Skip to the main content.
Home Security Real Estate Appraisers
FTC Safeguards Rule · 16 CFR Part 314

The rule names appraisers. Then it says the homeowner is not your customer. Both sentences are real.

16 CFR 314.2(h)(2)(iii) says a real estate appraiser is a financial institution. 16 CFR 314.2(e)(2)(ii)(D) says a consumer who obtains one-time appraisal services has no continuing relationship with you. The rule resolves its own puzzle in a third sentence, and that sentence is the one that decides what your practice has to do.

  • Every requirement is cited to the rule, quoted where it turns on the wording, with ABT’s reading marked as ours
  • What the under 5,000 consumer exception actually lifts, provision by provision
  • Why your lender and AMC clients started sending you security questionnaires
The FTC Safeguards Rule at 16 CFR 314.2(h)(2)(iii) names a real estate appraiser as a financial institution, shown beside the Microsoft 365 logo and the Entra ID, Purview and Defender controls that carry the rule's technical elements

The short answer. Yes. The FTC Safeguards Rule lists thirteen examples of businesses that are financial institutions, and a personal property or real estate appraiser is the third one. Being covered does not depend on your size, your license type, or whether you have ever heard of the rule. What changes with size is which four provisions of the rule stop applying, and that list is shorter than most appraisers expect.

The part that confuses people, reasonably, is that the same rule says a homeowner who gets a one-time appraisal from you is not your customer. If the program protects customer information and you have no customers, the obligation looks empty. It is not, and the reason is a single sentence in 314.1(b) that most summaries of the rule leave out.

3rd
of thirteen examples in the rule
16 CFR 314.2(h)(2)(iii)
4
provisions lifted under 5,000 consumers
16 CFR 314.6
30
days to notify the FTC at 500 consumers
16 CFR 314.4(j)(1)

Is a real estate appraiser a financial institution under the FTC Safeguards Rule?

Yes, and the rule says so by name rather than leaving it to be worked out. Section 314.2(h)(2) gives thirteen worked examples of what counts as a financial institution. The third reads:

"A personal property or real estate appraiser is a financial institution because real and personal property appraisal is a financial activity listed in 12 CFR 225.28(b)(2)(i) and referenced in section 4(k)(4)(F) of the Bank Holding Company Act, 12 U.S.C. 1843(k)(4)(F)."

16 CFR 314.2(h)(2)(iii)

It is worth seeing the company that sentence keeps. The same thirteen-item list also names, at (x), an entity that provides real estate settlement services, and at (xi), a mortgage broker. The appraiser, the title company, and the mortgage broker are all financial institutions under one rule, named in one list, working on one transaction. Which regulator enforces it depends on the counterparty. A bank or credit union answers to its own prudential regulator rather than to the FTC, as 314.1(b) sets out. An independent mortgage lender or broker with no such regulator sits under this rule, the same one that names you.

Two things this does not depend on. It does not depend on your firm's size, and it does not depend on being state-licensed or state-certified, which is a separate regime with separate obligations. The rule asks what activity your business engages in, and appraisal is on the list.

Then why does the same rule say the homeowner is not your customer?

Because it does say that, in plain words, and an appraiser who finds it is entitled to be confused. The Safeguards Rule protects something specific called customer information. Customer information is defined by reference to a customer, and a customer is a consumer who has a customer relationship with you. Section 314.2(e)(2) then gives examples of what does and does not create one. In the list of situations that do not, item (D) reads:

"The consumer obtains one-time personal or real property appraisal services from you"

16 CFR 314.2(e)(2)(ii)(D)

Read those two sentences together and the rule appears to name you and then hand you nothing to protect. That reading is the reason a lot of appraisal practices have concluded, in good faith, that the Safeguards Rule is a lender problem. The conclusion is wrong, but the confusion is well founded, and it comes from the rule's own drafting rather than from anyone's carelessness.

