Don’t do SECURITY. Do business SECURELY.

FTC Safeguards Rule breach notification requirement takes effect

US non-bank financial institutions must now notify the FTC within 30 days of discovering a breach affecting 500 or more consumers.

A new breach notification requirement under the FTC Safeguards Rule takes effect today in the United States, requiring non-bank financial institutions to report certain security events directly to the Federal Trade Commission.

Key points

  • Covered institutions must notify the FTC of a “notification event” involving the unencrypted information of at least 500 consumers.
  • Notice must be given as soon as possible and no later than 30 days after discovery.
  • The report is made through an online form and must describe the event, the data involved and the number of consumers affected.
  • Notifications may be made public in the FTC’s database.

UK suppliers to US lenders, fintechs and other non-bank financial firms should make sure their contracts and incident response plans support fast, accurate reporting to their US customers.

Source: FTC Safeguards Rule notification amendment (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights