The FTC Safeguards Rule for Auto Dealers
If your dealership finances, arranges financing, or leases vehicles for longer than 90 days, federal law treats you as a financial institution — and requires a written information security program with nine specific elements. Here is what the rule actually says, including the part most vendor summaries get wrong.
Key takeaways
- Dealers who finance, facilitate financing, or lease vehicles for longer than 90 days are financial institutions under the Safeguards Rule, regardless of how they describe themselves
- The rule requires a written information security program built on nine elements in 16 CFR 314.4, including MFA and encryption at rest and in transit
- Customer information must be securely disposed of no later than two years after your most recent use of it to serve that customer
- A breach involving unauthorized acquisition of 500 or more consumers' unencrypted information must be reported to the FTC within 30 days of discovery
- The under-5,000-consumer exception is narrower than commonly claimed: it excuses four specific provisions, and designating a Qualified Individual is not one of them
Disclaimer: This page is a general introduction to the FTC Safeguards Rule for dealership operators. It is not legal or information-security advice. Consult the FTC's Automobile Dealers and the FTC's Safeguards Rule FAQ, the rule text at 16 CFR Part 314, and qualified counsel and security professionals before making compliance decisions.
Quick Answer
The FTC Safeguards Rule, which implements the Gramm-Leach-Bliley Act, requires financial institutions to develop, implement, and maintain a comprehensive written information security program. Auto dealers who finance — or facilitate the financing of — vehicles for consumers are financial institutions for this purpose, because lending money is a financial activity and the test looks at what a business does rather than what it calls itself. Leasing is a second, independent route in: the rule names a dealership that, as a usual part of its business, leases vehicles on a nonoperating basis for longer than 90 days. Between them these sweep in franchised dealers, independents, lease-heavy stores, and buy-here-pay-here operations alike. The program must include the nine elements set out in 16 CFR 314.4, among them a designated Qualified Individual, encryption of customer information at rest and in transit, multi-factor authentication, secure disposal within two years, staff training, service-provider oversight, and a written incident response plan. Since May 2024, a breach involving the unauthorized acquisition of 500 or more consumers' unencrypted information must be reported to the FTC within 30 days of discovery.
Why a car dealership is a "financial institution"
This is the part that still surprises operators. Under the relevant definitions, financial institutions are businesses significantly engaged in financial activities or activities incidental to them — and the FTC is explicit that this "covers more entities than you might imagine, because it focuses on the kinds of activities a business engages in rather than on how the business might describe itself."
Dealers who finance, or facilitate the financing of, vehicles for consumers are financial institutions, since lending money is a financial activity. Facilitating counts, so submitting credit applications to a lender network puts you inside the rule even though the money is never yours.
Leasing is a second and independent route in, and it is named in the rule text rather than inferred from it: an automobile dealership that, as a usual part of its business, leases vehicles on a nonoperating basis for longer than 90 days is a financial institution with respect to its leasing business, because leasing personal property is itself a financial activity. A lease-heavy store that arranges none of its own financing is still inside the rule.
A business that does both financial and non-financial things is still a financial institution if it significantly engages in the financial side — selling cars does not cancel out arranging the loans.
What counts as customer information
The FTC gives dealers concrete examples of records that are always customer information covered by the rule:
- Applications you approved for financing or leasing, containing information like the customer's name, address, Social Security number, and financial account information
- Spreadsheets of names and addresses of customers who financed or leased vehicles from you
- Financial information relating to individual consumers who financed or leased from you
Records that do not qualify on their own — names and addresses you collect from everyone, for instance — fall outside the rule unless they are combined with customer information. That caveat does most of the work in a real dealership, where lists rarely stay separate for long. The practical consequence is that a marketing list which starts out uncovered becomes covered the moment someone joins it to finance data.
The nine required elements
Section 314.4 identifies nine elements your information security program must include. (If you open the CFR to check, you will count ten lettered paragraphs: (j) was added in 2023 and is the breach-notification duty covered further below, a reporting obligation rather than a program element.)
a. Designate a Qualified Individual
Someone must implement and supervise the program. The Qualified Individual can be your own employee, or work for an affiliate or a service provider. No particular degree or title is required — what matters is real-world know-how suited to your circumstances. If you use a service provider's or affiliate's person, your dealership retains responsibility for compliance — you can outsource the work, not the accountability. Two further obligations attach in that case and are widely missed: you must designate a senior member of your own personnel responsible for direction and oversight of the Qualified Individual, and you must require the provider or affiliate to maintain an information security program that protects you to the standard this rule sets.
b. Conduct a written risk assessment
Inventory what information you hold and where it lives, then assess foreseeable internal and external risks to its security, confidentiality, and integrity. The assessment must be written and must include criteria for evaluating those risks. It is not a one-time exercise — periodic reassessment is required as operations change and new threats emerge.
c. Design and implement safeguards
This element carries the specific technical mandates most dealerships feel:
- Encryption of customer information at rest and in transit over external networks. If encryption is not feasible, you may use effective alternative controls — but they must be approved by your Qualified Individual.
- Multi-factor authentication for any individual accessing any information system — and the rule defines an information system to include one merely connected to a system containing customer information, not only the systems holding it. That is broader than the common paraphrase "anyone accessing customer information," and it is the reason an adjacent system is not out of scope. The rule requires at least two of: a knowledge factor (a password), a possession factor (a token), and an inherence factor (a biometric). The only exception is where your Qualified Individual has approved in writing reasonably equivalent or more secure access controls.
- Secure disposal of customer information no later than two years after your most recent use of it to serve that customer, unless you have a legitimate business need or legal requirement to retain it, or targeted disposal is not feasible given how the information is held.
- Application security review for apps you develop or third-party apps you use to store, access, or transmit customer information.
- Change management, so that adding a server or altering a process does not quietly undermine existing controls.
- Access logging and monitoring of authorized users, with procedures to detect unauthorized access.
d. Monitor and test your safeguards
You have two routes. Either implement continuous monitoring of your systems, or — if you do not — conduct annual penetration testing plus vulnerability assessments, including system-wide scans every six months designed to test for publicly known vulnerabilities. You must also test whenever there are material changes to operations or circumstances that could materially affect the program.
e. Train your staff
Security awareness training with regular refreshers, and more specialized training for personnel with security responsibilities. The FTC's framing is worth repeating to a management team: a program is only as effective as its least vigilant staff member.
f. Monitor your service providers
Select providers capable of maintaining appropriate safeguards, and make it contractual. Your contracts must spell out your security expectations, build in ways to monitor the provider's work, and provide for periodic reassessment of their suitability. For a dealership this reaches your DMS, CRM, credit bureau access, digital retailing tools, and anyone else touching customer data.
g. Keep the program current
Adjust based on monitoring results, testing, risk assessments, emerging threats, and personnel changes. A program written once and filed is not a program.
h. Create a written incident response plan
A blueprint for responding to and recovering from a security event affecting the confidentiality, integrity, or availability of customer information — including roles, responsibilities, decision-making authority, remediation requirements, and documentation and reporting obligations.
i. Report to the board
Your Qualified Individual must report in writing, at least annually, to your board of directors or governing body — or, if you have neither, to a senior officer responsible for the program. The report must include an overall assessment of compliance and cover topics such as risk assessment and risk management.
The under-5,000 exception, precisely
Smaller dealerships get relief, but less than is commonly advertised. The exception at 16 CFR 314.6 reads, in its entirety:
"Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers."
