The FTC Safeguards Rule for Auto Dealers: What Your Dealership Must Have in Place

When it comes to the FTC Safeguards Rule auto dealers must follow, the bottom line is simple. If your dealership arranges financing or leasing, the federal government considers you a financial institution. That classification brings real obligations.
The FTC Safeguards Rule (16 CFR Part 314) requires non-bank financial institutions under FTC jurisdiction to develop, implement, and maintain a comprehensive written information security program. Its sole purpose is protecting customer information. This is not an optional guideline or a generic best practice; it is a federal mandate with severe consequences for noncompliance.
The FTC amended the Safeguards Rule in 2021, and the key prescriptive provisions became mandatory on June 9, 2023. That deadline forced many dealerships to completely overhaul how they handle it and cybersecurity. A breach-notification requirement took effect later, creating even tighter reporting timelines for dealership owners.
This guide covers: why the FTC targets auto dealers, how the nine required security elements apply to your showroom floor, and what happens if your systems are breached.
Key Takeaways
- If your dealership arranges financing or leasing, the FTC considers you a financial institution, and the Safeguards Rule (16 CFR Part 314) applies to you.
- Compliance means a comprehensive written information security program (WISP) built on nine required elements, including a designated Qualified Individual, a written risk assessment, encryption, and multi-factor authentication.
- The key prescriptive provisions became mandatory on June 9, 2023, and the breach-notification requirement took effect May 13, 2024.
- A security event involving the unencrypted information of 500 or more consumers must be reported to the FTC within 30 days of discovery.
- The Rule is enforced directly by the federal government, which can bring enforcement actions, impose consent orders, and seek civil penalties.

If Your Dealership Arranges Financing, You Are a Covered Financial Institution
The Gramm-Leach-Bliley Act (GLBA) is a 1999 US federal law requiring financial institutions to explain how they share and protect their customers’ nonpublic personal information. The Privacy Rule handles the privacy-notice piece of this law. The FTC Safeguards Rule implements the data-security piece for non-bank businesses.
The Rule covers non-bank financial institutions as the FTC defines them, which surprises many business owners. Covered entities include:
- Auto dealers that arrange financing or leasing
- Mortgage brokers
- Non-bank lenders
- Payday and consumer lenders
- Finance companies
- Tax preparation firms
- Accountants and CPA firms
- Debt collectors
- Check cashers
- Wire transferors
- Investment advisers not required to register with the SEC
- Real estate settlement services
- Colleges or universities participating in federal student aid
The rule of thumb: if your business is significantly engaged in providing financial products or services to consumers, assume you are covered until proven otherwise. For car dealerships, arranging a lease or a loan through a third-party lender places you firmly under FTC jurisdiction.
Why Dealerships Face Strict Safeguards Rule Requirements
Dealership customer financial data protection is a primary focus for federal regulators. The reason is straightforward: the sheer volume of sensitive information passing through your Finance and Insurance (F&I) office dwarfs what most businesses ever handle.
Your dealership collects credit applications, Social Security numbers, income verification documents, and detailed financing records. In the eyes of identity thieves and cybercriminals, your dealership holds the exact same highly valuable data as a traditional bank. Yet dealerships have historically invested far less in cybersecurity for car dealerships than major banks invest in their own security.
This is the gap the FTC is closing. The high value of the data meets the historically loose security on the showroom floor. Consumer data is only as secure as the weakest link in the financing chain, and the FTC recognized that dealerships were that weak link. That is exactly why GLBA Safeguards Rule motor vehicle dealers requirements are now strictly enforced.
The F&I data journey through a dealership: A customer hands over their credit application, Social Security number, and income documents at your sales desk. That data flows into your DMS, CRM, and F&I software — and from there it is accessed by sales staff, F&I managers, the service drive, third-party lenders, your DMS vendor, and your offsite backup. Each of those touchpoints is an attack surface the Safeguards Rule requires you to lock down.
The Nine Elements: A Dealership Compliance Matrix
Section 314.4 of the amended rule requires nine specific elements to achieve compliance. Meeting these dealership cybersecurity program requirements means translating federal regulatory text into actual it controls for your showroom, service drive, and F&I office.
The core deliverable of this entire process is your WISP. The written information security program auto dealer operators must create is a written document describing how the business protects customer information. It is built on a written risk assessment and covers all required safeguards, testing, training, vendor oversight, and incident response protocols.
Here is how the nine elements apply to your dealership operations. You can also review the full nine-element checklist for additional technical details.
| Element | What it Means | Dealership-Specific Action | Who Is Responsible |
|---|---|---|---|
| 1. Designated Qualified Individual | A single named person implements and supervises your information security program. | Designate one person — an employee or a person at an affiliate or service provider. Many SMBs designate a role supported by their MSP. | Dealership ownership (legal responsibility is non-delegable). |
| 2. Written Risk Assessment | A formal, documented assessment of foreseeable internal and external risks to customer information. | Document every risk to the security, confidentiality, and integrity of customer data. This cannot be a verbal conversation or a quick guess. | Qualified Individual, with it/MSP support. |
| 3. Technical Safeguards | Specific controls to mitigate identified risks: access controls, data inventory, encryption, MFA, secure disposal, and monitoring. | Eliminate shared logins at the sales desk. Encrypt customer information at rest and in transit. Apply MFA to every system holding customer data, unless the QI approves an equivalent control in writing. Inventory every location where customer data lives. Log and monitor authorized user activity. | IT provider or internal it, overseen by QI. |
| 4. Regular Testing | Continuously monitor or conduct annual penetration testing plus vulnerability assessments every six months. | Deploy continuous monitoring of systems and key controls. If you do not use continuous monitoring, schedule penetration tests and twice-yearly vulnerability scans. | IT provider or external security assessor. |
| 5. Staff Security Training | Train all staff on security awareness; provide specialized training for personnel running the security program. | Run regular phishing simulations and security-awareness sessions. F&I staff need role-specific training on handling customer PII. | QI or MSP, with management enforcement. |
| 6. Service Provider Oversight | Oversee third-party vendors by contract and assessment. | Review your DMS, CRM, and F&I software vendors. Ensure each contract requires appropriate safeguards and the right to assess their security. | QI and dealership management. |
| 7. Keep the Program Current | Evolve your WISP as your business, threats, or vendor stack change. | Review when you add software, change processes, or after any security incident. Schedule at least an annual refresh. | QI. |
| 8. Written Incident Response Plan | A documented plan for ransomware, data breach, or system compromise. | Write the plan, assign roles for recovery and communication, and test it with a tabletop exercise at least annually. | QI with management sign-off. |
| 9. Annual Leadership Report | QI must report in writing to the board or senior leadership at least annually. | Produce a written report covering the overall status of the information security program and Safeguards Rule compliance. | Qualified Individual. |
How to Evaluate Dealership Software and Fintech Vendors for Compliance
Google already surfaces this page for queries like “evaluate fintech company X for FTC Safeguards Rule compliance” — which means dealership owners are actively searching for help vetting their vendor stack. Here is how to think about it.
The nine-element framework above doubles as your vendor evaluation checklist. When a DMS provider, F&I platform, or credit-application processor tells you they are “compliant,” ask them to show you how they satisfy each element as it applies to the data you share with them:
- Access controls: Do they enforce unique user accounts and role-based access, or do their systems allow shared logins?
- Encryption: Do they encrypt your customer data at rest in their cloud and in transit to your dealership?
- MFA: Do they require multi-factor authentication for every user accessing their platform?
- Monitoring and logging: Can they produce logs of who accessed your customer data and when?
- Incident response: What happens when they are breached? Do they commit to notifying you within 24 hours?
The three layers every dealership needs to understand:
- Compliance-management platforms help document and track the nine elements, generate the annual report, and maintain audit trails. They organize the paperwork. They do not implement the technical controls.
- Your existing DMS / CRM / F&I tools (the platforms your dealership runs on) store and process customer data, so each one must satisfy the technical safeguard requirements in element 3.
