Scope
Who it applies to.
The rule reaches any business § 314.2(h) calls a financial institution — one “significantly engaged” in an activity financial in nature under section 4(k) of the Bank Holding Company Act. Section 314.2(h)(2) names accountants and tax-preparation services outright; § 314.1(b) adds mortgage brokers, collection agencies, credit counselors, investment advisers not required to register with the SEC, and finders. It covers all customer information in your possession — including records other institutions handed you (§ 314.1(b)).
- Designate a Qualified Individual
- Section 314.4(a) requires you to designate one “Qualified Individual” responsible for overseeing, implementing, and enforcing the program. That person may work for you, an affiliate, or a service provider — but if you outsource the role you keep responsibility for compliance, must name a senior member of your own personnel to direct and oversee them, and must require the provider to maintain a conforming program.
- Base the program on a written risk assessment
- Under § 314.4(b) the program must rest on a written risk assessment identifying reasonably foreseeable internal and external risks to customer information. It must set criteria for evaluating and categorizing threats, criteria for assessing confidentiality, integrity, and availability, and requirements describing how each identified risk will be mitigated or accepted. Firms holding information on fewer than 5,000 consumers are excepted from the writing requirement (§ 314.6).
- Encryption, multi-factor authentication & access controls
- Section 314.4(c) mandates specific technical safeguards: access controls limiting users to the data they need; encryption of all customer information in transit over external networks and at rest, with compensating controls only where encryption is infeasible and your Qualified Individual approves; multi-factor authentication for any individual accessing any information system; change-management procedures; and logging of authorized-user activity.
- Continuous monitoring, or scheduled testing
- Section 314.4(d)(2) gives you a choice: run continuous monitoring able to detect changes that create vulnerabilities, or else conduct annual penetration testing plus vulnerability assessments at least every six months. Assessments are also triggered by material changes to your operations or business arrangements. Firms with information on fewer than 5,000 consumers are excepted from this paragraph under § 314.6.
- Oversee your service providers
- Section 314.4(f) makes you answerable for anyone who receives, maintains, processes, or is permitted access to customer information through services provided to you (§ 314.2(r)). You must take reasonable steps to select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess each provider based on the risk it presents and the continued adequacy of its safeguards.
- Incident response plan & 30-day FTC notice
- Section 314.4(h) requires a written incident response plan covering goals, internal processes, roles and decision-making authority, communications, remediation, documentation, and post-event revision. Since § 314.4(j) took effect on May 13, 2024 (§ 314.5), you must also notify the FTC electronically as soon as possible and within 30 days of discovering a notification event affecting at least 500 consumers.
The vendor & sub-processor obligation
What it puts on you.
It explicitly makes you responsible for your service providers: you must select providers capable of safeguarding customer data, bind them by contract to do so, and periodically assess them. Every cloud or AI vendor that touches the data becomes one more provider you have to vet, contract with, and monitor.
Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; (2) Requiring your service providers by contract to implement and maintain such safeguards; and (3) Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards.
How self-hosting addresses it
Remove the third party, remove the burden.
When indexing, search, and AI all run on an appliance inside your own network, no customer information is disclosed to an outside provider — so there is no service-provider relationship to diligence, contract, or audit for that data in the first place.
How FileFerret applies
Because § 314.2(r) defines a service provider as one permitted access to customer information through services provided to you, an appliance no outside party can reach leaves § 314.4(f) with nothing to attach to. The box is still your information system under § 314.2(j): encryption at rest, multi-factor authentication, access controls, and logging remain your obligation. See how it’s built →
Full, current text is maintained at the official source: 16 CFR Part 314 — U.S. Federal Trade Commission.
Enforcement
Who enforces it, and how.
GLBA splits enforcement by sector: the banking agencies, the NCUA, the SEC, and state insurance authorities police their own, while 15 U.S.C. § 6805(a)(7) leaves the FTC every other financial institution — the accountants, tax preparers, and brokers this rule mostly reaches. The FTC proceeds by consent order: its 2004 sweep of mortgage companies and auto dealers produced an order requiring Sunbelt Lending to have its program certified by an independent professional every other year for ten years. Violating such an order carries civil penalties up to $53,088 (16 CFR § 1.98(c)).
Common questions
Questions firms ask.
Is our accounting or tax practice really a “financial institution”?
Very likely yes. Section 314.2(h)(2)(viii) states outright that an accountant or other tax preparation service in the business of completing income tax returns is a financial institution, because tax preparation is a financial activity listed in 12 CFR 225.28(b)(6)(vi). The label has nothing to do with taking deposits; it turns on being significantly engaged in an activity financial in nature.
We have fewer than 5,000 clients. Are we exempt?
Only partly. Section 314.6 excuses institutions maintaining customer information on fewer than five thousand consumers from four paragraphs: the written risk assessment (§ 314.4(b)(1)), the testing regime (§ 314.4(d)(2)), the written incident response plan (§ 314.4(h)), and the annual report to the board (§ 314.4(i)). Everything else — encryption, multi-factor authentication, access controls, disposal, service-provider oversight, FTC breach notice — still applies in full.
Does putting client files into a cloud AI tool trigger the service-provider rules?
If that tool receives, maintains, processes, or is otherwise permitted access to customer information through the service it provides you, it is a service provider under § 314.2(r), and § 314.4(f) applies: select it carefully, bind it by contract to maintain appropriate safeguards, and reassess it periodically. Separately, § 314.4(c)(3) requires that information be encrypted at rest and in transit over external networks.