• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Facebook
  • Instagram
  • LinkedIn
  • Twitter
  • YouTube
Big Ideas for Small Business logo

Barbara Weltman

Big Ideas for Small Business, Inc.

Whitepaper download

Subscribe and download our eBook, "150+ Tax Deductions for Small Business A to Z."

This field is hidden when viewing the form
Get the:

  • Home
  • About Us
  • Big Ideas For Your Business
    • Idea Of The Day ®
    • SMB Legal
    • SMB Taxes
    • SMB Financial
    • Small Business
    • Newsletter Archive
  • Services
  • Books
  • Blog
  • Multimedia
    • Videos
    • Radio Shows/Podcasts
  • Be a Guest Blogger

Are You Liable for Data Breaches?

March 14, 2024 / By Barbara Weltman

Are You Liable for Data Breaches?Data breaches—from hackers or insiders—can leak sensitive information about customers and employees. According to the Identity Theft Resource Center (ITRC)’s 2023 Business Impact Report, 73% of small business owners experienced a data breach or cyberattack in the past year. If this happens to you, are you liable? What do you do?

FTC Safeguards Rule

Banks and other financial institutions have long been subject to FTC rules governing data breaches…what to do to be secure and when to report breaches. Last year, the FTC adopted a rule for certain other businesses to guard customer information.  The FTC has the authority to impose penalties up to $100,000 per violation, and business officers can be personally liable.

Businesses subject to the rule. Only businesses over which the FTC has enforcement authority must comply with the rule. These include, but are not limited to, mortgage lenders, “pay day” lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, travel agencies operated in connection with financial services, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, investment advisors that are not required to register with the Securities and Exchange Commission, and entities acting as finders. But other types of businesses are subject to the rule because of the nature of their activities, including:

  • A retailer that extends credit directly to customers through its own credit cards (but merely “lay away” or deferred payment plans don’t make the retailer subject to the rule)
  • An automotive dealership that leases vehicles for longer than 90 days
  • A property appraiser
  • A career counselor providing services to individuals currently employed by or recently displaced from a financial organization, individuals who are seeking employment with a financial organization, or individuals who are currently employed by or seeking placement with the finance, accounting or audit departments of any company is a financial institution
  • A business that prints checks for consumers
  • A travel agency operating in connection with a financial institution

There is no small business exception. This means a solo CPA who does tax return preparation is subject to the FTC rule (and to the IRS requirement to guard customer information).

Actions required for compliance. Businesses subject to the rule must develop, implement, and maintain an information security program. This includes:

  1. Designating a qualified person responsible for overseeing the company’s program
  2. Basing the company’s program on a risk assessment of reasonably foreseeable internal and external risks.
  3. Periodically performing additional risk assessments
  4. Designing and implementing safeguards to control the risks
  5. Regularly monitoring the effectiveness of the safeguards
  6. Implementing policies and procedures to ensure personnel are able to do the program
  7. Overseeing service providers
  8. Evaluating and adjusting the program in light of the results of testing and monitoring
  9. Establishing a written incident response plan
  10. Requiring the qualified individual to report in writing on a regular basis (at least annually)

Practicalities

Even if you’re not subject to the FTC rule, it’s highly advisable to follow the same actions to ensure your data is protected to the extent possible. Companies that experience data breaches face liability from customers and employees. What’s more, customers may shun the companies going forward.

  • Assess where you are vulnerable. For example, you may have data breaches through remote workers or even through third-party vendors.
  • Determine the cost of complying with the FTC rule and following the same steps even if not mandatory so you can budget accordingly.
  • Prepare in advance for notifying customers and employees if you experience a data breach and what recovery services you’ll offer to them.

Final thoughts

Check your business owner policy (BOP) to see whether and to what extent you have cyber coverage. This may be an add-on to your BOP or a stand-alone policy. Check with your insurer on what’s required with respect to data security. Also check the FTC’s 10 cyber security tips for small business, which go beyond the FTC’s safeguards rule.