Notice the qualifier, because it carries weight. The sentence addresses one-time appraisal services. It does not say an appraiser can never have a customer relationship with a consumer. A practice built on repeat consumer engagements should read the whole of 314.2(e) with its own facts in hand rather than assume this item settles the question.

The rule answers its own question, in section 314.1(b)

The scope section of the Safeguards Rule closes with a sentence that resolves the whole thing, and it is the sentence most summaries omit:

"This part applies to all customer information in your possession, regardless of whether such information pertains to individuals with whom you have a customer relationship, or pertains to the customers of other financial institutions that have provided such information to you."

16 CFR 314.1(b)

That is the answer, stated by the rule rather than inferred from it. Work through it with an ordinary lending assignment:

  1. 1The lender is a financial institution. Nobody disputes this, and 314.2(e)(2)(i)(B) makes the relationship explicit: a consumer has a continuing relationship with you if the consumer "Obtains a loan from you."
  2. 2The borrower is that lender's customer. Which makes the borrower's file, in the lender's hands, customer information.
  3. 3The order reaches you carrying pieces of that file. The borrower's name and the subject property address at a minimum, and very often more: the contract, the loan number, the loan amount, the parties, sometimes the purchase agreement itself.
  4. 4314.1(b) applies the rule to it in your possession. The sentence names your exact situation: information that "pertains to the customers of other financial institutions that have provided such information to you."

So the obligation does not arrive through a relationship with the homeowner. It arrives with the file. An appraisal practice that never signs a consumer as a client can still be holding customer information the moment a lender sends an order, and the rule says so without requiring anyone to interpret it.

Diagram of three sections of the FTC Safeguards Rule: 314.2(h)(2)(iii) names appraisers as financial institutions, 314.2(e)(2)(ii)(D) says a one-time appraisal creates no continuing relationship, and 314.1(b) applies the rule to all customer information in your possession including the customers of other financial institutions
The three sentences that decide what an appraisal practice owes under the rule. Source: eCFR, 16 CFR Part 314.

Which records in your practice are actually covered?

The definition is broader than a file cabinet and it is indifferent to format:

"Customer information means any record containing nonpublic personal information about a customer of a financial institution, whether in paper, electronic, or other form, that is handled or maintained by or on behalf of you or your affiliates."

16 CFR 314.2(d)

Two phrases in that sentence do most of the work. "A customer of a financial institution" rather than "your customer," which is the same point 314.1(b) makes. And "whether in paper, electronic, or other form," which means the question is about the information, not about where it happens to sit.

In a working appraisal practice that usually reaches further than the report itself:

The order and the engagement

Borrower name, subject property, loan number, loan amount, the parties, and whatever the client attached when the order was placed.

The workfile

Contracts, listing history, prior reports, correspondence, notes, and the supporting documents you keep because your own professional standards require you to keep them.

Email, and everything that has ever been attached to it

A mailbox accumulates covered information for as long as it is kept, and it is the store most often left out of an inventory. The rule reaches it exactly as it reaches the report.

Field devices and the phone in your pocket

Photographs, sketches, and notes taken at the property, and whatever cloud account they sync to by default.

Nonpublic personal information is defined at 16 CFR 314.2(l) and turns on personally identifiable financial information rather than on the property record. Publicly available information, on its own, is outside it. A practice deciding what is in scope should work from that definition rather than from a general sense of what feels sensitive.

Why most appraisers have never been told any of this

There is a straightforward, checkable reason, and it is worth stating carefully because it is a measurement rather than an accusation.

The FTC publishes a plain-language guide to the Safeguards Rule, which states on its face that it "serves as the small entity compliance guide under the Small Business Regulatory Enforcement Fairness Act." It is the document a small firm is most likely to find first, and for most purposes it is an excellent one. Describing who is covered, it says the rule's Section 314.2(h) "lists 13 examples of the kinds of entities that are financial institutions," and then names them:

"mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, and investment advisors that aren't required to register with the SEC"

Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know

Read that list again looking for your own trade. The word appraiser appears once in the text of Part 314 and does not appear in that summary. An appraiser who checks the guidance, finds no mention, and concludes the rule is aimed elsewhere has done a sensible thing and reached the wrong answer.

