FTC Safeguards Rule Compliance for Car Dealerships
Car dealerships that arrange financing or leases are "financial institutions" under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) applies to them in full. Since June 9, 2023, a covered dealership must run a written information security program built on nine required elements, overseen by a designated Qualified Individual.
Does the FTC Safeguards Rule apply to car dealerships?
It applies to almost all of them. The Gramm-Leach-Bliley Act defines a "financial institution" as any business significantly engaged in financial activities, and arranging or leasing vehicle financing is one of those activities. The Federal Trade Commission has repeatedly confirmed that auto dealers fall under its jurisdiction for this purpose. A dealership does not need to lend its own money: routing credit applications to captive or third-party lenders is enough.
The amended rule took effect for its major new provisions on June 9, 2023. There is no grace period remaining and no phase-in left to rely on.
What does the FTC Safeguards Rule actually require?
16 CFR 314.4 sets out nine elements. A dealership's written information security program must contain all of them, sized to the dealership's complexity and the sensitivity of the customer information it holds.
| Citation | Requirement | What it means at a dealership |
|---|---|---|
| 314.4(a) | Designate a Qualified Individual | One named person accountable for the program. May be a service provider, but a senior employee must oversee them. |
| 314.4(b) | Written risk assessment | Documented assessment of threats to customer information, by department and by system, with criteria for evaluating them. |
| 314.4(c) | Design and implement safeguards | Eight named controls: access controls, data and asset inventory, encryption at rest and in transit, secure development, multi-factor authentication, disposal within two years of last use, change management, and logging of authorized user activity. |
| 314.4(d) | Regularly test and monitor | Continuous monitoring, or annual penetration testing plus vulnerability assessments every six months. |
| 314.4(e) | Security awareness training | Training for all personnel, refreshed as threats change, plus qualified security staff whose skills are kept current. |
| 314.4(f) | Oversee service providers | Vet vendors, require safeguards by contract, and periodically reassess them. |
| 314.4(g) | Evaluate and adjust | Update the program in response to testing results, business changes, and new threats. |
| 314.4(h) | Written incident response plan | A documented plan covering goals, roles, internal and external communication, remediation, and post-incident revision. |
| 314.4(i) | Annual written report | The Qualified Individual reports at least annually to the board or a senior officer on program status, risks, and incidents. |
Who should be the Qualified Individual at a dealership?
The Safeguards Rule requires a single named individual, not a committee. In practice the role lands in one of three places at a dealership: the IT director at a larger group, the CFO or controller at a single store, or an outside compliance provider acting under the direction of a designated senior employee.
The common failure is naming someone with the title but no authority. The Qualified Individual has to be able to direct remediation across departments, which means they need standing with the general manager. A part-time IT contractor who cannot compel the F&I office to change how deal jackets are stored is a nominal Qualified Individual only, and that gap will surface in an enforcement inquiry.
What has to be in the written risk assessment?
16 CFR 314.4(b) requires the risk assessment to be written, to state the criteria used to evaluate and categorise risks, to state the criteria used to assess the adequacy of existing safeguards, and to describe how identified risks will be addressed. It must be updated periodically.
At a dealership the assessment is most defensible when it is organised by department, because that is how customer nonpublic personal information actually moves. Each of these handles it differently and carries different risks:
- Sales — credit applications taken on the floor, desk logs, unattended workstations.
- F&I — the deepest concentration of NPI, plus deal jackets in physical storage.
- Service — repair orders carrying customer and sometimes payment data.
- Parts — account customers and payment records.
- Accounting — retained records, payoff information, and archived jackets.
What counts as continuous monitoring versus penetration testing?
16 CFR 314.4(d) offers two routes and a dealership must pick one. With continuous monitoring in place, there is no prescribed testing interval. Without it, the dealership owes annual penetration testing and vulnerability assessments at least twice a year, plus an assessment after any material change to operations.
Continuous monitoring here means ongoing detection of changes in the environment: new devices appearing on the network, ports opening, software drifting out of patch, and external exposure changing. Quarterly scans do not satisfy it. For most dealerships the continuous monitoring route is both cheaper and more defensible than committing to a penetration test every year plus semiannual assessments.
What does the rule require for vendors?
Dealerships run on third parties: the DMS, the CRM, the credit bureau interface, the document shredding service, the marketing agency with a copy of the customer list. 16 CFR 314.4(f) requires the dealership to take reasonable steps to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess the providers based on the risk they present.
The periodic reassessment is the part most often skipped. A signed vendor agreement from 2021 is not evidence of current oversight. What holds up is a maintained vendor inventory, a dated attestation from each vendor, and a record showing the dealership followed up when one did not respond.
Is a dealership with fewer than 5,000 consumers exempt?
