Thompson Hine lawyers Steven G. Stransky, Thomas F. Zych, Marla M. Izbicky and Thora Knight’s article titled "Federal Trade Commission Amends Safeguards Rule and Data Breach Notification Obligations,” published in the current issue of The Computer & Internet Lawyer.
The Federal Trade Commission (FTC) has approved an amendment1 to its Safeguards Rule that requires non-banking financial institutions to report certain data breaches and other security events to the agency. This data breach notification obligation is separate and distinct from the cybersecurity and risk management rule2 recently promulgated by the Securities and Exchange Commission (SEC), which requires certain publicly traded companies to make public disclosures related to security incidents impacting their business. The FTC and SEC regulations present organizations with an important opportunity to reassess their data security incident plans to ensure they align with evolving information security threats and new data breach notification obligations.
