In legal review — not indexed
These explainers are drafted and readable, and stay out of search until an attorney has cleared each one. Anything still to be checked is marked inline.
GLBA Safeguards Rule: What Are the Required Elements of an Information Security Program Under 16 CFR 314?
16 CFR 314.3(a) requires a written, comprehensive information security program. Section 314.4 sets out its elements in ten lettered paragraphs, (a) through (j): Qualified Individual, written risk assessment, eight enumerated safeguards including encryption and MFA, testing, training, service-provider oversight, program adjustment, written incident response plan, annual board report, and FTC breach notice.
Key facts
- 16 CFR 314.4(a) requires you to designate a qualified individual to oversee your information security program, and 314.4(a)(1) makes you retain responsibility even if that role is outsourced.
- 16 CFR 314.4(c)(3) requires encryption of all customer information in transit over external networks and at rest, with compensating controls only where your Qualified Individual approves them.
- 16 CFR 314.4(d)(2) requires annual penetration testing and vulnerability assessments "at least every six months" unless you have continuous monitoring in place.
- 16 CFR 314.4(c)(6)(i) requires secure disposal of customer information no later than two years after its last use for the customer, subject to three exceptions.
- 16 CFR 314.4(j)(1) requires FTC notice of a notification event involving 500 or more consumers "as soon as possible, and no later than 30 days after discovery of the event."
- 16 CFR 314.6 exempts only 314.4(b)(1), (d)(2), (h), and (i) for institutions holding information on "fewer than five thousand consumers"; the 314.4(j) FTC notice duty is never exempt.
Does the FTC Safeguards Rule at 16 CFR 314 apply to a creditor-side collections law firm?
It turns on the firm's activities, and the question is genuinely unresolved. 16 CFR 314.1(b) applies the Safeguards Rule to those "financial institutions" over which the FTC has rulemaking authority under section 501(b) of the Gramm-Leach-Bliley Act, and says those entities "include, but are not limited to, mortgage lenders, 'pay day' lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, travel agencies operated in connection with financial services, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, investment advisors that are not required to register with the Securities and Exchange Commission, and entities acting as finders." Collection activity is in scope through the chain 314.1(b) builds: it incorporates section 4(k) of the Bank Holding Company Act and the Federal Reserve Board's Regulation Y, and 12 CFR 225.28(b)(2)(iv) lists "Collection agency services. Collecting overdue accounts receivable, either retail or commercial." Law firms engaged in the practice of law are not listed anywhere in the Rule. In American Bar Ass'n v. FTC, Nos. 04-5257 and 04-5258 (D.C. Cir., decided December 6, 2005), the court affirmed judgment against the FTC because "the Commission's attempt to regulate the practice of law under the Act fell outside its statutory authority," reasoning that "[a]n attorney, or even a law firm, does not fit very neatly into the niche of a 'financial institution.'" As of July 2026 three limits on that decision matter: it reviewed an FTC determination under the GLBA privacy rule rather than the Safeguards Rule; its analysis ran through the Chevron framework, which the Supreme Court overruled in Loper Bright Enterprises v. Raimondo, No. 22-451 (decided June 28, 2024); and it is a D.C. Circuit decision. A firm's non-law-practice activities — an affiliated collection agency, purchasing or servicing accounts, holding and disbursing consumer funds — are analyzed on their own terms. In practice most creditor-side firms implement 16 CFR 314.4 regardless, because bank and debt-buyer clients impose it by contract.
Does 16 CFR 314 reach customer data that belongs to a firm's bank client rather than to the firm?
Yes, by the express terms of the scope provision. 16 CFR 314.1(b) closes with the sentence: "This part applies to all customer information in your possession, regardless of whether such information pertains to individuals with whom you have a customer relationship, or pertains to the customers of other financial institutions that have provided such information to you." For a collections firm that is the operative clause. A placement file from an issuing bank consists of customer information belonging to that bank's customers, and the scope provision reaches it in the firm's possession. 16 CFR 314.2(d) defines customer information as "any record containing nonpublic personal information about a customer of a financial institution, whether in paper, electronic, or other form, that is handled or maintained by or on behalf of you or your affiliates," which covers paper placement packets and scanned media as well as database records. Note the antecedent question this does not answer: 314.1(b) allocates the Rule's reach across information types once you are a covered entity — it does not by itself make a firm a covered entity.