What settles it is the rule, not the summary of it. 314.2(h)(2)(iii) names appraisers and 314.1(b) applies the part to customer information in your possession. Neither sentence is affected by which examples a guidance document chose to repeat.

Watch · 1 min

The rule requires multi-factor authentication at 314.4(c)(5). It does not say which kind, and the difference decides whether the control holds.

From the ABT channel.

The elements at 16 CFR 314.4, read for a small appraisal practice

What each element says, what it tends to mean for a firm of one to ten appraisers, and whether the under 5,000 consumer exception at 314.6 lifts it. The last column is the one worth reading twice. This covers the subsections an appraisal practice meets most often and is not the complete text of 314.4; secure development practices at (c)(4), change management at (c)(7) and the testing duty at (d)(1) also apply and are not reproduced here.

Selected elements of an information security program under 16 CFR 314.4, with the exceptions at 16 CFR 314.6 applied. Not the complete text of the section.
Element What the rule requires In a small practice Lifted under 5,000?
314.4(a)
Qualified Individual
Designate someone responsible for overseeing, implementing and enforcing the program. The rule says this person "may be employed by you, an affiliate, or a service provider." Usually the owner, or the outside provider who already runs the technology. Using a provider means you keep responsibility, name a senior person of your own to direct and oversee them, and require the provider to run its own program. No
314.4(b)
Risk assessment
Base the program on a risk assessment that identifies reasonably foreseeable internal and external risks and assesses whether existing safeguards control them. The thinking still has to happen. What is lifted below 5,000 consumers is the written form and its prescribed contents at (b)(1), not the duty to base the program on risk. (b)(1) only
314.4(c)(1)
Access controls
Authenticate and permit access only to authorized users, and limit each user to the information they need for their duties. Named accounts rather than a shared login, and the trainee who left in March no longer able to open last year's files. No
314.4(c)(2)
Inventory
Identify and manage the data, personnel, devices, systems and facilities that matter to the business. Knowing where covered information actually lives, which for most practices turns out to include two cloud accounts nobody listed. No
314.4(c)(3)
Encryption
"Protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest." Compensating controls only where encryption is infeasible, reviewed and approved by the Qualified Individual. The delivered report and the workfile behind it, at rest, and every email carrying borrower information on its way out. No
314.4(c)(5)
Multi-factor authentication
MFA "for any individual accessing any information system," unless the Qualified Individual approves in writing reasonably equivalent or more secure controls. Any individual, any system. Not just the ones that felt important, and the written approval is the only documented way out. No
314.4(c)(6)
Secure disposal
Dispose of customer information no later than two years after last use, with stated exceptions including information "otherwise required to be retained by law or regulation." The exception matters here more than the rule. See the retention section below. No
314.4(c)(8)
Logging
Monitor and log the activity of authorized users, and detect unauthorized access, use or tampering by those users. The capability that answers "what did they reach" after a mailbox is compromised. Without it the honest answer is that you cannot tell. No
314.4(d)(2)
Testing
Continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months. This is the expensive one, and it is lifted below 5,000 consumers. The duty at (d)(1) to regularly test or otherwise monitor the safeguards is not. Yes
314.4(e)
Personnel and training
Security awareness training updated to reflect the risks the assessment identified, and qualified security personnel of your own or through a provider. In a practice where one convincing email can move a file, this is the element with the shortest distance between training and outcome. No
314.4(f)
Service providers
Select providers capable of appropriate safeguards, require those safeguards by contract, and periodically assess them on risk. Your form software, your cloud storage, your email host, your delivery platform. This is also the element your clients are applying to you. No
314.4(g)
Evaluate and adjust
Adjust the program in light of testing, material changes to operations, risk assessment results, or anything else with a material impact. A short, dated note when something changes. The absence of any record is what makes this hard to answer later. No
314.4(h)
Incident response plan
A written plan addressing seven named areas, from goals and roles through documentation and post-incident revision. Lifted below 5,000 consumers. The separate duty at (j) to notify the FTC within 30 days of discovering a qualifying notification event is not lifted, so a practice can be excused the written plan and still owe the report. Yes
314.4(i)
Report to the board
The Qualified Individual reports in writing, regularly and at least annually, to the board or, if there is none, to a senior officer. Lifted below 5,000 consumers. For a firm with no board, this was the provision that read least naturally anyway. Yes
314.4(j)
Notify the FTC
Notify the FTC as soon as possible and no later than 30 days after discovery, where the event involves the information of at least 500 consumers. Effective since May 13, 2024. Electronic form on the FTC website. Not lifted at any size. No

