Recommended Free Tools
Protect borrower data by treating the entire mortgage workflow—not just the lender’s loan-origination system—as the security boundary. Inventory the information collected and where it moves, limit and review access, encrypt it in transit and at rest, assess every application and service provider, use multifactor authentication, and set retention and incident-response rules. The exact legal duties depend on the institution’s regulator, role, applicable laws, and contracts.
What borrower information should a mortgage lender protect?
Mortgage application details are sensitive financial information. Under the FTC’s GLBA Privacy Rule guidance, nonpublic personal information (NPI) includes information a consumer provides to obtain a financial product, such as a name, address, income, or Social Security number, as well as transactional and service-related information.
That means the protection boundary should follow information through intake, origination, settlement, and servicing—not stop at the point where an application is submitted. The CFPB’s Regulation X overview describes these mortgage stages, where information can pass among borrowers, lender staff, brokers, settlement providers, servicers, software, and other vendors.
How do I protect borrower data when automating mortgage workflows?
1. Map data, systems, people, and vendors
For each workflow step, record the fields and documents collected, where they are stored, which employees and service-provider accounts can access them, which systems exchange them, and when the information may be deleted. The FTC’s Safeguards Rule business guidance calls for an inventory of the information ecosystem. Include automated integrations, document platforms, and applications that store, access, or transmit customer information.
#1 Best Overall
- Hardware encrypted drive
- Simple to use pin access. RPM-5400
- Administrator password feature
- Bus powered
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
2. Restrict access and review it regularly
Give each employee and vendor account only the access needed for its role. Review permissions periodically, remove access when the need ends, and account for access paths created by automated workflows. The FTC identifies access controls and recurring review as elements of a covered company’s security program.
3. Encrypt data and assess every application in the path
Use encryption for customer information both in storage and while it is transmitted. Assess applications used to store, access, or transmit that information, including third-party applications. Automation can connect systems that were previously separate, so assess the actual data path and the protections of the services that handle it rather than relying only on the security of the lender’s own platform.
Rank #2
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
- Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
- Software Free Design - With no admin rights needed
- Sealed from Physical Attacks by Tough Epoxy Coating
- Brute Force Self Destruct Feature
4. Require multifactor authentication
The FTC describes multifactor authentication (MFA) as using at least two different factor types: something a person knows, has, or is. Its guidance allows an equivalent control instead only when the exception is supported by a written approval. Choose an implementation that works with the institution’s identity platform and account-recovery process, can be centrally enrolled and revoked, is usable for employees and vendors, and can be audited under the institution’s written risk assessment and policy.
A FIDO2 security key can be one possession factor, but no individual device is a complete security program or a compliance shortcut. Evaluate the complete authentication and recovery setup.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
5. Set retention and secure-disposal rules
The FTC guidance says covered companies must securely dispose of customer information no later than two years after its most recent use to serve the customer, subject to exceptions for legitimate business or legal retention needs and when targeted disposal is infeasible. Apply the full rule and any other applicable record-retention duties before deletion; a workflow’s technical ability to erase a file does not by itself establish that deletion is permitted.
6. Control disclosures and automated sharing
Before automating a disclosure, verify its purpose, the applicable law, the relevant contract, and any required borrower consent. Under the Fannie Mae Selling Guide confidentiality provisions, a seller/servicer generally must obtain borrower authorization to disclose NPI unless applicable law permits disclosure. The guide also addresses safeguards and secure destruction. These requirements apply through the relevant Fannie Mae relationship; they are not a universal rule for every mortgage business.
Rank #4
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
What security-program and contract duties apply?
For entities covered by the FTC Safeguards Rule, the program must be written and risk-appropriate to the organization’s size, complexity, activities, and the sensitivity of the information. The FTC identifies administrative, technical, and physical safeguards, including the controls described above. Its guidance also says the Rule covers customer information belonging to other financial institutions when a covered company handles or maintains it. Outsourcing a workflow therefore does not, by itself, remove the need to account for the information and provider access.
Coverage and legal obligations vary by entity and regulator. GLBA privacy duties and Safeguards Rule coverage are not identical for every institution. Fannie Mae requirements attach to the relevant seller/servicer relationship, and other laws, regulators’ rules, state privacy and breach-notification laws, and lender-specific contracts may also apply. Fannie Mae’s applicable-law guidance addresses borrower privacy as part of compliance. Determine which provisions apply to the institution and each workflow rather than treating a single checklist as a legal determination.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →How should mortgage teams prepare for an incident?
Include automated workflows and service providers in the incident-response plan. Define how to identify and escalate a suspected exposure, preserve relevant records, determine which information and systems were affected, and assess notification duties under applicable law and contracts.
Some Fannie Mae business partners subject to its Information Security and Business Resiliency Supplement must report covered cybersecurity incidents to Fannie Mae within 36 hours after identification. The requirement is limited to partners and incidents covered by the Supplement; it is not a universal statutory breach-notification deadline. Check the Supplement’s applicability categories and current terms against the organization’s relationship and obligations.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