- The it and security layer (MFA enforcement, encryption, endpoint monitoring, network segmentation, and incident response) is what actually satisfies the Rule’s technical mandates. This is typically implemented by an internal IT team or an MSP.
One thing no vendor can sell you: the liability transfer. No DMS contract, fintech SLA, or compliance-platform subscription removes your dealership’s legal responsibility under the Safeguards Rule. The dealership always owns the obligation. Choose vendors that make your compliance demonstrable, not vendors that claim to make it their problem.
You can also review the full nine-element checklist for a deeper dive on each element.
The FTC Data Breach Notification Clock
The FTC data breach notification auto dealers must follow adds a strict timeline to security incidents. It caps a series of compliance dates every dealership owner should have on the calendar. Here are the key dates in one place.
| Date | Milestone |
|---|---|
| 2021 | The FTC amends the Safeguards Rule with its key prescriptive provisions |
| June 9, 2023 | The prescriptive provisions become mandatory for covered businesses, including auto dealers |
| May 13, 2024 | The breach-notification requirement takes effect |
| Within 30 days of discovery | Deadline to notify the FTC of a security event involving the unencrypted information of 500 or more consumers |
The 30-day clock starts ticking the moment you realize a breach has occurred. Rapid incident response and accurate logging are not optional extras — they are the difference between a contained event and an FTC enforcement action.
Unlike PCI DSS requirements, which are contractually enforced by card brands and acquiring banks rather than by any government agency, the Safeguards Rule is enforced directly by the federal government. The FTC can investigate your dealership and bring enforcement actions. Those actions can saddle your business with consent orders requiring years of strict, costly oversight. The FTC can also seek civil penalties for violations. The financial and reputational damage of an FTC investigation can threaten a dealership’s survival.
See Where You Stand
Take our free 2-minute Safeguards Rule self-check to answer 8 plain-English questions, discover your risk level, and identify the gaps you need to fix with no sign-up required to see your result. free FTC Safeguards Rule checklist
Related Guides
- What Is the Gramm-Leach-Bliley Act (GLBA)? Plain English
- GLBA / FTC Safeguards Rule Requirements: The 9 Elements
- GLBA Compliance: Who it Covers and What it Requires
- What Is the FTC Safeguards Rule? Who it Covers, What Changed
Frequently Asked Questions
What are the requirements for the FTC safeguards rule?
The rule requires covered financial institutions to develop and maintain a comprehensive written information security program. You must designate a Qualified Individual, conduct written risk assessments, and implement specific technical controls like encryption and multi-factor authentication. You are also required to oversee your service providers and maintain a written incident response plan.
What is the customer safeguard rule?
The FTC Safeguards Rule is a federal regulation that implements the data-security requirements of the Gramm-Leach-Bliley Act. It mandates that non-bank financial institutions protect consumer financial information through strict technical and administrative cybersecurity controls. The rule is enforced directly by the federal government to prevent data breaches and identity theft.
What does the FTC safeguards rule require all tax preparers to do?
Because the rule covers all non-bank financial institutions, tax preparers face the exact same compliance requirements as auto dealers and mortgage brokers. They must implement a written information security program, use multi-factor authentication, and encrypt customer data. They are also subject to the same breach notification rules requiring them to report incidents involving 500 or more consumers within 30 days.
Is WISP mandatory for tax preparers?
Yes. A written information security program is mandatory for tax preparers, auto dealers, and any other business classified as a non-bank financial institution under FTC jurisdiction. This written document serves as the core deliverable proving your compliance with the Safeguards Rule.
Get Help With Dealership Cybersecurity
LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses since 2010. We serve roughly 200 organizations and 2,500+ users from our offices in Woodstock and Manteno. We help you become and stay compliant by implementing and operating the technical safeguards the Rule requires, including MFA, encryption, continuous monitoring, and incident response, and we can serve as or support your Qualified Individual role.
Learn more about LeadingIT’s FTC Safeguards compliance services, book a call to discuss your dealership’s needs, or contact us directly at 815-788-6041.
