FTC Safeguards Rule Compliance for Car Dealerships
Car dealerships that arrange financing or leases are "financial institutions" under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) applies to them in full. Since June 9, 2023, a covered dealership must run a written information security program built on nine required elements, overseen by a designated Qualified Individual.
Does the FTC Safeguards Rule apply to car dealerships?
It applies to almost all of them. The Gramm-Leach-Bliley Act defines a "financial institution" as any business significantly engaged in financial activities, and arranging or leasing vehicle financing is one of those activities. The Federal Trade Commission has repeatedly confirmed that auto dealers fall under its jurisdiction for this purpose. A dealership does not need to lend its own money: routing credit applications to captive or third-party lenders is enough.
The amended rule took effect for its major new provisions on June 9, 2023. There is no grace period remaining and no phase-in left to rely on.
What does the FTC Safeguards Rule actually require?
16 CFR 314.4 sets out nine elements. A dealership's written information security program must contain all of them, sized to the dealership's complexity and the sensitivity of the customer information it holds.
| Citation | Requirement | What it means at a dealership |
|---|---|---|
| 314.4(a) | Designate a Qualified Individual | One named person accountable for the program. May be a service provider, but a senior employee must oversee them. |
| 314.4(b) | Written risk assessment | Documented assessment of threats to customer information, by department and by system, with criteria for evaluating them. |
| 314.4(c) | Design and implement safeguards | Eight named controls: access controls, data and asset inventory, encryption at rest and in transit, secure development, multi-factor authentication, disposal within two years of last use, change management, and logging of authorized user activity. |
| 314.4(d) | Regularly test and monitor | Continuous monitoring, or annual penetration testing plus vulnerability assessments every six months. |
| 314.4(e) | Security awareness training | Training for all personnel, refreshed as threats change, plus qualified security staff whose skills are kept current. |
| 314.4(f) | Oversee service providers | Vet vendors, require safeguards by contract, and periodically reassess them. |
| 314.4(g) | Evaluate and adjust | Update the program in response to testing results, business changes, and new threats. |
| 314.4(h) | Written incident response plan | A documented plan covering goals, roles, internal and external communication, remediation, and post-incident revision. |
| 314.4(i) | Annual written report | The Qualified Individual reports at least annually to the board or a senior officer on program status, risks, and incidents. |
Who should be the Qualified Individual at a dealership?
The Safeguards Rule requires a single named individual, not a committee. In practice the role lands in one of three places at a dealership: the IT director at a larger group, the CFO or controller at a single store, or an outside compliance provider acting under the direction of a designated senior employee.
The common failure is naming someone with the title but no authority. The Qualified Individual has to be able to direct remediation across departments, which means they need standing with the general manager. A part-time IT contractor who cannot compel the F&I office to change how deal jackets are stored is a nominal Qualified Individual only, and that gap will surface in an enforcement inquiry.
What has to be in the written risk assessment?
16 CFR 314.4(b) requires the risk assessment to be written, to state the criteria used to evaluate and categorise risks, to state the criteria used to assess the adequacy of existing safeguards, and to describe how identified risks will be addressed. It must be updated periodically.
At a dealership the assessment is most defensible when it is organised by department, because that is how customer nonpublic personal information actually moves. Each of these handles it differently and carries different risks:
- Sales — credit applications taken on the floor, desk logs, unattended workstations.
- F&I — the deepest concentration of NPI, plus deal jackets in physical storage.
- Service — repair orders carrying customer and sometimes payment data.
- Parts — account customers and payment records.
- Accounting — retained records, payoff information, and archived jackets.
What counts as continuous monitoring versus penetration testing?
16 CFR 314.4(d) offers two routes and a dealership must pick one. With continuous monitoring in place, there is no prescribed testing interval. Without it, the dealership owes annual penetration testing and vulnerability assessments at least twice a year, plus an assessment after any material change to operations.
Continuous monitoring here means ongoing detection of changes in the environment: new devices appearing on the network, ports opening, software drifting out of patch, and external exposure changing. Quarterly scans do not satisfy it. For most dealerships the continuous monitoring route is both cheaper and more defensible than committing to a penetration test every year plus semiannual assessments.
What does the rule require for vendors?
Dealerships run on third parties: the DMS, the CRM, the credit bureau interface, the document shredding service, the marketing agency with a copy of the customer list. 16 CFR 314.4(f) requires the dealership to take reasonable steps to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess the providers based on the risk they present.
The periodic reassessment is the part most often skipped. A signed vendor agreement from 2021 is not evidence of current oversight. What holds up is a maintained vendor inventory, a dated attestation from each vendor, and a record showing the dealership followed up when one did not respond.
When must a dealership report a breach to the FTC?
Since May 13, 2024, 16 CFR 314.5 requires notice to the FTC as soon as possible and no later than 30 days after discovery of a notification event affecting the unencrypted customer information of 500 or more consumers. Notice is filed through the FTC's online form and the FTC publishes the submissions in a public database, so the reputational exposure is immediate.
State breach notification statutes run in parallel and several impose shorter deadlines. The federal 30-day clock is a ceiling, not a safe harbour.
What happens if a dealership is not compliant?
The FTC enforces the Safeguards Rule through Section 5 of the FTC Act. Exposure comes in three forms, and the first two are usually more damaging than the fine:
- Consent orders. FTC settlements in this area routinely impose 20 years of mandated program requirements, third-party assessments, and reporting.
