← Back to all tech guides
🔒 Small Business

The FTC Safeguards Rule: Does It Apply to You?

Last verified: October 2026

Who the Rule May Catch'Financial institution' is broader than banksWhy coveredAlso seeTax preparersHandle tax dataOur WISP guideAuto dealersArrangefinancingIf they financeMortgage brokersArrange loansLenders tooCollection agencyHandle financesCheck casherstooWhether you're covered is a legal question -- confirm with an attorney.
Who the rule may catch — 'financial institution' is broader than banks.
What the Program NeedsThe pieces the rule expectsIn plain termsExampleQualified personOne person ownsitOften the ownerSafeguardsMFA, encryptionAccess, backupsOversightMonitor + testTrain, vendorsIncident planWho to callThe 30-day clockCore amendments took effect June 9, 2023.
Must you notify the FTC? The breach duty and its 30-day clock.

The FTC Safeguards Rule requires certain businesses — 'financial institutions,' defined far more broadly than banks — to keep a written security program and report some breaches. Does it apply to you? Here's how to tell. Want help with the safeguards? My number is (330) 200-8042.

The Rule
16 CFR Part 314 (GLBA)
Who
Broad 'financial institutions'
Breach Duty
FTC, within 30 days
Not
Legal advice

The Safeguards Rule, at a Glance

The FTC Safeguards Rule (16 CFR Part 314, under the Gramm-Leach-Bliley Act) requires certain businesses to keep a written information security program. The surprise is who counts: 'financial institution' is defined broadly and catches tax preparers, accountants, auto dealers that arrange financing, mortgage and consumer lenders, collection agencies, and more. A compliant program needs a named Qualified Individual, a risk assessment, access controls, encryption, MFA, monitoring, training, vendor oversight, and an incident-response plan. Core amendments took effect June 9, 2023, and a breach-notification duty (effective May 13, 2024) requires notifying the FTC within 30 days of an event involving 500+ consumers' unencrypted information. Whether you're covered is a legal question — confirm with the FTC's guidance or an attorney. There's a printable 29-page version up top.

Common Questions

1 I'm not a bank — how could this rule apply to me?

Because 'financial institution' is defined broadly. It catches businesses significantly engaged in financial activities — tax preparers, accountants, mortgage and consumer lenders, auto dealers that arrange financing, collection agencies, and more. If you handle customers' financial information as part of your service, ask whether you're covered.

2 How do I know for sure whether I'm covered?

You confirm it with the FTC's own guidance and, for a definite answer, an attorney who knows the rule. Whether it applies is a legal question that depends on exactly what your business does — a guide can tell you when to ask, but not give the final word.

3 What does the rule actually require?

A written security program with a named Qualified Individual, a risk assessment, access controls, encryption, MFA, monitoring and testing, staff training, vendor oversight, and an incident-response plan. Most of it is what a well-run small office should do anyway.

4 What's the breach-notification duty?

Effective May 13, 2024 (16 CFR 314.4(j)), if you have a notification event involving the unencrypted information of 500 or more consumers, you must notify the FTC on its online form as soon as possible and no later than 30 days after discovering it. State laws like Ohio's may also apply.

5 I'm tiny — am I exempt?

Not exempt, but there's some relief. Institutions handling information on fewer than 5,000 consumers are excused from a few formal program elements, yet still must protect data and comply broadly, including the breach duty. An attorney can tell you exactly what you can scale back.

6 How does this relate to the tax-preparer WISP?

The tax-preparer WISP flows from this very rule — it's the slice of the Safeguards Rule aimed at tax professionals. If you prepare taxes, see our tax-preparer plan guide; the Safeguards Rule is the broader law behind it.

Would You Rather I Just Help?

I'm a tech helper, not a lawyer — so for the question of whether this rule applies to you, I'll point you to an attorney. But the safeguards it requires — MFA, encryption, access controls, monitoring, a tested backup, an incident plan — are exactly what I set up and verify for small offices. I'll make them real and leave you the proof. $99 flat for a visit, 30-day come-back-free.

🏡
In Your Home
No remote runaround. I come to you.
💵
$99 Flat
First visit, no surprise charges.
📅
30-Day Follow-Up
Included with every visit.
📍
Local
Based in Atwater — serving Portage County.

Would you rather I just do this for you?

No shame in it — plenty of folks would rather hand it off, and that's what I'm here for. I'll come to your home, set it up right, and make sure it's working before I leave. Flat $99 per visit — no jargon, no upsell, and every visit is 30-day come-back-free.

Not a hardware job? I can often fix it remotely for $49 — a secure screen-share, up to 2 hours, that you watch the whole time and can end whenever (included free for $39/mo Support Plan members, and it counts toward the $99 if it turns out I need to come out).