Hero background
Compliance Updates4 min read

GLBA Compliance for Lenders: The FTC Safeguards Rule in Practice

By Michael Dunleavey
August 4, 2026Updated August 4, 2026
ftc safeguards rulegramm-leach-bliley actsafeguards rule compliance

GLBA compliance — meeting the Gramm-Leach-Bliley Act's data-security obligations, chiefly the FTC's Safeguards Rule — is now one of the most concrete compliance duties a lender carries. What began as a principles-based expectation is today a prescriptive checklist of technical and administrative controls, backed by a breach-notification requirement that took effect in 2024. This guide covers who the rule reaches, what it requires, and how to put it into practice.

Who the Safeguards Rule covers

The FTC's Safeguards Rule (16 CFR Part 314) applies to "financial institutions" under the FTC's jurisdiction, and the definition is broad. It includes mortgage lenders, finance companies, mortgage brokers, account servicers, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, and entities acting as finders. In short: if your organization extends credit, services loans, or handles consumer financial information, assume the rule applies to you.

What the amended Safeguards Rule requires

The 2021 amendments, which became fully effective in June 2023, turned the rule into a specific set of requirements. The core obligations:

A written information security program

Every covered institution must develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards appropriate to its size, complexity, and the sensitivity of the customer information it handles.

A Qualified Individual

You must designate a single Qualified Individual to oversee the program. This person implements and enforces it and reports to your board or governing body at least annually. They can be an employee or an external provider, but the institution keeps responsibility for compliance.

A written risk assessment

You must conduct — and periodically update — a written risk assessment identifying reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information.

Technical safeguards

The rule requires specific controls: multi-factor authentication for anyone accessing customer information; encryption of customer information both in transit and at rest; access controls limiting information to authorized users; and secure disposal of customer information no later than two years after the last date it was used.

Testing and monitoring

Absent effective continuous monitoring, the rule requires annual penetration testing and vulnerability assessments at least every six months, plus additional assessments when there are material changes to operations.

Breach notification (effective May 2024)

As of May 13, 2024, covered institutions must notify the FTC as soon as possible — and no later than 30 days after discovery — of a security breach involving the unencrypted information of at least 500 consumers. Information counts as unencrypted if the encryption key was also acquired by an unauthorized person. The notice is filed through the FTC's electronic reporting form and includes the types of information involved, the date range of the event, the number of consumers affected, and whether law enforcement has requested a delay.

The small-business exception

Institutions that maintain customer information on fewer than 5,000 consumers are exempt from several requirements — the written risk assessment, the penetration testing and vulnerability assessment mandates, the written incident response plan, and board reporting. They must still maintain reasonable safeguards appropriate to their size and operations.

A GLBA compliance checklist

  • Designate a Qualified Individual to oversee the information security program.
  • Develop and maintain a written information security program.
  • Conduct and document a written risk assessment.
  • Implement multi-factor authentication for all systems holding customer information.
  • Encrypt customer information in transit and at rest.
  • Limit access to authorized users, and securely dispose of data within two years of last use.
  • Run annual penetration testing and semiannual vulnerability assessments (absent continuous monitoring).
  • Maintain a written incident response plan.
  • Configure FTC breach-notification procedures for events affecting 500 or more consumers.
  • Report to the board or senior management at least annually.
  • Assess service providers and require contractual security commitments.

Where Salesforce and LASER fit

For lenders on Salesforce, the platform supplies a strong foundation — multi-factor authentication, role-based access controls, field-level security, encryption at rest and in transit, and audit logging — but the Safeguards Rule makes it your responsibility to configure those correctly and document them as part of your written program. LASER Credit Access adds controls specific to credit bureau data: a permission-set architecture that governs who can pull and view credit reports, and protection of managed fields on the credit report records. LASER helps you surface and track these obligations; it does not discharge your institution's legal duties for you.

For how GLBA sits alongside the other rules that govern a lending stack, see our adverse action notice guide, the OFAC checks guide, and our lending compliance software.

This article is for informational and educational purposes only and is not legal advice. Requirements change and vary by institution type; confirm current requirements with qualified legal counsel before acting.

Frequently Asked Questions

What is GLBA compliance?

GLBA compliance means meeting the requirements of the Gramm-Leach-Bliley Act, most notably the FTC's Safeguards Rule (16 CFR Part 314), which requires financial institutions to build and maintain a written information security program to protect customer information. It applies broadly to lenders, servicers, brokers, and other companies that handle consumer financial data.

Who has to comply with the FTC Safeguards Rule?

Financial institutions under the FTC's jurisdiction. The definition is broad and includes mortgage lenders, finance companies, mortgage brokers, account servicers, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, and entities acting as finders. If your organization extends credit, services loans, or otherwise handles consumer financial information, the Safeguards Rule almost certainly applies.

What does the amended Safeguards Rule require?

A written information security program overseen by a designated Qualified Individual; a written risk assessment; technical controls including multi-factor authentication, encryption of customer data in transit and at rest, access controls, and secure disposal no later than two years after last use; annual penetration testing and semiannual vulnerability assessments absent continuous monitoring; a written incident response plan; and, since May 2024, notification to the FTC of qualifying data breaches.

What is the Safeguards Rule breach-notification requirement?

As of May 13, 2024, covered financial institutions must notify the FTC as soon as possible, and no later than 30 days after discovery, of a security breach involving the unencrypted information of at least 500 consumers. The notice is filed electronically through the FTC's reporting form.

Is there a small-business exception?

Institutions that maintain customer information on fewer than 5,000 consumers are exempt from certain requirements — the written risk assessment, penetration testing and vulnerability assessment mandates, the written incident response plan, and board reporting — but must still maintain reasonable safeguards appropriate to their size and operations.

Michael Dunleavey

Founder — LASER Credit Access

Michael Dunleavey brings over 15 years of experience in credit infrastructure and lending compliance, helping financial institutions streamline operations on Salesforce.

Ready to Transform Your Credit Operations?

Discover how LASER Credit Access streamlines compliance and decisioning natively inside Salesforce — unified in a single app, ready from day one.