Skip to content
RiskTemplates · The Daily Brief Tuesday, August 25, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature Regulatory Compliance

FTC Safeguards Rule: The 30-Day Breach Notification Clock Non-Banking Financial Institutions Keep Missing

The FTC Safeguards Rule requires non-banking financial institutions to notify the FTC within 30 days of a breach affecting 500+ consumers. Two years in, enforcement is still finding the same deficiencies.

By Rebecca Leung · August 22, 2026 ·
Table of Contents

TL;DR

  • If you’re a non-banking financial institution covered by GLBA, the FTC Safeguards Rule requires you to notify the FTC within 30 days of discovering a breach that exposed 500 or more consumers’ unencrypted customer information.
  • The clock runs from discovery — not from when the breach began, and not after your investigation concludes.
  • Two years into enforcement, examiners are still finding institutions without a written information security program, without a designated qualified individual, and without documented breach notification procedures.
  • This FTC notification is separate from your consumer notification obligations under state law. Both clocks can run simultaneously.

You notified your affected customers. Your legal team drafted the state AG notices. You updated your incident log.

Did you notify the FTC?

Since May 13, 2024, non-banking financial institutions covered by the Gramm-Leach-Bliley Act have been required to report security breaches to the Federal Trade Commission — not just to consumers and state authorities, but to the federal regulator itself — within 30 days of discovery. Two years in, the requirement is still catching organizations that never built it into their incident response playbooks.

If you’re a mortgage lender, payday lender, auto dealer, tax preparer, check casher, credit counselor, collection agency, or investment adviser not registered with the SEC, this requirement applies to you. It is not a banking agency requirement. Your primary federal banking regulator, if you have one, has its own 36-hour rule. This is a separate, FTC-administered obligation, and it runs on a different clock, with different content requirements, and its own penalty structure.

Who the FTC Safeguards Rule Actually Covers

The FTC’s Safeguards Rule, codified at 16 C.F.R. Part 314, applies to “financial institutions” as defined under GLBA — entities engaged in a significant financial activity. The FTC’s version covers a large swath of non-bank businesses that handle customer financial data:

  • Mortgage lenders and mortgage brokers
  • Payday lenders and short-term credit providers
  • Motor vehicle dealers that arrange or extend financing
  • Check cashers and wire transferors
  • Collection agencies
  • Credit counselors and financial advisors (outside SEC registration)
  • Tax preparation firms
  • Non-federally insured credit unions
  • Investment advisers not required to register with the SEC
  • Travel agencies operating in connection with financial services
  • Account servicers

If your business earns revenue primarily by providing financial products or services to individual consumers for personal, family, or household use, the Safeguards Rule likely applies. The coverage test is activity-based, not charter-based. A fintech lending company that is not a bank is still a financial institution under GLBA and the FTC’s rule.

One coverage question that still trips firms up: state-licensed investment advisers who are exempt from SEC registration. If you manage under the SEC registration threshold, you fall under the FTC’s Safeguards Rule, not the SEC’s Regulation S-P. Those are two separate frameworks with overlapping but distinct requirements.

What Counts as a “Notification Event”

Not every security incident triggers the FTC notification duty. The rule defines a specific threshold.

A notification event is the unauthorized acquisition of unencrypted customer information involving the data of 500 or more consumers.

Two key clarifications matter here:

On “unencrypted”: The rule treats data as unencrypted if an unauthorized person accessed or acquired the encryption key used to protect it. Technically encrypted data that was compromised along with its key is still a notification event. You cannot avoid the duty by pointing to encryption alone if the encryption was itself compromised.

On “acquisition”: The FTC does not require you to demonstrate actual harm. Unauthorized access to the data is enough if acquisition can be reasonably inferred. A successful ransomware deployment that touched systems containing customer records can meet this threshold even without proof that the attacker extracted specific files.

The 500-consumer threshold matters for distinguishing this obligation from your other breach notification duties. Many state laws have much lower thresholds — some require notification for any breach regardless of volume. Your FTC notification duty is a floor at 500, running in parallel with whatever state notification obligations apply.