- Civil penalties. Assessed per violation and adjusted annually for inflation. Because each affected record and each day of continued violation can be counted separately, totals compound quickly.
- Downstream consequences. Lender and manufacturer agreements increasingly require Safeguards attestations, and cyber insurers have denied claims where the insured could not produce the written program it attested to holding.
The practical risk for most dealerships is not a surprise FTC audit. It is being asked to produce the written program — by a lender, an insurer, a manufacturer, or a plaintiff's attorney after an incident — and having nothing to hand over.
A dealership compliance checklist
Work through these in order. Each one produces a document, and the documents are the compliance record.
- Designate the Qualified Individual in writing, with the senior employee who oversees them if the role is outsourced.
- Inventory every system, device, and location holding customer NPI, including physical deal jacket storage.
- Complete the written risk assessment, organised by department, with stated evaluation criteria.
- Write the information security program itself. The rule requires it to be a written document.
- Turn on multi-factor authentication for every system holding customer information, without exception for managers.
- Confirm encryption of customer information at rest and in transit across external networks.
- Set and enforce a disposal schedule: no later than two years after last use unless a legitimate business need or law requires retention.
- Choose the testing path — continuous monitoring, or annual penetration test plus semiannual vulnerability assessments — and calendar it.
- Assign security awareness training to every employee and track completion and expiry, not just enrolment.
- Build the vendor inventory and collect dated safeguards attestations from each one.
- Write the incident response plan and identify who calls whom at 6pm on a Friday.
- Produce the annual written report to the board or owner, and keep the prior years.
How ARMP covers each requirement
ARMP was built around this specific rule, which is why the platform maps to the citation structure rather than to a generic security framework.
| Requirement | How ARMP covers it |
|---|---|
| 314.4(a) Qualified Individual | A dedicated Qualified Individual role in the platform, with permissions scoped to program oversight across every rooftop. |
| 314.4(b) Risk assessment | Generated information security program document containing a per-department risk assessment of customer NPI — Sales, F&I, Service, Parts, and Accounting — based on the on-site internal audit. |
| 314.4(c) Safeguards | GLBA compliance audits scored against the rule's controls, with findings tracked to remediation and an activity log that redacts sensitive fields. |
| 314.4(d) Testing and monitoring | Ridgeback continuous network monitoring, plus vulnerability, external IP exposure, and open port scanning with an archived, downloadable report history. |
| 314.4(e) Training | Assigned security awareness courses with quizzes, expiry dates, automatic reminders, and completion tracking by department. |
| 314.4(f) Service providers | Vendor inventory with a hosted attestation form, signature capture, automated follow-up for non-responders, and a vendor score in the compliance dashboard. |
| 314.4(g) Evaluate and adjust | Compliance scores snapshotted over time across audit, cyber, documentation, training, and vendor pillars, with overdue remediations surfaced. |
| 314.4(h) Incident response plan | Incident response and NPI breach response sections maintained inside the information security program document. |
| 314.4(i) Annual report | Annual report to the board or equivalent produced from the platform's own audit and remediation record. |
Primary sources
Frequently asked questions
Does the FTC Safeguards Rule apply to a dealership that never finances in-house?
Usually yes. The trigger is arranging or brokering financing and leases, not carrying the paper. A dealership that routinely sends credit applications to lenders is "significantly engaged" in a financial activity and is a financial institution under the Gramm-Leach-Bliley Act. A store that only takes cash and never touches a credit application has a genuine argument that it is out of scope, but that is a rare fact pattern in retail automotive.
Can a dealership outsource the Qualified Individual role?
Yes. 16 CFR 314.4(a) permits the Qualified Individual to be employed by an affiliate or a service provider. Two conditions come with it: the dealership must keep responsibility for compliance, and it must designate a senior member of its own personnel to direct and oversee that outside Qualified Individual. Outsourcing the work does not outsource the liability.
Is there a small-dealer exemption?
A partial one. A financial institution that maintains customer information on fewer than 5,000 consumers is exempt from four requirements: the written risk assessment, the continuous monitoring or penetration testing and vulnerability assessment requirement, the written incident response plan, and the annual written report to the board. Every other element still applies. Most franchised and mid-sized independent dealerships hold records on far more than 5,000 consumers once historical customers are counted, so the exemption rarely helps.
How often does a dealership have to do vulnerability assessments?
It depends on which path is chosen under 16 CFR 314.4(d). A dealership running continuous monitoring of its systems has no fixed testing cadence. A dealership without continuous monitoring must complete annual penetration testing and vulnerability assessments at least every six months, plus additional assessments whenever there is a material change to operations or business arrangements.
When does a dealership have to notify the FTC about a data breach?
Since May 13, 2024, 16 CFR 314.5 requires notice to the FTC as soon as possible and no later than 30 days after discovering a notification event involving the unencrypted customer information of 500 or more consumers. Notice is filed through the FTC online form, and the FTC publishes the entries in a public database. State breach notification laws apply separately and often carry shorter deadlines.
What is the difference between an ISP and the Safeguards Rule?
The Safeguards Rule is the regulation. The information security program, or ISP, is the written document and set of practices a dealership builds to satisfy it. The rule tells a dealership what its ISP must contain; it does not supply the ISP. A dealership that has bought security tools but never written and maintained the program document is not compliant, because 16 CFR 314.3 requires the program itself to be written.