The US Federal Trade Commission (FTC) has made some amendments to the Safeguards Rules, requiring all non-bank financial institutions to report potential data breaches within 30 days.

Such financial entities (not banks) include mortgage lenders, car dealerships, payday lenders, companies , insurance companies, peer-to-peer lenders, and asset management companies.
The aim of this amendment and timely notification within 30 days is to improve data security measures to protect customer information.
See also: LastPass: Previous breach allowed $4.4 million worth of crypto to be stolen
The new regulation should apply to security incidents and data breaches affecting 500 or more consumers, especially if unauthorized third parties had access to unencrypted (cleartext) information.
“Companies that handle sensitive financial information must betransparentif that information has been breached,” said FTC Bureau of Consumer Protection Director Samuel Levine.
“Adding this disclosure requirement to the Safeguards Rule will provide companies with an additional incentive to protect consumer data,” he said.
The notification will not be necessary if the consumer information is encrypted and the attackers do not have access to the encryption key.
Companies that have suffered a data breach and meet the above criteria must submit the notification to the online portal , providing some details about the security incident:
- Name and contact details of the organization.
- Number of affected consumers and those who may be affected.
- Description of the types of data that have potentially been exposed.
- Date of exposure and, if possible, duration of the event.
- Confirmation of whether authorities believe that public disclosure of the breach could hinder an investigation or threaten national security.
Financial institutions affected by a data breach will be able to delay notification for 60 daysif a law enforcement official requests an extension for public disclosure of the incident.
See also: Boeing: Assessing allegations of LockBit ransomware breach
The FTC emphasizes that filing a data breach report does not automatically constitute a violation of the Safeguards Rule, nor does it initiate an investigation.
The new 30-day notice requirement will take effect 180 days after the rule is published in the Federal Register. This means the new regulation will be effective as of April 2024.
For more details about the modifications, you can read this document.

Why is data breach notification important?
The potential consequences of a data breach at a financial entity can be severe and affect both the organization itself and its customers.
One of the most significant impacts of a data breach is the loss of customer trust. Customers may become concerned about the security of their personal data and decide not to continue using the organization.
Additionally, data breaches can lead to financial losses. Leaks of personal information and financial data can lead to damages, lost revenue, and even lost market share.
See also: Redcliffe Labs: Data breach exposes 12 million patient records
Additionally, data breaches can have an impact on an organization’s communications and reputation. Negative news about a data can affect public perception of the company and cause a decline in its trust and business value.
Finally, data breaches can have legal consequences. Government regulations on the protection of personal data can impose fines and penalties in the event of a breach, while customers may be able to claim compensation if their personal data is breached.
Source: www.bleepingcomputer.com
