Regulatory anatomy · GLBA § 501(b) · Interagency Guidelines · 16 CFR 314 · FFIEC

The GLBA & FFIEC Field Guide: Financial Data Disposal, Vendor Oversight, and What Examiners Expect

Financial institutions live under one safeguarding statute and two rulebooks. The Gramm-Leach-Bliley Act of 1999 required regulators to set standards protecting the security and confidentiality of customer information; the banking agencies answered with the Interagency Guidelines Establishing Information Security Standards, and the Federal Trade Commission answered for everyone else — mortgage companies, finance companies, tax preparers, dealers, advisers — with the Safeguards Rule. Both reach retired hardware through the same three duties: dispose of customer information properly, vet and contract the service providers who touch it, and monitor them. Layered on top are the FFIEC IT Examination Handbook, which tells examiners what to look for, and the 2023 Interagency Guidance on Third-Party Relationships, which tells institutions how to run vendor risk from planning to termination. This guide walks each at the pattern level and translates it into an IT asset disposition program an examiner will recognize. Not legal advice. For the disposal rule that reaches non-financial businesses, see the FTC Disposal Rule guide; for the sector video, Financial Services ITAD.

Reading time: ~16 min Published: September 1, 2026 Author: Brian Boynton Applies to: GLBA; 12 CFR 30/208/364 App. B; 16 CFR 314; FFIEC IT Handbook

STRAIGHT ANSWER

What does GLBA require for retired IT equipment?

Proper disposal of customer information, vetted and contracted service providers, and ongoing monitoring. Banks follow the Interagency Guidelines, which require appropriate disposal measures inside the information security program, due diligence and contractual safeguards for service providers, and annual board reporting. Non-bank financial institutions follow the FTC Safeguards Rule, which adds disposal within two years of last use, encryption, and FTC breach notification. Examiners check against the FFIEC handbook.

TL;DR

One statute, two rulebooks, same three duties. Banks and credit unions: the Interagency Guidelines require an information security program whose objectives include ensuring “the proper disposal of customer information and consumer information,” with due diligence in selecting service providers, contracts requiring appropriate safeguards, monitoring where risk warrants, and an annual report to the board. Everyone else in financial services: the FTC Safeguards Rule (16 CFR 314), amended in 2021, requires a written program under a qualified individual, encryption of customer information at rest and in transit, secure disposal no later than two years after last use absent a legitimate reason, service-provider selection-contract-assessment, a written incident response plan, and since 2024 FTC notification within 30 days of a notification event involving 500+ consumers. The FFIEC IT Examination Handbook is how examiners test all of it, and the June 2023 Interagency Third-Party Guidance defines the vendor life cycle — planning, due diligence and selection, contract negotiation, ongoing monitoring, termination — that an ITAD relationship is expected to follow. None of these documents names a sanitization technique; NIST SP 800-88 Rev. 2 is how an institution shows disposal was proper.

Section 01

GLBA: one safeguarding duty, two regulators

Section 501(b) of the Gramm-Leach-Bliley Act directed regulators to establish standards for safeguarding customer information. Who your regulator is determines which rulebook you read.

GLBA’s safeguarding provisions require financial institutions to protect the security and confidentiality of customer records and information, to protect against anticipated threats or hazards to their security or integrity, and to protect against unauthorized access or use that could result in substantial harm or inconvenience to a customer. Section 505(b) assigned enforcement to each institution’s functional regulator. The Fair and Accurate Credit Transactions Act of 2003 later added the duty to properly dispose of consumer report information, which the regulators folded into the same programs.

The result is a split that confuses vendors and buyers alike. Depository institutions — banks, savings associations, and, through the NCUA’s parallel rule, credit unions — are examined by the federal banking agencies against the Interagency Guidelines Establishing Information Security Standards, codified as appendices to the agencies’ safety-and-soundness rules (for example, 12 CFR Part 364 Appendix B for FDIC-supervised institutions, Part 30 Appendix B for the OCC, Part 208 Appendix D-2 for the Federal Reserve). Every other “financial institution” under GLBA’s broad definition — significantly engaged in financial activities but not a bank — falls to the FTC’s Safeguards Rule at 16 CFR Part 314. SEC-registered entities have the SEC’s Regulation S-P.

Bottom line

Find your regulator, then your rulebook: Interagency Guidelines for banks and credit unions; FTC Safeguards Rule for non-bank financial institutions; Regulation S-P for SEC registrants. The disposal and vendor duties are similar in substance across all three.

Section 02

The Interagency Guidelines: disposal inside the security program

For a bank, disposal is not a separate rule. It is a stated objective of the information security program the Guidelines require.

