>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Strategies_To_Implement_FTC_Safeguards_Rule\"><\/span>Strategies To Implement FTC Safeguards Rule<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">According to the FTC Safeguards Rule nine elements should be comprised within your information security program. These are strategies to implement and maintain your data security.&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>A Qualified Individual, an employee, or a service provider should implement and supervise your business\u2019 information security program.&nbsp;<\/li>\n\n\n\n<li>Conduct a <a href=\"https:\/\/www.getastra.com\/blog\/compliance\/glba\/glba-risk-assessment\/\">GLBA risk assessment<\/a> to find internal and external threats to your customer\u2019s non-public information.<\/li>\n\n\n\n<li>Design and implement safeguards to control the risks identified in the risk assessment.&nbsp;<\/li>\n\n\n\n<li>Regularly monitor and test the effectiveness of your safeguards through annual penetration tests or regular vulnerability scans.&nbsp;<\/li>\n\n\n\n<li>Train your staff and schedule regular refreshers on their responsibility in the information security program.&nbsp;<\/li>\n\n\n\n<li>Monitor your service providers, spell out clear security expectations, and build a way to monitor the provider&#8217;s work.&nbsp;<\/li>\n\n\n\n<li>Keep your information security program current by changing it based on learnings from your risk assessments, vulnerability scans, and penetration tests.<\/li>\n\n\n\n<li>Create a written incident response plan that includes the goals of the plan and internal response events to an incident.&nbsp;<\/li>\n\n\n\n<li>Your Qualified Individual should report to the Board of Directors in writing, regularly or annually providing an assessment of the company\u2019s compliance with the program.&nbsp;<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_Can_Astra_Security_Help\"><\/span>How Can Astra Security Help?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1825\" height=\"919\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2022\/10\/Astra.png\" alt=\"Astra Pentest\" class=\"wp-image-23306\" srcset=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2022\/10\/Astra.png 1825w, \/cdn-cgi\/image\/width=1536,height=773,fit=crop,quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2022\/10\/Astra.png 1536w\" sizes=\"auto, (max-width: 1825px) 100vw, 1825px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.getastra.com\/\">Astra Security<\/a> is a vulnerability assessment and penetration testing company that provides round-the-clock security testing services to assess internet-facing assets as quickly and efficiently as possible to detect vulnerabilities. <a href=\"https:\/\/www.getastra.com\/pentesting\/web-app\">Web application penetration tests by Astra Security<\/a> are carried out by seasoned professionals who have vulnerabilities in payment gateways and the information security programs of your organization.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1515\" height=\"852\" src=\"\/cdn-cgi\/image\/quality=80,format=auto,onerror=redirect,metadata=none\/https:\/\/cdn-blog.getastra.com\/2023\/02\/astra-compliance.png\" alt=\"astra compliance\" class=\"wp-image-24909\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">It offers the option to scan for specific compliances required by an organization. Compliance-specific scans provided by Astra include PCI-DSS, HIPAA, SOC2, ISO 27001, and GDPR. Once your penetration test is complete and all reported vulnerabilities are patched, an Astra Pentest certificate with a 180-day validity period is issued to certify your organization\u2019s security measures.&nbsp;<\/p>\n\n\n<div class=\"gb-container gb-container-0d16e733\">\n<div class=\"gb-container gb-container-5c89a587\">\n\n<div class=\"wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-8f761849 wp-block-group-is-layout-flex\">\n<div class=\"gb-headline gb-headline-b9454617 gb-headline-text\">See Astra\u2019s continuous Pentest platform in action.<\/div>\n<\/div>\n\n<\/div>\n\n<div class=\"gb-container gb-container-c6f37f68\">\n\n<a class=\"gb-button gb-button-c5f2ad3e gb-button-text\" href=\"https:\/\/astra.sh\/product-demo\" target=\"_blank\" rel=\"noopener\"><strong>Take a Product Tour<\/strong><\/a>\n\n<\/div>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span>Conclusion<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The FTC Safeguards Rule was implemented under the Gramm-Leach-Billey Act of 1999 to ensure that customer&#8217;s personal data is secured by organizations that come under the jurisdiction of the FTC. With the 2023 amendment to the FTC Safeguards Rule, even non-banking financial institutions such as mortgage companies, and motor vehicle dealers are supposed to inform the FTC if a breach affecting more than 500 customers occurs.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nowadays, hackers are getting more innovative in terms of hacking to obtain personal information for malicious purposes. Therefore, as an organization, it becomes your responsibility to keep up with the latest security measures to ensure such a plight does not fall on your customers.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conduct regular risk assessments, penetration tests, and vulnerability scans to ensure your company\u2019s FTC-mandated information security program is up-to-date and capable of protecting your customers&#8217; data.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"FAQs\"><\/span>FAQs<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1701405687759\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is the FTC Safeguards Rule?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>The FTC Safeguards Rule also known as the\u00a0 Standards for Safeguarding Customer Information under the Gramm-Leach-Bliley Act (GLBA), is a set of regulations that mandates financial institutions to create and maintain comprehensive information security programs to protect consumers&#8217; non-public personal information.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1701405702646\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is required under the FTC Safeguards Rule?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Financial institutions are required to develop and implement written information security programs, assess risks, implement safeguards, oversee service providers, and regularly monitor security measures through penetration tests or vulnerability assessments.\u00a0<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1701405717328\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What happens if a financial institution fails to comply?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>FTC Safeguards Rule applies to banking and non-banking financial institutions under the FTC jurisdiction. If any such company is non-compliant it may result in regulatory actions, fines, or penalties imposed by the FTC or other overseeing regulatory bodies.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The Federal Trade Commission or FTC, established in 1914, was put forth by then-president Woodrow Wilson to protect consumers, investors, and businesses from anti-competition or industry monopoly. Essentially this meant promoting competition and providing more opportunities for others to enter the market sector.&nbsp; Federal Trade Commission\u2019s major role in the U.S economy is helping with &#8230; <a title=\"FTC Safeguards Rule: 2023 Amendment &#038; Strategies\" class=\"read-more\" href=\"https:\/\/www.getastra.com\/blog\/compliance\/ftc-safeguards-rule\/\" aria-label=\"Read more about FTC Safeguards Rule: 2023 Amendment &#038; Strategies\">Read more<\/a><\/p>\n","protected":false},"author":106,"featured_media":29699,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[696,718],"tags":[],"class_list":["post-29609","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","category-glba"],"_links":{"self":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts\/29609","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/users\/106"}],"replies":[{"embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/comments?post=29609"}],"version-history":[{"count":6,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts\/29609\/revisions"}],"predecessor-version":[{"id":46464,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/posts\/29609\/revisions\/46464"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/media\/29699"}],"wp:attachment":[{"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/media?parent=29609"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/categories?post=29609"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.getastra.com\/blog\/wp-json\/wp\/v2\/tags?post=29609"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}