WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Pro Bono
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
FTC Releases Updated Safeguards Rule for Financial Institutions
Alerts
November 2, 2021

On October 27, 2021, the Federal Trade Commission (FTC) released a final rule that updates the Safeguards Rule of the Gramm-Leach-Bliley Act (Final Rule). This Final Rule comes after the FTC sought comment on proposed changes to the Safeguards Rule in 2019 and held a public workshop in 2020.

The Safeguards Rule applies to non-banking financial institutions, including certain financial technology companies, that are engaged in financial activities. The Final Rule makes significant updates to the original Safeguards Rule promulgated in 2003, most notably by 1) requiring financial institutions to follow more specific criteria for implementing safeguards to help protect their customers' information; and 2) adding provisions that are intended to increase the accountability of information security programs.

Key Provisions

Key provisions in the Final Rule include:

  • Guidance on how to implement specific aspects of an information security program: Among other things, the Final Rule requires that financial institutions implement safeguards that address access controls, data inventory and classification, encryption, secure development practices, authentication, information disposal procedures, change management, testing, and incident response. Companies must also implement policies and procedures to enact those safeguards, hold trainings for employees on information security, and oversee any third-party service providers. Although the Final Rule has more specific requirements than the current Rule, it still provides financial institutions the flexibility to design an information security program that is appropriate to the size and complexity of the financial institution, the nature and scope of its activities, and the sensitivity of any customer information at issue.
  • Additional provisions that are intended to increase the accountability of information security programs: While the current rule allows for multiple individuals to have responsibility over a covered financial institution's information security program, the Final Rule narrows that responsibility to a single "Qualified Individual," who must periodically report to a board of directors or equivalent governing body, or to a senior officer responsible for the information security program.
  • Partial exemption of financial institutions that collect less customer information: Financial institutions that collect information on less than 5,000 customers are exempt from certain requirements, including documenting the required risk assessment in writing, performing vulnerability and penetration testing, establishing a written incident response plan, and annual reporting to the board.
  • Expansion of the definition of covered "financial institutions": Covered financial institutions now include entities that engage in activities that the Federal Reserve Board considers incidental to financial activities. This change brings only one activity into the definition that was not covered before: the act of "finding," which is defined as bringing together one or more buyers and sellers of any product or service for transactions that the parties themselves negotiate and consummate.

The final updated Safeguards Rule was passed 3-2, with Commissioners Noah Joshua Phillips and Christine S. Wilson dissenting. In their dissent, Phillips and Wilson criticized the updated rule for being too inflexible and prescriptive, and claimed that the record failed to show a need for updates to the Rule at all. The dissent argued that both competition and security itself would suffer, as smaller companies are less able to absorb the financial costs of new regulatory mandates, and covered companies may be incentivized to engage in a check-the-box exercise, rather than a thoughtful risk assessment. Chair Lina M. Khan and Commissioner Rebecca Kelly Slaughter wrote separately to push back on the dissenting commissioners' criticisms, and assert that these updates were necessary to protect consumer information and address an increasing amount of data breaches.

Separately, the FTC is also inviting comments on a proposed rulemaking to add a reporting requirement to the Safeguards Rule, which would require covered financial institutions to report data breaches and other security events to the commission.

Conclusion

Financial institutions—including financial technology companies—that are covered by the GLBA are encouraged to reexamine their information security programs under the new Safeguards Rule to ensure compliance. Wilson Sonsini Goodrich & Rosati routinely assists financial technology companies with GLBA compliance, and will monitor developments in enforcement and industry standards to continue to assist our clients.

For more information or advice concerning the updated Safeguards Rule, or for assistance with drafting a comment to the FTC about its proposed rulemaking, please contact Libby Weingarten, Roger Li, or another member of the firm's privacy and cybersecurity practice.

Contributors

  • Libby J. Weingarten
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.