<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-03-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>3084-AB50</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202304</PUBLICATION_ID>
            <PUBLICATION_TITLE>Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>3084</CODE>
            <NAME>Federal Trade Commission</NAME>
            <ACRONYM>FTC</ACRONYM>
        </AGENCY>
        <RULE_TITLE>Identity Theft Rules</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>On December 11, 2018, the Commission initiated periodic review of the Identity Theft Rules, which include the Red Flags Rule and the Card Issuer Rule. The public comment period closed on February 11, 2019, and staff is reviewing the comments. Staff plans to submit a recommendation to the Commission by&nbsp;December 2023.</p>
<p>The Red Flags Rule requires financial institutions and creditors to develop and implement a written Identity Theft Prevention Program. By identifying red flags for identity theft in advance, businesses can be better equipped to spot suspicious patterns that may arise and take steps to prevent potential problems from escalating into a costly episode of identity theft. An Identity Theft Prevention Program must have four parts. First, the program must include reasonable policies and procedures to identify signs or red flags of identity theft in the day-to-day operations of the business. Second, the program must be designed to detect the red flags of identity theft identified by the business. Third, the program must set out the actions the business will take to detect red flags. Finally, because identity theft is an ever-changing threat, a business must re-evaluate its program periodically to reflect new risks from this crime.&nbsp;</p>
<p>The Card Issuer Rule requires credit and debit card issuers to implement reasonable policies and procedures to assess the validity of a change of address if it receives notification of a change of address for a consumer's debit or credit card account and, within a short period of time afterward, also receives a request for an additional or replacement card for the same account.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Substantive, Nonsignificant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Prerule Stage</RULE_STAGE>
        <MAJOR>Undetermined</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>16 CFR 681</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>15 U.S.C. 1681m(e)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 1681m(e)(4)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>15 U.S.C. 1681c(h)</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Rule Review; Request for Comments</TTBL_ACTION>
                <TTBL_DATE>12/11/2018</TTBL_DATE>
                <FR_CITATION>83 FR 63604</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Rule Review Comment Period Closed                                                            </TTBL_ACTION>
                <TTBL_DATE>02/11/2019</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Recommendation to Commission</TTBL_ACTION>
                <TTBL_DATE>12/00/2023</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Undetermined</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
            <SMALL_ENTITY>Governmental Jurisdictions</SMALL_ENTITY>
            <SMALL_ENTITY>Organizations</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Local</GOVT_LEVEL>
            <GOVT_LEVEL>State</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <FURTHER_INFO_URL>https://www.ftc.gov/news-events/press-releases/2018/12/ftc-seeks-comment-identity-theft-detection-rules</FURTHER_INFO_URL>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <RELATED_RIN_LIST>
            <RELATED_RIN>
                <RIN>3084-AA94</RIN>
                <RIN_RELATION>Split from</RIN_RELATION>
            </RELATED_RIN>
        </RELATED_RIN_LIST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Whitney</FIRST_NAME>
                <LAST_NAME>Moore</LAST_NAME>
                <TITLE>Attorney</TITLE>
                <AGENCY>
                    <CODE>3084</CODE>
                    <NAME>Federal Trade Commission</NAME>
                    <ACRONYM>FTC</ACRONYM>
                </AGENCY>
                <PHONE>202 326-2645</PHONE>
                <EMAIL>wmoore@ftc.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>600 Pennsylvania Avenue NW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20580</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