Translated, a dealership under that threshold is excused from exactly four things:
- The written risk assessment — 314.4(b)(1)
- The continuous-monitoring-or-annual-pen-testing regime — 314.4(d)(2)
- The written incident response plan — 314.4(h)
- The Qualified Individual's periodic written report to the board — 314.4(i)
Everything else still applies in full. That includes designating a Qualified Individual, because the exception reaches 314.4(i) — the reporting obligation — and not 314.4(a), which is the designation itself. Several vendor and trade summaries describe the exception as excusing small dealers from "appointing a Qualified Individual to report to a board," which blurs two separate provisions and can leave an operator believing they need no Qualified Individual at all. They do. Encryption, multi-factor authentication, secure disposal, training, service-provider oversight, and access controls are likewise untouched by the exception.
Note also what the threshold counts: customer information concerning fewer than five thousand consumers — a cumulative measure of records held, not annual volume. A store retaining finance applications for years can be over the line while selling modestly, which is one more reason the two-year disposal requirement is worth taking seriously.
The notification event: 500 consumers, 30 days
Since May 2024 the rule has carried a federal breach-reporting obligation. You must notify the FTC as soon as possible, and no later than 30 days after discovery, of a security breach involving the unauthorized acquisition of at least 500 consumers' unencrypted information. The rule calls this a "notification event."
Two details make the trigger broader than a quick read suggests:
- Unauthorized access is presumed to be acquisition. The rule provides that unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing there has not been, and could not reasonably have been, unauthorized acquisition. It is rebuttable — but the burden runs against you, and rebutting it means having the evidence already.
- Encrypted information counts if the key was exposed. Customer information is treated as unencrypted for this purpose where the encryption key was accessed by an unauthorized person — encryption protects you only while the key does.
Thirty days is not long for a dealership discovering an incident, which is the practical argument for the written incident response plan even where the under-5,000 exception technically excuses it. A store that has to invent its response process while the clock runs tends to use most of the window deciding who is in charge.
How this differs from Canada
Canadian dealers have no Safeguards Rule equivalent, and the difference is one of regulatory philosophy rather than degree.
- Prescriptive versus principles-based. The Safeguards Rule names controls: multi-factor authentication, encryption at rest and in transit, penetration testing on a stated cadence, disposal within two years. Canadian federal privacy law under PIPEDA instead requires safeguards appropriate to the sensitivity of the information, leaving the specific controls to the organization's judgment. A Canadian dealer can be compliant without a documented MFA mandate; an American one generally cannot.
- A headcount trigger versus a harm test. The US breach obligation turns on a bright line — 500 consumers, 30 days, report to the FTC. Canada's turns on judgment: a breach of security safeguards must be reported to the Office of the Privacy Commissioner where it is reasonable to believe it creates a real risk of significant harm to an individual, with no minimum number of affected people. A five-person breach can be reportable in Canada and fall well under the US threshold.
- Record-keeping. PIPEDA requires organizations to keep a record of every breach of security safeguards, whether or not it meets the reporting threshold, and to retain those records and produce them to the Commissioner on request.
A dealer group operating on both sides therefore cannot run one program and assume it satisfies both. The American requirements are more specific about controls; the Canadian ones are more expansive about which incidents have to be recorded and potentially reported.
Where dealerships actually fall down
Most stores that fail an assessment do not fail on encryption or MFA — those are purchasable. They fail on the parts that are ongoing obligations rather than one-time projects.
Service-provider oversight is the most commonly thin area. The rule requires contracts that state security expectations, provide for monitoring, and build in periodic reassessment. A typical dealership has dozens of vendors touching customer data, most engaged years ago on the vendor's paper, and no schedule for revisiting any of them.
Disposal is the second. Two years after last use sounds generous until you consider how many copies of a credit application exist — the DMS, the scanned deal jacket, an email attachment, a desking tool, a departed F&I manager's folder. Disposal is only meaningful if you know where the copies are.
Training and reassessment cadence is the third: the annual items quietly become biennial, then lapse, because nobody owns the calendar.
