Section node
Notification of a security event
16 CFR 314.5
- What this page is
- Section node, 16 CFR 314.5
- Checked against the official source
- 2026-08-15Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does 16 CFR 314.5 require, and where does it carry an outcome in the rule tree?
16 CFR 314.5 is the paragraph the GLBA decision agent rests on for this question. Notice to the agency when unencrypted customer information of 500 or more consumers is acquired without authorisation. The block was read against the publisher on 2026-08-15 and carries 1 outcomes in the agent's rule tree. The reference can be cited as it stands, with a link to the official text and a content hash.
16 CFR 314.5Checked against the publisher 2026-08-15Official text
A source reference, not legal advice.
- Jurisdiction
- 16 CFR Part 314
- Section node
- notification
- Read
- 2026-08-15
- Hash
- sha256:2f3356aa5f803058
Outcomes resting on this section
The rules below point to this section in their outcome. The verdict is a machine classification, not a judgment on an individual matter.
glba-small
The full rule applies, including risk assessment and incident response
16 CFR 314.6 exempts those maintaining information on fewer than 5,000 customers from certain parts. At 5,000 customers or more the written risk assessment in 16 CFR 314.4(b), the incident response plan in 314.4(h) and the board report in 314.4(i) also apply.
risk, Requirement applies
Section nodes
- Information security program16 CFR 314.4(a)
- Risk assessment16 CFR 314.4(b)
- Safeguards16 CFR 314.4(c)
The verdict is a machine classification of the outcome, not legal advice and not a compliance decision.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act