FTC Safeguards Rule Extension: What Central Valley Financial Firms Should Review Before October 2026 — Datapath managed IT, cybersecurity, and compliance
Back to Blog
GENERAL Insights • Published September 26, 2026 • Updated September 26, 2026 • 10 min read

FTC Safeguards Rule Extension: What Central Valley Financial Firms Should Review Before October 2026

The FTC’s August 2026 Safeguards Rule information-collection notice does not create a new cybersecurity rule, but it signals that written GLBA security evide…

David Darmstandler, Co-CEO & Co-Founder at Datapath

By

David Darmstandler

Co-CEO & Co-Founder

Central Valleycompliancecybersecurity

Quick summary

  • What did the FTC’s August 2026 Safeguards Rule notice change?
  • Why does the 2026 FTC notice matter if it is not a new rule?
  • Who in Modesto and the Central Valley should pay attention?

What did the FTC’s August 2026 Safeguards Rule notice change?

The FTC’s August 24, 2026 notice does not create a new Safeguards Rule requirement. It asks for public comment on extending the information-collection requirements tied to the Safeguards Rule for another three years, with comments due October 26, 2026 and the current clearance expiring December 31, 2026.1 For covered firms, the practical message is simple: keep your evidence current.

That matters for Modesto, Fresno, and Central Valley organizations that handle consumer financial information but do not always think of themselves as “financial institutions.” Under the Safeguards Rule, the term can include more than banks. Depending on the activity, covered entities can include mortgage brokers, finance companies, account servicers, check cashers, wire transferors, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, some investment advisers, and companies acting as finders.2

If your business handles customer information for lending, tax, accounting, financing, settlement, advisory, collection, leasing, or related financial activity, this is a good time to verify that your written security program, vendor controls, testing evidence, and incident-response records would survive scrutiny.

Why does the 2026 FTC notice matter if it is not a new rule?

The notice matters because it confirms the FTC still expects covered firms to maintain documented Safeguards Rule compliance evidence. The Paperwork Reduction Act process is about information-collection burden, not a new cybersecurity mandate, but the underlying rule still requires written policies, risk assessments, controls, testing, vendor oversight, incident-response planning, board or senior-officer reporting, and breach-notification readiness.

For a lean financial firm, the dangerous mistake is treating the August 2026 notice as administrative noise. Administrative notices tell you which regulatory machinery is still alive. In this case, the machinery is the documentation layer behind GLBA security: what you wrote down, what you tested, what you reviewed, what your vendors agreed to, and what your Qualified Individual can prove.

A Central Valley mortgage office, accounting practice, finance company, or multi-location dealership group does not need an enterprise bureaucracy. It does need a defensible operating file. That file should show who owns the information security program, what customer information exists, where it lives, which safeguards protect it, how vendors are monitored, when controls were tested, and how leadership receives status updates.

Datapath’s financial services cybersecurity services and GLBA Safeguards Rule compliance services are built around that operational reality: not theoretical compliance, but evidence that a regulated business can actually produce.

Who in Modesto and the Central Valley should pay attention?

Covered financial activity is broader than many local businesses assume. The current eCFR text for 16 CFR Part 314 lists examples that include mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, travel agencies operated in connection with financial services, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, certain investment advisers, and finders.2

That means the Safeguards Rule can become relevant to organizations such as:

  • Mortgage and real estate finance firms
  • Tax preparation and accounting practices
  • Auto dealers arranging financing or qualifying lease activity
  • Collection agencies and account servicers
  • Credit counseling and financial advisory firms
  • Specialty finance companies
  • Businesses acting as finders in covered financial transactions
  • Service providers that receive, maintain, process, or access customer information for covered firms

The rule’s coverage depends on what the organization actually does, not how its website describes it. A company can market itself as a professional services firm, dealership, local office, or back-office provider and still touch customer information covered by GLBA obligations.

What evidence should covered firms review before October 26, 2026?

Covered firms should review the evidence that proves their Safeguards Rule program is operating, not just written. The FTC’s 2026 notice gives firms a timely trigger to clean up their compliance file before the current clearance expires at the end of 2026.

Start with these evidence categories.

1. Qualified Individual ownership

The Safeguards Rule requires a Qualified Individual responsible for overseeing and implementing the information security program. The Qualified Individual may be internal, affiliated, or provided by a service provider, but the covered firm retains responsibility for compliance when using an outside provider.2

Your evidence should answer:

  • Who is the Qualified Individual?
  • Who supervises that person if the role is outsourced?
  • What authority does the role have?
  • When was the role last reviewed?
  • Where are recurring reports to leadership stored?

For smaller financial firms, this is often where compliance becomes fuzzy. Someone is “handling IT,” but nobody can produce a formal assignment, responsibility matrix, or leadership report.

