Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Regulations & Laws

GLBA Safeguards Rule

Also known as: Safeguards Rule, FTC Safeguards Rule, Gramm-Leach-Bliley Act Safeguards Rule
Simply put

The GLBA Safeguards Rule is a U.S. federal regulation that requires certain financial institutions to protect the security of their customers' personal information. It obligates covered businesses to create and maintain a written program describing how they safeguard that information. It is a binding legal requirement, not a voluntary standard, and it is enforced by the Federal Trade Commission (FTC) for institutions within its jurisdiction.

Formal definition

The Safeguards Rule is a regulation promulgated under the Gramm-Leach-Bliley Act (GLBA) that requires financial institutions subject to FTC jurisdiction to develop, implement, and maintain a comprehensive information security program incorporating administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer information. Covered institutions are generally required to document this program as a written information security plan (WISP). The Rule applies specifically to entities meeting the GLBA definition of a 'financial institution' within the FTC's enforcement scope; institutions supervised by other functional regulators may be subject to parallel requirements administered by those agencies rather than this FTC Rule. The FTC amended the Rule with substantive changes to its requirements, and available evidence indicates the compliance date for most of those changes was June 9, 2023. This entry describes the Rule qualitatively; because the regulatory text and its requirements are periodically amended, readers should verify current obligations, scope, and effective dates against the latest authoritative FTC source. Application to any specific organization depends on fact-specific factors and requires professional judgment.

Why it matters

For financial institutions within the FTC's jurisdiction, the Safeguards Rule converts information security from a discretionary best practice into a binding legal obligation. Unlike voluntary frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework, which an organization adopts by choice or contract, the Safeguards Rule carries the force of federal law and is enforceable by the FTC against covered entities. This distinction matters because a covered institution cannot satisfy the Rule merely by aligning informally with a security standard; it must develop, implement, and maintain a documented program that meets the Rule's specific requirements.

The Rule also reflects the reality that many businesses handling customer financial information are not traditional banks. The GLBA definition of a 'financial institution' reaches a broad range of entities engaged in financial activities, and those that fall within the FTC's enforcement scope are directly affected. Because the FTC amended the Rule with substantive changes—with available evidence indicating a compliance date of June 9, 2023 for most of those changes—organizations that had older programs in place may have needed to revisit and update them to remain compliant.

Because obligations under the Rule are fact-specific and the regulatory text is periodically amended, the practical significance for any given organization depends on whether it meets the GLBA definition of a financial institution and falls within FTC jurisdiction rather than under another functional regulator. Readers should verify current scope and requirements against the latest authoritative FTC source rather than relying on any single summary as permanent.

Who it's relevant to

Compliance officers at non-bank financial institutions
Professionals responsible for regulatory compliance at businesses that meet the GLBA definition of a financial institution and fall within FTC jurisdiction need to determine whether the Rule applies and ensure a documented information security program is in place. Because the Rule was amended with substantive changes, compliance teams should confirm their program reflects current requirements rather than a prior version.
Information security professionals
Those who design and operate security programs are the practitioners who translate the Rule's requirement for administrative, technical, and physical safeguards into concrete controls. Their work generally underpins the written information security plan that covered institutions are expected to maintain, though the specific controls appropriate to an organization depend on fact-specific factors.
Legal counsel and privacy specialists
Advisers assessing whether an entity is a 'financial institution' within the FTC's enforcement scope—as opposed to one supervised by another functional regulator subject to parallel requirements—play a key role in scoping obligations. Given that the regulatory text is periodically amended, counsel should verify current scope and effective dates against the latest authoritative FTC source.
Auditors and assessors
Professionals evaluating a covered institution's safeguards may reference the Rule as a binding legal benchmark. They should distinguish an assessment of alignment with the Rule from certification against a voluntary standard, and recognize that a favorable review does not itself establish legal compliance, which remains fact-specific and subject to FTC interpretation.

