Regulatory anatomy · FACTA § 216 · 16 CFR Part 682 · 16 CFR Part 314

The FTC Disposal Rule & FACTA Field Guide: The Federal Floor Under Every Consumer Record

Most U.S. businesses that never think about privacy law are covered by one disposal rule anyway. The Fair and Accurate Credit Transactions Act of 2003 (FACTA) directed federal agencies to require proper disposal of consumer report information, and the Federal Trade Commission’s implementing rule — 16 CFR Part 682, the Disposal Rule — has applied since June 1, 2005 to any person under FTC jurisdiction that “for a business purpose, maintains or otherwise possesses consumer information.” It is short, it is written in the language of reasonableness rather than technique, and it does something unusual for a federal rule: it tells you what due diligence to perform before hiring a disposal company. This guide walks the rule, the statute behind it, the parallel rules the banking agencies issued, and the FTC Safeguards Rule’s newer two-year disposal clock — and translates each into IT asset disposition practice. Not legal advice. For the state overlay, see the multi-state guide; for financial institutions specifically, the GLBA & FFIEC guide.

Reading time: ~14 min Published: September 1, 2026 Author: Brian Boynton Applies to: 16 CFR Part 682; 16 CFR Part 314; FACTA § 216

STRAIGHT ANSWER

What does the FTC Disposal Rule require?

Anyone under FTC jurisdiction who holds consumer report information for a business purpose must take reasonable measures to protect it against unauthorized access or use when disposing of it. The rule’s examples include burning, pulverizing, or shredding paper, destroying or erasing electronic media so the information cannot practicably be read or reconstructed, and hiring a disposal company only after due diligence: audits, references, certifications, and security policies.

TL;DR

16 CFR Part 682 covers any FTC-regulated person that “for a business purpose, maintains or otherwise possesses consumer information” — records that are, or derive from, a consumer report. “Dispose” includes discarding and selling, donating, or transferring the medium the data sits on, so a resold laptop is a disposal. The standard is reasonable measures against unauthorized access, and 682.3(b) illustrates it: burn, pulverize, or shred paper; destroy or erase electronic media so the information “cannot practicably be read or reconstructed”; and, when hiring a disposal company, exercise due diligence — independent audits, information about the company, certification by a recognized trade association, and review of its security policies. Banks follow the parallel Interagency Guidelines; FTC-regulated financial institutions also follow the amended Safeguards Rule (16 CFR 314), which requires disposing of customer information no later than two years after last use absent a legitimate reason to keep it, and oversight of service providers. The rule tells you the outcome and the diligence; NIST SP 800-88 Rev. 2 tells you the technique.

Section 01

FACTA Section 216: where the rule comes from

The Disposal Rule is an implementing regulation. Its authority, and its parallel versions at other agencies, trace to one section of a 2003 credit-reporting statute.

The Fair and Accurate Credit Transactions Act of 2003 amended the Fair Credit Reporting Act. Its Section 216 added a provision requiring the federal regulators — the FTC for the businesses under its jurisdiction, and the banking agencies and others for theirs — to issue regulations requiring “any person that maintains or otherwise possesses consumer information, or any compilation of consumer information, derived from consumer reports for a business purpose” to properly dispose of it. The statute set the target; each agency wrote its own rule to hit it.

That is why the same disposal obligation appears in several places with slightly different wording: the FTC’s Disposal Rule at 16 CFR Part 682 for most businesses; the banking agencies’ Interagency Guidelines Establishing Information Security Standards (for example, 12 CFR Part 364 Appendix B for FDIC-supervised institutions), which fold the FACTA disposal duty into the GLBA information security program; and the SEC’s and NCUA’s equivalents for their regulated entities. A business is generally covered by exactly one of them, determined by its regulator — but the obligation is the same in substance everywhere.

Bottom line

One statute, several rules. FACTA § 216 required proper disposal of consumer report information; the FTC’s Part 682 is the version that reaches most businesses, and the banking agencies’ guidelines carry the same duty for banks.

Section 02

Who and what the rule covers

The Disposal Rule’s reach is wider than its name suggests, because “consumer information” and “dispose” are both defined broadly.

Who. Section 682.1 states the rule applies to “any person over which the Federal Trade Commission has jurisdiction, that, for a business purpose, maintains or otherwise possesses consumer information.” That is not a list of industries; it is anyone who holds the covered information and is not otherwise regulated by a banking agency or the SEC. Employers that pull background checks, landlords that run credit checks, lenders, auto dealers, debt collectors, insurers, and the disposal companies that serve them are commonly cited examples.

What. “Consumer information” means “any record about an individual, whether in paper, electronic, or other form, that is a consumer report or is derived from a consumer report.” It excludes information that does not identify individuals. The “derived from” language matters: a spreadsheet built from credit-report data is covered even though it is not itself a credit report.

Dispose. The definition is the disposition industry’s reason to care. “Dispose” includes “the discarding or abandonment of consumer information” and “the sale, donation, or transfer of any medium, including computer equipment, upon which consumer information is stored.” Selling a used laptop, donating a server, returning a leased copier, or transferring a phone to an employee is a disposal of whatever consumer information the device holds. The rule reaches remarketing as squarely as it reaches the dumpster.

Why the definition matters for ITAD

Every path a retired device can take — resale, donation, lease return, employee transfer, recycling — is a “disposal” under 682.1 if consumer report information is on it. There is no reuse path that sits outside the rule. Sanitize first, then choose the path.

Section 03

The reasonable-measures standard and its examples

Section 682.3 states the obligation in one sentence and then, unusually, shows its work.

The standard, 682.3(a): any covered person “must properly dispose of such information by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.” Reasonableness is a flexible standard — the FTC has said it depends on the sensitivity of the information, the costs and benefits of disposal methods, and available technology — but 682.3(b) anchors it with examples of measures that would satisfy the rule:

  • Implementing and monitoring compliance with policies and procedures that require burning, pulverizing, or shredding of papers containing consumer information “so that the information cannot practicably be read or reconstructed.”
  • Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media containing consumer information “so that the information cannot practicably be read or reconstructed.”
  • After due diligence, entering into and monitoring compliance with a contract with another party engaged in the business of record destruction to dispose of the material in a manner consistent with the rule.
  • For a person subject to the GLBA Safeguards Rule, incorporating the proper disposal of consumer information into its information security program.

The phrase “cannot practicably be read or reconstructed” is the rule’s performance target for both paper and electronic media, and it is the bridge to technical standards. The rule does not say how to make electronic media unreadable; it says that is the result you must reasonably achieve. NIST SP 800-88 Rev. 2’s Purge and Destroy methods, with IEEE 2883 techniques, are the recognized ways to demonstrate you did — and a “delete” or a quick format, which leaves data trivially reconstructable, is the clearest example of a measure that is not reasonable.

Bottom line

The target is “cannot practicably be read or reconstructed,” and the rule accepts destruction or erasure of electronic media that achieves it. Sanitization to a recognized standard is how you show your measures were reasonable.

Section 04

The due-diligence examples: the federal rule that reads like a vendor checklist

Section 682.3(b)(3) is the part of the rule an ITAD buyer should know by heart, because it enumerates what the FTC considers due diligence on a disposal company.

The rule states that due diligence on a record-destruction contractor “could include” the following: reviewing an independent audit of the disposal company’s operations and/or its compliance with the rule; obtaining information about the disposal company from several references or other reliable sources; requiring that the disposal company be certified by a recognized trade association or similar third party; reviewing and evaluating the disposal company’s information security policies or procedures; or taking other appropriate measures to determine the competency and integrity of the potential disposal company.

Read that list against the disposition industry’s credentials and it maps almost one-to-one. An independent audit is what a NAID AAA certification represents — scheduled and unannounced audits of the destruction operation against a published specification. Certification by a recognized trade association describes NAID AAA (i-SIGMA) and, for the recycling side, R2v3 (SERI) precisely. Information security policies are what a due-diligence questionnaire elicits. And references are references. The rule then adds that the contract should be monitored for compliance — diligence is not a one-time event.

This is the reason the site’s vendor due-diligence guide and scorecard look the way they do: the structure is the FTC’s. An organization that documents those four steps before engaging a disposal vendor, and revisits them, has done what 682.3(b)(3) describes.

682.3(b)(3) due-diligence exampleWhat it looks like in ITAD
Review an independent auditThird-party certification audits — NAID AAA (destruction security), R2v3 (responsible recycling); ask for the certificate numbers and check the registries
Obtain information from references or reliable sourcesClient references; public registries; the vendor’s regulatory record
Require certification by a recognized trade associationNAID AAA from i-SIGMA; R2v3 from SERI; RIOS
Review information security policies and proceduresDue-diligence questionnaire; SOPs; chain-of-custody process; sample certificate of sanitization
Monitor compliance with the contractSerialized certificates reconciled to inventory; periodic review; downstream disclosures
Section 05

The banking-agency parallel and the Safeguards Rule’s two-year clock

Two neighboring rules carry the same disposal duty into financial services — one for banks, one for the financial institutions the FTC regulates — and the second added a deadline in 2021.