2. Written risk assessment

The rule requires a written risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information. The assessment must include criteria for evaluating risks, assessing confidentiality/integrity/availability, and deciding how risks will be mitigated or accepted.2

Your evidence should answer:

  • What customer information do we collect, store, transmit, and dispose of?
  • Which systems contain it?
  • Which users and vendors can access it?
  • Which risks are accepted, mitigated, transferred, or still open?
  • When will the assessment be refreshed?

A generic template is not enough. The assessment should reflect actual systems: Microsoft 365, line-of-business finance platforms, tax systems, CRM tools, document management, endpoint fleet, backup systems, vendor portals, and file-sharing workflows.

3. Access control and MFA

The current rule requires covered firms to implement and periodically review access controls, limit authorized users to information they need, and implement multi-factor authentication for individuals accessing information systems unless a Qualified Individual has approved equivalent or more secure controls in writing.2

Your evidence should answer:

  • Are privileged accounts inventoried?
  • Are inactive users removed quickly?
  • Are shared mailboxes and service accounts reviewed?
  • Is MFA enforced consistently?
  • Are exceptions documented and approved?
  • Are vendor accounts separated from employee accounts?

If you need a practical internal review path, Datapath’s guidance on Microsoft 365 tenant hardening and guest user access review maps well to the kind of identity hygiene regulated firms need.

4. Encryption and data retention

The Safeguards Rule requires protection of customer information by encryption at rest and in transit over external networks, unless infeasible and replaced by approved compensating controls. It also requires secure disposal procedures and periodic review of retention policies to minimize unnecessary data retention.2

Your evidence should answer:

  • Is customer information encrypted at rest?
  • Is it encrypted in transit?
  • Are encryption keys protected?
  • Are file shares and SaaS exports included?
  • Which data is retained for legal or business reasons?
  • Which data should be disposed of after the retention period?
  • Who approves retention exceptions?

Retention is a common weak spot. Many firms keep old client packets, tax records, loan documents, scanned IDs, bank statements, ACH forms, and exported spreadsheets longer than necessary because nobody owns the cleanup process.

5. Security testing and continuous monitoring

The rule requires regular testing or monitoring of safeguards. For information systems, that means continuous monitoring or periodic penetration testing and vulnerability assessments. Without effective continuous monitoring, firms must conduct annual penetration testing and vulnerability assessments at least every six months, plus additional testing after material changes or circumstances that may affect the program.2

Your evidence should answer:

  • Are endpoints monitored?
  • Are vulnerabilities scanned and tracked?
  • Are critical findings assigned owners?
  • Are remediation deadlines enforced?
  • Are test results preserved for leadership review?
  • Are material system changes followed by risk review?

The key word is evidence. A firm may have endpoint protection, firewalls, backups, and cloud security settings, but if no one preserves test results, risk decisions, and remediation records, the compliance story is incomplete.

6. Service provider oversight

The Safeguards Rule requires covered firms to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, require them by contract to implement and maintain safeguards, and periodically assess providers based on the risk they present.2

Your evidence should answer:

  • Which vendors receive, process, maintain, or access customer information?
  • Which contracts include security obligations?
  • Which vendors have access to Microsoft 365, finance systems, CRM, backups, or customer records?
  • How often are vendor safeguards reviewed?
  • Are vendor incidents tracked?
  • Are high-risk vendors reapproved periodically?

This is especially important for smaller firms that rely on outsourced IT, SaaS finance tools, document portals, payment processors, CRM tools, scanning vendors, tax platforms, or marketing systems.

7. Incident response and breach notification

The Safeguards Rule requires a written incident-response plan addressing goals, internal response processes, roles, communications, remediation, documentation, reporting, and post-incident revision. The FTC’s breach-notification requirement is already in effect. Covered firms must notify the FTC as soon as possible and no later than 30 days after discovery of a notification event involving at least 500 consumers’ unencrypted customer information.3

The FTC’s guidance also notes that unauthorized access to unencrypted customer information is presumed to include unauthorized acquisition unless reliable evidence shows there has not been, or could not reasonably have been, acquisition.3

Your evidence should answer:

  • Who declares a security event?
  • Who decides whether outside counsel, cyber insurance, law enforcement, or regulators are notified?
  • Who can determine whether information was encrypted?
  • Who can determine the number of affected consumers?
  • How are logs preserved?
  • How are vendors required to cooperate?
  • Who submits the FTC notification if required?
  • Where is the post-incident review stored?

Do not wait for an incident to define these decisions. During a real event, clocks run faster than leadership meetings.

What should a practical 30-day review include?

A practical 30-day Safeguards Rule evidence review should produce a short gap list, not a giant binder. The output should tell leadership what is complete, what is missing, what is stale, and what needs funding.

Use this sequence:

  1. Confirm coverage assumptions.
  2. Name the Qualified Individual and supervising executive.
  3. Inventory systems containing customer information.
  4. Pull the latest written risk assessment.
  5. Review MFA, privileged access, and inactive accounts.
  6. Confirm encryption and backup status.
  7. Review data-retention and disposal procedures.
  8. Collect vulnerability, monitoring, and testing evidence.
  9. Review contracts and access for high-risk service providers.
  10. Refresh the incident-response plan and breach-notification workflow.
  11. Prepare a short leadership report with gaps, owners, dates, and risk decisions.

