FTC Amends Safeguards Rule: Non-Banking Financial Institutions to Report Data Breaches

The Federal Trade Commission (FTC) approved amendments to the Standards for Safeguarding Customer Information Rule, colloquially known as the Safeguards Rule, on October 27, 2023. These amendments will require non-banking financial institutions overseen by the FTC, including financial technology companies, mortgage brokers, credit counselors, financial planners, and tax preparers, to report specific types of data breaches and other security events directly to the FTC. As reported by WilmerHale.

These amendments are notable because non-banking financial institutions comprise a large portion of the financial sector, and data disruptions in these institutions can have far-reaching economic and financial implications. The reporting of data breaches and other security incidents, which have escalated in recent years due to increased technological complexity and cyber threats, is crucial to stemming consumer damage and maintaining confidence in the sector.

It is integral for legal professionals representing non-banking financial institutions to be aware of these amendments to the Safeguards Rule. A failure to properly report data breaches or security incidents can result in steep fines, increased regulatory scrutiny, and potential reputational damage for both the institution and its legal advisors. Understanding the nuances of these amendments and how they should be properly reported to the FTC will help legal professionals protect their clients and maintain legal compliance.

A further exploration of the exact provisions of these amendments and the steps non-banking financial institutions should take to comply with them is a valuable investment of time for all legal professionals working within the financial industry.