ARTICLE
20 November 2023

FTC Updates Safeguards Rule With Data Breach Notification Requirement

GT
Greenberg Traurig, LLP

Contributor

Greenberg Traurig, LLP has more than 2750 attorneys in 47 locations in the United States, Europe and the Middle East, Latin America, and Asia. The firm is a 2022 BTI “Highly Recommended Law Firm” for superior client service and is consistently among the top firms on the Am Law Global 100 and NLJ 500. Greenberg Traurig is Mansfield Rule 6.0 Certified Plus by The Diversity Lab. The firm is recognized for powering its U.S. offices with 100% renewable energy as certified by the Center for Resource Solutions Green-e® Energy program and is a member of the U.S. EPA’s Green Power Partnership Program. The firm is known for its philanthropic giving, innovation, diversity, and pro bono. Web: www.gtlaw.com.
On Oct. 27, 2023, the Federal Trade Commission (FTC) amended its Standards for Safeguarding Customer Information (the Safeguards Rule), promulgated under the Gramm-Leach-Bliley Act (GLBA)...
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.
Go-To Guide:
  • The FTC will require financial institutions to notify the agency of data breaches impacting 500 or more consumers.
  • The notification must be made via a web form on the FTC's website within 30 days of discovering a notification event.
  • The FTC will publish these notices publicly on its website.
  • Notification events include any incident where unencrypted customer data is acquired. Unauthorized acquisition is presumed in cases of unauthorized access.


On Oct. 27, 2023, the Federal Trade Commission (FTC) amended its Standards for Safeguarding Customer Information (the Safeguards Rule), promulgated under the Gramm-Leach-Bliley Act (GLBA), to require financial institutions to provide notice to the FTC of data breaches that impact more than 500 consumers (the Amendment). This comes after the FTC's major update to the Safeguards Rule's proactive security requirements in 2021.

The Safeguards Rule applies to financial institutions regulated by the FTC, which typically include non-banking entities.

Notification Event

The Amendment requires that financial institutions report any "notification event," which the FTC has defined as an acquisition of unencrypted customer information without authorization of the individual to which the information pertains. Notably, the Amendment specifies that unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information, unless the financial institution has reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information. Financial institutions should accordingly presume that unauthorized access is a notification event unless there is proof that no acquisition occurred.

There are no exceptions for events that do not or are not likely to result in consumer harm. Similarly, there are no exceptions for breaches that involve non-sensitive types of information. This distinguishes the FTC's Safeguards Rule requirements from the GLBA Interagency Guidance relied upon by banking entities, which requires notification only if sensitive customer information (e.g., Social Security number, driver's license number, etc.) has been impacted.

30-Day Timing Requirement

The notification event must be reported to the FTC within 30 days of the event being "discovered." The Amendment clarifies that an event is discovered on the first day when such event is known to the financial institution, including any person, other than the person committing the breach, who is the financial institution's employee, officer, or other agent.

Notification Content and Publication

Notices to the FTC will be submitted electronically via a form on the FTC's website. The notices will require the following information:

  • Name and contact of the financial institution;
  • Description of the types of information held by the reporting financial institution;
  • If the information is possible to determine, the date or date range of the notification event; and
  • A general description of the notification event.

The FTC intends to publish the notices it receives, which may lead to an increased risk of consumer class action lawsuits against the reporting entity. As stated in its comments to the amendment, the FTC believes that making the notices public will enable consumers to make more informed decisions about which financial institutions they choose to entrust with their information, providing financial institutions an "additional incentive" to comply with the Safeguards Rule.

No Individual Notification Requirement

Unlike the GLBA Interagency Guidance issued by banking regulators, the Amendment only requires notification to the FTC and does not require that financial institutions notify individuals. Financial institutions regulated by the FTC will still need to rely on state data breach notification laws to determine their obligations for individual notification.

Timeline

The breach notification requirement will become effective 180 days after the Amendment is published in the Federal Register.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More