<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-04-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>3084-AB35</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202404</PUBLICATION_ID>
            <PUBLICATION_TITLE>Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>3084</CODE>
            <NAME>Federal Trade Commission</NAME>
            <ACRONYM>FTC</ACRONYM>
        </AGENCY>
        <RULE_TITLE>Standards for Safeguarding Customer Information</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Safeguards Rule,&nbsp;which was issued under the Gramm-Leach-Bliley (GLB) Act, requires each financial institution&nbsp;subject to the FTC's jurisdiction to develop a written information security program to keep customer information secure that is appropriate to its size and complexity, the nature and scope of its activities, and the sensitivity of the customer information at issue. Companies covered by the rule are also responsible for taking steps to ensure that their service providers safeguard customer information in their care. The Commission believes that the rule strikes an appropriate balance between allowing&nbsp;financial institutions flexibility and establishing standards for safeguarding customer information that are consistent with GLB's requirements.</p>
<p>&nbsp;</p>
<p>As part of its ongoing systematic review of all rules and guides, on September 7,&nbsp;2016, the Commission requested public comments on, among other things, the economic impact and benefits of the rule; possible conflict between the rule and State, local, or other Federal laws or regulations; and the effect on the rule of any technological, economic, or other industry changes. 81 FR 61632 (Sept. 7, 2016). The comment period closed on November 7, 2016. On March 5, 2019, the Commission announced a Notice of Proposed Rulemaking (NPRM).&nbsp;84 FR 13158 (April 4, 2019).&nbsp;The public comment period as extended closed on August 2, 2019. 84 FR 24049 (May 24, 2019). Staff is reviewing approximately 50 comments that were submitted. On March 6, 2020, the Commission announced that a public workshop relating to the April 4, 2019 NPRM would be held on May 13, 2020. 85 FR 13082 (Mar. 6, 2020). However, due to the COVID-19 pandemic, the workshop was postponed until July 13, 2020.</p>
<p>&nbsp;</p>
<p class="GPOHtml">On December 9, 2021, the Commission issued a final rule that, among other amendments, provides additional requirements for financial institutions&rsquo; information security programs. 86 FR 70272 (Dec. 9, 2021). The final rule also expands the definition of "financial institution&rdquo; to include entities that are significantly engaged in activities that are incidental to financial activities, so that the rules would cover "finders" for example, companies that serve as lead generators for payday loan companies or mortgage companies. This rule was effective January 10, 2022, except that the provisions set forth in section &thinsp;314.5 are applicable beginning June 9, 2023. 87 FR 71509 (Nov. 23, 2022).</p>
<p class="GPOHtml">&nbsp;</p>
<p>On December 9, 2021, the Commission also issued a Supplemental Notice of Proposed Rulemaking that proposes to further amend the Safeguards Rule to require financial institutions to report to the Commission any security event where the financial institutions have determined misuse of customer information has occurred or is reasonably likely and that at least 1,000 consumers have been affected or reasonably may be affected. 86 FR 70062 (Dec. 9, 2021). The comment period closed on February 7, 2022.</p>
<p>&nbsp;</p>
<p class="GPOHtml">On November 13, 2023, the Commission issued a final rule amendment that requires covered financial institutions to notify the FTC as soon as possible, and no later than 30 days after discovery, of a security breach involving the information of at least 500 consumers. 88 FR 77499 (Nov. 13, 2023). Such an event requires notification if unencrypted customer information has been acquired without the authorization of the individual to which the information pertains. The notice to the FTC must include certain information about the event, such as the number of consumers affected or potentially affected. The breach notification requirement was effective on May 13, 2024.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Substantive, Nonsignificant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Completed Actions</RULE_STAGE>
        <MAJOR>No</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>16 CFR 314</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>The Gramm-Leach-Bliley Act as codified at 15 U.S.C. 6801(b), 6805(b)(2)</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Rule Review, Request for Public Comment</TTBL_ACTION>
                <TTBL_DATE>09/07/2016</TTBL_DATE>
                <FR_CITATION>81 FR 61632</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Comment Period End</TTBL_ACTION>
                <TTBL_DATE>11/07/2016</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>04/04/2019</TTBL_DATE>
                <FR_CITATION>84 FR 13158</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period Extended</TTBL_ACTION>
                <TTBL_DATE>05/24/2019</TTBL_DATE>
                <FR_CITATION>84 FR 24049</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Extended Comment Period End</TTBL_ACTION>
                <TTBL_DATE>08/02/2019</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Public Workshop Announcement</TTBL_ACTION>
                <TTBL_DATE>03/06/2020</TTBL_DATE>
                <FR_CITATION>85 FR 13082</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Public Workshop Rescheduled (Press Release)</TTBL_ACTION>
                <TTBL_DATE>04/21/2020</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Public Workshop</TTBL_ACTION>
                <TTBL_DATE>07/13/2020</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Public Workshop Comment Period End</TTBL_ACTION>
                <TTBL_DATE>08/12/2020</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Supplemental NPRM</TTBL_ACTION>
                <TTBL_DATE>12/09/2021</TTBL_DATE>
                <FR_CITATION>86 FR 70062</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Rule</TTBL_ACTION>
                <TTBL_DATE>12/09/2021</TTBL_DATE>
                <FR_CITATION>86 FR 70272</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Rule Effective (All Except Section 314.5)</TTBL_ACTION>
                <TTBL_DATE>01/10/2022</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Supplemental NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>02/07/2022</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Rule Effective Date Extended</TTBL_ACTION>
                <TTBL_DATE>11/23/2022</TTBL_DATE>
                <FR_CITATION>87 FR 71509</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Rule Effective (Section 314.5)</TTBL_ACTION>
                <TTBL_DATE>06/09/2023</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Rule</TTBL_ACTION>
                <TTBL_DATE>11/13/2023</TTBL_DATE>
                <FR_CITATION>88 FR 77499</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Rule Effective Date</TTBL_ACTION>
                <TTBL_DATE>05/13/2024</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>No</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>None</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <FURTHER_INFO_URL>https://www.ftc.gov/news-events/news/press-releases/2023/10/ftc-amends-safeguards-rule-require-non-banking-financial-institutions-report-data-security-breaches</FURTHER_INFO_URL>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>Yes</INTERNATIONAL_INTEREST>
        <RELATED_RIN_LIST>
            <RELATED_RIN>
                <RIN>3084-AA87</RIN>
                <RIN_RELATION>Previously reported as</RIN_RELATION>
            </RELATED_RIN>
        </RELATED_RIN_LIST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>David</FIRST_NAME>
                <LAST_NAME>Lincicum</LAST_NAME>
                <AGENCY>
                    <CODE>3084</CODE>
                    <NAME>Federal Trade Commission</NAME>
                    <ACRONYM>FTC</ACRONYM>
                </AGENCY>
                <PHONE>202 326-2773</PHONE>
                <EMAIL>dlincicum@ftc.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>600 Pennsylvania Avenue NW, CC-8232,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20580</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