Each of those is the same failure the rest of dealership operations produces — a recurring obligation with no named owner and no due date attached. READY HUB is an operations platform rather than a security tool, and it will not make a store compliant with this rule. What it does is the general version of the problem underneath: giving recurring work an owner, a status, and visibility across departments, so that things scheduled actually happen. Your Safeguards program needs a security partner; it also needs somebody to notice when the review date passed.
Frequently asked questions
Does the FTC Safeguards Rule apply to car dealerships?
Yes — by either of two routes. Dealers who finance or facilitate the financing of vehicles for consumers are financial institutions, because lending money is a financial activity and the test looks at what a business does rather than how it describes itself. Separately, the rule names a dealership that leases vehicles on a nonoperating basis for longer than 90 days as a financial institution with respect to its leasing business, so a lease-heavy store that arranges no financing is still covered. Facilitating financing — submitting applications to a lender network — is enough.
What are the nine elements of a Safeguards Rule program?
Designate a Qualified Individual; conduct a written risk assessment; design and implement safeguards (including encryption, MFA, secure disposal, app security, change management, and access logging); monitor and test those safeguards; train staff; oversee service providers; keep the program current; create a written incident response plan; and have the Qualified Individual report in writing at least annually to the board or a senior officer.
Does a small dealership need a Qualified Individual?
Yes. The under-5,000-consumer exception in 16 CFR 314.6 excuses only four provisions — the written risk assessment, the monitoring and testing regime, the written incident response plan, and the Qualified Individual's report to the board. Designating the Qualified Individual is a separate requirement that is not excepted. Summaries describing the exception as removing the Qualified Individual entirely are conflating two provisions.
What does the under-5,000 exception actually cover?
Sections 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions maintaining customer information concerning fewer than five thousand consumers. Encryption, multi-factor authentication, secure disposal, staff training, service-provider oversight, access controls, and designation of a Qualified Individual all still apply.
Is multi-factor authentication mandatory?
Effectively, yes — and for more systems than most summaries suggest. The rule requires it for any individual accessing any information system, and defines an information system to include one connected to a system containing customer information, not only the systems that hold it. It requires at least two of three factor types: knowledge (a password), possession (a token), and inherence (a biometric). The sole exception is where your Qualified Individual has approved in writing reasonably equivalent or more secure access controls.
How long can a dealership keep customer information?
Customer information must be securely disposed of no later than two years after your most recent use of it to serve that customer. The exceptions are a legitimate business need or legal requirement to retain it, or where targeted disposal is not feasible because of how the information is maintained.
When must a dealership report a breach to the FTC?
As soon as possible and no later than 30 days after discovery, where the breach involves unauthorized acquisition of at least 500 consumers' unencrypted information. Unauthorized access counts as well as acquisition, encrypted information counts if the encryption key was also accessed, and unauthorized acquisition is presumed absent reliable evidence to the contrary.
Can we outsource Safeguards Rule compliance?
You can outsource the work but not the responsibility. The Qualified Individual may be an employee of an affiliate or service provider, but the dealership retains ultimate responsibility, must designate a senior member of its own personnel to direct and oversee that Qualified Individual, and must require the provider to maintain a conforming information security program. The rule separately requires you to select capable service providers, contract for your security expectations, monitor their work, and periodically reassess them.
The bottom line
The Safeguards Rule is the most demanding federal obligation most dealerships carry, and it applies for a reason that has nothing to do with selling cars: you arrange financing or write leases, so federal law treats you as a financial institution. The nine elements are specific enough that compliance is assessable, and the 30-day breach clock is short enough that improvising is expensive.
If you take one thing from this page, make it the exception. Being under five thousand consumers removes four obligations, not the rule — and it does not remove your Qualified Individual. Check the actual text at 16 CFR 314.6 rather than a vendor's summary of it, because the summaries circulating in the dealer market are not reliably accurate on precisely that point.
Related reading
Recurring work that actually recurs
READY HUB is a dealership operations platform, not a security product — but the reason annual reviews lapse is the reason deliveries slip. Give recurring work an owner, a due date, and visibility across departments.