The Guidelines require each institution to implement a comprehensive written information security program appropriate to its size and complexity. Its objectives (Section III.B) are to ensure the security and confidentiality of customer information, protect against anticipated threats or hazards, protect against unauthorized access or use that could result in substantial harm or inconvenience, and — added to implement FACTA — “ensure the proper disposal of customer information and consumer information.”

The disposal duty itself is Section III.C.4: each institution “shall develop, implement, and maintain, as part of its information security program, appropriate measures to properly dispose of customer information and consumer information.” Like the FTC’s Disposal Rule, it states an outcome rather than a technique, leaving the institution to choose and justify measures — which is where recognized standards enter.

Section III.D governs service providers, and it is the part an ITAD engagement lives under. The institution must “exercise appropriate due diligence in selecting its service providers,” must “require its service providers by contract to implement appropriate measures designed to meet the objectives of these Guidelines,” and, where indicated by its risk assessment, must “monitor its service providers to confirm that they have satisfied their obligations,” including by reviewing audits, summaries of test results, or other equivalent evaluations. Section III.F requires a report to the board or a board committee at least annually describing the program’s overall status and compliance, including risk assessment, control decisions, service provider arrangements, testing results, and security incidents. And Supplement A — the response-program guidance — requires notifying the primary federal regulator “as soon as possible” of unauthorized access to sensitive customer information and notifying affected customers when misuse has occurred or is reasonably possible.

Guidelines provisionWhat it means for disposition
III.B objectivesProper disposal of customer and consumer information is a stated program objective, not an afterthought
III.C.4 disposalDocumented, appropriate disposal measures — in practice, sanitization to a recognized standard with records
III.D service providersDue diligence in selecting the ITAD vendor; a contract requiring safeguards; monitoring via audits and evaluations where risk warrants
III.F board reportingThe ITAD arrangement and its oversight appear in the annual board report
Supplement AA retired device causing unauthorized access to sensitive customer information triggers regulator and customer notification analysis
Section 03

The FTC Safeguards Rule: the non-bank rulebook, with a clock

The Safeguards Rule was a principles-based rule for two decades. Its 2021 amendments made it specific — and one of the specifics is about disposal.

16 CFR Part 314 applies to financial institutions under FTC jurisdiction: the FTC’s own examples include mortgage lenders and brokers, payday lenders, finance companies, account servicers, check cashers, wire transferors, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, and investment advisers not required to register with the SEC. The amended rule (most provisions effective in 2023, with the notification provision added in 2024) requires a written information security program with named elements in Section 314.4:

  • A qualified individual responsible for the program, and a written risk assessment identifying reasonably foreseeable internal and external risks.
  • Safeguards including access controls, an inventory of data and systems, encryption of customer information in transit over external networks and at rest (or approved compensating controls), secure development practices, multi-factor authentication, and change management.
  • Disposal — Section 314.4(c)(6): procedures for the secure disposal of customer information “no later than two years after the last date the information is used in connection with the provision of a product or service to the customer to which it relates,” unless retention is necessary for business operations or other legitimate business purposes, is otherwise required by law, or targeted disposal is not reasonably feasible; plus periodic review of the data retention policy to minimize unnecessary retention.
  • Service provider oversight — Section 314.4(f): take reasonable steps to select and retain providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess providers based on the risk they present.
  • A written incident response plan (314.4(h)), annual reporting to the board or senior officer (314.4(i)), and notification to the FTC within 30 days of discovering a notification event involving the information of at least 500 consumers (314.4(j)).

Institutions maintaining customer information on fewer than 5,000 consumers are exempt from some of the program elements. Everyone covered is subject to the disposal and service-provider provisions.

Bottom line

For non-bank financial institutions the amended Safeguards Rule turns disposition into a dated obligation: customer information disposed no later than two years after last use absent a documented reason, encrypted while it exists, handled by providers you selected, contracted, and periodically assess — with a 30-day FTC notification if a disposition failure exposes 500 or more consumers.

Section 04

FFIEC: what examiners actually check

The Federal Financial Institutions Examination Council does not write rules. It writes the handbook examiners carry, which for practical purposes is what the rules mean.

The FFIEC is the interagency body through which the federal banking regulators coordinate examination standards. Its IT Examination Handbook — a set of booklets including Information Security (September 2016), Outsourcing Technology Services, and Business Continuity Management — is the reference examiners use to evaluate an institution’s information security program under the Interagency Guidelines. The Information Security booklet addresses the full control environment, including the handling, storage, transport, and disposal of media holding customer information and the oversight of third parties that perform those functions, and it points institutions toward recognized standards such as NIST publications for technical detail.

For a disposition program the examination questions are predictable from the Guidelines: Is disposal of customer information addressed in the written program? Are media containing customer information tracked from removal through destruction? Is the disposal vendor selected with documented due diligence, bound by contract, and monitored? Does the board report cover the arrangement? Can the institution produce the destruction records for a sample of retired assets? An examiner who asks for the certificate matching a specific decommissioned server’s serial number is not being difficult; the Guidelines’ monitoring and accountability language is what puts that question in the handbook.

A note on sourcing

The FFIEC booklets are published at ithandbook.ffiec.gov and revised periodically; this guide describes their role and general expectations rather than quoting booklet text. Institutions should work from the current booklets and their examiner’s guidance.

Section 05

The 2023 Interagency Third-Party Guidance: the vendor life cycle

On June 6, 2023 the OCC, Federal Reserve, and FDIC replaced their separate vendor-risk guidance with one document. It describes the relationship an ITAD engagement is expected to be.

The Interagency Guidance on Third-Party Relationships: Risk Management organizes vendor oversight into a life cycle with five stages: planning (understanding the risk before engaging), due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. It emphasizes that the depth of oversight should be proportionate to the risk and criticality of the relationship, and it replaced each agency’s prior general third-party guidance to promote consistency in supervisory approach.

An IT asset disposition relationship is a textbook case for the life cycle. Planning: the vendor will take custody of media holding customer information — a high-sensitivity activity. Due diligence: certifications (NAID AAA for destruction security, R2v3 for downstream), insurance, references, financial condition, subcontractor use. Contract: scope, sanitization standard (NIST SP 800-88 Rev. 2, IEEE 2883 techniques), chain of custody, per-device certificates, breach notification duties, audit rights, subcontractor controls, insurance requirements, termination terms. Ongoing monitoring: certificates reconciled to asset records, periodic review of certifications and audits, incident review. Termination: return or destruction of any retained data and records, transition of in-process assets. An institution that can show a file organized along those five headings for its ITAD vendor has anticipated the examination.

Bottom line

Plan, select, contract, monitor, terminate. The 2023 guidance is the outline of the vendor file an examiner expects to see for an ITAD relationship — and the disposition industry’s credentials, contracts, and certificates map onto it stage by stage.

Section 06

Where the technique comes from

None of the financial rules names a sanitization method. The gap is filled the same way across every regulated sector.

The Interagency Guidelines say “appropriate measures to properly dispose.” The Safeguards Rule says “secure disposal.” The Disposal Rule says information that “cannot practicably be read or reconstructed.” Each is an outcome, and each leaves the institution to choose a technique and be able to defend it. In practice the defense is a recognized standard: NIST SP 800-88 Rev. 2 for the program and decision flow, IEEE 2883 for the technique by interface, and NSA/CSS specifications as the destruction benchmark. A written disposal procedure that cites those, applied through a vendor whose SOP cites the same, with per-device certificates carrying the fields 800-88 Section 4.6 describes, is what “appropriate” and “secure” look like in a file an examiner can read.

Encryption deserves its own sentence. The Safeguards Rule requires it for customer information at rest; the Guidelines’ risk-based framework generally leads there; and NIST 800-88 Rev. 2 makes cryptographic erase a valid purge technique when encryption was in place from first use with sanitizable keys and a validated implementation. For a financial institution, encrypting the fleet at deployment is both a current compliance control and the cheapest sanitization decision it will ever make.

Section 07

The ITAD program, GLBA edition

An examination-ready disposition program for a financial institution is a short list of documents and habits.

  • Put disposal in the written program. A disposal section in the information security program that names the standard (NIST SP 800-88 Rev. 2, IEEE 2883), the process, and the records — satisfying III.C.4 or 314.4(c)(6) on its face.
  • Inventory customer-information media. The Safeguards Rule requires a data and systems inventory; the Guidelines’ monitoring presumes one. Devices tagged by data category are the foundation for both the two-year clock and the examiner’s sample.
  • Encrypt at rest, from deployment. Required under 314.4(c)(3); risk-indicated under the Guidelines; the pre-condition for cryptographic erase under 800-88 Rev. 2.
  • Run the vendor life cycle and keep the file. Planning memo, due-diligence package (certifications, insurance, references, subcontractors), contract with sanitization standard and breach duties, monitoring evidence (certificates reconciled to inventory, annual certification check), termination terms. The due-diligence guide and scorecard cover the middle three stages.
  • Start the two-year clock if the Safeguards Rule applies. Customer information on retired devices more than two years past last use needs a documented retention reason or a disposition date.
  • Reconcile certificates to serials. The examiner’s sample question — “show me the destruction record for this asset” — is answered by per-device certificates matched to the asset list, not by pallet weights.
  • Report it to the board. The Guidelines require the annual report to cover service provider arrangements; the Safeguards Rule requires annual reporting to the board or senior officer. Include the disposition vendor and its oversight.
  • Wire breach notification into the contract. Supplement A (banks) and 314.4(j) (FTC-regulated) put notification duties on you; the vendor’s contractual duty to tell you promptly is what makes those achievable.

