Call us now!
DALLAS: 972-640-8471
In 2021, the FTC amended the Safeguards Rule (which originally took effect in 2003) to ensure its contents reflect advancements in technology. Originally, the rule was developed to ensure financial institutions protect consumers’ private data. According to the FTC, the 2021 update provides “more concrete guidance for businesses,” including the data security principles affected companies must implement. It will also now apply to a much broader scope of business types.
While the amendment was made in 2021 and the deadline for requirements is approaching, many companies still lack clarity about whether they’re affected and if so, what must be done to ensure compliance. Here’s a quick guide to the New FTC Safeguards Rule to help clear up any uncertainties.
The amended rule expands the definition of financial institutions, meaning many businesses which previously were not impacted by the rule will be now. The 2003 Safeguards Rule was meant to regulate financial institutions — or organizations “significantly engaged in financial activities.” Now, however, it’s not just banks and similar financial institutions that will be covered under the rule.
By the FTC’s updated definition, affected organizations will be those significantly involved in financial activities, as well as activities incidental to such financial activities. In other words, companies that extend credit lines, offer loans, or are somehow involved with consumers’ ability to access money will all be regulated under the new rule. As the FTC puts it , “The definition of a ‘financial institution’ isn’t a hushed hall with tellers, deposit slips, and ballpoint pens on chains.”
In addition to financial institutions, the FTC cites several other examples of business types that will be impacted by the new rule:
Clearly, a seemingly simple change in verbiage makes the updated rule much more expansive, and many businesses will have to implement changes to ensure compliance with the rule before it takes effect. The above list isn’t exhaustive, however, so as the FTC notes , “If you aren’t sure if you’re covered, now’s the time to nail that down.”
Originally, the deadline for the FTC’s Revised Safeguards Rule was December 9, 2022. The new deadline for the Revised Safeguards Rule is June 9, 2023 . In November 2022, the FTC issued a statement which cited “reports of personnel shortages and supply chain issues” as the driver for the extension.
At the most basic level, the Safeguards Rule requires covered organizations to develop, implement, and maintain a program that protects consumer data. Yet, the rule’s provisions are far more complex than that, calling for a written information security program that’s tailored to each business’s size, complexity, and nature of activities. According to the FTC, the program should:
Indeed, covered companies will need to implement a robust information security program. The FTC outlines nine core elements for the program:
As you can see, the requirements are robust and call for an equally comprehensive approach. When considering your company’s compliance measures, allow us to assist by providing sophisticated solutions for data security that fit your business’s unique needs.
The post FTC Safeguards Rule appeared first on IT ArchiTeks.