The FTC Safeguards Rule requires most automobile dealers that arrange financing or lease vehicles to build and maintain a written information security program protecting customer information. If your store arranges financing, you are covered — the FTC classifies you as a financial institution under the Gramm-Leach-Bliley Act, and the Rule specifies nine elements your program must contain.
This guide covers who is covered, the nine required elements, the breach reporting threshold, and where dealership programs most often fall apart in practice.
This is an operational summary, not legal advice. The Safeguards Rule is enforced by the FTC and its application depends on your specific circumstances. Work with counsel who knows dealership compliance before making decisions based on any summary, including this one. Primary sources are linked throughout.
Does the FTC Safeguards Rule apply to my dealership?
Almost certainly, if you arrange financing or lease vehicles.
The Rule implements the Gramm-Leach-Bliley Act and applies to financial institutions under FTC authority — a category that explicitly includes most automobile dealers who finance or lease automobiles. The FTC publishes FAQs specifically for auto dealers, which is a reasonable signal of how squarely the industry sits inside the Rule's scope.
Two points dealers frequently get wrong:
Arranging financing counts, even when you do not lend. Brokering or arranging financing creates a continuing relationship, which makes that person your customer for these purposes.
A completed application is not required. The related Privacy Rule applies even when you collect personal information in connection with potential financing or leasing and the person never fills out a formal application. A credit pull on a shopper who walks is still customer information.
Is there a small-dealer exemption?
Partial, and narrower than it sounds. Financial institutions maintaining customer information on fewer than 5,000 consumers are exempt from certain provisions — not from the Rule.
Count carefully before relying on it. The threshold counts consumers whose information you maintain, which includes historical records, not just this year's buyers. A store that has been open a decade crosses 5,000 quickly.
What are the nine required elements?
Section 314.4 of the Rule specifies what the program must contain. In the FTC's own framing:
| # | Element | What it means for a store |
|---|---|---|
| 1 | Designate a Qualified Individual | One named person accountable for the program |
| 2 | Conduct a written risk assessment | Documented, identifying foreseeable threats |
| 3 | Design and implement safeguards | Access controls, encryption, MFA, secure disposal |
| 4 | Monitor and test effectiveness | Continuous monitoring, or annual penetration testing |
| 5 | Train staff on security awareness | With regular refreshers, not one-time onboarding |
| 6 | Monitor service providers | Contracts plus periodic reassessment |
| 7 | Keep the program current | Periodic modification as circumstances change |
| 8 | Written incident response plan | Goals, processes, roles, communications, post-incident review |
| 9 | Annual report to the Board | Delivered by the Qualified Individual |
The Qualified Individual, specifically
This role causes more confusion than the other eight elements combined.
- No specific degree, title or certification is required. The FTC's standard is real-world know-how suited to your circumstances.
- It can be an employee, an affiliate, or a service provider. Outsourcing to an MSP or compliance vendor is permitted.
- You remain responsible either way. Senior company oversight is mandatory regardless of who holds the title — you cannot contract away accountability.
The common failure is naming someone on paper who has neither the authority nor the time to actually run the program.
What has to be reported, and when?
The 2023 amendment added a breach notification requirement with a hard clock.
You must notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event involving unauthorized acquisition of unencrypted customer information of at least 500 consumers.
Three things worth internalizing:
- The clock starts at discovery, not at resolution, and not when you finish investigating.
- Encryption matters to the threshold. The requirement is keyed to unencrypted information — which is a concrete reason element three is not optional.
- Thirty days is not much if you have no incident response plan. Which is exactly why element eight exists.
Where dealership programs actually fall short
The Rule is not technically difficult. The gaps are almost always organizational.
Vendor access nobody has inventoried
Element six requires monitoring service providers. A typical store grants DMS or customer-data access to a CRM, a website provider, a marketing vendor, a service scheduler, an F&I product administrator, a reputation tool and an IT contractor — each with its own credentials and its own retention of your customer data.
Most stores cannot produce that list on request. If you cannot list who has access, you cannot monitor them, and element six is unmet by definition.
MFA that covers the office but not the vendors
Multi-factor authentication is called out explicitly in element three. Stores often deploy it on email and the DMS, then leave it off the third-party tools that hold the same customer information.
A risk assessment that was never written down
Element two says written. A conversation about risks is not a risk assessment. Neither is a vendor's marketing PDF.
Training that happened once
Element five requires regular refreshers. Onboarding-only training does not satisfy it, and in a business with dealership-level turnover, it decays fast.
No incident response plan until there is an incident
Element eight requires the plan in writing, in advance, with named roles. Writing it during a breach while a 30-day clock runs is the scenario the requirement exists to prevent.
Credentials shared between people
Shared logins make access control and audit trails impossible. They also tend to be the thing that turns a small incident into an unbounded one, because nobody can establish who did what.
A practical sequence for a store starting from zero
- Name the Qualified Individual and give them actual authority and time.
- Inventory your data: what customer information you hold, where it lives, who can reach it — DMS, CRM, email, paper deal jackets, third-party tools.
- Inventory your vendors and what each can access. This feeds elements two, three and six at once.
- Write the risk assessment. It does not need to be elaborate; it needs to exist and be honest.
- Close the obvious gaps: MFA everywhere customer data lives, encryption in transit and at rest, individual credentials, and disposal procedures.
- Write the incident response plan with named roles and the 30-day reporting obligation built in.
- Schedule the recurring work: training with refreshers, vendor reassessment, testing, and the annual board report.
Steps two and three are the ones stores skip, and they are the ones that make the rest possible.
Frequently asked questions
Does the FTC Safeguards Rule apply to independent used car dealers?
If the dealer arranges financing or leases vehicles, yes. The Rule covers most automobile dealers that finance or lease, regardless of franchise status. A cash-only dealer that never arranges financing has a different analysis, and that is a question for counsel.
Who can be the Qualified Individual at a dealership?
An employee, an affiliate, or an outside service provider. No specific certification or degree is required — the standard is real-world know-how suited to your circumstances. Senior company oversight remains mandatory regardless of who holds the role.
What is the threshold for reporting a breach to the FTC?
A notification event involving unauthorized acquisition of unencrypted customer information of at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery.
Are small dealerships exempt from the Safeguards Rule?
Financial institutions maintaining customer information on fewer than 5,000 consumers are exempt from certain provisions, not from the Rule itself. Count historical records, not just current-year customers — most established stores exceed the threshold.
Does the Safeguards Rule require multi-factor authentication?
Yes. MFA is named among the safeguards in element three, for individuals accessing systems containing customer information. That includes third-party systems holding your customer data, not only systems you host.
Do my vendors' security failures become my problem?
Element six requires you to select and retain service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically reassess them. Your obligation to oversee them does not transfer to them.
How often does the risk assessment need to be updated?
The Rule requires keeping the program current through periodic modification as circumstances change — including material changes to your operations, systems or vendors. Many stores review annually alongside the board report, and after any significant system change.
Is a vendor's compliance certificate enough to satisfy the Rule?
No. A vendor attestation can support element six, but it does not substitute for your own written risk assessment, your own safeguards, or your own program. The obligations sit with the dealership.
Conclusion
- If you arrange financing or lease, you are covered. The FTC publishes dealer-specific guidance for a reason.
- Nine elements, all required — the written risk assessment, the incident response plan and the annual board report are the ones most often missing.
- Thirty days from discovery to report a breach affecting 500+ consumers' unencrypted information.
- Vendor access is the common gap. Element six is unmet the moment you cannot list who has access to customer data.
- The Qualified Individual must be real. A name on a document with no authority satisfies nobody.
Start with the two inventories — your data and your vendors. Everything else in the Rule becomes tractable once you know what you hold and who can reach it.
Primary sources: FTC Safeguards Rule guidance · Automobile Dealers and the FTC's Safeguards Rule FAQs
Last updated: