Feature Regulatory Compliance
FTC Safeguards Rule: The 30-Day Breach Notification Clock Non-Banking Financial Institutions Keep Missing
The FTC Safeguards Rule requires non-banking financial institutions to notify the FTC within 30 days of a breach affecting 500+ consumers. Two years in, enforcement is still finding the same deficiencies.
Table of Contents
TL;DR
- If you’re a non-banking financial institution covered by GLBA, the FTC Safeguards Rule requires you to notify the FTC within 30 days of discovering a breach that exposed 500 or more consumers’ unencrypted customer information.
- The clock runs from discovery — not from when the breach began, and not after your investigation concludes.
- Two years into enforcement, examiners are still finding institutions without a written information security program, without a designated qualified individual, and without documented breach notification procedures.
- This FTC notification is separate from your consumer notification obligations under state law. Both clocks can run simultaneously.
You notified your affected customers. Your legal team drafted the state AG notices. You updated your incident log.
Did you notify the FTC?
Since May 13, 2024, non-banking financial institutions covered by the Gramm-Leach-Bliley Act have been required to report security breaches to the Federal Trade Commission — not just to consumers and state authorities, but to the federal regulator itself — within 30 days of discovery. Two years in, the requirement is still catching organizations that never built it into their incident response playbooks.
If you’re a mortgage lender, payday lender, auto dealer, tax preparer, check casher, credit counselor, collection agency, or investment adviser not registered with the SEC, this requirement applies to you. It is not a banking agency requirement. Your primary federal banking regulator, if you have one, has its own 36-hour rule. This is a separate, FTC-administered obligation, and it runs on a different clock, with different content requirements, and its own penalty structure.
Who the FTC Safeguards Rule Actually Covers
The FTC’s Safeguards Rule, codified at 16 C.F.R. Part 314, applies to “financial institutions” as defined under GLBA — entities engaged in a significant financial activity. The FTC’s version covers a large swath of non-bank businesses that handle customer financial data:
- Mortgage lenders and mortgage brokers
- Payday lenders and short-term credit providers
- Motor vehicle dealers that arrange or extend financing
- Check cashers and wire transferors
- Collection agencies
- Credit counselors and financial advisors (outside SEC registration)
- Tax preparation firms
- Non-federally insured credit unions
- Investment advisers not required to register with the SEC
- Travel agencies operating in connection with financial services
- Account servicers
If your business earns revenue primarily by providing financial products or services to individual consumers for personal, family, or household use, the Safeguards Rule likely applies. The coverage test is activity-based, not charter-based. A fintech lending company that is not a bank is still a financial institution under GLBA and the FTC’s rule.
One coverage question that still trips firms up: state-licensed investment advisers who are exempt from SEC registration. If you manage under the SEC registration threshold, you fall under the FTC’s Safeguards Rule, not the SEC’s Regulation S-P. Those are two separate frameworks with overlapping but distinct requirements.
What Counts as a “Notification Event”
Not every security incident triggers the FTC notification duty. The rule defines a specific threshold.
A notification event is the unauthorized acquisition of unencrypted customer information involving the data of 500 or more consumers.
Two key clarifications matter here:
On “unencrypted”: The rule treats data as unencrypted if an unauthorized person accessed or acquired the encryption key used to protect it. Technically encrypted data that was compromised along with its key is still a notification event. You cannot avoid the duty by pointing to encryption alone if the encryption was itself compromised.
On “acquisition”: The FTC does not require you to demonstrate actual harm. Unauthorized access to the data is enough if acquisition can be reasonably inferred. A successful ransomware deployment that touched systems containing customer records can meet this threshold even without proof that the attacker extracted specific files.
The 500-consumer threshold matters for distinguishing this obligation from your other breach notification duties. Many state laws have much lower thresholds — some require notification for any breach regardless of volume. Your FTC notification duty is a floor at 500, running in parallel with whatever state notification obligations apply.
The 30-Day Clock and What It Runs From
The 30-day clock begins running when you discover the notification event — the date you reasonably believe a notification event has occurred.
This is not the date the breach began. It is not the date your forensic investigation concludes. It is the date your organization reasonably should have known a notification event occurred, which typically means the date your incident response team determined (or should have determined) that 500 or more consumers’ unencrypted information was acquired without authorization.
An ongoing investigation does not toll the clock. If your IR team has sufficient evidence by Day 5 to conclude that 500+ consumers’ data was accessed, the clock started on Day 5 — not on the later date when the investigation is formally closed. This is one of the places where incident response decision documentation matters: you need a contemporaneous record of when you reached each determination, not just a final report.
Law enforcement delay: A law enforcement official can request that you delay public notification for up to 60 days if public disclosure would impede an investigation or cause damage to national security. If such a request is made, your FTC notification should still go out on time — the delay provision applies to public consumer notification, not to the federal regulator report.
What Goes Into the FTC Report
The FTC notification is filed electronically through a form on the FTC’s website. You are not mailing a letter or calling a hotline. The form requires:
| Required element | Notes |
|---|---|
| Institution name and contact information | Who you are, who to contact |
| Types of customer information involved | Specific categories (SSN, account numbers, etc.) |
| Date or date range of the breach | If known — leave this field accurate |
| Number of consumers affected | Use your best current estimate |
| General description of the incident | How it happened, what was accessed |
| Law enforcement delay status | Whether an official has requested delayed public notification |
The filed notification becomes publicly available. This is a meaningful consideration: the FTC Safeguards Rule notification is not a confidential regulatory filing — it is disclosed. Your description of the incident, the data involved, and the consumer count will be visible. This creates reputational stakes that reinforce the value of having an accurate, professionally drafted notification ready to file rather than an improvised description produced under deadline pressure.
