Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

GLBA · Safeguards Rule (16 CFR 314)

Customer-information logging & breach notice.

Applies to: FTC-regulated financial institutions. Built · breach notice since 13 May 2024

What the signed record shows

Authorized-user activity logging, safeguard testing, and incident detail; FTC notice marked external.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: 16 CFR §314.4(c)(8)/(d)/(h)/(j)

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

FTC Standards for Safeguarding Customer Information (GLBA Safeguards Rule), 16 CFR Part 314. Provisions addressed:

§314.4(c)(8)
Implement policies, procedures and controls to monitor and log the activity of authorized users and detect unauthorized access to, use of, or tampering with customer information.
§314.4(d)
Regularly test or otherwise monitor the effectiveness of the safeguards (continuous monitoring or annual pen test + 6-monthly vulnerability assessments).
§314.4(h)
Written incident response plan, including (h)(6) documentation and reporting regarding security events and incident-response activities.
§314.4(j)
Notify the FTC of a notification event involving >=500 consumers' unencrypted information, no later than 30 days after discovery (effective 13 May 2024).

Taken from the Regulayer entry for this instrument, which is built against the primary text.