CyberCrunch is NAID AAA certified continuously since 2012 and R2v3, RIOS, and PA DEP certified; sanitizes to NIST SP 800-88 Rev. 2 with IEEE 2883 technique selection; and documents every device with a serialized certificate. The credentials packet is the due-diligence stage of the third-party life cycle in one file. The Financial Services ITAD video covers the sector in eight minutes.

Bottom line

Written disposal section, media inventory, encryption at rest, a five-stage vendor file, the two-year clock where it applies, certificates reconciled to serials, board reporting, breach duties in the contract. That is a GLBA-examination-ready disposition program.

Section 08

Frequently asked questions

Does GLBA apply to my organization's IT asset disposal?

If you are a financial institution under GLBA's broad definition, yes, through your regulator's safeguarding rule. Banks, savings associations, and credit unions follow the Interagency Guidelines Establishing Information Security Standards, whose objectives include ensuring the proper disposal of customer information and consumer information. Non-bank financial institutions such as mortgage companies, finance companies, tax preparers, and dealers that extend credit follow the FTC Safeguards Rule at 16 CFR Part 314, which requires secure disposal procedures. Both frameworks also govern how you select, contract, and monitor the vendor that performs disposal.

What is the difference between the Interagency Guidelines and the FTC Safeguards Rule?

They implement the same GLBA safeguarding duty for different regulated populations. The Interagency Guidelines are issued by the federal banking agencies and bind depository institutions; they require a written information security program with disposal as an objective, service-provider due diligence, contracts, and monitoring, and annual board reporting. The FTC Safeguards Rule binds financial institutions under FTC jurisdiction and, as amended in 2021, adds specific elements including a qualified individual, encryption at rest and in transit, disposal of customer information no later than two years after last use, service-provider assessment, an incident response plan, and FTC notification of events affecting 500 or more consumers.

What does GLBA require when hiring an ITAD vendor?

Under the Interagency Guidelines, due diligence in selecting the service provider, a contract requiring the provider to implement appropriate safeguards, and monitoring, through audits or equivalent evaluations, where the risk assessment indicates. Under the Safeguards Rule, reasonable steps to select and retain a provider capable of maintaining appropriate safeguards, contractual safeguard requirements, and periodic assessment based on risk. The 2023 Interagency Guidance on Third-Party Relationships organizes this into a life cycle of planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination.

Does GLBA specify how customer data must be destroyed?

No. The Guidelines require appropriate measures to properly dispose of customer and consumer information, and the Safeguards Rule requires secure disposal; neither names a technique. Institutions demonstrate that their measures were appropriate by adopting a recognized standard, in practice NIST SP 800-88 Rev. 2 with IEEE 2883 techniques and NSA/CSS-benchmarked destruction equipment, and by keeping per-device records that an examiner can match to the asset inventory.

What is the FFIEC and why does it matter for disposition?

The Federal Financial Institutions Examination Council is the interagency body through which the federal banking regulators coordinate examination standards. Its IT Examination Handbook, including the Information Security booklet, is the reference examiners use to evaluate an institution's program under the Interagency Guidelines, including how media holding customer information is handled and disposed of and how third parties that perform those functions are overseen. It matters because it determines the questions an examiner asks about your disposition program and the records they expect you to produce.

EXAMINATION-READY DISPOSITION

The vendor file your examiner expects, ready before the exam

CyberCrunch is NAID AAA certified continuously since 2012 and R2v3, RIOS, and PA DEP certified; sanitizes to NIST SP 800-88 Rev. 2; and delivers serialized certificates you can reconcile to your asset inventory. The credentials packet is the due-diligence stage of the third-party life cycle in one document.

NAID AAA · SINCE 2012 R2v3 · APPENDICES A/B/C RIOS PA DEP · WMGR081

This guide is informational only and reflects, as of September 2026, the Gramm-Leach-Bliley Act's safeguarding provisions, the Interagency Guidelines Establishing Information Security Standards as published in the Code of Federal Regulations, the FTC Safeguards Rule at 16 CFR Part 314 as amended, the June 6, 2023 Interagency Guidance on Third-Party Relationships, and the public role of the FFIEC IT Examination Handbook. It describes these frameworks at the pattern level and does not quote FFIEC booklet text; state financial-privacy laws, agency guidance, and examination practice add requirements. It is not legal, regulatory, or compliance advice, creates no attorney-client relationship, and should not be relied on to determine any institution’s obligations; consult qualified counsel and your regulator’s current guidance. CyberCrunch credential and practice statements reflect certificates and procedures at the time of publication.