How many elements does 16 CFR 314.4 require, and what are they?
The regulation text sets them out in ten lettered paragraphs, (a) through (j), though the FTC's own compliance guide counts nine because it treats the breach-notification duty separately. 16 CFR 314.3(a) requires a "comprehensive information security program that is written in one or more readily accessible parts" containing administrative, technical, and physical safeguards "appropriate to your size and complexity, the nature and scope of your activities, and the sensitivity of any customer information at issue," and provides that the program "shall include the elements set forth in § 314.4." Those elements are: (a) designate a Qualified Individual; (b) base the program on a risk assessment, which under (b)(1) must be written; (c) design and implement safeguards, itself an eight-item list at (c)(1) through (c)(8); (d) regularly test or monitor the effectiveness of key controls; (e) implement policies ensuring personnel can enact the program, including security awareness training; (f) oversee service providers; (g) evaluate and adjust the program; (h) establish a written incident response plan; (i) require the Qualified Individual to report in writing at least annually to the board or equivalent governing body; and (j) notify the FTC about notification events. The FTC's small entity compliance guide states that "Section 314.4 of the Safeguards Rule identifies nine elements that your company's information security program must include" and then walks through a. through i., addressing (j) under a separate breach-notification heading. As of July 2026 the count discrepancy is presentational, not substantive: all ten paragraphs are operative text.
Who is the Qualified Individual under 16 CFR 314.4(a), and can that role be outsourced?
16 CFR 314.4(a) requires a financial institution to "[d]esignate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program," and states that "[t]he Qualified Individual may be employed by you, an affiliate, or a service provider." Outsourcing is permitted but conditional. Where the role is filled by a service provider or affiliate, 314.4(a)(1) through (3) require the institution to "[r]etain responsibility for compliance with this part," to "[d]esignate a senior member of your personnel responsible for direction and oversight of the Qualified Individual," and to "[r]equire the service provider or affiliate to maintain an information security program that protects you in accordance with the requirements of this part." A collections firm that retains a virtual CISO therefore still needs a named senior internal person accountable for that vendor, and the Rule forecloses the argument that the vendor's program substitutes for the firm's. The Rule specifies no credential, degree, or title for the Qualified Individual; the FTC's compliance guide states only that "[w]hat matters is real-world know-how suited to your circumstances."
What must the written risk assessment under 16 CFR 314.4(b) actually contain?
16 CFR 314.4(b) requires the program to be based on a risk assessment identifying "reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information," and assessing "the sufficiency of any safeguards in place to control these risks." Section 314.4(b)(1) requires that the assessment "shall be written" and include three specified items: "[c]riteria for the evaluation and categorization of identified security risks or threats you face"; "[c]riteria for the assessment of the confidentiality, integrity, and availability of your information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats you face"; and "[r]equirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks." Section 314.4(b)(2) requires periodic additional risk assessments that reexamine those risks and reassess safeguard sufficiency; it sets no interval. 16 CFR 314.6 exempts 314.4(b)(1) — the written-assessment requirement, not the underlying duty in 314.4(b) to base the program on a risk assessment — for institutions maintaining customer information on fewer than five thousand consumers.
Are encryption and multi-factor authentication mandatory under 16 CFR 314.4, and must the exceptions be in writing?
Both are mandatory, each with a narrow exception running through the Qualified Individual, but only the multi-factor authentication exception must be in writing. 16 CFR 314.4(c)(3) requires you to "[p]rotect by encryption all customer information held or transmitted by you both in transit over external networks and at rest," and provides that "[t]o the extent you determine that encryption of customer information, either in transit over external networks or at rest, is infeasible, you may instead secure such customer information using effective alternative compensating controls reviewed and approved by your Qualified Individual." That paragraph requires review and approval but does not on its face require a written record. 16 CFR 314.4(c)(5) requires you to "[i]mplement multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls" — here the writing requirement is express. 16 CFR 314.2(k) defines multi-factor authentication as verification of at least two of knowledge, possession, and inherence factors. As of July 2026, a firm relying on either exception is making a determination attributable to a named individual; documenting the encryption determination is prudent evidence practice rather than a literal command of 314.4(c)(3).
How often does 16 CFR 314.4(d) require a firm to test its controls?
