(GENERAL-23-09) Updates to the Gramm-Leach-Bliley Act Cybersecurity Requirements

Federal Student Aid 

AUTHOR – Federal Student Aid
ELECTRONIC ANNOUNCEMENT ID: GENERAL-23-09
SUBJECT: Updates to the Gramm-Leach-Bliley Act Cybersecurity Requirements
On December 9, 2021, the Federal Trade Commission (FTC) issued final regulations (Final Rule) to amend the Standards for Safeguarding Customer Information (Safeguards Rule), an important component of the Gramm-Leach-Bliley Act’s (GLBA) requirements for protecting the privacy and personal information of consumers. The effective date for most of the changes to the Safeguards Rule is June 9, 2023. This Electronic Announcement provides a summary of the changes to the GLBA requirements resulting from the Final Rule, explains the impacts of the changes on postsecondary institutions, and describes changes to the Department of Education’s (Department) enforcement of the GLBA requirements. Institutions should coordinate with their leadership and appropriate staff to implement the requirements in the Final Rule by June 9.

Background

Postsecondary institutions and third-party servicers must protect student financial aid information provided to them by the Department or otherwise obtained in support of the administration of the Federal student financial aid programs (Title IV programs) authorized under Title IV of the Higher Education Act of 1965, as amended (HEA). Each institution that participates in the Title IV programs has agreed in its Program Participation Agreement (PPA) to comply with the GLBA Safeguards Rule under 16 C.F.R. Part 314. Institutions and servicers also sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that they will ensure that all Federal Student Aid applicant information is protected from access by, or disclosure to, unauthorized personnel, and that they are aware of and will comply with all of the requirements to protect and secure data obtained from the Department’s systems for the purposes of administering the Title IV programs.

CONTINUE READING