← Independent regulator rules (SEC/Fed/FDIC/SBA/FTC/NCUA/CPSC/FHFA/EEOC/NLRB)

Standards for Safeguarding Customer Information

FTC · final-rule · Published 2021-12-09 · Effective 2022-01-10 · 86 FR 70272

Document

Document number
2021-25736
Federal Register citation
86 FR 70272
CFR reference
16 CFR 314
Type
Rule
Action
Final rule.
Category
final-rule
Agency
US Federal Trade Commission
Publication date
2021-12-09
Effective date
2022-01-10

Abstract

The Federal Trade Commission ("FTC" or "Commission") is issuing a final rule ("Final Rule") to amend the Standards for Safeguarding Customer Information ("Safeguards Rule" or "Rule"). The Final Rule contains five main modifications to the existing Rule. First, it adds provisions designed to provide covered financial institutions with more guidance on how to develop and implement specific aspects of an overall information security program, such as access controls, authentication, and encryption. Second, it adds provisions designed to improve the accountability of financial institutions' information security programs, such as by requiring periodic reports to boards of directors or governing bodies. Third, it exempts financial institutions that collect less customer information from certain requirements. Fourth, it expands the definition of "financial institution" to include entities engaged in activities the Federal Reserve Board determines to be incidental to financial activities. This change adds "finders"--companies that bring together buyers and sellers of a product or service--within the scope of the Rule. Finally, the Final Rule defines several terms and provides related examples in the Rule itself rather than incorporates them from the Privacy of Consumer Financial Information Rule ("Privacy Rule").

Source

Authoritative
Federal Register document
Machine
JSON-LD · Markdown