16 CFR 314.4(d)(1) requires a financial institution to "[r]egularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems, and procedures, including those to detect actual and attempted attacks on, or intrusions into, information systems," without stating an interval. Section 314.4(d)(2) sets the cadence for information systems: monitoring and testing "shall include continuous monitoring or periodic penetration testing and vulnerability assessments." The fixed schedule applies only "[a]bsent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities" — that second clause is broader than continuous monitoring alone and is often overlooked. Where the schedule applies, the firm must conduct "[a]nnual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment" and vulnerability assessments "at least every six months; and whenever there are material changes to your operations or business arrangements; and whenever there are circumstances you know or have reason to know may have a material impact on your information security program." 16 CFR 314.2(n) defines penetration testing as a methodology in which "assessors attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or controls from outside or inside your information systems." 16 CFR 314.6 exempts 314.4(d)(2) below the five-thousand-consumer threshold; it does not exempt 314.4(d)(1).
What does 16 CFR 314.4(c)(6) require about retaining and disposing of customer information?
Two duties, one of them a deadline. 16 CFR 314.4(c)(6)(i) requires a financial institution to "[d]evelop, implement, and maintain procedures for the secure disposal of customer information in any format no later than two years after the last date the information is used in connection with the provision of a product or service to the customer to which it relates." The same paragraph carries three exceptions, and they are stated as conditions on that deadline rather than as separate safe harbors: unless the information "is necessary for business operations or for other legitimate business purposes," unless it "is otherwise required to be retained by law or regulation," or "where targeted disposal is not reasonably feasible due to the manner in which the information is maintained." 16 CFR 314.4(c)(6)(ii) adds the second duty: "[p]eriodically review your data retention policy to minimize the unnecessary retention of data." For a collections law firm the two-year clock is harder than it looks, because it runs from the last use of the information in providing a product or service to the customer, while the other retention duties on the same records run on their own clocks and usually run longer — the three-year rule in 12 CFR 1006.100(a), state bar file-retention rules, client and creditor contract terms, and litigation holds. The "legitimate business purposes" exception is what reconciles them, and because it is an exception rather than a default it is a determination the firm should be able to produce, not one it can assume. 16 CFR 314.6 does not exempt 314.4(c)(6) at any size.
What does 16 CFR 314.4(f) require a collections firm to do about its own vendors?
16 CFR 314.4(f) requires the firm to "[o]versee service providers" by three specified means: "[t]aking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue"; "[r]equiring your service providers by contract to implement and maintain such safeguards"; and "[p]eriodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards." The operative definition is 16 CFR 314.2(r): a service provider is "any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution that is subject to this part." Two limits follow from that text — the vendor must have access to customer information, and the services must be provided directly to a covered financial institution. For a collections firm the population it typically has to work through includes dialer and telephony providers, print and mail houses, skip-trace and data vendors, e-filing and process-service platforms, payment processors, hosted case-management software, and offshore document-review resources; which of those meet 314.2(r) is a factual determination about data access, not something the Rule decides. The three obligations are sequential — selection, contract, recurring reassessment — and 314.4(f) sets no interval for the third. Meeting the first two and never performing the third does not satisfy the paragraph.
What must the incident response plan cover under 16 CFR 314.4(h), and when must the FTC be told about a breach?
16 CFR 314.4(h) requires a written incident response plan "designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in your control," addressing seven areas: the plan's goals; "[t]he internal processes for responding to a security event"; "[t]he definition of clear roles, responsibilities, and levels of decision-making authority"; external and internal communications and information sharing; "[i]dentification of requirements for the remediation of any identified weaknesses in information systems and associated controls"; documentation and reporting of security events; and evaluation and revision of the plan following a security event. Separately, 16 CFR 314.4(j)(1) provides that upon discovery of a notification event involving the information of at least 500 consumers, "you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event," electronically on a form on the FTC's website, with six specified content items. 16 CFR 314.2(m) defines a notification event as "acquisition of unencrypted customer information without the authorization of the individual to which the information pertains," adds that "[c]ustomer information is considered unencrypted for this purpose if the encryption key was accessed by an unauthorized person," and provides that "[u]nauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information." Under 314.4(j)(2), a firm is "deemed to have knowledge of a notification event if such event is known to any person, other than the person committing the breach, who is your employee, officer, or other agent." Paragraph (j)(1)(vi) permits a law enforcement official to request "an initial delay of up to 30 days," extendable "for an additional period of up to 60 days" on a written request, with further delay only if Commission staff so determines. 16 CFR 314.5 states that "Section 314.4(j) is effective as of May 13, 2024."
