FACTA Disposal Rule: What Businesses Must Shred and How

The FACTA Disposal Rule requires any business that holds consumer report information to take “reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.” For paper, the rule's own example is burning, pulverizing or shredding “so that the information cannot practicably be read or reconstructed.” It does not name a shred size or a security level.

The rule is short, it is broader than most businesses assume, and it has been in force since 2005. This article covers who it captures, exactly what it says, how compliance is judged, and what that means when you are specifying equipment.

Where the rule comes from

The Fair and Accurate Credit Transactions Act of 2003 (FACTA) amended the Fair Credit Reporting Act and directed federal agencies to write rules on the proper disposal of consumer report information. The Federal Trade Commission's version is codified at 16 CFR Part 682 and is commonly called the Disposal Rule. It took effect on 1 June 2005. The underlying statutory authority sits at 15 U.S.C. § 1681w.

Parallel disposal rules were issued by the banking regulators and by the Securities and Exchange Commission for entities under their jurisdiction, so if you are a bank, credit union or broker-dealer, check whether your primary regulator's version applies to you rather than the FTC's.

Who the rule applies to

Far more businesses than expect it. The rule reaches “any person over which the Federal Trade Commission has jurisdiction, that, for a business purpose, maintains or otherwise possesses consumer information.”

The FTC's own business guidance states that the Disposal Rule “applies to people and both large and small organizations that use consumer reports,” and gives these examples:

  • Consumer reporting companies
  • Lenders
  • Insurers
  • Employers
  • Landlords
  • Government agencies
  • Mortgage brokers
  • Automobile dealers
  • Attorneys or private investigators
  • Debt collectors
  • Individuals who obtain a credit report on prospective nannies, contractors, or tenants

Two items in that list deserve emphasis. Employers are covered — if you run background or credit checks on job applicants, you are in scope, whatever industry you are in. And individuals are covered — a homeowner who pulls a credit report on a prospective tenant has obligations under this rule.

What counts as consumer information

The rule defines consumer information as “any record about an individual, whether in paper, electronic, or other form, that is a consumer report or is derived from a consumer report.”

The phrase to watch is derived from. It is not only the credit report itself. It includes the internal summary someone typed from it, the spreadsheet of applicant scores, the note in a file that records a decision made on the basis of a report, and the email attaching it. In practice, the population of documents in scope is usually much larger than the stack of printed reports.

“Dispose” is defined broadly too: it covers “the discarding or abandonment of consumer information” and also “the sale, donation, or transfer of any medium, including computer equipment, upon which consumer information is stored.” Selling old laptops, donating office computers or trading in a copier all count as disposal.

What the rule actually requires

The operative standard, at 16 CFR 682.3(a), is one sentence:

“Any person who maintains or otherwise possesses consumer information for a business purpose must properly dispose of such information by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.”

The rule then gives examples of measures that satisfy it. The two that matter for equipment buyers are:

“Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing consumer information so that the information cannot practicably be read or reconstructed.”

“Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media containing consumer information so that the information cannot practicably be read or reconstructed.”

The rule also expressly permits using a third-party destruction contractor after conducting due diligence, and treats compliance with the Gramm-Leach-Bliley Safeguards Rule information security programme as a route to compliance for entities subject to it.

The standard is flexible, and the FTC says so

This is the point that most vendor material obscures. The FTC's guidance states plainly:

“the standard for the proper disposal of information derived from a consumer report is flexible, and allows the organizations and individuals covered by the Rule to determine what measures are reasonable based on the sensitivity of the information, the costs and benefits of different disposal methods, and changes in technology.”

There is no particle size in the rule. There is no DIN level, no cut type and no equipment list. Anyone claiming that FACTA “requires a cross-cut shredder” or “requires Level 3” is inventing a requirement. What the rule requires is that your chosen measures be reasonable in light of how sensitive the information is — and consumer report information is, by any measure, sensitive.

Enforcement and consequences

The Disposal Rule is enforced by the FTC and, for entities under their supervision, by the federal banking agencies and the SEC. State attorneys general also have enforcement authority under the FCRA framework.

It is worth being precise about liability rather than repeating the round numbers that circulate online. The Disposal Rule's own statutory section, 15 U.S.C. § 1681w, contains no penalty provision; it is a rulemaking directive with a rule of construction stating that “Nothing in this section shall be construed — (1) to require a person to maintain or destroy any record pertaining to a consumer that is not imposed under other law.” Remedies for violations therefore run through the general FCRA enforcement machinery, which provides for administrative enforcement, state enforcement, and private actions for wilful and negligent non-compliance. Amounts and availability depend on the theory pleaded and change over time.