Source: 16 CFR 314.4 and 16 CFR 314.6, read from the current rule text. The middle column is ABT's reading of how each element tends to land in a small practice and is not part of the rule.

We are well under 5,000 consumers. Does the rule still apply?

Yes, and this is the single most consequential misreading of the Safeguards Rule in small practices. The exception is real, it is narrow, and it is written as a list of four subsections rather than as a size threshold for the rule as a whole:

"Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers."

16 CFR 314.6

The FTC's own guidance describes it the same way, as having "exempted from certain provisions of the Rule" institutions below that count. Certain provisions, named individually. Here is exactly what comes off:

  • 314.4(b)(1) the written risk assessment and the specific contents it must include
  • 314.4(d)(2) continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months
  • 314.4(h) the written incident response plan and its seven required areas
  • 314.4(i) the Qualified Individual's regular, at least annual, written report to the board or a senior officer

Everything else in 314.4 stays. The Qualified Individual stays. Encryption stays. Multi-factor authentication stays. Access controls, disposal, logging, training, service provider oversight, and the 30-day notice to the FTC all stay. A practice that reads 314.6 as an exemption and stops there has set aside four named subsections and left the rest of 314.4 unaddressed.

Worth counting carefully, too. The threshold is customer information concerning fewer than five thousand consumers maintained, not five thousand assignments this year. A two-appraiser firm that has kept workfiles for a decade because its professional standards require retention can hold information on more consumers than its current volume suggests. That arithmetic is worth doing once, deliberately, rather than assumed.

Checklist showing that 16 CFR 314.6 lifts only four provisions for institutions with fewer than 5,000 consumers, the written risk assessment contents, continuous monitoring or penetration testing, the written incident response plan and the annual board report, while nine other provisions including MFA, encryption and the 30-day FTC notice still apply
What 16 CFR 314.6 lifts, and what it leaves in place. Source: eCFR, 16 CFR 314.6 and 314.4.

Two years to dispose, unless the law says otherwise

Appraisers are among the few covered businesses with a professional obligation to keep files for years, which makes the disposal element read like a collision the first time through. It is not one, because the rule anticipated it. Section 314.4(c)(6)(i) requires procedures to securely dispose of customer information "no later than two years after the last date the information is used in connection with the provision of a product or service to the customer to which it relates," and then names its own exceptions. The information may be kept where it is necessary for business operations or other legitimate business purposes, where it "is otherwise required to be retained by law or regulation," or where targeted disposal is not reasonably feasible.

That middle exception is the one that carries appraisal practice. A retention duty imposed by your state licensing regime or by the professional standards you work under is a reason the rule already accepts. The duty that remains is narrower and more practical: know which retention obligation applies to you, keep what it requires, and securely dispose of what falls outside it rather than keeping everything forever by default.

Two honest notes on this. The specific retention period that applies to you comes from your state and from your professional standards, and this page does not state one, because the question is answered by documents outside the FTC rule. And "securely dispose" in 314.4(c)(6) means what it says: material in a cloud mailbox or a storage account is disposed of when it is actually gone, which is a different operation from moving it out of sight.