Banks and credit unions do not follow Part 682; they follow their regulators’ Interagency Guidelines Establishing Information Security Standards, which implement GLBA sections 501(b) and 505(b) and, for disposal, the FACTA duty. The Guidelines require each institution to “develop, implement, and maintain, as part of its information security program, appropriate measures to properly dispose of customer information and consumer information,” to exercise due diligence in selecting service providers, to require safeguards by contract, and to monitor providers where the risk warrants. Our GLBA & FFIEC guide covers that framework in full.

FTC-regulated financial institutions — mortgage lenders and brokers, finance companies, tax preparers, auto dealers that extend credit, and similar businesses — follow the FTC’s Safeguards Rule, 16 CFR Part 314, in addition to the Disposal Rule. The Safeguards Rule was substantially amended in 2021, with most new requirements effective in 2023, and the amendments added a provision that changes disposition planning directly: institutions must develop procedures for the secure disposal of customer information “no later than two years after the last date the information is used” in connection with providing a product or service, unless retention is necessary for business operations or other legitimate purposes, is required by law, or targeted disposal is not reasonably feasible. The rule also requires periodic review of data retention policies to minimize unnecessary retention, encryption of customer information at rest and in transit (or approved compensating controls), oversight of service providers — select, contract, and periodically assess — a written incident response plan, and, since 2024, notification to the FTC within 30 days of discovering a notification event involving 500 or more consumers.

For a covered institution the practical effect is that the storeroom of retired equipment has a clock on it. Customer information sitting on decommissioned devices more than two years after its last use is, absent a documented retention reason, information the rule says should have been disposed of.

Bottom line

Banks: Interagency Guidelines, disposal inside the GLBA program. FTC-regulated financial institutions: Disposal Rule plus the amended Safeguards Rule, with a two-year disposal clock, encryption, provider oversight, and FTC breach notification. Both point the same way — dispose on schedule, through a vetted vendor, with records.

Section 06

Relation to other laws: a floor, not a ceiling

Section 682.4 is a single paragraph, and it settles a question buyers ask constantly.

The rule states that it does not require any person to maintain or destroy records not otherwise required, and that it does not alter or affect any requirement imposed under other federal or state law to maintain or destroy records. In plain terms: the Disposal Rule is a floor. It does not preempt stricter state data-disposal statutes — roughly two-thirds of states have them — and it does not override retention schedules that require you to keep records longer. Where a state law requires more (a specific destruction method, a broader definition of personal information, a notice duty), the state law governs on top of the federal rule.

The disposition consequence is a sequencing rule that appears in every compliant program: records management clears retention before IT sanitizes. The Disposal Rule tells you to destroy properly when you dispose; it does not tell you when you may dispose. That answer comes from the retention schedule — the same reason NIST SP 800-88 Rev. 2 names a records management officer among its program roles.

Section 07

The ITAD program, Disposal Rule edition

The rule is short enough that a compliant disposition program can be described in a short list — and most of the list is what a good program does anyway.

  • Assume coverage. If any part of the organization uses consumer reports — employment screening, tenant screening, credit decisions — consumer information exists somewhere on the fleet, and Part 682 applies to its disposal.
  • Treat every exit path as a disposal. Resale, donation, lease return, employee transfer, recycling. “Dispose” includes them all; sanitize before any of them.
  • Write the policy the examples describe. 682.3(b) rewards documented policies and procedures with monitored compliance: paper shredded to unreadability; electronic media destroyed or erased to the same standard.
  • Adopt a technique standard for “cannot practicably be read or reconstructed.” NIST SP 800-88 Rev. 2 with IEEE 2883 techniques, verified and validated; destruction benchmarked to NSA/CSS specifications where destroy is chosen.
  • Run the four-step due diligence and write it down. Independent audit (certification), references, recognized certification (NAID AAA, R2v3), security policies — then a contract, then monitoring. The scorecard records exactly these.
  • Keep per-device evidence. Serialized certificates reconciled to the asset list are how “monitoring compliance with the contract” is demonstrated after the fact.
  • If you are an FTC-regulated financial institution, start the clock. Customer information disposed no later than two years after last use absent a documented reason; encryption at rest; provider oversight; incident response; FTC notification for events of 500+ consumers.
  • Layer the state rules. Part 682 is a floor; the state disposal statutes and breach laws sit on top. The Compliance Map shows which apply to you.

