WISP for finders
Finders need a WISP when the business is covered by the FTC Safeguards Rule category finder. The practical coverage trigger is that the firm brings together buyers and sellers for transactions the parties negotiate and consummate. Finder data may live in lead forms, marketplace profiles, referral databases, eligibility screens, CRM records, email introductions, and analytics exports. The WISP should distinguish ordinary marketing leads from consumer financial information collected to make a financial-service match.
Key facts
- Finders should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: brings together buyers and sellers for transactions the parties negotiate and consummate.
- The data map should be vertical-specific: Finder data may live in lead forms, marketplace profiles, referral databases, eligibility screens, CRM records, email introductions, and analytics exports. The WISP should distinguish ordinary marketing leads from consumer financial information collected to make a financial-service match.
- Lead-generation volume can make the 5,000-consumer threshold arrive quickly. If below it, the firm still needs the core written security program and safeguards.
Key takeaways
- Finders should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: brings together buyers and sellers for transactions the parties negotiate and consummate.
- The data map should be vertical-specific: Finder data may live in lead forms, marketplace profiles, referral databases, eligibility screens, CRM records, email introductions, and analytics exports. The WISP should distinguish ordinary marketing leads from consumer financial information collected to make a financial-service match.
- Lead-generation volume can make the 5,000-consumer threshold arrive quickly. If below it, the firm still needs the core written security program and safeguards.
- We are only a marketplace or lead source. If the finder role is tied to covered financial activity and the business maintains customer information, the label marketplace does not end the analysis.
Why finders are covered
Finders are covered when their business activity fits finder. 16 CFR 314.2(h)(2)(xiii) names entities acting as finders as financial institutions when the activity is financial in nature or incidental to a financial activity.
The coverage test is factual. For this vertical, Policywright treats the trigger as: brings together buyers and sellers for transactions the parties negotiate and consummate. The sources block below is limited to primary-source or regulator materials so the page does not drift into unsourced compliance folklore.
The page does not invent a coverage theory beyond the cited category and factual trigger.
Where customer information lives
Finder data may live in lead forms, marketplace profiles, referral databases, eligibility screens, CRM records, email introductions, and analytics exports. The WISP should distinguish ordinary marketing leads from consumer financial information collected to make a financial-service match.
That data-flow map changes the WISP. A tax preparer worries about portals and e-file records; a collection agency worries about placement files, dialers, and dispute queues; an auto dealer worries about the credit application, F&I office, DMS, and lender portals.
A useful written program should name the systems, roles, vendors, access paths, retention points, and evidence records that fit the trade.
Common objection
We are only a marketplace or lead source. If the finder role is tied to covered financial activity and the business maintains customer information, the label marketplace does not end the analysis.
Policywright handles that objection by writing the factual basis into the packet rather than hiding it. If coverage is unclear, the firm should preserve the question for counsel instead of turning a WISP into an unsupported legal conclusion.
Under-5,000-consumer analysis
Lead-generation volume can make the 5,000-consumer threshold arrive quickly. If below it, the firm still needs the core written security program and safeguards.
16 CFR 314.6 exempts smaller covered firms only from 314.4(b)(1), (d)(2), (h), and (i). It does not remove the written-program duty or the need to protect customer information with reasonable administrative, technical, and physical safeguards.
A serious small-firm packet should document the count assumption and keep the fuller controls where they are operationally useful.
| Question | Vertical-specific answer | Source |
|---|---|---|
| Coverage trigger | brings together buyers and sellers for transactions the parties negotiate and consummate | 16 CFR 314.2(h)(2)(xiii) |
| Customer data flow | Finder data may live in lead forms, marketplace profiles, referral databases, eligibility screens, CRM records, email introductions, and analytics exports. The WISP should distinguish ordinary marketing leads from consumer financial information collected to make a financial-service match. | Document in WISP data inventory |
| Common objection | We are only a marketplace or lead source. If the finder role is tied to covered financial activity and the business maintains customer information, the label marketplace does not end the analysis. | 16 CFR 314.2(h)(2)(xiii) |
| Small-firm exception | Lead-generation volume can make the 5,000-consumer threshold arrive quickly. If below it, the firm still needs the core written security program and safeguards. | 16 CFR 314.6 |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
What makes finders different from tax preparers?
The data flow and objection pattern are different. Finders need a WISP that follows Finder data may live in lead forms, marketplace profiles, referral databases, eligibility screens, CRM records, email introductions, and analytics exports. The WISP should distinguish ordinary marketing leads from consumer financial information collected to make a financial-service match.
Does Policywright cover related non-Safeguards obligations?
No separate related obligation is claimed on this page. Policywright is focused on the Safeguards Rule policy packet and does not replace counsel.
Sources
Build a WISP for finders.
Answer plain questions and receive a source-cited policy packet tailored to the firm's systems, vendors, and gaps.
Build my plan