GLBA Safeguards Rule Breach Notification Amendment
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 13 May 2024.
A breach notification rule binding private bodies.
As of 23 August 2026.
What it requires
- Notify the FTC within 30 days of discovering a security event that has compromised unencrypted customer information for 500 or more consumers.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Requires a financial institution covered by the FTC's Safeguards Rule to notify the FTC as soon as possible, and no later than 30 days after discovery, of a security event involving unauthorized acquisition of unencrypted customer information affecting 500 or more consumers. The notification requirement in Section 314.4(j) took effect on May 13, 2024, per 16 CFR 314.5's own effective-date provision.
When LexLint raises it
provides_financial_services
Read the law
eCFR, current regulatory text, 16 CFR Section 314.4(j)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.