Most people associate GLBA with banks. That's the wrong mental model. The Gramm-Leach-Bliley Act's Safeguards Rule — enforced by the FTC for the vast majority of covered businesses — applies to a much broader category of "financial institutions" than most small business owners realize. If your business handles customer financial information in almost any context, you may be covered.
And if you haven't looked at your Safeguards Rule compliance since before June 2023, you're working from the old version of the rule.
Who Is Actually Covered
Under GLBA, a "financial institution" is any business that is "significantly engaged" in financial activities. The FTC's definition is broader than the banking definition and includes:
- Mortgage brokers and lenders
- Auto dealers that arrange or offer financing
- Financial advisors and investment advisors not regulated by the SEC
- State-registered investment advisors (RIAs with AUM below the SEC registration threshold)
- Tax preparers
- Accountants who prepare tax returns
- Insurance agents and companies
- Check cashing and payday lending businesses
- Real estate settlement services
- Retailers that issue store credit cards or offer financing
- Debt collectors
In Maine, this covers a significant number of small businesses that don't think of themselves as financial institutions. A tax preparation firm in Portland, a mortgage broker in Bangor, an independent financial advisor in Augusta — all covered under GLBA's Safeguards Rule and all subject to the FTC's June 2023 requirements.
One important carve-out: banks, credit unions, and other financial institutions regulated by federal banking agencies (OCC, Federal Reserve, FDIC, NCUA) are covered by their own regulators' Safeguards-equivalent rules, not the FTC's version. This post is about the FTC's Safeguards Rule for non-bank financial institutions.
What Changed in June 2023
The FTC's Safeguards Rule was originally enacted in 2002 and hadn't been substantially updated until the 2021 revision that took effect in phases with most provisions required by June 9, 2023. The changes are significant.
The original rule required a written information security program and "reasonable" safeguards. The 2023 rule specifies what "reasonable" means. If you built your Safeguards compliance around the old rule, you have gaps.
What the 2023 rule specifically requires:
Designated qualified individual: One person must be responsible for your information security program. This can be an employee or a third party (like a vCISO). Their name must be on record and they must report to your governing body at least annually.
Written risk assessment: A documented assessment identifying reasonably foreseeable risks to the security, confidentiality, and integrity of customer information. The assessment must be in writing, must address all business operations, and must be used to design your safeguards.
Access controls: Limit access to customer information to users who need it for their role. Implement physical and technical controls restricting access. Keep an inventory of data systems and who has access.
Encryption: Customer information must be encrypted both in transit over external networks and at rest. "At rest" means on servers, laptops, backup media, and portable devices. This is specific — encryption is no longer an option you weigh in a risk assessment; it's required.
Multi-factor authentication: MFA is required for any individual accessing any information system with customer information. The rule allows for equivalent controls with documented justification, but MFA is the default expectation.
Secure development: If you develop software to access customer information, your development process must include security review.
Penetration testing and vulnerability assessments: Annual penetration testing of your systems and continuous monitoring or vulnerability assessments at least every six months. This is one of the most significant new requirements for small businesses — many had never conducted a penetration test.
Incident response plan: A written plan for responding to security events. The plan must address goals, internal processes, roles and responsibilities, external communications, and post-incident review procedures.
Vendor oversight: Service providers who access customer information must be selected and retained through a process that considers their security practices. Contracts with those providers must include appropriate security requirements.
Annual report to the board: Your qualified individual must provide a written report to your board of directors (or senior officer equivalent if you have no board) at least annually. The report must cover the state of your information security program, compliance with the Safeguards Rule, material changes to risk assessment, recommendations for changes, and any security events.
The Small Business Exemption — and Its Limits
The FTC built a limited exemption into the 2023 rule for businesses that maintain customer information of fewer than 5,000 consumers. If your business falls below that threshold, you're exempt from a specific subset of requirements:
- The written risk assessment format requirements
- Continuous monitoring or periodic vulnerability assessments
- Annual penetration testing
- Maintaining an audit trail of authorized user access
You are not exempt from: the written information security program, designated qualified individual, access controls, encryption, MFA, incident response plan, vendor oversight, or the annual board report. The exemption trims the more burdensome technical requirements for the smallest businesses; it doesn't create a safe harbor.
If you're unsure whether your customer count places you above or below 5,000, assume you're above it. The exemption covers a narrow category of very small operations, and building your program to the full standard is safer than betting on the exemption.
The FTC Notification Requirement (Since May 2024)
The 2023 Safeguards Rule update added a notification requirement effective May 13, 2024: financial institutions subject to the FTC's Safeguards Rule must notify the FTC within 30 days of discovering a security event that involves the information of 500 or more customers.
This is FTC notification, not customer notification. Customer notification is handled separately under the GLBA Privacy Rule and your state's breach notification law. In Maine, that means the Attorney General and affected Maine residents must be notified under 10 M.R.S. § 1347, regardless of how many customers are involved.
These are parallel obligations. A breach affecting 600 Maine customers triggers:
- FTC notification within 30 days (Safeguards Rule)
- Maine AG notification without unreasonable delay (Maine breach notification law)
- Affected resident notification without unreasonable delay (Maine breach notification law)
Practical Priorities for Maine Financial Services Businesses
If you're starting from a baseline of minimal Safeguards compliance:
First: Designate your qualified individual. This is a named person — not a job title, not "IT" — who is responsible for your security program. Document it.
Second: Conduct a written risk assessment. Identify what customer information you hold, where it's stored, who has access, and what the risks are. This doesn't need to be complex; it needs to be specific to your business.
Third: Confirm encryption is in place for customer information at rest and in transit. Laptops with unencrypted customer data are a common and serious gap.
Fourth: Implement MFA on all systems that access customer information. Most modern systems support it; many businesses haven't turned it on.
Fifth: Draft an incident response plan. Even a short, practical document that defines who does what when something goes wrong is better than nothing.
Sixth: Conduct or arrange a penetration test. If you've never done one, the results are often informative. Annual testing is now required.
Seventh: Schedule the annual board report. If you have a board, put it on the calendar. If you don't, the equivalent report goes to your senior officer.
SOURCES
- 16 CFR Part 314 — FTC Standards for Safeguarding Customer Information (2023 final rule): ecfr.gov
- FTC, "FTC Safeguards Rule: What Your Business Needs to Know": ftc.gov/tips-advice/business-center/guidance/ftc-safeguards-rule-what-your-business-needs-know
- FTC, "FTC Amends Safeguards Rule to Require Non-Banking Financial Institutions to Report Data Breaches" (2024): ftc.gov
- GLBA enacted text, 15 U.S.C. § 6801 et seq.: congress.gov
Running a financial services business in Maine and not sure where your Safeguards Rule compliance stands? Schedule a consultation to walk through what the 2023 requirements mean for your specific operation.
