Skip to content
The WesternTechSystems facility at blue hour

Compliance · GLBA

The Safeguards Rule two-year provision, including the part usually left out

16 CFR 314.4(c)(6)(i) is widely quoted as a two-year destruction deadline. The same sentence carries three exceptions, and a programme built on the headline alone will either destroy what it needed or claim an obligation it does not have.

In one paragraph

The short version

The FTC Safeguards Rule requires procedures for the secure disposal of customer information in any format, no later than two years after last use — subject to exceptions for legitimate business need, legal retention, and cases where targeted disposal is not reasonably feasible.

Alongside it, 314.4(f) makes overseeing your service providers your duty: select capable providers, require safeguards by contract, assess them periodically. Nothing in the rule certifies a disposal vendor, and nothing in it lets a vendor's paperwork stand in for your own diligence record.

1 · The obligation

What the rule actually says

Cited to the eCFR and the FTC's published guidance. Quoted rather than paraphrased, because the paraphrases in circulation are where most of the confusion starts.

16 CFR 314.4(c)(6)(i) — secure disposal

Develop, implement, and maintain procedures for the secure disposal of customer information in any format no later than two years after the last date the information is used in connection with the provision of a product or service to the customer to which it relates…

The two-year clock runs from last use, not from collection or from account closure. The same sentence carries exceptions — where retention is necessary for business operations or other legitimate business purposes, where law or regulation requires retention, or where targeted disposal is not reasonably feasible given how the information is maintained. A page that states a flat two-year destruction mandate without those exceptions is misreading the rule.

https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.4

16 CFR 314.4(f) — oversee service providers

Three duties, all yours: select and retain providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider based on the risk they present. The FTC's own plain-language guidance restates it as selecting providers with the skills and experience to maintain appropriate safeguards. Note what it does not say — it does not say select a certified provider.

https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.4

2 · The misreading

What the rule does not say

This is the section most vendor pages omit, and it is the one that decides whether the rest of the page can be trusted.

  • It does not certify, approve or accredit disposal vendors. The FTC operates no such programme. The duty in 314.4(f) is your diligence, performed and documented by you.

  • It does not impose a flat two-year destruction deadline. The exceptions in 314.4(c)(6)(i) are part of the requirement, and a programme built on the headline number alone will either destroy records it needed or claim an obligation it does not have.

  • It does not name a sanitization method. No standard, technology or particle size appears in the rule.

  • It does not apply only to banks. The Safeguards Rule reaches a wide range of non-bank financial institutions — lenders, brokers, advisers, and others — many of which do not think of themselves as regulated by the FTC until they are.

  • The phrase “GLBA-compliant ITAD service” has no legal referent. A vendor either produces evidence that supports your 314.4(f) diligence, or it does not.

3 · The evidence

What an auditor actually asks for

Your written disposal procedures

314.4(c)(6)(i) asks you to develop, implement and maintain them. An examiner reads yours first and the vendor's paperwork second.

Your retention policy and evidence it is reviewed

The review obligation at (c)(6)(ii) is separate from the disposal one, and it is the easier of the two to have quietly skipped.

Documented diligence on the provider

Under 314.4(f), what you assessed, when, and on what basis. A certificate from us is an input to that, not a substitute for it.

A contract requiring the safeguards

314.4(f)(2) is explicit that the safeguards are required by contract. Verbal assurance and a good relationship are not the standard.

Disposal evidence that reconciles to the record

Customer information in any format — which includes the drive in a retired branch workstation that nobody classified as holding customer information.

4 · Our part

What our documentation provides against it

Artefact What it answers
Per-serial erasure certificate Evidence at the device rather than the consignment, so disposal can be reconciled against a specific system.
Chain-of-custody record Every transfer from collection onward, which is the part of your diligence you cannot reconstruct afterwards.
Method statement What was applied to which media class. The rule names no method, so what matters is that yours is documented and defensible.
Contractual safeguards Written commitments you can point to under 314.4(f)(2), scoped to the services actually performed.
Facility and records access Walkthrough and records review by appointment — the periodic assessment at 314.4(f)(3), made into something you can evidence.
R2v3 and RIOS certification Third-party certification of the management system. Not a legal status, and we will not present it as one — but it is exactly the kind of independent assessment the diligence duty contemplates.

5 · Your part

What remains your obligation

No vendor can discharge these for you. Any vendor implying otherwise is selling you a risk you will still be holding.

  • Writing, implementing and maintaining the disposal procedures. The obligation names you, not your vendor.
  • Reviewing the retention policy periodically, and being able to show that you did.
  • Deciding whether an exception to the two-year rule genuinely applies, and recording the reasoning.
  • Selecting, contracting with and periodically assessing us under 314.4(f) — and keeping the record of having done so.
  • Knowing where customer information sits in your estate, including the formats nobody thinks of as records.

FAQ

Safeguards Rule disposal questions

Does the Safeguards Rule really require destruction after two years?
It requires procedures for secure disposal no later than two years after the last date the information was used for the customer's product or service — and then immediately qualifies that. Disposal is not required where the information is necessary for business operations or other legitimate business purposes, where law or regulation requires retention, or where targeted disposal is not reasonably feasible given how the information is maintained. The two-year figure is real, but quoting it without the exceptions gets the rule wrong in both directions.
Is there a GLBA-certified disposal vendor?
No. The FTC certifies no one for this. What 16 CFR 314.4(f) requires is that you select a provider capable of maintaining appropriate safeguards, require those safeguards by contract, and assess the provider periodically. A vendor's third-party certification can support that diligence. It cannot perform it for you, and it confers no status under the rule.
We are not a bank. Does this apply to us?
Possibly. The Safeguards Rule reaches non-bank financial institutions well beyond depository banking — and the organizations most often caught out are the ones that had not thought of themselves as FTC-regulated. If you are unsure, that is a question for your counsel rather than for a disposal vendor, and it is worth settling before an examination rather than during one.
What counts as customer information on a retired device?
The rule says customer information in any format, which is broader than most asset registers assume. In practice the hard cases are the machines nobody classified: a retired branch workstation, a loan officer's laptop, a shared scanner's internal storage. The disposal evidence is straightforward once a device reaches us. Identifying that it should have is the part that fails.

Send us your examiner's request.

Tell us what has been asked for and we will tell you which of it we can evidence — and which of it is yours to produce.