Partially, and far less than the exemption is usually assumed to mean. 16 CFR 314.6 exempts a financial institution that maintains customer information concerning fewer than five thousand consumers from exactly four provisions:
| Exempted | What drops away |
|---|---|
| 314.4(b)(1) | The prescribed written form of the risk assessment, including the stated evaluation criteria. |
| 314.4(d)(2) | The annual penetration test and semiannual vulnerability assessment schedule. |
| 314.4(h) | The written incident response plan. |
| 314.4(i) | The annual written report to the board or governing body. |
Everything else still applies in full: the written information security program itself, the Qualified Individual, all eight safeguards at 314.4(c) including multi-factor authentication and encryption, security awareness training, service provider oversight, and the 30-day FTC notification duty. A small store is not exempt from the Safeguards Rule. It is exempt from four of its provisions.
The count is also larger than dealers expect. The threshold is consumers whose information the dealership maintains, not customers it sold to this year. Service customers, credit applicants who never bought, co-signers, and records retained from prior years all count. A single-rooftop store with a service drive is usually well past 5,000 once the archive is measured honestly, which is why the exception is worth testing against a real inventory before anyone relies on it.
Does every dealership employee need multi-factor authentication?
16 CFR 314.4(c)(5) requires multi-factor authentication for any individual accessing any information system, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls. Three points decide most dealership arguments about this:
- "Any individual" includes owners and managers. The most common finding in practice is an MFA rollout with an exception carved out for the people who found it inconvenient. There is no seniority exemption in the text.
- "Any information system" is broader than the DMS. Email is an information system, and dealership email routinely carries credit applications and payoff quotes. So is the CRM, the desking tool, and remote access into the network.
- The alternative has to be written down. A dealership can use something other than MFA, but only where the Qualified Individual has assessed it as reasonably equivalent or more secure and recorded that approval. An undocumented decision is not the alternative the rule permits; it is a gap with an explanation attached.
How long can a dealership keep customer information?
16 CFR 314.4(c)(6) requires customer information to be disposed of securely no later than two years after the last date the information was used in connection with providing a product or service, unless retention is necessary for business operations or another legitimate business purpose, is required by law or regulation, or targeted disposal is not reasonably feasible because of the way the information is maintained. The same provision requires periodic review of data retention policies to minimise unnecessary retention.
Dealerships almost never fail this by deleting too aggressively. They fail it by never deciding: deal jackets from a decade ago in a storage unit, terminated employees' mailboxes retained indefinitely, DMS archives nobody has scoped. Every one of those records enlarges the consumer count under 314.6, enlarges any future notification event under 314.4(j), and serves no purpose. Retention that is genuinely required — by state record-keeping rules, by a lender agreement, by litigation hold — is permitted, but the rule expects the dealership to have made that determination rather than defaulted into it.
When must a dealership report a breach to the FTC?
16 CFR 314.4(j) requires notice to the FTC as soon as possible and no later than 30 days after discovery of a notification event affecting the information of at least 500 consumers. The provision has been effective since May 13, 2024, the date set by 16 CFR 314.5. Much dealership-facing commentary cites the notification duty as "314.5"; that section does nothing but fix the effective date, and the substantive requirement is 314.4(j).
The notice is filed electronically on a form on the FTC's website and must state the reporting entity's name and contact details, the types of information involved, the date or date range of the event where it can be determined, the number of consumers affected, a general description of the event, and whether a law enforcement official has requested a delay in public disclosure. The FTC publishes the submissions, so the reputational exposure is immediate.
State breach notification statutes run in parallel and several impose shorter deadlines. The federal 30-day clock is a ceiling, not a safe harbour.
What counts as a notification event?
A notification event is the acquisition of unencrypted customer information without the authorisation of the individual it relates to. Two consequences follow that most dealerships miss.
First, encryption is the hinge. Information that was encrypted is outside the definition — unless the encryption key was also acquired, in which case the information is treated as unencrypted. This is the clearest commercial argument for encrypting deal data at rest: it is the difference between a reportable federal event and an internal one.
Second, the rule presumes acquisition. Where information was accessed without authorisation, unauthorised acquisition is presumed unless the dealership has reliable evidence showing there was no acquisition. The burden runs against the dealership, so a store with no logging of who touched which record cannot rebut the presumption and will end up reporting events it might not have had to report. That is a reporting cost created purely by the absence of the logging that 314.4(c)(8) already requires.
What happens if a dealership is not compliant?
The FTC enforces the Safeguards Rule through Section 5 of the FTC Act. Exposure comes in three forms, and the first two are usually more damaging than the fine:
- Consent orders. FTC settlements in this area routinely impose 20 years of mandated program requirements, third-party assessments, and reporting.
- Civil penalties. Assessed per violation and adjusted annually for inflation. Because each affected record and each day of continued violation can be counted separately, totals compound quickly.
- Downstream consequences. Lender and manufacturer agreements increasingly require Safeguards attestations, and cyber insurers have denied claims where the insured could not produce the written program it attested to holding.
The practical risk for most dealerships is not a surprise FTC audit. It is being asked to produce the written program — by a lender, an insurer, a manufacturer, or a plaintiff's attorney after an incident — and having nothing to hand over.
