Skip to content

menu

Open Legal Blog Archive logo
HomeAboutBlogsFAQsSubmit

FTC Amends Safeguards Rule to Require Certain Financial Institutions to Report Data Security Breaches

By Hunton Andrews Kurth LLP & Cristina Pluchino on October 30, 2023

On October 27, 2023, the Federal Trade Commission announced that it has approved an amendment to the Safeguards Rule that would require non-banking institutions to report certain data breaches to the FTC. The FTC’s Safeguards Rule currently requires certain types of non-banking financial institutions, such as mortgage brokers, motor vehicle dealers, and payday lenders, to develop, implement and maintain a comprehensive security program to keep their customers’ information safe. The amendment will require such financial institutions to notify the FTC as soon as possible, and no later than 30 days after discovery, of a security breach involving the unauthorized acquisition of unencrypted customer  information of at least 500 consumers. The notice to the FTC will need to include certain information about the event, such as the number of consumers affected or potentially affected.

The breach notification requirement becomes effective 180 days after publication of the rule in the Federal Register.

  • Posted in:
    Privacy & Data Security
  • Blog:
    Privacy & Information Security Law Blog
  • Organization:
    Hunton Andrews Kurth LLP

Open Legal Blog Archive, Inc. logo
Seattle, Washington
Copyright © 2026, Open Legal Blog Archive, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo