The FTC Safeguards Rule Explained: Does It Apply to Your Business?

By J. Mesa

Tax season puts thousands of Social Security numbers and bank account details into the hands of small firms. If you prepare tax returns, the federal government classifies you as a financial institution, and the FTC Safeguards Rule applies to you. The same holds for car dealers, mortgage brokers, and a long list of businesses that never thought of themselves as banks.

What is the FTC Safeguards Rule?

The Safeguards Rule is a federal regulation that requires certain businesses to build and maintain a written information security program that protects customer information. The Federal Trade Commission issued it under the Gramm-Leach-Bliley Act, or GLBA. The FTC updated the rule with detailed technical requirements that took effect on June 9, 2023.

Banks and credit unions answer to their own regulators. The FTC’s rule covers the non-bank financial institutions.

Who has to comply?

The rule applies to businesses that are “significantly engaged” in financial activities. Examples include:

  • Tax preparers and accounting firms that prepare returns
  • Mortgage brokers and lenders
  • Auto dealers that arrange financing or leasing
  • Payday and title lenders
  • Finance companies
  • Check cashers and wire transfer services
  • Collection agencies
  • Credit counselors and financial advisors not registered with the SEC
  • Real estate settlement and appraisal services
  • Businesses that connect borrowers with lenders, which the rule calls finders

A retailer that only accepts credit cards issued by others is not covered. A retailer that issues its own credit card is.

What counts as customer information?

Customer information means any record containing nonpublic personal information about a customer that you or your service providers handle, on paper or in electronic form. For a tax firm that means returns, W-2s, Social Security numbers, dates of birth, bank account and routing numbers, and income details. For a dealership it means credit applications, credit reports, driver’s license copies, and financing documents.

What does the Safeguards Rule require?

Your information security program must contain nine elements.

  1. Designate a Qualified Individual to run the program. This can be an employee or an outside provider. If you outsource the role, a senior person at your business still oversees it.
  2. Conduct a written risk assessment that identifies the risks to customer information and judges the safeguards you have.
  3. Design and implement safeguards to control those risks. The rule names specific ones, listed below.
  4. Monitor and test the safeguards on a regular schedule.
  5. Train your staff in security awareness.
  6. Oversee your service providers. Choose vendors that can protect the data, put security terms in the contract, and reassess them.
  7. Keep the program current as your business, your risks, and your test results change.
  8. Write an incident response plan.
  9. Report to the board or governing body in writing at least once a year. In a small firm, the Qualified Individual reports to the owner or senior officer.

What specific safeguards does the rule name?

  • Access controls that limit customer information to people who need it, with periodic review
  • An inventory of your data, devices, systems, and where the information lives
  • Encryption of customer information at rest and in transit
  • Secure development practices for any applications you build or use to handle the data
  • Multi-factor authentication for anyone accessing customer information on your systems
  • Secure disposal of customer information no later than two years after you last used it to serve the customer, unless a law or a business need requires you to keep it
  • Change management procedures
  • Logging and monitoring of user activity to detect unauthorized access

Is there an exemption for small businesses?

A partial one. If you maintain customer information on fewer than 5,000 consumers, you are exempt from four items:

  • The written risk assessment
  • Continuous monitoring, or the annual penetration test and twice-yearly vulnerability assessments
  • The written incident response plan
  • The annual written report to the board

Everything else still applies: the Qualified Individual, the safeguards, encryption, multi-factor authentication, training, vendor oversight, and secure disposal. You must still assess your risks. The exemption removes the requirement to write the assessment in the prescribed form. Writing it anyway gives you proof that you did the work.

Count carefully. The 5,000 figure covers every consumer whose information you hold, including former customers still in your files.

Who can serve as the Qualified Individual?

The rule sets no degree or certification requirement. The person needs enough real-world security knowledge to fit the size and complexity of your business. A small firm can appoint a capable office manager supported by an outside security provider, or hire a provider to fill the role. You keep the responsibility in either case.

What testing does the rule require?

Businesses above the 5,000-consumer threshold must either monitor their systems continuously or perform:

  • A penetration test once a year
  • Vulnerability assessments every six months, and after material changes

Our post on vulnerability assessments and penetration tests explains what each one involves and what it costs.

What is the breach notification requirement?

Since May 13, 2024, covered businesses must notify the FTC of a “notification event.” That means the unauthorized acquisition of unencrypted customer information involving 500 or more consumers. Report through the FTC’s online form as soon as possible, and no later than 30 days after discovery. The FTC publishes these reports.

Encrypted data counts as unencrypted if the attacker also obtained the key. State breach laws and the IRS add their own reporting duties.

What do tax preparers need to know?

The IRS ties directly into this rule.

  • Each paid preparer confirms a data security plan when renewing a Preparer Tax Identification Number.
  • That plan is a Written Information Security Plan, or WISP.
  • IRS Publication 5708 provides a WISP template built for small firms. Publication 4557 covers safeguarding taxpayer data.
  • Report client data theft to your IRS Stakeholder Liaison right away.

A WISP built from the IRS template and filled in with your real practices goes a long way toward meeting the Safeguards Rule. A template with only your firm’s name typed at the top does not.

What are the penalties for non-compliance?

The FTC can bring an enforcement action that ends in a consent order. Those orders commonly last 20 years and require outside security assessments at your expense. Violating an order brings civil penalties of more than $50,000 per violation. Individuals who run the business can be named. Beyond the FTC, you face state regulators, lawsuits from customers, and the loss of clients who trusted you with their finances.

How do I comply?

  1. Name your Qualified Individual in writing.
  2. Inventory the customer information you hold: systems, paper files, devices, and vendors.
  3. Perform and document a risk assessment.
  4. Turn on multi-factor authentication for email, tax or lending software, remote access, and cloud storage.
  5. Encrypt laptops, phones, backups, and portable drives.
  6. Limit access by role and remove former employees.
  7. Set a retention schedule and dispose of old records on time.
  8. Review vendor contracts for security terms.
  9. Train your staff, with attention to phishing aimed at tax and finance professionals.
  10. Write your incident response plan.
  11. Test, review, and report to ownership each year.

Your next step

Count the consumers in your files, current and former. That number tells you which requirements apply. Then check whether you have a written security program that matches what your office does each day. Cerberus Cybersecurity assesses small businesses against GLBA and the Safeguards Rule and writes the program documents the rule requires. See our services or contact us.