GLBA Safeguards Rule
The GLBA Safeguards Rule is a U.S. federal regulation that requires certain financial institutions to protect the security of their customers' personal information. It obligates covered businesses to create and maintain a written program describing how they safeguard that information. It is a binding legal requirement, not a voluntary standard, and it is enforced by the Federal Trade Commission (FTC) for institutions within its jurisdiction.
The Safeguards Rule is a regulation promulgated under the Gramm-Leach-Bliley Act (GLBA) that requires financial institutions subject to FTC jurisdiction to develop, implement, and maintain a comprehensive information security program incorporating administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer information. Covered institutions are generally required to document this program as a written information security plan (WISP). The Rule applies specifically to entities meeting the GLBA definition of a 'financial institution' within the FTC's enforcement scope; institutions supervised by other functional regulators may be subject to parallel requirements administered by those agencies rather than this FTC Rule. The FTC amended the Rule with substantive changes to its requirements, and available evidence indicates the compliance date for most of those changes was June 9, 2023. This entry describes the Rule qualitatively; because the regulatory text and its requirements are periodically amended, readers should verify current obligations, scope, and effective dates against the latest authoritative FTC source. Application to any specific organization depends on fact-specific factors and requires professional judgment.
Why it matters
For financial institutions within the FTC's jurisdiction, the Safeguards Rule converts information security from a discretionary best practice into a binding legal obligation. Unlike voluntary frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework, which an organization adopts by choice or contract, the Safeguards Rule carries the force of federal law and is enforceable by the FTC against covered entities. This distinction matters because a covered institution cannot satisfy the Rule merely by aligning informally with a security standard; it must develop, implement, and maintain a documented program that meets the Rule's specific requirements.
The Rule also reflects the reality that many businesses handling customer financial information are not traditional banks. The GLBA definition of a 'financial institution' reaches a broad range of entities engaged in financial activities, and those that fall within the FTC's enforcement scope are directly affected. Because the FTC amended the Rule with substantive changes—with available evidence indicating a compliance date of June 9, 2023 for most of those changes—organizations that had older programs in place may have needed to revisit and update them to remain compliant.
Because obligations under the Rule are fact-specific and the regulatory text is periodically amended, the practical significance for any given organization depends on whether it meets the GLBA definition of a financial institution and falls within FTC jurisdiction rather than under another functional regulator. Readers should verify current scope and requirements against the latest authoritative FTC source rather than relying on any single summary as permanent.
Who it's relevant to
Inside GLBA Safeguards Rule
Common questions
Answers to the questions practitioners most commonly ask about GLBA Safeguards Rule.

