Does the FTC Safeguards Rule apply to title companies?
Yes. The rule names real estate settlement services directly. Here is what it requires, and which parts are relaxed for small agencies.
Why title companies are covered
The Safeguards Rule comes from the Gramm-Leach-Bliley Act and applies to "financial institutions," a term much broader than banks. The regulation gives examples, and one of them is explicit: "An entity that provides real estate settlement services is a financial institution" (16 CFR 314.2(h)(2)(x)).
The FTC's plain-language guide lists other examples, such as mortgage brokers and tax preparers, and doesn't mention settlement services by name, which is why many agency owners haven't heard that it applies to them. The regulation itself is clear.
What the rule requires
At its core, the rule requires a written information security program that fits the size of your business and the sensitivity of the information you hold. The FTC's guidance describes these elements:
| Requirement | In plain English | Applies under 5,000 consumers? |
|---|---|---|
| Qualified Individual | Name one person (or an outside provider) responsible for the security program | Yes |
| Written risk assessment | Document where customer information lives and what could go wrong | Exempt |
| Access controls and data inventory | Know what you hold and limit who can reach it | Yes |
| Encryption | Encrypt customer information in transit and at rest | Yes |
| Multi-factor authentication | Two-step sign-in for anyone accessing customer information | Yes |
| Secure disposal | Get rid of customer information you no longer need | Yes |
| Logging and monitoring | Keep a record of who accessed what, and watch for misuse | Yes |
| Continuous monitoring, or annual penetration test plus vulnerability scans every six months | Regular technical testing of your defenses | Exempt |
| Staff training | Security awareness training for everyone | Yes |
| Service provider oversight | Choose vendors that protect your data, and put it in the contract | Yes |
| Written incident response plan | A documented plan for a security event | Exempt |
| Annual report to the board | A yearly written status report to leadership | Exempt |
The small-business exemption (16 CFR 314.6) covers businesses that maintain customer information on fewer than 5,000 consumers. Even where you're exempt, your underwriter and ALTA Best Practices may still expect the same thing: ALTA's Pillar 3, for example, calls for an incident response plan regardless of size. See the ALTA 5.0 IT checklist.
Key dates
- June 9, 2023: compliance date for most of the updated requirements, including multi-factor authentication and the qualified individual.
- May 2024: the breach notification requirement took effect (notify the FTC within 30 days of discovering a breach affecting at least 500 consumers).
Where a small agency should start
- Turn on two-step sign-in for every mailbox and every system with customer information.
- Name your qualified individual. For an office without IT staff, this can be an outside provider overseen by an owner.
- Write a short security program that matches what you actually do.
- Encrypt laptops and send NPI only by encrypted email or a secure portal.
- Turn on sign-in and mailbox logging so you have a record if something goes wrong.
These are the same controls that stop most email-based wire fraud, so the work pays for itself twice. Title Office Guard sets up and maintains the technical pieces as part of managed IT for Maryland title agencies.
Sources
- 16 CFR 314.2, definitions (Cornell Legal Information Institute)
- 16 CFR 314.6, exceptions (Cornell Legal Information Institute)
- FTC Safeguards Rule: What Your Business Needs to Know (Federal Trade Commission)
Common questions
Does the FTC Safeguards Rule apply to title and settlement agencies?
Yes. The rule's definition of a financial institution includes this example at 16 CFR 314.2(h)(2)(x): an entity that provides real estate settlement services is a financial institution.
Is there an exemption for small title agencies?
Partly. Under 16 CFR 314.6, a business that maintains customer information on fewer than 5,000 consumers is exempt from four specific requirements: the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan, and the annual report to the board. Everything else still applies, including a written information security program, a designated qualified individual, and multi-factor authentication.
Is multi-factor authentication required by the FTC Safeguards Rule?
Yes. The rule requires multi-factor authentication for anyone accessing customer information on your systems, and the small-business exemption does not remove that requirement.
Do we have to report a data breach to the FTC?
Since May 2024, the rule requires notifying the FTC within 30 days of discovering a breach involving the unencrypted information of at least 500 consumers. State breach notification laws may apply separately.