16 CFR 314.3
§ 314.3 Standards for safeguarding customer information.
United States · 16 CFR — Commercial Practices · Status: effective
Cite this
- Citation
- 16 CFR 314.3, § 314.3 Standards for safeguarding customer information, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/64394
- Permanent ID
ys:prov:64394@1- SHA-256
5e56fb742b38b0b320fb0d1e4df5c6de529f5563987d0e96fe036e72d918d00f
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) Information security program. You shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate to your size and complexity, the nature and scope of your activities, and the sensitivity of any customer information at issue. The information security program shall include the elements set forth in § 314.4 and shall be reasonably designed to achieve the objectives of this part, as set forth in paragraph (b) of this section.
(b) Objectives. The objectives of section 501(b) of the Act, and of this part, are to:
(1) Insure the security and confidentiality of customer information;
(2) Protect against any anticipated threats or hazards to the security or integrity of such information; and
(3) Protect against unauthorized access to or use of such information that could result in substantial harm or inconvenience to any customer.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.