A dealership compliance checklist
Work through these in order. Each one produces a document, and the documents are the compliance record.
- Designate the Qualified Individual in writing, with the senior employee who oversees them if the role is outsourced.
- Inventory every system, device, and location holding customer NPI, including physical deal jacket storage.
- Complete the written risk assessment, organised by department, with stated evaluation criteria.
- Write the information security program itself. The rule requires it to be a written document.
- Turn on multi-factor authentication for every system holding customer information, without exception for managers.
- Confirm encryption of customer information at rest and in transit across external networks.
- Set and enforce a disposal schedule: no later than two years after last use unless a legitimate business need or law requires retention.
- Choose the testing path — continuous monitoring, or annual penetration test plus semiannual vulnerability assessments — and calendar it.
- Assign security awareness training to every employee and track completion and expiry, not just enrolment.
- Build the vendor inventory and collect dated safeguards attestations from each one.
- Write the incident response plan and identify who calls whom at 6pm on a Friday.
- Produce the annual written report to the board or owner, and keep the prior years.
How ARMP covers each requirement
ARMP was built around this specific rule, which is why the platform maps to the citation structure rather than to a generic security framework.
| Requirement | How ARMP covers it |
|---|---|
| 314.4(a) Qualified Individual | A dedicated Qualified Individual role in the platform, with permissions scoped to program oversight across every rooftop. |
| 314.4(b) Risk assessment | Generated information security program document containing a per-department risk assessment of customer NPI — Sales, F&I, Service, Parts, and Accounting — based on the on-site internal audit. |
| 314.4(c) Safeguards | GLBA compliance audits scored against the rule's controls, with findings tracked to remediation and an activity log that redacts sensitive fields. |
| 314.4(d) Testing and monitoring | Ridgeback continuous network monitoring, plus vulnerability, external IP exposure, and open port scanning with an archived, downloadable report history. |
| 314.4(e) Training | Assigned security awareness courses with quizzes, expiry dates, automatic reminders, and completion tracking by department. |
| 314.4(f) Service providers | Vendor inventory with a hosted attestation form, signature capture, automated follow-up for non-responders, and a vendor score in the compliance dashboard. |
| 314.4(g) Evaluate and adjust | Compliance scores snapshotted over time across audit, cyber, documentation, training, and vendor pillars, with overdue remediations surfaced. |
| 314.4(h) Incident response plan | Incident response and NPI breach response sections maintained inside the information security program document. |
| 314.4(i) Annual report | Annual report to the board or equivalent produced from the platform's own audit and remediation record. |
Primary sources
Frequently asked questions
Does the FTC Safeguards Rule apply to a dealership that never finances in-house?
Usually yes. The trigger is arranging or brokering financing and leases, not carrying the paper. A dealership that routinely sends credit applications to lenders is "significantly engaged" in a financial activity and is a financial institution under the Gramm-Leach-Bliley Act. A store that only takes cash and never touches a credit application has a genuine argument that it is out of scope, but that is a rare fact pattern in retail automotive.
Can a dealership outsource the Qualified Individual role?
Yes. 16 CFR 314.4(a) permits the Qualified Individual to be employed by an affiliate or a service provider. Two conditions come with it: the dealership must keep responsibility for compliance, and it must designate a senior member of its own personnel to direct and oversee that outside Qualified Individual. Outsourcing the work does not outsource the liability.
Is there a small-dealer exemption?
A partial one. A financial institution that maintains customer information on fewer than 5,000 consumers is exempt from four requirements: the written risk assessment, the continuous monitoring or penetration testing and vulnerability assessment requirement, the written incident response plan, and the annual written report to the board. Every other element still applies. Most franchised and mid-sized independent dealerships hold records on far more than 5,000 consumers once historical customers are counted, so the exemption rarely helps.
How often does a dealership have to do vulnerability assessments?
It depends on which path is chosen under 16 CFR 314.4(d). A dealership running continuous monitoring of its systems has no fixed testing cadence. A dealership without continuous monitoring must complete annual penetration testing and vulnerability assessments at least every six months, plus additional assessments whenever there is a material change to operations or business arrangements.
When does a dealership have to notify the FTC about a data breach?
16 CFR 314.4(j) requires notice to the FTC as soon as possible and no later than 30 days after discovering a notification event involving the unencrypted customer information of at least 500 consumers. The provision has been effective since May 13, 2024, the date set by 16 CFR 314.5, which does nothing else. Notice is filed on a form on the FTC website, and the FTC publishes the entries in a public database. State breach notification laws apply separately and often carry shorter deadlines.
What is the difference between an ISP and the Safeguards Rule?
The Safeguards Rule is the regulation. The information security program, or ISP, is the written document and set of practices a dealership builds to satisfy it. The rule tells a dealership what its ISP must contain; it does not supply the ISP. A dealership that has bought security tools but never written and maintained the program document is not compliant, because 16 CFR 314.3 requires the program itself to be written.