Compliance guide

Does the FTC Safeguards Rule apply to title companies?

Yes. The rule names real estate settlement services directly. Here is what it requires, and which parts are relaxed for small agencies.

Not legal advice. This is a plain-English summary of a federal regulation. Talk to counsel about how it applies to your agency.

Why title companies are covered

The Safeguards Rule comes from the Gramm-Leach-Bliley Act and applies to "financial institutions," a term much broader than banks. The regulation gives examples, and one of them is explicit: "An entity that provides real estate settlement services is a financial institution" (16 CFR 314.2(h)(2)(x)).

The FTC's plain-language guide lists other examples, such as mortgage brokers and tax preparers, and doesn't mention settlement services by name, which is why many agency owners haven't heard that it applies to them. The regulation itself is clear.

What the rule requires

At its core, the rule requires a written information security program that fits the size of your business and the sensitivity of the information you hold. The FTC's guidance describes these elements:

RequirementIn plain EnglishApplies under 5,000 consumers?
Qualified IndividualName one person (or an outside provider) responsible for the security programYes
Written risk assessmentDocument where customer information lives and what could go wrongExempt
Access controls and data inventoryKnow what you hold and limit who can reach itYes
EncryptionEncrypt customer information in transit and at restYes
Multi-factor authenticationTwo-step sign-in for anyone accessing customer informationYes
Secure disposalGet rid of customer information you no longer needYes
Logging and monitoringKeep a record of who accessed what, and watch for misuseYes
Continuous monitoring, or annual penetration test plus vulnerability scans every six monthsRegular technical testing of your defensesExempt
Staff trainingSecurity awareness training for everyoneYes
Service provider oversightChoose vendors that protect your data, and put it in the contractYes
Written incident response planA documented plan for a security eventExempt
Annual report to the boardA yearly written status report to leadershipExempt

The small-business exemption (16 CFR 314.6) covers businesses that maintain customer information on fewer than 5,000 consumers. Even where you're exempt, your underwriter and ALTA Best Practices may still expect the same thing: ALTA's Pillar 3, for example, calls for an incident response plan regardless of size. See the ALTA 5.0 IT checklist.

Key dates

  • June 9, 2023: compliance date for most of the updated requirements, including multi-factor authentication and the qualified individual.
  • May 2024: the breach notification requirement took effect (notify the FTC within 30 days of discovering a breach affecting at least 500 consumers).

Where a small agency should start

  1. Turn on two-step sign-in for every mailbox and every system with customer information.
  2. Name your qualified individual. For an office without IT staff, this can be an outside provider overseen by an owner.
  3. Write a short security program that matches what you actually do.
  4. Encrypt laptops and send NPI only by encrypted email or a secure portal.
  5. Turn on sign-in and mailbox logging so you have a record if something goes wrong.

These are the same controls that stop most email-based wire fraud, so the work pays for itself twice. Title Office Guard sets up and maintains the technical pieces as part of managed IT for Maryland title agencies.

Sources

Common questions

Does the FTC Safeguards Rule apply to title and settlement agencies?

Yes. The rule's definition of a financial institution includes this example at 16 CFR 314.2(h)(2)(x): an entity that provides real estate settlement services is a financial institution.

Is there an exemption for small title agencies?

Partly. Under 16 CFR 314.6, a business that maintains customer information on fewer than 5,000 consumers is exempt from four specific requirements: the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan, and the annual report to the board. Everything else still applies, including a written information security program, a designated qualified individual, and multi-factor authentication.

Is multi-factor authentication required by the FTC Safeguards Rule?

Yes. The rule requires multi-factor authentication for anyone accessing customer information on your systems, and the small-business exemption does not remove that requirement.

Do we have to report a data breach to the FTC?

Since May 2024, the rule requires notifying the FTC within 30 days of discovering a breach involving the unencrypted information of at least 500 consumers. State breach notification laws may apply separately.