Inside GLBA Safeguards Rule

Scope and Applicability
The Safeguards Rule is issued under the Gramm-Leach-Bliley Act (GLBA) and applies to 'financial institutions' within the jurisdiction of the U.S. Federal Trade Commission that are not otherwise regulated by another functional regulator. This covers a broad range of entities beyond traditional banks, including mortgage brokers, payday lenders, auto dealers engaged in financing, tax preparers, and certain financial advisors. Whether a given entity qualifies is fact-specific and should be verified against the current rule text and FTC guidance.
Information Security Program Requirement
The rule generally requires covered financial institutions to develop, implement, and maintain a written, comprehensive information security program containing administrative, technical, and physical safeguards appropriate to the institution's size, complexity, the nature and scope of its activities, and the sensitivity of the customer information at issue.
Qualified Individual
The rule generally calls for designating a person responsible for overseeing, implementing, and enforcing the information security program. This individual may be an employee or a third party, though accountability for oversight typically remains with the institution.
Risk Assessment
Institutions are generally expected to conduct a written risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information, and to base safeguards on the results of that assessment. The precise required elements should be confirmed against the current rule text.
Safeguards and Controls
The rule contemplates specific categories of controls designed to address identified risks, which may include access controls, inventory and classification of data, encryption, secure development practices, multi-factor authentication, disposal procedures, change management, and monitoring of authorized user activity. Applicability of particular controls can depend on the institution's risk profile.
Testing and Monitoring
Covered institutions are generally expected to regularly test or otherwise monitor the effectiveness of their safeguards, including monitoring for attempted and actual attacks on or intrusions into information systems.
Personnel and Training
The rule addresses security awareness training for personnel and ensuring that staff and any service providers are capable of maintaining appropriate safeguards.
Service Provider Oversight
Institutions are generally required to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards and to contractually require those providers to implement and maintain such safeguards.
Incident Response and Program Governance
The rule contemplates a written incident response plan and periodic reporting to a board of directors or governing body (or equivalent) on the status of the information security program, with periodic evaluation and adjustment of the program in light of changes and test results.

Common questions

Answers to the questions practitioners most commonly ask about GLBA Safeguards Rule.

