The FTC Safeguards Rule protects nonpublic personal information held by non-bank financial institutions. A payday lender's daily work sits squarely inside that definition.
It collects borrower financial data, verifies income and bank accounts, and moves funds through processors. The rule names payday lenders as a covered financial institution.
Payday and consumer lenders hold high-value financial data.
Every application contains Social Security numbers, bank account and routing numbers, income and employment information, and government ID. That is precisely the customer financial information the Safeguards Rule is written to protect.
Account takeover and business email compromise target this data directly. The controls the rule requires are MFA, verification procedures, and encryption. They are the same controls that defend against the most common attacks on lenders.
A written program is the baseline, not the ceiling.
The rule requires a written information security program, a Qualified Individual, a documented risk assessment, and an incident response plan. These exist whether or not you have ever had an incident.
We produce these documents to reflect what is actually running in your environment, so the program survives an FTC inquiry or a funding-partner security questionnaire rather than reading as boilerplate.
Vendor oversight is part of compliance.
Lending operations rely on loan origination, management, and servicing platforms, payment processors and ACH providers, credit-reporting agencies, and lead aggregators.
The rule requires you to oversee the service providers that handle your customer information.
We inventory those vendors, document the security expectations, and fold vendor oversight into your written program so the requirement is met and evidenced.
The breach-notification duty applies to every lender, regardless of size.
A 2023 amendment added a federal notification requirement that took effect in May 2024. A notification event is the unauthorized acquisition of unencrypted customer information involving at least 500 consumers.
If you discover one, you must report it to the FTC through the FTC reporting portal. Report as soon as possible and no later than 30 days after discovery.
The under-5,000-consumer exemption relaxes certain other elements, but it does not waive this duty. The duty reaches even the smallest covered lender. The requirement applies to unencrypted information.
That is one more concrete reason we encrypt customer data in transit and at rest by default. We build the incident response plan, define what counts as a notification event for your environment, and prepare the reporting workflow.
A real event is then handled inside the window rather than improvised.