CyberCrunch is NAID AAA certified continuously since 2012 and R2v3, RIOS, and PA DEP certified — the independent-audit and trade-association-certification steps the rule’s due-diligence examples describe — and documents every device with a serialized certificate. The credentials packet collects the evidence a 682.3(b)(3) review asks for in one file.

Bottom line

Assume coverage, treat every exit as a disposal, write the policy, adopt a standard, do the four-step diligence, keep per-device records, watch the two-year clock if it applies, layer the states. The Disposal Rule is the federal floor; a good ITAD program clears it without noticing.

Section 08

Frequently asked questions

Who has to comply with the FTC Disposal Rule?

Under 16 CFR 682.1, any person over which the Federal Trade Commission has jurisdiction that, for a business purpose, maintains or otherwise possesses consumer information, meaning any record about an individual that is a consumer report or is derived from one. That reaches employers that use background checks, landlords that run credit checks, lenders, auto dealers, debt collectors, and the disposal companies that serve them. Banks and credit unions follow their own regulators' parallel Interagency Guidelines instead, and SEC-regulated entities follow the SEC's version.

Does selling or donating a used computer count as 'disposal' under the rule?

Yes. The rule defines dispose to include not only discarding or abandoning consumer information but also the sale, donation, or transfer of any medium, including computer equipment, on which consumer information is stored. A resold laptop, a donated server, a returned leased copier, or a phone handed to an employee is a disposal of whatever consumer information the device holds, so the reasonable-measures standard applies before any of those paths is taken.

What counts as 'reasonable measures' for electronic media under the Disposal Rule?

Section 682.3(b) gives the example of policies and procedures, with monitored compliance, that require the destruction or erasure of electronic media so that the information cannot practicably be read or reconstructed. The rule does not name a technique; organizations demonstrate reasonableness by sanitizing to a recognized standard, in practice NIST SP 800-88 Rev. 2 with IEEE 2883 techniques, verified and documented. Simple deletion or a quick format, which leaves data readily recoverable, is the clearest example of a measure that would not be reasonable.

What due diligence does the FTC expect before hiring a disposal or ITAD company?

Section 682.3(b)(3) says due diligence could include reviewing an independent audit of the company's operations or compliance, obtaining information about the company from references or other reliable sources, requiring that it be certified by a recognized trade association or similar third party, reviewing and evaluating its information security policies or procedures, or other appropriate measures to determine its competency and integrity. The rule then expects the resulting contract to be monitored for compliance. In ITAD terms that maps to checking NAID AAA and R2v3 certification registries, taking references, reviewing SOPs and a sample certificate, and reconciling certificates to inventory over time.

What is the two-year disposal requirement in the FTC Safeguards Rule?

The amended Safeguards Rule, 16 CFR 314.4(c)(6), requires FTC-regulated financial institutions to develop procedures for the secure disposal of customer information no later than two years after the last date the information is used in connection with providing a product or service to the customer, unless retention is necessary for business operations or other legitimate business purposes, is otherwise required by law, or targeted disposal is not reasonably feasible. Institutions must also periodically review their data retention policy to minimize unnecessary retention. It applies to the financial institutions the FTC regulates, not to banks, and it sits alongside the Disposal Rule rather than replacing it.

THE DUE DILIGENCE THE RULE DESCRIBES

Independent audits, trade-association certification, and per-device records — ready to review

CyberCrunch is NAID AAA certified continuously since 2012 and R2v3, RIOS, and PA DEP certified, with serialized certificates for every device and a credentials packet that collects the evidence a 682.3(b)(3) review asks for. Run the scorecard, then ask us for the file.

NAID AAA · SINCE 2012 R2v3 · APPENDICES A/B/C RIOS PA DEP · WMGR081

This guide is informational only and reflects 16 CFR Part 682 and 16 CFR Part 314 as published in the Electronic Code of Federal Regulations, Section 216 of the Fair and Accurate Credit Transactions Act of 2003, and the Interagency Guidelines Establishing Information Security Standards, as of September 2026. Quotations are from the published regulations. It describes federal requirements at the pattern level; state disposal and breach-notification statutes, agency guidance, and enforcement practice add requirements that vary. It is not legal advice, creates no attorney-client relationship, and should not be relied on to determine any organization’s obligations; consult qualified counsel. CyberCrunch credential and practice statements reflect certificates and procedures at the time of publication.