GLBA Safeguards Rule
GLBA Safeguards Rule is a federal rule published as 16 CFR Part 314. Adopted 2021-12-09, applies from 2023-06-09. In force: In force. The amended rule applies in full, including the notification duty added in 2023.
- GLBA Safeguards Rule covers information security program, risk assessment, safeguards and notification of a security event.
- GLBA Safeguards Rule does not settle whether a single company meets it. That is read in the company's own text and its filings.
- Supervised by U.S. Federal Trade Commission. The text is published by Electronic Code of Federal Regulations.
- The text names financial services, insurance and technology.
- nis2-2022-2555: Both texts require a written security programme, a documented risk assessment and notice of significant incidents. The EU text covers essential entities, the US rule covers financial institutions.
- US regulatory register
- Financial services
- Insurance
- Technology
- U.S. Federal Trade Commission
- NIS2 — Directive (EU) 2022/2555
Identity
| Identifier | 16 CFR Part 314 |
|---|---|
| Adopted | 2021-12-09 |
| Applies from | 2023-06-09 |
| Status | In force. The amended rule applies in full, including the notification duty added in 2023. |
| Supervision | U.S. Federal Trade Commission |
| Sectors named | Financial services, Insurance, Technology |
| Risk areas | Information security, Personal data |
Requirements in the text
- Information security program, Reference: 16 CFR 314.4(a). A written programme with a named qualified individual responsible for it.
- Risk assessment, Reference: 16 CFR 314.4(b). Written assessment of foreseeable risks to customer information.
- Safeguards, Reference: 16 CFR 314.4(c). Access controls, encryption, multi-factor authentication, disposal and change management.
- Notification of a security event, Reference: 16 CFR 314.5. Notice to the agency when unencrypted customer information of 500 or more consumers is acquired without authorisation.
Official sources
- 16 CFR Part 314, Standards for Safeguarding Customer Information, Electronic Code of Federal Regulations
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.