Find more blogs about data security here.

Tags data breach data security FTC FTC safeguard rules tax return preparer

Share
Share on Facebook
Share
Share this
Share
Share on LinkedIn

Primary Sidebar

Categories

  • General Business (497)
  • Guest Blog (108)
  • Homepage (18)
  • Small Business (987)
  • SMB Financial (322)
  • SMB Legal (65)
  • SMB Taxes (324)

Barbara’s Recent Posts

  • The Numbers Are Up for Sole Proprietorships May 22, 2025
  • New Business or Project Crowdfunding: What To Know May 20, 2025
  • Old-School Estimating vs. Smart Solutions: What’s Really Holding You Back? May 19, 2025
  • Employees Getting Called to Public Service: What to Know May 15, 2025
  • Not Too Late to Prep for Summer Now May 13, 2025
  • How Will the Next Generation of Learners Affect the Workplace May 12, 2025
  • Moms Know Best: Lessons for Entrepreneurs May 8, 2025
  • Mental Health Challenges in the Workplace May 6, 2025
  • Let’s Celebrate Small Business! May 1, 2025
  • Scaling Your Business: Adding a New State Location April 29, 2025
  • What to Do about Waste Management in Your Warehouse April 28, 2025
  • Restrooms: Not Front Office but Just as Important April 25, 2025
Awarded Top 100 Small Business Blog medal (link will open in a new window or tab)
Marquis Who's Who 2023 Badge
Top Small Business Blogs (Link will open in a new window or tab.)
8 Financial blogs small business Owners Need to Read. Invoice home.  (link will open in a new window or tab)
Best Small Business Blog, Expertido.org
Top 50 Small Business Blogs 2018
Best Small Business Blogs
BizHumm Top 100 Business Blog Award to Barbara Weltman
FitsSmallBusiness.com: Award for Best Small Business Blog 2017 (link will open in a new window or tab)
FitsSmallBusiness.com: Award for Best Small Business Blog 2016 (link will open in a new window or tab)

Footer

Big Ideas for Small Business logo

Small business ideas, business tax news and small business consulting from Barbara Weltman to provide business owners with the information they need to succeed. Visit our small business blog, Idea of The Day®, small business books and articles on small business taxes, small business finance and small business legal advice.

Contact Us

barbara@bigideasforsmallbusiness.com

(772) 492-9593

gacor maxwin situs slot thailand terpercaya situs slot gacor situs gacor akun pro thailand slot bandar togel terpercaya

Latest Tweets

bigideas4sb Big Ideas for Small Business® @bigideas4sb ·
May 24

#Video - Are you lucky? This matters to business success - via YouTube https://youtu.be/BFErCfpyXvU?si=s-LAXbnvEb8VZx0E #smallbusiness #luck #smallbiz

Reply on Twitter 1926383563512922397 Retweet on Twitter 1926383563512922397 Like on Twitter 1926383563512922397 Twitter 1926383563512922397
bigideas4sb Big Ideas for Small Business® @bigideas4sb ·
May 24

How Will the Next Generation of Learners Affect the Workplace - https://bit.ly/3S3mhgV #smallbiz #workplace #learning #GenZ

Reply on Twitter 1926370902171631873 Retweet on Twitter 1926370902171631873 Like on Twitter 1926370902171631873 Twitter 1926370902171631873
bigideas4sb Big Ideas for Small Business® @bigideas4sb ·
May 24

5 Key Reminders on Why Lower Personal Income Tax Rates Benefit Entrepreneurship and Small Business via @SBECouncil - https://bit.ly/44Y994t #smallbusiness #taxes #entrepreneurship #smallbiz

Reply on Twitter 1926347576120324464 Retweet on Twitter 1926347576120324464 Like on Twitter 1926347576120324464 Twitter 1926347576120324464
Load More

Copyright © 2008–2025 Big Ideas for Small Business, Inc  |  Designed by Hudson Fusion

  • Privacy Policy
  • Sitemap

Notifications