The Federal Trade Commission’s updated Safeguards Rule — which took full effect in 2023 — significantly strengthened the information security requirements for financial institutions. If your New York business operates in financial services, mortgage lending, tax preparation, or a related sector, you need a clear FTC Safeguards Rule 2023 shredding checklist to ensure your document disposal practices meet federal requirements. Failing to comply can result in FTC enforcement actions, reputational damage, and potential civil liability.
The updated rule expanded both the scope of covered businesses and the specificity of required security controls. Importantly, the disposal of customer financial records — both paper and electronic — is a central requirement. This guide breaks down exactly what you need to do and how a certified shredding program can help you check every box.

What Is the FTC Safeguards Rule?
The FTC Safeguards Rule was originally enacted under the Gramm-Leach-Bliley Act (GLBA) in 2003 and requires financial institutions to implement a written information security program. The 2023 updates — effective June 2023 for most provisions — added specific technical requirements and expanded the definition of “financial institution” to include businesses like mortgage brokers, payday lenders, tax preparers, and auto dealerships.
The updated rule requires covered businesses to implement these key safeguard elements, among others:
- Designate a qualified individual to oversee the information security program
- Conduct regular risk assessments
- Implement physical and technical safeguards to protect customer information
- Establish secure disposal procedures for customer financial records
- Train employees on security and disposal requirements
- Monitor and test the information security program regularly
Document disposal is directly addressed in the rule’s physical safeguard requirements. Our compliance shredding services are designed specifically to help financial institutions meet these standards.
FTC Safeguards Rule 2023 Shredding Checklist
Use this checklist to assess whether your document destruction practices comply with the updated FTC Safeguards Rule. This list is designed for financial institutions, mortgage companies, tax preparers, and other covered entities operating in New York City, Long Island, Westchester, and the Hudson Valley.
- ☐ Written information security program (WISP) addresses document disposal procedures
- ☐ All paper records containing customer financial information are destroyed by a certified shredding company — not placed in recycling or trash
- ☐ Electronic media (hard drives, USB drives, backup tapes) is physically destroyed or rendered unreadable before disposal
- ☐ Locked collection consoles are deployed throughout the office to prevent unauthorized access to documents awaiting destruction
- ☐ A Certificate of Destruction is obtained from your shredding vendor after each destruction event
- ☐ Shredding vendor is certified, bonded, and insured, with a signed confidentiality/service agreement
- ☐ Employees are trained on which document types require secure disposal and the procedures for doing so
- ☐ A records retention schedule defines when each document category must be destroyed
- ☐ Destruction events are logged and records are maintained for audit purposes
- ☐ The qualified security individual reviews disposal procedures annually as part of the risk assessment process
Our shredding services are designed to help financial institutions check every item on this list. We serve all five boroughs and surrounding areas — contact us to get set up with a shredding schedule today.
Disposal Requirements for Customer Financial Records
Under the updated FTC Safeguards Rule, financial institutions must properly dispose of customer information in any format — paper, electronic, or otherwise. The rule’s disposal standard requires that customer records be made “unreadable or indecipherable” before disposal. For paper documents, this means shredding with industrial-grade equipment that reduces paper to particles that cannot be reassembled.
Documents that must be securely destroyed include:
- Loan applications, credit reports, and underwriting documents
- Bank account statements and financial account records
- Social Security numbers, tax IDs, and identification documents
- Tax returns and supporting financial documentation
- Insurance policies and claim records
- Any document containing a customer’s “nonpublic personal information” (NPI)
It’s important to note that consumer-grade office shredders do not meet the standard for shredding sensitive financial records under NIST guidelines, which the FTC references. A certified commercial shredding company using cross-cut or micro-cut shredding technology is required to demonstrate compliance.
Electronic Media Destruction Under the FTC Safeguards Rule
The 2023 updates to the FTC Safeguards Rule added explicit requirements for the secure disposal of electronic records and storage media. Simply deleting files or formatting a hard drive is not sufficient — data recovery tools can restore deleted files from drives that weren’t physically destroyed.
The FTC Safeguards Rule requires that electronic storage media be rendered unreadable or indecipherable. Compliant methods include:
- Physical destruction: Hard drive shredding or crushing that destroys the drive platters
- Degaussing: Erasing data with a strong magnetic field (applicable to magnetic media)
- Certified data wiping: Multi-pass overwriting that meets DoD or NIST standards (with Certificate of Destruction)
New York Shredding offers hard drive and electronic media destruction services for financial institutions across New York City, Long Island, Westchester, and the Hudson Valley. Every destruction event includes a Certificate of Destruction that specifies the serial numbers of the devices destroyed. Learn more on our how it works page.
Choosing a Compliant Shredding Vendor Under the FTC Safeguards Rule
The FTC Safeguards Rule requires covered businesses to oversee their service providers and ensure those providers maintain appropriate safeguards. Before engaging a shredding company, financial institutions should verify that the vendor meets these criteria:
- NAID AAA Certification or equivalent industry certification
- Background-checked and trained employees
- Locked, GPS-tracked transport vehicles
- Certificates of Destruction issued for every job
- Signed confidentiality and business associate agreements
- Adequate insurance coverage including general liability and employee dishonesty
New York Shredding Document Destruction, Inc. meets all of these criteria. We work with financial institutions, mortgage companies, tax preparers, and other FTC-covered entities throughout New York. View our pricing to see how to get started.
Why New York Businesses Choose New York Shredding
For over a decade, New York Shredding Document Destruction, Inc. has helped businesses across New York City, Long Island, Westchester, and the Hudson Valley protect their sensitive information through certified, HIPAA-compliant shredding services. Our industrial-grade shredding equipment, locked on-site consoles, and Certificate of Destruction give your business the proof it needs for any FTC audit or other compliance review.
Whether you need scheduled shredding, a one-time purge, or hard drive destruction, we serve all five boroughs and surrounding areas with fast, reliable service. Request a free quote today and get your office on a shredding schedule that keeps you protected year-round.
Ready to get started? Contact New York Shredding for a free quote, or explore our full range of shredding services.

