The FTC Safeguards Rule Covers More Businesses Than You Think

Many businesses are covered by the FTC Safeguards Rule without realizing they count as financial institutions. Here are the core requirements in plain terms.

When people hear the phrase financial institution, they picture banks. The Federal Trade Commission uses a much broader definition, and that is why so many businesses are surprised to learn the FTC Safeguards Rule applies to them. If you handle customer financial information as part of your work, you may be covered even if you have never thought of yourself as being in finance.

The revised Safeguards Rule brought its main requirements into effect in June 2023, and a breach notification requirement took effect in May 2024. Understanding whether you are covered, and what is expected, is worth an afternoon of your time.

You might be a financial institution and not know it

The Rule applies broadly to non-bank financial institutions. That category is wider than most business owners expect and includes many companies whose core business is not lending or banking at all.

  • Auto dealers that arrange financing for buyers.
  • Mortgage brokers and mortgage lenders.
  • Tax preparers and many accounting practices.
  • Other businesses that extend credit or handle customer financial data.

If your business collects, stores, or processes customer financial information, the safest assumption is that you should check your status carefully rather than assume the Rule does not apply.

The reason this catches so many businesses off guard is that the definition follows the activity, not the industry label on your door. A dealership that arranges a car loan, an accountant who prepares returns, and a broker who matches borrowers with lenders are all handling exactly the kind of customer financial information the Rule is designed to protect. If any part of what you do looks like that, it is worth an honest look rather than a hopeful assumption.

The core requirements in plain terms

The Rule asks you to build a written information security program with a handful of concrete elements. Stripped of jargon, they come down to knowing your risks and putting sensible controls in place.

  • Name a qualified individual responsible for your security program.
  • Perform a written risk assessment of where customer data lives and how it could be exposed.
  • Require multi-factor authentication for access to customer information.
  • Encrypt sensitive customer data both in storage and in transit.
  • Oversee your vendors and hold them to appropriate security standards.

Alongside these, the Rule expects you to have a written incident response plan so that a breach is met with a rehearsed process rather than improvisation.

The breach notification clock

As of May 2024, the Rule includes a breach notification requirement. Certain qualifying security incidents must be reported to the FTC within thirty days. That is a short window, which is exactly why the incident response plan matters. If you have to figure out who to call and what to say after an incident, you will lose days you cannot afford.

Build the reporting step directly into your response plan, including who makes the determination and who files the notification.

It also helps to decide in advance how you will investigate an incident, because the thirty-day clock does not pause while you gather facts. Knowing who will preserve evidence, who will assess what data was involved, and who has authority to sign off on a filing turns a stressful scramble into a sequence of steps you have already thought through.

Why the qualified individual matters

Naming a qualified individual is not just a formality. It creates clear ownership. Someone has to be accountable for the program, keep it current, and report on it to leadership. For a small business, this does not have to be a full-time hire. It can be an existing leader supported by an outside partner, as long as the accountability is real and documented.

What to do if you may be covered

Start by confirming your status honestly. If you extend credit, arrange financing, or handle customer financial data, assume you are in scope until you can show otherwise. From there, the path is practical.

  • Designate the qualified individual and put it in writing.
  • Complete a written risk assessment of your customer data.
  • Turn on multi-factor authentication and encryption where they are missing.
  • Write an incident response plan that includes the FTC reporting step.

None of these steps are exotic. They are the same disciplines that protect any well-run business, formalized and written down. A managed services partner can help you sequence this work so that you meet the requirements without disrupting how you serve your customers.