The 30-Day Clock and What It Runs From

The 30-day clock begins running when you discover the notification event — the date you reasonably believe a notification event has occurred.

This is not the date the breach began. It is not the date your forensic investigation concludes. It is the date your organization reasonably should have known a notification event occurred, which typically means the date your incident response team determined (or should have determined) that 500 or more consumers’ unencrypted information was acquired without authorization.

An ongoing investigation does not toll the clock. If your IR team has sufficient evidence by Day 5 to conclude that 500+ consumers’ data was accessed, the clock started on Day 5 — not on the later date when the investigation is formally closed. This is one of the places where incident response decision documentation matters: you need a contemporaneous record of when you reached each determination, not just a final report.

Law enforcement delay: A law enforcement official can request that you delay public notification for up to 60 days if public disclosure would impede an investigation or cause damage to national security. If such a request is made, your FTC notification should still go out on time — the delay provision applies to public consumer notification, not to the federal regulator report.

What Goes Into the FTC Report

The FTC notification is filed electronically through a form on the FTC’s website. You are not mailing a letter or calling a hotline. The form requires:

Required elementNotes
Institution name and contact informationWho you are, who to contact
Types of customer information involvedSpecific categories (SSN, account numbers, etc.)
Date or date range of the breachIf known — leave this field accurate
Number of consumers affectedUse your best current estimate
General description of the incidentHow it happened, what was accessed
Law enforcement delay statusWhether an official has requested delayed public notification

The filed notification becomes publicly available. This is a meaningful consideration: the FTC Safeguards Rule notification is not a confidential regulatory filing — it is disclosed. Your description of the incident, the data involved, and the consumer count will be visible. This creates reputational stakes that reinforce the value of having an accurate, professionally drafted notification ready to file rather than an improvised description produced under deadline pressure.

The WISP Requirement That Comes Before All of This

The 30-day notification duty is one component of a broader information security program that the Safeguards Rule requires. And two years into enforcement, the FTC is still finding covered entities that haven’t built the foundation.

The Safeguards Rule’s 16 C.F.R. § 314.4 requires a written information security program (WISP) that includes:

  • Designation of a Qualified Individual to oversee the program (can be an employee or a service provider, but must be designated in writing)
  • Written risk assessment identifying foreseeable risks to the security of customer information
  • Implementation of safeguards addressing identified risks, including encryption standards, access controls, multi-factor authentication, and monitoring
  • Continuous monitoring or periodic penetration testing and vulnerability assessments
  • Service provider oversight: select and retain capable providers, require safeguards by contract, periodically assess them
  • Incident response plan covering how to detect, respond to, and recover from a security event — and, now, how to notify the FTC

The incident response plan requirement is where the 30-day notification obligation lives. An institution without a written IR plan that explicitly covers the FTC notification duty — including who owns the determination, what evidence is needed, and when the 30-day clock starts — has a Safeguards Rule violation separate from any breach notification failure.

Civil penalties can reach $51,744 per violation per day. An institution without a WISP, without a Qualified Individual, and without an IR plan has multiple independent violations, each accumulating daily.

What Enforcement Is Still Finding

Two years after the notification requirement took effect, enforcement investigations are surfacing the same gaps:

No written program. The requirement to maintain a WISP has existed since the original 2003 Safeguards Rule. Enforcement continues to find covered businesses operating without a documented information security program. The requirement is not new; the penalty exposure for ignoring it is not new.

No Qualified Individual designation. The 2021 amendments added the explicit requirement to designate a Qualified Individual responsible for the program. Many smaller institutions have not made this designation in writing or have designated someone without the required authority.

No documented breach notification procedures. Institutions frequently have informal practices but no written procedures specifying who makes the FTC notification determination, what evidence is required, what the clock-start date is, and who drafts the form submission.

No service provider oversight. The rule requires covered entities to select service providers capable of maintaining appropriate safeguards and to require those safeguards by contract. Institutions that use third-party vendors to store or process customer information without written data security terms in their contracts have a Safeguards Rule violation that exists independent of any breach.