The more predictable consequences are the indirect ones: a discovered disposal failure typically triggers a state data breach notification obligation, remediation costs, and a consent order that imposes a long-running compliance programme. The FTC's historical Disposal Rule cases have generally involved documents left in unsecured dumpsters and consumer files abandoned in vacated premises — not machines that produced particles a millimetre too large.

Practical compliance

1. Map where consumer report information lives

Applicant files, tenant files, loan and lease files, collections records, and anything derived from them. Include email, shared drives, and the copier or MFP hard drive. You cannot dispose of what you have not located.

2. Write the policy before buying the machine

The rule's language is about “implementing and monitoring compliance with policies and procedures.” The policy is the compliance artefact; the shredder is how the policy gets executed. A policy that names the documents, the method, the responsible role and the review cadence is what an examiner will ask for.

3. Secure documents awaiting destruction

Consumer information sitting in an open box next to a shredder is not disposed of — it is unsecured. Locked collection consoles close this gap and are inexpensive relative to the risk.

4. Choose a level you can defend

Since the rule sets an outcome (“cannot practicably be read or reconstructed”) rather than a dimension, pick a level that makes that outcome obvious:

  • P-4 (max 160 mm²) is a sound minimum for consumer report information and is what most offices should be running. See P-4 shredders.
  • P-5 (max 30 mm²) is the stronger position where volumes include Social Security numbers, full account numbers and credit scores together on the same page — which is exactly what a consumer report looks like. See P-5 shredders.
  • P-1 and P-2 strip-cut output leaves whole lines of text intact and is difficult to reconcile with the rule's standard for this category of document.

These are our recommendations based on the sensitivity of the material, not requirements drawn from the rule. Our full explanation of the DIN 66399 security levels sets out the figures, and the same reasoning applies under HIPAA, which is written to a very similar outcome-based standard.

5. Handle electronic disposal deliberately

Erasure must render the information unreadable, and the rule treats transferring storage media as disposal. That means wiping or destroying drives before a laptop is sold, a server is decommissioned or a leased copier goes back. Physical destruction via digital media shredders is the simplest thing to evidence.

6. Do due diligence on any destruction vendor

The rule specifically contemplates contracting out, but it expects due diligence — reviewing the contractor's information security policies, checking references, or relying on an independent audit or trade certification. Keep the evidence of that review.

Frequently Asked Questions

Does FACTA require a specific shred size or security level?

No. 16 CFR 682.3 requires “reasonable measures” and gives shredding “so that the information cannot practicably be read or reconstructed” as an example. The FTC explicitly describes the standard as flexible. Any claim that FACTA mandates a particular DIN level or cut type is incorrect.

Does the Disposal Rule apply to a small business with no credit operation?

Very possibly. If you have ever run a background or credit check on a job applicant or a tenant, you possess consumer report information for a business purpose and the rule applies. Size is irrelevant; the FTC's guidance explicitly covers individuals as well as organisations.

What is the difference between the FACTA Disposal Rule and the FACTA Red Flags Rule?

They address different obligations. The Disposal Rule governs how you get rid of consumer report information. The Red Flags Rule requires certain financial institutions and creditors to maintain an identity theft prevention programme. Both came out of FACTA; being subject to one does not tell you whether you are subject to the other.

Are we covered if we use an outside shredding company?

You can be, but the responsibility stays with you. The rule contemplates hiring a contractor “after conducting due diligence,” and expects you to have reviewed and documented their practices. If they fail, your due diligence is what is examined.

Does the rule cover electronic records and old computers?

Yes. Consumer information is covered “in paper, electronic, or other form,” and the definition of disposal expressly includes the sale, donation or transfer of any medium on which consumer information is stored, including computer equipment.

How does the Disposal Rule interact with state law?

Many states have their own record disposal or data destruction statutes, and some are more prescriptive than the federal rule. Federal compliance does not displace them. Check your state's requirements, particularly if you operate in more than one.


This article is general guidance for facilities and compliance staff and is not legal advice. Quoted language is from 16 CFR Part 682 as published on eCFR and from FTC business guidance at ftc.gov. Verify current requirements against the primary sources and consult counsel on your specific obligations.

Back to blog