16 CFR §314.6 — Exceptions (FTC GLBA Safeguards Rule)

glba-safeguards-16cfr-314-6

16 CFR §314.6 establishes a small-institution exception for the written-risk-assessment-contents, continuous-monitoring-or-pen-test, incident-response plan, and annual-board-reporting requirements where customer information is maintained on fewer than 5,000 consumers.

Get this register: .xlsx .csv More bundles →

Verbatim regulatory text (1)

Verbatim provisions from 16 CFR §314.6 — Exceptions (FTC GLBA Safeguards Rule) — each quote is a verified substring of the regulator-published source snapshot, not retyped. Quoted for reference; this is not legal advice. The operational layer (P&P updates, prompts) lives in the regulation update kits.

16 CFR §314.6

Section 314.4(b)(1) , (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers. [ 86 FR 70308 , Dec. 9, 2021] CFR Toolbox Law about... Articles from Wex Table of Popular Names Parallel Table of Authorities Accessibility About LII Contact us Advertise here Help Terms of use Privacy

Source: 16 CFR §314.6 · source URL · snapshot 606c7f5a2fe08fcd

Operationalizing 16 CFR §314.6 — Exceptions (FTC GLBA Safeguards Rule)

This is verbatim, source-snapshotted regulator text from the Claude for Compliance open corpus. To turn a rule like this into compliance work product: gap-analyze your policies and procedures (P&Ps) against these requirements to surface stale, conflicting, or missing provisions; operationalize any change with a ready-to-run update kit; and produce audit-ready evidence — every step grounded only in the regulator’s own words, never invented.

Source of record: https://claudeforcompliance.com/regs/glba-safeguards-16cfr-314-6/ · register glba-safeguards-16cfr-314-6 · Claude for Compliance. Free to read and download; see regulatory updates and methodology.