Claremont SecurityManaged compliance · Enterprise AI protection
FTC Safeguards Rule · 16 CFR 314.4(j)

How long does a firm have to notify the FTC after a data breach?

Published 16 CFR 314.4(j); 314.4(j)(1)(vi); 314.2(m)Read time 4 min
The short answer

500 or more consumers: tell the FTC as soon as possible, within 30 days.

If someone without permission gets unencrypted customer information on 500 or more consumers, your firm must report it to the Federal Trade Commission. Report as soon as possible; 30 days after discovery is the latest. The 30 days start when anyone at the firm first knows, not when the partners hear (the person who committed the breach does not count). If the data was encrypted and no unauthorized person got the key, the clock does not start. Your firm should write down now who decides, who is called and what the notice says. Firms holding information on fewer than 5,000 consumers need no written incident response plan, but they still have to meet the deadline.

What the rule says

Thirty days. 16 CFR 314.4(j) requires notice to the Federal Trade Commission as soon as possible and no later than 30 days after discovery of a notification event involving the information of at least 500 consumers.

A notification event is the unauthorized acquisition of unencrypted customer information, defined at 16 CFR 314.2(m). Where the acquired information was encrypted and the encryption key was not accessed by an unauthorized person, the event is not a notification event and the 30-day clock does not start.

Discovery is the first day the event is known to any employee, officer or agent of the firm, other than the person who committed the breach. The clock runs from that day, not from the day the partners were told.

What has to be in the notice

The FTC form asks for:

  • your firm’s name and contact details
  • the types of information involved
  • the date or date range of the event
  • the number of consumers affected or potentially affected
  • a general description of the event
  • whether a law enforcement official has determined that making it public would impede a criminal investigation.

If a law enforcement official has made that call, the official can ask the FTC to keep your notice from the public for a time. Under 16 CFR 314.4(j)(1)(vi), the hold lasts up to 30 days from the day the notice was filed. It can be extended in writing by up to 60 further days.

You still file with the FTC on time. Only the date it is made public moves.

The three numbers that decide the answer

  • 500 consumers. At 500 or more, your firm must tell the FTC. Below that, no FTC notice is required, but any state deadline that applies to your firm still applies.
  • 30 days. Counted from discovery. Not from when the breach is contained, and not from the forensic investigator’s report.
  • Encrypted or not. Encrypted data does not start the FTC clock, but only if no unauthorized person got the key. If someone gets into unencrypted customer information without permission, the rule presumes they took it (unauthorized acquisition). That holds unless your firm has reliable evidence otherwise. That encryption exception is why encrypting stored data is still the first control we look at on every assessment.

The FTC deadline is not the only clock

A breach usually starts several clocks at once. They start on different days and end on different days. If your firm has an affiliated investment adviser, a Regulation S-P notice to customers runs alongside the FTC one. We checked that rule against its text, 17 CFR 248.30.

A deadline for notifying Wisconsin residents and the IRS e-file reporting duty run too. We checked both against their own text for our table of breach clocks, linked at the foot of this page. The Wisconsin row rests on Wis. Stat. 134.98, the IRS row on Publication 1345 (Rev. 10-2024). The IRS has since issued a later revision, which that table says to check.

Which deadlines apply to your firm depends on where its clients live and what licences it holds. That table lists the ones we have read. Use it to see which apply to you now, rather than working it out on the day.

What to do before a breach

You can only meet the 30-day deadline if your firm already knows who decides, who is called, and what the notice says. Under 16 CFR 314.4(h), a firm must have a written incident response plan. 16 CFR 314.6 exempts a firm holding information on fewer than 5,000 consumers from that requirement. Those firms are exempt from the plan, not from the deadline.

So write the plan now. Writing it after the event is what turns a reportable incident into a missed deadline.

Related questions

Does the 30-day clock start when the partners find out?+

No. Under 16 CFR 314.4(j)(2), the clock starts on the first day anyone at the firm knows about the event: any employee, officer or agent, other than the person who committed the breach. A staff member who notices on a Friday starts the clock on that Friday.

Does a firm below 5,000 clients have to notify the FTC?+

Yes, if the event involves at least 500 consumers. The exemption at 16 CFR 314.6 frees a smaller firm from the written risk assessment, the testing schedule, the incident response plan and the annual report. It does not free it from the duty to notify the FTC under 16 CFR 314.4(j).

Does encryption remove the obligation entirely?+

It can remove the FTC duty. Under 16 CFR 314.2(m), the event is not a notification event if the data was encrypted and no unauthorized person accessed the encryption key. State notification laws have their own encryption provisions. They are similar but not identical, so the state question has to be answered separately.

What happens if a firm misses the deadline?+

The Safeguards Rule (Part 314) sets no fixed civil penalty. The Federal Trade Commission enforces it under Section 5 of the FTC Act. If that leads to an order and the firm then breaks it, each violation carries civil penalties under 15 U.S.C. 45(l).

The obligations on this page are three of the many that bind a firm holding client financial data. The map shows the rest, and which control satisfies each one.

See every clock that startsSee the obligation mapTalk to us

General reference, not legal or tax advice. Every figure and deadline on this page was read against the primary source. Claremont Security does not perform audits, issue certifications, or attest to any examination.

16 CFR 314.4(j) · 30 days to notify the FTC of a notification event of 500 or more consumers16 CFR 314.6 · below 5,000 consumers, 314.4(b)(1), (d)(2), (h) and (i) do not apply; every other paragraph does16 CFR 314.2(m) · encrypted customer information with the key intact is not a notification event16 CFR 314.4(c)(5) · multi-factor authentication for any individual accessing any information system, unless an equivalent control is approved in writing16 CFR 314.4(c)(6) · secure disposal within two years of last use, unless a named exception applies16 CFR 314.4(f) · service providers bound by contract to maintain safeguards, and reassessed26 U.S.C. §6713 · $250 per disclosure of return information, $10,000 per calendar year26 CFR §301.7216-2(d)(1), (d)(3) · return information goes without consent only to a preparer located in the United States; a contractor’s employee abroad who only views it puts the disclosure outside the United States