Is the GLBA Safeguards Rule the same as the GLBA Privacy Rule?
No. Although both arise under the Gramm-Leach-Bliley Act and are administered largely through the same federal framework, they address distinct obligations. The Safeguards Rule concerns the security of customer information—requiring financial institutions to develop, implement, and maintain an information security program to protect that data. The Privacy Rule addresses privacy: how institutions handle the disclosure of nonpublic personal information to nonaffiliated third parties and the related notice and opt-out obligations owed to consumers. Security and privacy are related but separate concepts, and compliance with one does not establish compliance with the other. Readers should consult the current official text of each rule to confirm the specific requirements applicable to their situation.
Does the GLBA Safeguards Rule apply only to banks?
No. The Rule reaches a broad category of entities that fall within the statutory definition of 'financial institution,' which extends well beyond traditional banks and depository institutions. It can capture businesses engaged in activities that are financial in nature, potentially including entities such as mortgage lenders, certain auto dealers engaged in financing, payday lenders, tax preparers, and similar service providers, depending on the nature of their activities. Whether a particular organization qualifies is a fact-specific determination that turns on the activities it conducts rather than its industry label. Coverage and the allocation of enforcement authority among federal regulators can vary, so organizations should verify their status against the current definitions in the authoritative text.
Who within an organization is responsible for the information security program under the Safeguards Rule?
The Rule generally contemplates that a covered financial institution designate a qualified individual to oversee, implement, and be accountable for its information security program. The intent is to establish clear ownership and accountability rather than to prescribe a specific job title. In practice, organizations assign this responsibility in ways that reflect their size, structure, and risk profile, and the designated individual need not personally perform every task. Because expectations regarding qualifications and the scope of oversight can depend on organizational circumstances, and because the requirement may be interpreted in light of enforcement practice, readers should confirm the current text and apply professional judgment to their own context.
What role does a risk assessment play in complying with the Safeguards Rule?
A risk assessment is generally central to the Rule's approach, which is designed to be risk-based rather than a fixed checklist. The information security program is typically expected to be based on an assessment that identifies reasonably foreseeable risks to the security, confidentiality, and integrity of customer information, so that the safeguards an institution adopts are proportionate to the risks it faces. This means that appropriate controls may differ from one organization to another based on size, complexity, and the nature and scope of activities. The precise content and documentation expectations for a risk assessment can evolve, so readers should verify the current requirements in the authoritative text.
How does the Safeguards Rule address the use of third-party service providers?
The Rule generally addresses oversight of service providers that handle or have access to customer information. In most cases this involves selecting providers capable of maintaining appropriate safeguards, addressing security expectations through contractual arrangements, and monitoring or overseeing those providers over time. Engaging a vendor does not, on its own, transfer the covered institution's own accountability for protecting customer information. The specific diligence and contractual steps that are considered adequate are fact-specific and may depend on the sensitivity of the data and the services provided, so organizations should confirm the applicable requirements against the current official text and apply professional judgment.
How does the Safeguards Rule relate to voluntary security frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework?
The Safeguards Rule is a binding legal requirement for covered financial institutions, whereas frameworks such as ISO/IEC 27001 and the NIST Cybersecurity Framework are voluntary and carry no legal force unless incorporated by contract or otherwise adopted. Organizations may use such frameworks to help structure and operationalize the information security program the Rule requires, and mapping controls to a recognized framework can support a consistent approach. However, alignment with or certification against a voluntary framework does not, by itself, establish legal compliance with the Rule, which sets its own requirements. Framework versions and certification schemes change over time, so readers should treat these as complementary tools and verify obligations against the current text of the Rule.

Common misconceptions

The Safeguards Rule is a voluntary security framework similar to ISO/IEC 27001 or the NIST Cybersecurity Framework.
The Safeguards Rule is a binding federal regulation issued under GLBA and enforced by the FTC for institutions within its jurisdiction, not a voluntary standard. Voluntary frameworks may help an institution structure its program, but adopting such a framework does not by itself satisfy the rule, and the rule carries legal force where it applies.
The rule applies only to banks and other traditional depository institutions.
The FTC's Safeguards Rule reaches a broad set of 'financial institutions' that are not regulated by another functional regulator, which can include non-bank entities such as mortgage brokers, auto dealers offering financing, tax preparers, and certain financial advisors. Coverage is fact-specific and should be confirmed against the current rule and FTC guidance.
Implementing a fixed checklist of controls guarantees compliance for every institution.
The rule generally calls for safeguards that are appropriate to the institution's size, complexity, activities, and the sensitivity of the customer information, and it ties controls to a documented risk assessment. Compliance is risk-based and context-dependent rather than a one-size-fits-all checklist, and application to particular circumstances requires professional judgment.

Best practices

Maintain a current, written information security program and a documented risk assessment, and revisit both when your systems, services, data, or threat landscape change materially.
Clearly designate the qualified individual responsible for the program and establish a reporting line to the board or governing body so oversight and accountability are documented.
Map which of your activities and data bring you within the definition of a 'financial institution' under the rule, and confirm this analysis against the current FTC rule text and guidance rather than relying on assumptions about entity type.
Build service provider oversight into procurement and contracting, requiring vendors to implement appropriate safeguards and periodically assessing their continued capability.
Implement and document testing or continuous monitoring of key controls, along with a written incident response plan, and retain evidence of both to demonstrate ongoing program effectiveness.
Verify specific requirements, effective dates, and any amendments against the latest authoritative FTC source, and treat this entry as informational rather than as legal advice for a particular situation.
Promotional banner for the Pentest Readiness checklist download