Ask a business owner whether they run a financial institution and you will get a strange look. Banks are financial institutions. A three person tax office, a used car lot, or a collections desk is not. Right?
Under the FTC Safeguards Rule, it very well might be. The rule defines “financial institution” far more broadly than the everyday meaning of the phrase, and it has quietly swept in a long list of ordinary businesses that handle consumer financial information. Most of them have no idea. We meet them regularly in Denton County, usually right after a customer, an insurance carrier, or an auditor asks a question nobody can answer.
One thing up front: this is general information, not legal advice. We are an IT company, not a law firm. Whether the Safeguards Rule applies to your business, and what it requires, is a question for a lawyer or qualified compliance advisor who can look at what you actually do. Use this to get oriented, then get real confirmation.
What the Safeguards Rule Actually Is
The Safeguards Rule comes out of the Gramm-Leach-Bliley Act and is enforced by the Federal Trade Commission. It requires covered businesses to develop and maintain a written information security program that protects customer information. Not a shared folder of good intentions. A documented program with a named owner, specific controls, and regular review.
The part that catches people is how coverage gets decided. The FTC is blunt: what matters are the types of activities your business undertakes, not how you or others categorize your company. If those activities are financial in nature, the rule is looking at you.
Who Is Covered, and It Is More Businesses Than You Think
The FTC lists specific examples of businesses that count as financial institutions. A sample:
- Tax preparation firms. The one that surprises people most. If your CPA firm or tax office prepares returns, the FTC names tax preparation firms directly.
- Mortgage lenders and brokers. Anyone originating or arranging home loans.
- Collection agencies. Chasing consumer debt is a financial activity.
- Payday lenders and finance companies. Short term lending in any form.
- Credit counselors and financial advisors. Including investment advisors not registered with the SEC.
- Check cashers, wire transferors, and account servicers. Moving or servicing other people’s money.
- Finders. Companies that bring buyers and sellers together.
Auto dealers get their own paragraph, because the FTC wrote a whole set of frequently asked questions just for them. The Commission’s position is that dealers who finance, or facilitate the financing of, automobiles for consumers are financial institutions under the rule, since lending money is a financial activity. Leasing for longer than 90 days counts too. And if your dealership arranges or brokers a loan through a third party lender, the FTC says you are in a continuing relationship with that customer for purposes of safeguarding the information they gave you. You did not lend the money and you are still responsible for the file.
That last point is worth sitting with. Plenty of businesses that would never call themselves lenders arrange credit or offer their own payment plans. If that describes you, or you work in an adjacent field like appraisal or settlement services, ask an attorney rather than guess.
What the Rule Actually Requires
The written program has to include a specific set of elements. The FTC’s list, translated out of regulation language:
- A Qualified Individual. One designated person to implement and supervise the program. Good news for small shops: the FTC says that individual can be an employee, or someone who works for an affiliate or service provider. You can hire the expertise. You cannot skip the role.
- A written risk assessment. Identify the foreseeable risks and threats, internal and external, to the security, confidentiality, and integrity of customer information. Written down, not discussed over lunch.
- Access controls and a data inventory. Know where customer information lives, who can reach it, and review access regularly.
- Encryption. Customer information encrypted both in transit and at rest.
- Multi-factor authentication. The FTC defines this as at least two of three things: a knowledge factor such as a password, a possession factor such as a token, and an inherence factor such as a fingerprint. We compared the options in YubiKey vs Passkey vs MFA.
- Secure disposal. Customer information disposed of no later than two years after your most recent use of it, with limited exceptions. Old data is a liability, not an asset.
- Monitoring and testing. Either continuous monitoring, or annual penetration testing plus vulnerability assessments every six months for publicly known vulnerabilities.
- Employee training. Security awareness training with regular refreshers, not one slideshow at onboarding.
- Vendor oversight. Select service providers with the skills and experience to maintain appropriate safeguards, and hold them to it in writing.
- A written incident response plan. Goals, internal processes, roles, communications, remediation, documentation, and post-incident review.
- Reporting. Your Qualified Individual must report in writing regularly, and at least annually, to your board or governing body.
There is also a notification requirement with teeth. A notification event means the unauthorized acquisition of at least 500 consumers’ unencrypted information, and covered businesses must notify the FTC as soon as possible and no later than 30 days after discovery. Thirty days sounds generous until you have lived through the first week of an incident.
The Small Business Exemption Is Smaller Than It Sounds
The FTC has exempted businesses that maintain customer information concerning fewer than 5,000 consumers from certain provisions of the rule. That is real relief, and we would rather you hear it from us than over-engineer something.
But read it carefully. It is an exemption from certain provisions, not from the rule. The obligation to protect customer information does not disappear at 4,999 consumers. Counting is also trickier than it looks, because the number covers information you maintain, which often includes records going back years. Ask your attorney how to count before deciding you are under the line.
Where to Start, in the Honest Order
Nobody does all of this in a weekend. Here is the sequence we use, ordered by risk reduced per hour spent:
- Name your Qualified Individual. One name, in writing, today. Every other item stalls without an owner.
- Turn on multi-factor authentication everywhere. Email first, then line of business software, then remote access. Highest return item on the list, and usually free.
- Find your customer data. Build the inventory. You cannot protect or dispose of what you cannot locate, and most businesses are surprised by what turns up in old file shares.
- Write the risk assessment. Much easier once the inventory exists, and it becomes the document your attorney and insurance carrier will ask for.
- Fix access and encryption. Close accounts that should have been closed months ago, then encrypt where encryption is missing.
- Write the incident response plan and train your people. Last only because the first five reduce the odds you will need them.
The Bottom Line
The Safeguards Rule is not a trap. It is a reasonable description of what any business holding sensitive consumer information should already be doing, written down and assigned to a person. The businesses that struggle with it are rarely the ones with bad security. They are the ones who never realized it pointed at them.
Almost every item on that list is something we would recommend anyway. Compliance is just the deadline. For the broader case, see Why Cybersecurity Is No Longer Optional. And one more time, because it matters: confirm your actual obligations with a lawyer or compliance advisor. We handle the technical side. They handle the legal one.
If you are not sure whether the Safeguards Rule touches your business, or you know it does and the written program never got written, we can build the technical half and document what you already have. Contact us today.
Sources:
- Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know
- Federal Trade Commission, Automobile Dealers and the FTC’s Safeguards Rule: Frequently Asked Questions

Comments are closed