RegImpact
ftcfinal· Published 12/9/2021· Effective 1/10/2022

Standards for Safeguarding Customer Information

The Federal Trade Commission ("FTC" or "Commission") is issuing a final rule ("Final Rule") to amend the Standards for Safeguarding Customer Information ("Safeguards Rule" or "Rule"). The Final Rule contains five main modifications to the existing Rule. First, it adds provisions designed to provide covered financial institutions with more guidance on how to develop and implement specific aspects of an overall information security program, such as access controls, authentication, and encryption. Second, it adds provisions designed to improve the accountability of financial institutions' information security programs, such as by requiring periodic reports to boards of directors or governing bodies. Third, it exempts financial institutions that collect less customer information from certain requirements. Fourth, it expands the definition of "financial institution" to include entities engaged in activities the Federal Reserve Board determines to be incidental to financial activities. This change adds "finders"--companies that bring together buyers and sellers of a product or service--within the scope of the Rule. Finally, the Final Rule defines several terms and provides related examples in the Rule itself rather than incorporates them from the Privacy of Consumer Financial Information Rule ("Privacy Rule").

What this rule actually says

The FTC updated its data security rules to require financial institutions to protect customer information better. This means stronger passwords, encryption, access controls, and regular security reports to leadership. It's basically saying: if you hold financial customer data, you need to prove you're actually securing it—not just claiming you are.

Who it applies to

  • You're covered if: You collect financial information (bank accounts, payment methods, credit card numbers, loan details) from customers AND you're considered a "financial institution" under FTC rules
  • Financial institution = you if you: Process payments, handle lending decisions, manage customer bank data, or act as a "finder" connecting buyers/sellers (expanded definition as of this rule)
  • Likely examples that trigger this:
  • AI hiring assistant that processes applicant payment info or banking details
  • Medical scribe tool that handles patient insurance/billing data
  • Support chatbot integrated with payment processing
  • Any tool that stores or transmits customer financial information
  • You're probably NOT covered if: You only collect names, emails, or health data without financial information; you're a B2B SaaS tool with no direct consumer financial data
  • Jurisdictions: This is a federal FTC rule, so it applies everywhere in the US

What founders need to do

  1. Audit your data (1-2 days): List exactly what financial customer information you collect, store, or process. If it's none—you're done here.
  1. Document security controls (3-5 days): Write down how you're already securing this data: encryption standards, password requirements, who can access what, how you handle breaches. Don't overthink—describe reality.
  1. Set up board/leadership reporting (1 day): Even as a solo founder, document a simple quarterly security checklist and review it yourself. The rule wants "accountability to leadership"—you're the leadership.
  1. Add encryption and access controls (1-2 weeks): If you're not encrypting financial data at rest and in transit, fix that now. Implement basic access controls (not everyone on your team needs production database access).
  1. Create an incident response plan (2-3 days): Write a one-page plan for what you'll do if customer financial data gets breached (notify FTC/customers, investigate, remediate). Post-it-on-the-wall simple is fine.

Bottom line

If you handle customer financial data, act now—this rule has real teeth and the FTC actively enforces it; if you don't, monitor only in case you add payments later.