Why your lender and AMC clients started sending security questionnaires

Because a service provider oversight duty tells them to. Where the client is covered by this rule, that duty is 16 CFR 314.4(f); a bank or credit union carries an equivalent obligation under its own regulator instead. Section 314.4(f) requires a covered financial institution to oversee its service providers by:

  1. 1"Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue"
  2. 2"Requiring your service providers by contract to implement and maintain such safeguards"
  3. 3"Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards"

To a lender, an appraiser holding borrower information is a service provider inside that obligation. The questionnaire, the contract language about safeguards, and the periodic re-check are not a procurement fashion. They are a financial institution performing its own oversight duty, and they will keep arriving.

There is a useful consequence in this. A practice that can answer those questions concretely, naming what is switched on and where the evidence sits, is answering a question its clients are required to ask and will have to record an answer to. The same work serves both ends of the order.

And the obligation runs downhill as well as up. Your form software, cloud storage, email host, and delivery platform are your service providers, and 314.4(f) applies to them in your hands exactly as it applies to you in your client's.

Thirty days, five hundred consumers, and the word that starts the clock

Since May 13, 2024, the Safeguards Rule has carried a reporting duty. Section 314.4(j)(1) requires notice to the Federal Trade Commission "as soon as possible, and no later than 30 days after discovery of the event" where a notification event involves the information of at least 500 consumers. The notice goes on an electronic form on the FTC's website and must state who is reporting, the types of information involved, the dates if determinable, the number of consumers affected or potentially affected, and a description of the event.

The FTC's guidance describes the triggering event as a breach "involving the unauthorized acquisition of at least 500 consumers' unencrypted information," and adds a detail worth holding onto: unencrypted "includes encrypted customer information when its encryption key was accessed by an unauthorized person." Encryption is a defense that can be undone by the loss of the key, and the rule accounts for that.

Discovery is the word that starts the clock, and it is defined more broadly than most people assume. Under 314.4(j)(2) an event is treated as discovered as of the first day it is known to you, and knowledge is imputed from any employee, officer or other agent other than the person who committed the breach. The trigger is discovery of a qualifying notification event rather than any suspicious observation, so a strange login on its own does not start anything. But once an event does qualify, the day a staff member knew of it can be the day the thirty days began, whether or not it reached the owner that week.

Two features of this land hard on a small practice. The 500-consumer threshold counts consumers, not clients, and a compromised mailbox holding a decade of lending assignments can pass it without the practice ever having had 500 consumers of its own. And this duty survives the under 5,000 exception entirely: 314.6 lifts the written incident response plan at 314.4(h), and does not lift the reporting duty at 314.4(j). A firm can be exempt from the written plan for handling an incident and still owe the report within thirty days of discovering a qualifying notification event.

Whether a specific event is a notification event, and what any given practice must do about it, is a determination for the firm's own counsel. What is stated here is what the rule says.

We already work under this rule, on the other side of your orders

Access Business Technologies is a Tier 1 Microsoft Cloud Solution Provider and manages Microsoft 365 tenants for more than 750 financial institutions, most of them banks, credit unions and mortgage companies. The mortgage lenders among them are covered by 16 CFR Part 314, which means the rule on this page is the rule ABT's engineers work inside every day, from the client side of the orders your practice receives.

Several of the technical safeguards 314.4 asks for are capabilities a Microsoft 365 tenant already includes, and an assessment usually finds some of them switched off, or switched on for some accounts and not others. Multi-factor authentication, access controls and least privilege, encryption in transit and at rest, audit logging of user activity, and secure disposal are capabilities a Microsoft 365 tenant can provide, though which ones you already hold depends on your licensing and feature level. The distance between owning a capability and enforcing it is where assessments usually land.