This mirrors what regulators are finding across other breach notification frameworks: the notification failures trace back to a broken or absent underlying program, not just a missed deadline.

Connecting FTC and State Notification Obligations

The FTC notification and your state consumer notification obligations are parallel, independent duties. Meeting one does not satisfy the other.

FrameworkRecipientDeadlineThresholdContent
FTC Safeguards RuleFTC (federal regulator)30 days from discovery500+ consumersRegulatory form
State breach notification lawsConsumers (and often state AG)30–90 days (varies)Varies (often 1+)Consumer notice + AG report

A breach affecting 1,000 consumers in California could simultaneously require: FTC notification within 30 days; California consumer notification (CCPA/CPRA) within 45 days; California AG notification if more than 500 residents are affected; and potentially other state notifications depending on where affected consumers reside.

Each clock runs independently. Your incident response procedures need to track all of them — not assume that notifying consumers in the affected states satisfies the FTC duty. For a detailed view of how state breach notification requirements compare, the variation in thresholds, deadlines, and content requirements is significant across jurisdictions.

So What?

If you are a non-banking financial institution and you do not have:

  1. A written information security program with a designated Qualified Individual
  2. A written incident response plan that specifies how you identify a notification event, when the clock starts, and who files the FTC report
  3. A service provider oversight program with contractual data security requirements

Then the FTC Safeguards Rule has open violations today — before any breach has occurred.

The 30-day clock is not the hardest part. The hard part is building the infrastructure that lets you identify a notification event accurately, document when discovery occurred, and file a complete report without scrambling for two weeks to figure out who is responsible for it.

If you haven’t built that infrastructure yet, start with the written program and the IR plan. The FTC has published detailed Safeguards Rule guidance that identifies the required program elements; the compliance question is whether you have documented each of them.

The notification form is the easy part. Getting to a defensible answer on Day 30 is the work.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Who is required to notify the FTC under the Safeguards Rule?
The FTC's Safeguards Rule covers non-banking financial institutions — entities subject to GLBA but not directly supervised by federal banking regulators. Covered entities include mortgage lenders and brokers, payday lenders, motor vehicle dealers, check cashers, wire transferors, collection agencies, credit counselors and financial advisors, tax preparation firms, non-federally insured credit unions, and investment advisers not registered with the SEC. If your business earns revenue by providing financial products or services primarily to individuals for personal, family, or household purposes, this requirement likely applies.
What triggers the 30-day FTC notification requirement?
A 'notification event' occurs when there is unauthorized acquisition of the customer information of 500 or more consumers. For this purpose, customer information is treated as unencrypted even if it is technically encrypted but the encryption key was also accessed by the unauthorized person. You do not need to demonstrate actual harm to consumers — acquisition of the data without authorization is sufficient to trigger the duty.
When does the 30-day clock start?
The clock runs from discovery of the notification event, not from the date the breach began. Discovery is the date you reasonably believe the notification event occurred. An ongoing investigation does not stop the clock from running. Law enforcement can request a 60-day delay in public notification if disclosure would impede a criminal investigation or damage national security, but the initial FTC notification must still be made on time.
What does the FTC notification form require?
The FTC notification form, submitted electronically via FTC.gov, must include: the name and contact information of your institution; a description of the types of customer information involved; the date or date range of the breach, if known; the number of consumers affected; a general description of the incident; and whether a law enforcement official has determined that notifying the public would impede a criminal investigation or cause damage to national security.
What are the penalties for failing to notify the FTC?
Violations of the Safeguards Rule can result in civil penalties of up to $51,744 per violation per day. The FTC notification also becomes public, which creates substantial reputational stakes on top of the financial penalty. The FTC can also seek injunctive relief and consent orders requiring remediation of the entire information security program.
How does this FTC notification differ from state breach notification requirements?
The FTC Safeguards Rule notification is a report to a federal regulator — not a consumer notification. You are telling the FTC that a breach occurred. State laws separately require you to notify affected consumers (and in many states, the state AG) within 30 to 90 days, depending on jurisdiction. Both obligations can apply simultaneously, and they run on different clocks with different content requirements.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.