The WISP Requirement That Comes Before All of This
The 30-day notification duty is one component of a broader information security program that the Safeguards Rule requires. And two years into enforcement, the FTC is still finding covered entities that haven’t built the foundation.
The Safeguards Rule’s 16 C.F.R. § 314.4 requires a written information security program (WISP) that includes:
- Designation of a Qualified Individual to oversee the program (can be an employee or a service provider, but must be designated in writing)
- Written risk assessment identifying foreseeable risks to the security of customer information
- Implementation of safeguards addressing identified risks, including encryption standards, access controls, multi-factor authentication, and monitoring
- Continuous monitoring or periodic penetration testing and vulnerability assessments
- Service provider oversight: select and retain capable providers, require safeguards by contract, periodically assess them
- Incident response plan covering how to detect, respond to, and recover from a security event — and, now, how to notify the FTC
The incident response plan requirement is where the 30-day notification obligation lives. An institution without a written IR plan that explicitly covers the FTC notification duty — including who owns the determination, what evidence is needed, and when the 30-day clock starts — has a Safeguards Rule violation separate from any breach notification failure.
Civil penalties can reach $51,744 per violation per day. An institution without a WISP, without a Qualified Individual, and without an IR plan has multiple independent violations, each accumulating daily.
What Enforcement Is Still Finding
Two years after the notification requirement took effect, enforcement investigations are surfacing the same gaps:
No written program. The requirement to maintain a WISP has existed since the original 2003 Safeguards Rule. Enforcement continues to find covered businesses operating without a documented information security program. The requirement is not new; the penalty exposure for ignoring it is not new.
No Qualified Individual designation. The 2021 amendments added the explicit requirement to designate a Qualified Individual responsible for the program. Many smaller institutions have not made this designation in writing or have designated someone without the required authority.
No documented breach notification procedures. Institutions frequently have informal practices but no written procedures specifying who makes the FTC notification determination, what evidence is required, what the clock-start date is, and who drafts the form submission.
No service provider oversight. The rule requires covered entities to select service providers capable of maintaining appropriate safeguards and to require those safeguards by contract. Institutions that use third-party vendors to store or process customer information without written data security terms in their contracts have a Safeguards Rule violation that exists independent of any breach.
This mirrors what regulators are finding across other breach notification frameworks: the notification failures trace back to a broken or absent underlying program, not just a missed deadline.
Connecting FTC and State Notification Obligations
The FTC notification and your state consumer notification obligations are parallel, independent duties. Meeting one does not satisfy the other.
| Framework | Recipient | Deadline | Threshold | Content |
|---|---|---|---|---|
| FTC Safeguards Rule | FTC (federal regulator) | 30 days from discovery | 500+ consumers | Regulatory form |
| State breach notification laws | Consumers (and often state AG) | 30–90 days (varies) | Varies (often 1+) | Consumer notice + AG report |
A breach affecting 1,000 consumers in California could simultaneously require: FTC notification within 30 days; California consumer notification (CCPA/CPRA) within 45 days; California AG notification if more than 500 residents are affected; and potentially other state notifications depending on where affected consumers reside.
Each clock runs independently. Your incident response procedures need to track all of them — not assume that notifying consumers in the affected states satisfies the FTC duty. For a detailed view of how state breach notification requirements compare, the variation in thresholds, deadlines, and content requirements is significant across jurisdictions.
So What?
If you are a non-banking financial institution and you do not have:
- A written information security program with a designated Qualified Individual
- A written incident response plan that specifies how you identify a notification event, when the clock starts, and who files the FTC report
- A service provider oversight program with contractual data security requirements
Then the FTC Safeguards Rule has open violations today — before any breach has occurred.
The 30-day clock is not the hardest part. The hard part is building the infrastructure that lets you identify a notification event accurately, document when discovery occurred, and file a complete report without scrambling for two weeks to figure out who is responsible for it.
If you haven’t built that infrastructure yet, start with the written program and the IR plan. The FTC has published detailed Safeguards Rule guidance that identifies the required program elements; the compliance question is whether you have documented each of them.
The notification form is the easy part. Getting to a defensible answer on Day 30 is the work.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Who is required to notify the FTC under the Safeguards Rule?
What triggers the 30-day FTC notification requirement?
When does the 30-day clock start?
What does the FTC notification form require?
What are the penalties for failing to notify the FTC?
How does this FTC notification differ from state breach notification requirements?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Regulatory Compliance
Colorado Rewrote Its AI Law. The New Version Has No Financial Institution Exemption—and the Rules Just Dropped.
Colorado SB 26-189, signed May 2026, repeals and replaces SB 24-205 with a narrower automated decision-making technology law. Financial institutions lost their exemption. The AG proposed rules on August 11. Here's what fintechs and lenders need to do before January 1, 2027.
Aug 24, 2026
Regulatory Compliance
How to Test a Bank CIP: Sampling, Evidence, Exceptions, and Conclusions
Customer identification program testing that covers population completeness, CIP attributes, evidence, exceptions, and defensible workpaper conclusions.
Aug 21, 2026
Regulatory Compliance
SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed
The SEC's Tricolor fraud case alleges $1.9B in ABS offerings and an $800M collateral hole. Here are the controls lenders should test now.
Aug 21, 2026