MenuMENU
SearchSEARCH

FTC Strengthens Security Safeguards for Consumer Financial Information Following Widespread Data Breaches

Agency updates Safeguards Rule to better protect the American public from breaches and cyberattacks that lead to identity theft and other financial losses.

October 27, 2021
FTC Strengthens Security Safeguards for Consumer Financial Information Following Widespread Data Breaches

Agency updates Safeguards Rule to better protect the American public from breaches and cyberattacks that lead to identity theft and other financial losses.

3 min to read


FTC – The Federal Trade Commission today announced a newly updated rule that strengthens the data security safeguards that financial institutions are required to put in place to protect their customers’ financial information. In recent years, widespread data breaches and cyberattacks have resulted in significant harms to consumers, including monetary loss, identity theft, and other forms of financial distress. The FTC’s updated Safeguards Rule requires non-banking financial institutions, such as mortgage brokers, motor vehicle dealers, and payday lenders, to develop, implement, and maintain a comprehensive security system to keep their customers’ information safe. 

“Financial institutions and other entities that collect sensitive consumer data have a responsibility to protect it,” said Samuel Levine, Director of the FTC’s Bureau of Consumer Protection. “The updates adopted by the Commission to the Safeguards Rule detail common-sense steps that these institutions must implement to protect consumer data from cyberattacks and other threats.”

The changes adopted by the Commission to the Safeguards Rule include more specific criteria for what safeguards financial institutions must implement as part of their information security program such as limiting who can access consumer data and using encryption to secure the data. Under the updated Safeguards Rule, institutions must also explain their information sharing practices, specifically the administrative, technical, and physical safeguards the financial institutions use to access, collect, distribute, process, protect, store, use, transmit, dispose of, or otherwise handle customers’ secure information. In addition, financial institutions will be required to designate a single qualified individual to oversee their information security program and report periodically to an organization’s board of directors, or a senior officer in charge of information security.

The Safeguards Rule was mandated by Congress under the 1999 Gramm-Leach-Bliley Act. Today’s updates are the result of years of public input. In 2019, the FTC sought comment on proposed changes to the Safeguards Rule and, in 2020 held a public workshop on the Safeguards Rule.

In addition to the updates, the FTC is seeking comment on whether to make an additional change to the Safeguards Rule to require financial institutions to report certain data breaches and other security events to the Commission. The FTC is issuing a supplemental notice of proposed rulemaking, which will be published in the Federal Register shortly. The public will have 60 days after the notice is published in the Federal Register to submit a comment.

Today, the FTC also announced it adopted largely technical changes to its authority under a separate Gramm-Leach Bliley Act rule, which requires financial institutions to inform customers about their information-sharing practices and allow customers to opt out of having their information shared with certain third parties. These changes align the rule with changes made under the 2010 Dodd-Frank Wall Street Reform and Consumer Protection Act (Dodd-Frank). Under Dodd-Frank, Congress narrowed the FTC’s jurisdiction under that rule to only apply to motor vehicle dealers.

The Commission voted 5-0 to publish the final revisions to update the FTC’s jurisdiction under Dodd-Frank and the supplemental notice of proposed rulemaking to the Safeguards Rule in the Federal Register. The Commission voted 3-2 to publish the revisions to the Safeguards Rule in the Federal Register. Commissioners Noah Joshua Phillipsand Christine S. Wilson voted no and issued a joint dissenting statement. Chair Lina M. Khan and Rebecca Kelly Slaughter issued a separate joint statement.

More Compliance

ComplianceOctober 6, 2025

The Jurisprudence of Pricing

Legal concept helps makes sense of California’s recently passed version of the failed federal CARS legislation.

Read More →
Digitalby Hannah MitchellSeptember 5, 2025

Cyber Threats Continue Apace

Hackers, seeing auto retail vulnerabilities in 2024 CDK incident, are taking advantage, data show.

Read More →
IndustryJuly 17, 2025

Trump 2.0 and Enforcement Priorities

The upshot is don’t relax, because regulation indeed continues.

Read More →
Ad Loading...
Blue and white Automotive Service Professionals logo presented over a blue background with various wrench tools.
Fixed Opsby StaffJune 11, 2025

June Is Automotive Service Professionals Month

Observance is opportunity to thank technicians for their crucial role in auto retail.

Read More →
DigitalJune 9, 2025

The Real ID Deadline

Challenges auto dealers may still face verifying identities

Read More →
Complianceby StaffApril 28, 2025

Law Firms Tops in Auto Work

They bested all others on value or volume in the first quarter on major deals.

Read More →
Ad Loading...
Complianceby StaffJanuary 30, 2025

Cox Automotive Releases Compliance Guide

New edition walks auto dealers through relevant regulations for 2025.

Read More →
ComplianceJanuary 1, 2025

Safeguarding Customer Data

Encryption serves a critical role in automotive retail today.

Read More →
Complianceby StaffDecember 24, 2024

Trump 2.0 and Retail Automotive

Administration’s plans should generally bode well for the industry.

Read More →
Ad Loading...
Product & Technologyby StaffOctober 30, 2024

CDK Global Wasn’t the Only Cyber Victim

Report says criminals also targeted thousands of auto dealerships and sustained an elevated volume of attacks in the industry.

Read More →