If your office prepares tax returns, brokers mortgages, chases unpaid accounts, or advises people on their money, a federal data-security rule almost certainly applies to you. And the client count you may be counting on for relief probably doesn’t get you out of it. The FTC’s Safeguards Rule exempts firms holding information on fewer than five thousand consumers from certain provisions, not from the rule itself. Most owners in these categories have never been told any of this.

The confusion starts with the name. “Financial institution” sounds like a bank. Under this rule, it isn’t.

Does the FTC Safeguards Rule Actually Apply to Your Business?

Coverage depends on what your business does, not on what it calls itself. The rule reaches companies engaged in activities that are financial in nature, and the FTC’s guidance names the categories outright. If you handle other people’s financial information as a routine part of your service, assume you’re in scope until someone confirms otherwise in writing.

Section 314.2(h) of the rule lists 13 example categories of covered financial institutions, and the list runs well past banking. Mortgage brokers and mortgage lenders. Tax preparation firms. Collection agencies. Credit counselors and other financial advisors. Check cashers, wire transferors, account servicers, and investment advisors who aren’t required to register with the SEC. A 2021 amendment added “finders” — companies that bring buyers and sellers together and then step back while the parties negotiate the deal themselves.

Your Label Doesn’t Decide This. Your Activities Do.

The FTC is direct about this: what matters is the type of activity your business undertakes, not how you or anyone else categorizes the company. A four-person bookkeeping practice that also files client tax returns is doing something financial in nature. So is the dealership arranging financing in the back office. Neither one thinks of itself as a financial institution, and neither one gets a pass for it.

There’s a second trap worth naming. The FTC points out that a business outside the original rule may sit inside it now, because operations change over two decades. Adding a payment plan, a financing partner, or a bookkeeping line to an existing practice can move you in scope without anyone noticing. That belongs in the same review where you’re getting your systems documented and audit-ready.

What Does the Under-5,000-Client Exemption Really Cover?

It’s a partial exemption, not an escape hatch. The FTC has exempted financial institutions that maintain customer information concerning fewer than five thousand consumers from certain provisions of the rule. The underlying obligation to run an information security program suited to your size and the sensitivity of what you hold stays exactly where it was.

Here’s where small firms get burned. They hear “under five thousand,” stop reading, and never build the one artifact every version of this rule assumes already exists: a written picture of what customer data the business holds and where it lives. That inventory is also the hardest part of the job, because customer information almost never sits in one tidy place. It’s in the practice-management system, the shared drive, the email archive, a spreadsheet on somebody’s desktop, and a filing cabinet nobody has opened since 2019.

If you’ve never mapped it, start by working out where sensitive information actually leaves a small office during an ordinary week. The exits tend to be more boring and more numerous than owners expect.

The Nine Elements, Translated Into Office Reality

Section 314.4 sets out nine elements a compliant information security program has to include. In the original text they’re dense. Translated, they describe a setup that a well-run office is usually halfway to already: name someone to run the program, assess your risk in writing, control and encrypt access to customer data, test whether those controls hold, train your people, vet the vendors who touch your data, keep the program current as things change, write an incident response plan, and report on all of it to leadership once a year.

What Most Offices Already Have

Multifactor authentication is the common one. For anyone reaching customer information, the rule wants at least two of three factor types — something you know, something you have, something you are — and most offices switched that on for email a while back. Encryption in transit and at rest usually ships with the platforms you already pay for. Backups run. Endpoint protection runs. Staff have sat through a phishing talk at least once.

Those overlap heavily with what your carrier asks you to prove at renewal, so the work does double duty rather than piling up.

What’s Usually Missing

Three gaps, almost every time. The written risk assessment doesn’t exist. Nobody has been named to run the program. And there’s no testing rhythm — the rule asks for continuous monitoring of your systems, or, if you don’t have that, annual penetration testing plus vulnerability assessments including system-wide scans every six months. A fourth gap shows up in older practices: the rule expects customer information to be disposed of securely no later than two years after you last used it to serve that customer, and almost nobody is deleting anything.

