Sullivan & Cromwell LLP Logo Sullivan & Cromwell LLP Logo
  • Lawyers
  • Practices
  • Insights
  • About
  • Careers
  • Alumni
  • Twitter icon
  • LinkedIn icon
  •  icon
  • Podcasts icon
© 2026 Sullivan & Cromwell LLP
    • Home
    • Lawyers
    • Practices
    • Insights
    • About
    • Careers
    • Alumni
    Home /  Insights /  Memos and Newsletters /  Memo
    S&C Memos

    Federal Trade Commission Requires Non-Bank Financial Institutions to Report Certain Data Breaches

    Amendment to the Safeguards Rule Will Require Reporting of Breaches of Unencrypted Customer Information Affecting at Least 500 Consumers

    November 1, 2023 | min read |
    • Related Practices

    On October 27, 2023, the FTC voted to approve supplemental amendments to the Safeguards Rule that will require non-bank financial institutions to notify the FTC electronically as soon as possible, and no later than 30 days after discovery, of any unauthorized acquisition of unencrypted customer information that affects at least 500 consumers. The breach notification must include certain information about the event, including a description of the event and the number of consumers affected or potentially affected. Notably, the FTC has stated that it intends to make the notifications publicly available through an online database. The final rule will become effective 180 days after publication in the Federal Register.

    Read More

    Read More
    Stay Updated

    Subscribe to stay current on S&C Insights.

    Related Practices Related Practices

    • Consumer Financial Services
    • Cybersecurity
    • Fintech
    • Intellectual Property & Technology Transactions
    Sullivan & Cromwell LLP Logo Sullivan & Cromwell LLP Logo
    • Twitter icon
    • LinkedIn icon
    • RSS Feed icon
    • Podcasts icon
    • Contact Us
    • Cookies
    • Privacy & Disclaimers
    • Attorney Advertising
    © 2026 Sullivan & Cromwell LLP