No cost, no obligation
A free security assessment of your Microsoft 365 tenant

ABT engineers read the tenant and report what is actually configured, mapped to the element of 16 CFR 314.4 each finding belongs to. You get the findings whether or not you ever become a client, and they are yours to hand to a lender or an AMC that asks.

  • Which accounts have multi-factor authentication enforced, and which are exempt without anyone having decided that
  • Whether encryption is applied to information at rest and in transit, and where it is not
  • Whether user activity is being logged at all, which determines what can be answered after an incident
  • Where covered information is actually stored, including the accounts and devices nobody inventoried
  • Which findings map to which element, so the report is usable as evidence rather than as a list of opinions

ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies.

Two boundaries worth stating plainly, because they are the questions a careful reader will have. The assessment reads the Microsoft 365 tenant configuration, so anything outside it is outside the report: paper files, a workstation, a personal device, or a system hosted somewhere else. Some findings also depend on the licensing you hold, and the report says which. And an assessment reports on technical configuration. Whether your practice is covered by the Safeguards Rule, what its information security program must contain, and what any specific incident requires are determinations for your own counsel and compliance advisor. ABT's engineers read tenants, not obligations.

Where the facts on this page come from

Every quoted sentence on this page was read from a primary source on September 11, 2026. Where a claim could not be sourced primarily, it was left off rather than softened.

  • 16 CFR Part 314, the FTC Safeguards Rule. Read in full from the eCFR, which publishes the current text of the Code of Federal Regulations. Sections quoted: 314.1(b), 314.2(d), 314.2(e), 314.2(h)(2), 314.3, 314.4(a) through (j), 314.5, and 314.6. eCFR, 16 CFR Part 314
  • Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know. The source of the thirteen-example summary, the description of 314.6 as an exemption from certain provisions, and the unencrypted-information detail in the breach notification section. ftc.gov business guidance
  • Appraisal Subcommittee, USPAP Compliance and Appraisal Independence. A federal source for the professional-ethics framing, which lists failing to protect the confidential nature of the appraiser and client relationship among USPAP ethics violations. asc.gov

Deliberately absent: any retention period from USPAP or state law, any count of appraisers or appraisal firms, and any breach or loss statistic scoped to appraisal. None of those could be established from a primary source, so none is asserted. This page is general information about a published federal rule and is not legal advice.

