Does the under-5,000-consumer exemption apply to us?
It might apply to specific elements.
Title companies maintaining customer information concerning fewer than 5,000 consumers are exempt from four requirements: the written risk assessment, penetration testing and the twice-yearly vulnerability assessment, the written incident response plan, and
the annual board report. They must still maintain a written information security program and the other safeguards, including access controls and MFA, encryption, audit logging of access to customer information, secure disposal, and training.
The FTC 30-day breach-notification duty still applies. We confirm your consumer count during onboarding and scope the program to what actually applies to you.
How long does it take to get a title company compliant?
It depends on your current posture, but a program built from scratch typically takes 60 to 120 days to establish. Work starts with the gap analysis and risk assessment, then moves through control implementation and documentation.
We scope every engagement to what your environment actually needs rather than to a fixed package.
Does the Safeguards Rule apply to our remote notaries and independent closers?
If a remote online notary, mobile notary, or independent closing agent receives or handles the nonpublic personal information of your customers on your behalf, they fall within the service-provider oversight the rule requires.
Remote and mobile closings widen the circle of people who touch Social Security numbers, bank details, and loan data. Each connection is a place that information can be exposed.
The rule expects you to select providers capable of maintaining appropriate safeguards. You must also require those safeguards by contract.
We inventory these relationships, define the security expectations in writing, and extend access controls and monitoring to the systems they use. The requirement is then met and documented rather than assumed.