GLBA Safeguards Rule:
Cryptography for Non-Bank Financial Institutions
| Region | United States non-banking financial institutions, with parallel requirements or depository institutions |
| Applicability | Financial Institutions under FTC jurisdiction: non-bank lenders, mortgage brokers, tax preparers, auto dealers offering financing, and other businesses meeting GLBA’s “financial activity” test Qualified Individual: the designated person responsible for overseeing and implementing the information security program Service Providers: contractually required to maintain appropriate safeguards for the customer information they handle |
| Relevant sections | 16 CFR §314.4(c)(3): Encryption of customer information at rest and in transit §314.4(a): Designation of a Qualified Individual §314.2(m) / §314.5: Breach notification to the FTC for events affecting 500 or more consumers |
Overview
The FTC’s Safeguards Rule implements GLBA Section 501(b) for financial institutions under FTC jurisdiction. The Final Rule updating the Safeguards Rule took effect June 9, 2023, replacing a principles-based approach with nine prescriptive program elements, one of which is an explicit encryption mandate. A further amendment adding breach notification to the FTC took effect May 13, 2024.
Section 314.4(c)(3) requires encryption of customer information both at rest and in transit. Where encryption is not feasible, the Qualified Individual must approve, in writing, effective alternative controls. This is one of the few Safeguards Rule provisions with almost no interpretive flexibility: the default expectation is encryption, and any departure from it must be documented and justified.
Why it matters
Civil penalties reach $100,000 per violation for the institution, and officers and directors can be personally fined up to $10,000. The 2024 breach-notification amendment ties directly to encryption status: a “notification event” is defined as the unauthorized acquisition of unencrypted customer information involving 500 or more consumers, reportable to the FTC within 30 days.
That definition means encryption status is not just a security control, it is the determining factor in whether an incident triggers a federal reporting obligation at all. An organization that can demonstrate its exposed data was encrypted may have a materially different disclosure posture than one that cannot.
How this maps to cryptography
GLBA Safeguards Rule addresses cryptography through several interlocking control areas. The key areas with direct cryptographic implications are:
| Section | Function | What it says | Supporting Products |
| §314.4(c)(3) | Encryption of Customer Information | Encryption of customer information at rest and in transit, with Qualified-Individual-approved and documented compensating controls where encryption is infeasible. | EJBCA |
| §314.4(c)(5) | Multi-Factor Authentication | MFA for anyone accessing customer information systems, with certificate-based options available for stronger assurance. | EJBCA |
| §314.4(a) | Qualified Individual Oversight | Centralized reporting on cryptographic control status feeding the Qualified Individual’s oversight responsibilities and required annual report to the board. | Keyfactor Command |
| §314.4(f) | Vendor and Service Provider Assurance | Cryptographic due-diligence evidence supporting service-provider contract requirements for organizations handling customer information. | AgileSec |
| §314.2(m) / §314.5 | Breach Notification Determination | A documented process for determining whether exposed customer information was encrypted, which directly determines the 30-day FTC notification obligation. | EJBCA |
| §314.4(c)(4) | Secure Application Development | Code-signing and secure development practices for in-house applications that access or transmit customer information. | SignServer |
Audit readiness
Assessments and examinations, whether self-conducted, performed by a regulator, or reviewed by an independent assessor, focus on demonstrated evidence rather than policy statements alone. Key areas that examiners and assessors commonly probe:
- Encryption Coverage Evidence: Can the institution demonstrate encryption of customer information at rest and in transit across its systems?
- Qualified-Individual-Approved Compensating Controls: Where encryption is not used, is there a written, QI-approved justification and description of the alternative control?
- MFA Deployment Evidence: Is MFA enforced for all access to systems containing customer information?
- Service Provider Contract Language: Do contracts with service providers require appropriate safeguards, including encryption, for customer information they handle?
- Breach Notification Readiness: Is there a documented process for determining, within the required timeframe, whether an incident involved unencrypted customer information?
- Annual Board Reporting Package: Does the Qualified Individual’s required report to the board include the status of encryption and other technical safeguards?
TAKE THIS TO MANAGEMENT
The Safeguards Rule’s encryption requirement leaves very little room for interpretation, and since May 2024 it has a direct legal consequence attached: whether customer information was encrypted determines whether an incident is a reportable “notification event” to the FTC within 30 days at all.
Penalties reach $100,000 per violation for the company and $10,000 personally for officers and directors. If we cannot show, quickly, which systems encrypt customer information and where our Qualified Individual approved an alternative control in writing, we cannot make that 30-day notification determination with any confidence.