Appraiser questions, answered from the rule text

Yes. 16 CFR 314.2(h)(2)(iii) states that a personal property or real estate appraiser is a financial institution because real and personal property appraisal is a financial activity listed in 12 CFR 225.28(b)(2)(i). It is the third of thirteen worked examples in the rule, alongside entities providing real estate settlement services at (x) and mortgage brokers at (xi). Coverage does not depend on firm size or on state license type.
The information the lender sent you. 16 CFR 314.2(e)(2)(ii)(D) does say that a consumer who obtains one-time appraisal services from you has no continuing relationship with you, so that consumer is not your customer. But 16 CFR 314.1(b) states that the part applies to all customer information in your possession, regardless of whether it pertains to individuals with whom you have a customer relationship, or pertains to the customers of other financial institutions that have provided it to you. The borrower is the lender's customer, the lender is a financial institution, and the file is in your hands.
No. 16 CFR 314.6 lifts exactly four provisions: the written risk assessment contents at 314.4(b)(1), continuous monitoring or periodic penetration testing and vulnerability assessments at 314.4(d)(2), the written incident response plan at 314.4(h), and the annual written report to the board at 314.4(i). Everything else in 314.4 continues to apply, including the Qualified Individual, encryption, multi-factor authentication, access controls, secure disposal, logging, training, service provider oversight, and the 30-day notice to the FTC. The FTC describes it as an exemption from certain provisions rather than from the rule.
Not where another law or regulation requires you to keep them. 16 CFR 314.4(c)(6)(i) requires procedures for secure disposal no later than two years after the last date the information is used, and then states its own exceptions: information necessary for business operations or other legitimate business purposes, information otherwise required to be retained by law or regulation, and cases where targeted disposal is not reasonably feasible. A retention obligation from your state licensing regime or your professional standards falls inside that second exception. The practical duty is to know which obligation applies to you, keep what it requires, and securely dispose of the rest rather than keeping everything by default.
Because they carry a service provider oversight duty of their own. Where the client is covered by this rule that duty is 16 CFR 314.4(f); a bank or credit union carries an equivalent obligation under its own prudential regulator instead, since 16 CFR 314.1(b) reaches only institutions not subject to another regulator under section 505 of the Gramm-Leach-Bliley Act. Section 314.4(f) obliges a covered financial institution to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess providers based on the risk they present. An appraiser holding borrower information sits inside that obligation, so the questionnaire and the contract language are a client performing its own duty. The same section applies to your own providers, including form software, cloud storage, email, and delivery platforms.
The duty applies at any size. 16 CFR 314.4(j)(1) requires notice to the Federal Trade Commission as soon as possible and no later than 30 days after discovery, where the notification event involves the information of at least 500 consumers. 16 CFR 314.5 makes that provision effective as of May 13, 2024. The under 5,000 consumer exception at 314.6 lifts the written incident response plan at 314.4(h) and does not lift the reporting duty at 314.4(j). Note also that the threshold counts consumers rather than clients, so a mailbox holding years of lending assignments can reach 500 consumers in a practice that has never had 500 clients.
At discovery, which the rule defines broadly. Under 16 CFR 314.4(j)(2) an event is treated as discovered as of the first day on which it is known to you, and knowledge is imputed from any employee, officer or other agent, other than the person who committed the breach. In practice that means the clock can start on the day a staff member first saw something wrong, whether or not it reached the owner that week. The FTC also notes that unencrypted information includes encrypted customer information where the encryption key was accessed by an unauthorized person.
Yes, with three conditions the rule states directly. 16 CFR 314.4(a) says the Qualified Individual may be employed by you, an affiliate, or a service provider. Where you use a provider or affiliate, 314.4(a)(1) to (3) require you to retain responsibility for compliance with the part, designate a senior member of your own personnel responsible for direction and oversight of the Qualified Individual, and require that provider or affiliate to maintain an information security program that protects you in accordance with the rule. Responsibility can be supported from outside. It cannot be handed over.
Because of how the Gramm-Leach-Bliley Act divides supervision. 16 CFR 314.1(b) states that the part applies to financial institutions over which the FTC has jurisdiction, namely those not otherwise subject to the enforcement authority of another regulator under section 505 of that Act. Banks and credit unions answer to their prudential regulators. An appraisal practice has no such regulator for this purpose, so the FTC's rule is the one that reaches it. In ABT’s experience that is part of why coverage goes unnoticed: nothing arrives on a schedule to raise the question, so it usually surfaces when a client asks or an incident forces it.
The rule text does; the guidance summary does not. The FTC's plain-language page, which states that it serves as the small entity compliance guide under the Small Business Regulatory Enforcement Fairness Act, says Section 314.2(h) lists 13 examples and then names mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, and investment advisors that are not required to register with the SEC. Appraisers are not in that summary, and they are in the rule at 314.2(h)(2)(iii). The rule text is what governs.
Talk to an Expert

Find out what your practice
can honestly claim.

Tell us roughly how many appraisers work in the practice and where completed reports and workfiles are kept. Our engineers will read the Microsoft 365 tenant and come back with what is switched on, what is not, and which element of the rule each finding belongs to.

SOC 1 Type 2 · Security Controls
Tier-1 CSP
SOC 2 Type 1
25+
Years on Microsoft
750+
Institutions Served
$0
Assessment Cost
Get Your Free Security Assessment
Response within one business day. No obligation.
I am interested in... (optional)
First name is required
Last name is required
Valid email is required
Response within 1 business day. No obligation.
You are in.
An ABT security specialist will review your request and reach out within one business day.