A new breach notification requirement under the FTC Safeguards Rule takes effect today in the United States, requiring non-bank financial institutions to report certain security events directly to the Federal Trade Commission.
Key points
- Covered institutions must notify the FTC of a “notification event” involving the unencrypted information of at least 500 consumers.
- Notice must be given as soon as possible and no later than 30 days after discovery.
- The report is made through an online form and must describe the event, the data involved and the number of consumers affected.
- Notifications may be made public in the FTC’s database.
UK suppliers to US lenders, fintechs and other non-bank financial firms should make sure their contracts and incident response plans support fast, accurate reporting to their US customers.
Source: FTC Safeguards Rule notification amendment (Federal Register)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.