The FTC’s own business guidance begins where a real assessment begins — take stock, and inventory the equipment where sensitive data is stored. Laptops, mobile devices, flash drives, digital copiers. The copier is the one that surprises people.

Who Should Be Your Qualified Individual?

It can be one of your employees, or it can be someone who works for an affiliate or a service provider. The rule doesn’t ask for a particular degree or title. It asks for real-world know-how suited to your circumstances. If you place the role outside your company, you also have to designate a senior employee to supervise that person.

That last clause is the one firms skip. Handing the job to an outside provider doesn’t hand off the accountability, and the provider itself has to maintain an information security program that protects your business. Ask for that before you sign anything.

For most small firms the practical answer is shared. An owner or office manager holds the formal designation and signs the annual report, while the technical program runs through an outside IT director who owns the security roadmap and reports back on what changed.

If you’re not sure where your office stands today, a free security risk assessment of your domain is a reasonable first move. O&O Systems scans email, cloud, web, and infrastructure, then returns a weighted risk score in plain English along with the specific weak spots: missing DKIM or DMARC records, outdated encryption, services exposed to the internet that shouldn’t be.

What Happens When Client Data Gets Out

The rule puts a clock on it. A notification event means a security breach involving the unauthorized acquisition of at least 500 consumers’ unencrypted information, and the FTC has to be told as soon as possible and no later than 30 days after discovery.

Read “unencrypted” again, because that word is doing real work. Information that stays encrypted, with the key intact and unexposed, isn’t the same event. Which is why encrypting the laptops that leave your office is worth doing long before you need it.

You’ll also need the written incident response plan the rule calls for. Not a paragraph buried in the employee handbook. A real document naming who decides, who gets called, how the event gets recorded, and what changes afterward.

Frequently Asked Questions

Is the Safeguards Rule the same thing as the Gramm-Leach-Bliley Act?

Not quite. The Safeguards Rule is the FTC’s standard for safeguarding customer information, and it applies to financial institutions under the FTC’s jurisdiction that aren’t overseen by another regulator under section 505 of the Gramm-Leach-Bliley Act. The act is the statute. The rule is the operational requirement your office actually has to meet.

How long are we supposed to keep client records?

The rule expects secure disposal no later than two years after the most recent use of that information to serve the customer. There are exceptions when you have a legitimate business need or a legal requirement to keep it, or when targeted deletion isn’t feasible given how the information is stored. Retention rules from your own industry still apply on top.

Does the rule tell us which security products to buy?

No. It describes outcomes and controls rather than brands. Multifactor authentication has to use at least two of the three recognized factor types, and the only exception is when your Qualified Individual approves an equivalent secure access control in writing. How you get there is your call, which is why two compliant offices can look very different.

Who receives the annual report if we don’t have a board?

A senior officer responsible for the information security program. The report has to be in writing, delivered at least annually, and it needs to cover overall compliance plus specifics like risk management decisions, service provider arrangements, test results, and any security events and how management responded.

Our IT is outsourced. Does that cover us?

Partly, and only if the arrangement is set up correctly. A service provider can supply your Qualified Individual, but that provider must maintain an information security program that protects your business, and you still have to name a senior employee internally to supervise the relationship. Outsourcing the work is fine. Outsourcing the responsibility isn’t possible.

Find Out Where Your Office Actually Stands

Compliance work stalls when nobody can describe the current state. Starting with a policy template solves the wrong problem first.

O&O Systems works with small businesses across the Treasure Coast and South Florida on cybersecurity and compliance: assessments and audits that prepare you for regulatory inspection, security policies drafted and maintained so your systems stay audit-ready, multifactor authentication deployed across your accounts, and ongoing staff training so the program doesn’t depend on one careful person. Request a free security risk assessment and you’ll have the first honest page of your risk assessment in hand.