Does the small-entity exception in 16 CFR 314.6 relieve a firm of the FTC breach-reporting duty?
No. 16 CFR 314.6 provides in full: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." Four paragraphs are exempted — the written risk assessment, the annual-penetration-testing and six-month vulnerability-assessment schedule, the written incident response plan, and the annual report to the board. Every other element of 314.4 continues to apply below the threshold, including the breach-notification duty at 314.4(j), the Qualified Individual at 314.4(a), the encryption and multi-factor authentication requirements at 314.4(c)(3) and (c)(5), the general testing duty at 314.4(d)(1), and service-provider oversight at 314.4(f). The threshold is stated in terms of consumers whose customer information the institution maintains, not matters, clients, or employees. For a collections firm holding bank placement files, that count is driven by the volume of debtor records in its possession, and 314.1(b) makes clear those records count even though the consumers are another institution's customers. As of July 2026 the counting method is not further specified in the regulation.
Does implementing every control in 16 CFR 314.4 make a collections firm compliant?
It satisfies the Safeguards Rule's own text and nothing more, and the Rule is explicit about where responsibility sits. 16 CFR 314.4(a)(1) requires the institution to "[r]etain responsibility for compliance with this part" even when it delegates the Qualified Individual role. 16 CFR 314.4(g) requires the firm to "[e]valuate and adjust your information security program in light of the results of the testing and monitoring required by paragraph (d) of this section; any material changes to your operations or business arrangements; the results of risk assessments performed under paragraph (b)(2) of this section; or any other circumstances that you know or have reason to know may have a material impact on your information security program" — four independent triggers, including the risk-assessment results, which is easy to lose in a shortened quotation. A control set that is accurate the day it is deployed can fall out of compliance through an unassessed vendor change. The Safeguards Rule also does not displace state breach notification statutes, state data security laws, contractual security schedules imposed by bank clients, or a lawyer's independent confidentiality obligations under the applicable rules of professional conduct, any of which can be stricter. No software product can certify compliance with 16 CFR 314. Software can implement and evidence individual controls, but the determinations the Rule assigns to a person — infeasibility of encryption under 314.4(c)(3), written approval of equivalent access controls under 314.4(c)(5), risk acceptance under 314.4(b)(1)(iii) — remain human decisions attributed to a named Qualified Individual.
Primary sources
-
This part applies to all customer information in your possession, regardless of whether such information pertains to individuals with whom you have a customer relationship, or pertains to the customers of other financial institutions that have provided such information to you.
-
16 CFR § 314.4, Elements (eCFR, current)
Protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest. To the extent you determine that encryption of customer information, either in transit over external networks or at rest, is infeasible, you may instead secure such customer information using effective alternative compensating controls reviewed and approved by your Qualified Individual
-
Develop, implement, and maintain procedures for the secure disposal of customer information in any format no later than two years after the last date the information is used in connection with the provision of a product or service to the customer to which it relates, unless such information is necessary for business operations or for other legitimate business purposes, is otherwise required to be retained by law or regulation, or where targeted disposal is not reasonably feasible due to the manner in which the information is maintained
-
16 CFR § 314.5, Effective date (eCFR, current)
Section 314.4(j) is effective as of May 13, 2024.
-
16 CFR § 314.6, Exceptions (eCFR, current)
Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.
-
Section 314.4 of the Safeguards Rule identifies nine elements that your company's information security program must include.
-
Because we agree with the District Court that the Commission's attempt to regulate the practice of law under the Act fell outside its statutory authority, we affirm the judgment under review.
-
Collection agency services. Collecting overdue accounts receivable, either retail or commercial.
-
15 U.S.C. § 6801, Protection of nonpublic personal information (Cornell LII)
each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of those customers' nonpublic personal information
-
courts may not defer to an agency interpretation of the law simply because a statute is ambiguous; Chevron is overruled
This is an informational reference, not legal advice, and using it creates no attorney-client relationship. Limitations periods turn on facts this page cannot know — which state's law governs, the contract type, when the claim accrued, and whether anything tolled or revived it. Confirm against the primary source and your own counsel before acting.