This is not just a compliance exercise. It also improves security operations. The same artifacts used for Safeguards Rule evidence are useful for cyber insurance renewals, vendor questionnaires, board reporting, incident response, and M&A diligence.

How should leadership interpret the October 2026 comment deadline?

Leadership should treat the October 26, 2026 FTC comment deadline as a calendar prompt to review documentation before year-end, not as a reason to pause work. The underlying rule is already in force. The FTC’s 2026 notice concerns extension of information-collection requirements; it does not suspend the obligations covered firms already have under 16 CFR Part 314.1

A defensible leadership position looks like this:

  • We know whether the rule applies to us.
  • We know who owns the program.
  • We know where customer information lives.
  • We know which safeguards are operating.
  • We know which vendors can access covered data.
  • We test and monitor controls.
  • We report material status to leadership.
  • We can respond to a notification event within the required timeline.

A weak position looks like this:

  • “Our IT provider handles that.”
  • “We have MFA somewhere.”
  • “The vendor probably encrypts it.”
  • “We would figure out notification if something happened.”
  • “We do not know which old client records are still stored.”
  • “We have policies, but they have not been updated.”

The first position is manageable. The second position is exactly how firms end up discovering their compliance gap during an incident.

What should Central Valley firms do next?

Central Valley firms covered by the Safeguards Rule should use the FTC’s August 2026 notice as a reason to run a focused evidence review before October 26, 2026 and a remediation sprint before year-end. The goal is not paperwork for its own sake. The goal is to make sure security controls, vendor oversight, testing, leadership reporting, and incident response are provable.

Datapath works with regulated and data-sensitive organizations that need practical security operations, not vague compliance theater. If your firm handles customer financial information and needs help validating your GLBA Safeguards Rule evidence, start with Datapath’s cybersecurity compliance services or financial services cybersecurity services.

You can also review related Datapath resources on GLBA Safeguards Rule checklists, vendor risk management, and cyber insurance evidence packages.

FAQ

Did the FTC create a new Safeguards Rule requirement in August 2026?

No. The FTC’s August 24, 2026 notice seeks comment on extending the information-collection requirements associated with the Safeguards Rule. It does not create a new cybersecurity obligation by itself. Covered firms should still treat it as a useful deadline for reviewing written evidence and operational readiness.

When are comments due on the FTC’s 2026 Safeguards Rule information-collection notice?

Comments are due October 26, 2026. The FTC notice states that the current clearance expires December 31, 2026 and that the agency is proposing to extend the information-collection requirements for another three years.1

Does the Safeguards Rule apply only to banks?

No. The Safeguards Rule applies to financial institutions under FTC jurisdiction, and the definition is broader than traditional banks. The current rule text includes examples such as mortgage brokers, finance companies, account servicers, collection agencies, tax preparation firms, non-federally insured credit unions, certain investment advisers, and finders.2

What is the most important Safeguards Rule evidence to maintain?

The most important evidence includes the written information security program, Qualified Individual assignment, written risk assessment, access-control reviews, MFA status, encryption and retention records, testing and monitoring results, vendor oversight records, incident-response plan, breach-notification workflow, and leadership reports.

What is the FTC breach-notification timeline under the Safeguards Rule?

For a covered notification event involving at least 500 consumers’ unencrypted customer information, the rule requires notification to the FTC as soon as possible and no later than 30 days after discovery.3

Can a service provider serve as the Qualified Individual?

Yes, the rule allows the Qualified Individual to be employed by the covered firm, an affiliate, or a service provider. However, when a firm uses a service provider or affiliate, the covered firm retains responsibility for compliance and must designate a senior member of its own personnel to direct and oversee the Qualified Individual.2

What should a small covered firm do first?

Start by confirming whether the rule applies, naming the owner of the information security program, inventorying customer information systems, and collecting current evidence for MFA, backups, encryption, risk assessment, vendor access, vulnerability management, and incident response. Then create a short remediation list with owners and dates.

Footnotes

  1. Federal Trade Commission, “Agency Information Collection Activities; Proposed Collection; Comment Request; Extension,” posted August 24, 2026, comment due October 26, 2026. Source ↩ ↩2 ↩3

  2. Electronic Code of Federal Regulations, 16 CFR Part 314, “Standards for Safeguarding Customer Information,” current as accessed September 26, 2026. Source ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10

  3. Federal Trade Commission, “Safeguards Rule notification requirement now in effect,” May 2024. Source ↩ ↩2 ↩3

See also

Disclaimer: This blog is intended for marketing purposes only, and nothing presented in here is contractually binding or necessarily the final opinion of the authors.

Need a practical roadmap for regulated-industry IT performance?

Datapath can benchmark your current model and define the next 90 days of high-impact improvements.

Book an IT Consultation