Skip to main content
How the FTC Safeguards
Rule Applies to Dealerships

In today’s digital world, protecting customer information is more critical than ever. For auto dealerships, this responsibility is formalized by the Federal Trade Commission’s (FTC) Standards for Safeguarding Customer Information, commonly known as the Safeguards Rule. Because dealerships often extend credit, arrange financing, or handle sensitive financial applications, they are classified as “financial institutions” under federal law. This designation means that strict compliance with the Safeguards Rule is not optional, it is mandatory. The rule requires dealerships to develop, implement, and maintain a comprehensive information security program to keep their customers’ sensitive data secure. Understanding how this rule applies to your daily operations is the first step toward building a compliant, trustworthy business that protects both your customers and your reputation from significant risk. Our commitment to these standards is a core part of our business philosophy, detailed further in our privacy policy.

Adhering to the FTC Safeguards Rule is more than just a legal obligation; it is a fundamental aspect of modern customer service and sound business management. A robust security program demonstrates a deep respect for customer privacy, which builds lasting trust and loyalty. By proactively protecting financial data, dealerships can prevent costly data breaches, avoid steep regulatory fines, and safeguard their hard-earned reputation in the community. Compliance is an investment in the long-term health and integrity of the dealership.

how-the-ftc-safeguards-rule-applies-to-dealerships

A Deep Dive into the FTC Safeguards Rule for Auto Dealers

The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. The Safeguards Rule is the part of the GLBA that dictates exactly how these institutions must protect that information. For a long time, many dealerships operated without fully realizing the extent of their responsibilities under this rule. However, recent amendments have clarified and expanded these requirements, putting a renewed focus on data security across the automotive industry.

Any dealership that collects personal and financial information to arrange financing for a vehicle purchase falls under the rule's definition of a financial institution. This includes Buy Here Pay Here (BHPH) lots and traditional used car dealerships that work with third-party lenders. The information you handle daily, from credit applications and driver’s licenses to income verification and bank account numbers, is exactly the type of nonpublic personal information (NPI) the rule was designed to protect.

Key Requirements of a Compliant Information Security Program

The updated Safeguards Rule outlines several specific actions and policies that dealerships must enact. These elements form the foundation of a required Information Security Program. Failing to implement these can lead to significant penalties. Here are the core components your dealership must have in place.

  • Designate a Qualified Individual: Your dealership must appoint a single person, known as the "Qualified Individual," to oversee, implement, and enforce your information security program. This person can be an employee or an outside contractor, but they must have the authority and knowledge to manage the program effectively. This is a critical role that connects your policies with our team, which you can learn more about on our meet our staff page.
  • Conduct a Written Risk Assessment: You must perform and document a thorough risk assessment. This process involves identifying potential threats to customer information, assessing the vulnerability of your systems, and evaluating the sufficiency of your current controls. The assessment must be written and should guide the development of your entire security program.
  • Implement Specific Safeguards: Based on your risk assessment, you need to design and implement safeguards to control the risks you have identified. These fall into several categories, including encrypting all customer data, implementing multi-factor authentication for anyone accessing customer information, and developing secure data disposal procedures.
  • Continuous Monitoring and Testing: A "set it and forget it" approach is not compliant. The rule requires continuous monitoring of your security systems. This may involve penetration testing for larger systems and regular vulnerability assessments to ensure your safeguards remain effective against evolving threats.
  • Train Your Staff: Every employee who handles customer information must receive regular security awareness training. They need to understand the risks, recognize potential threats like phishing scams, and know their responsibilities under your dealership’s information security program.
  • Oversee Service Providers: Your responsibility does not end with your own systems. You must take steps to ensure that your service providers, such as your DMS, CRM, or IT management companies, also maintain adequate safeguards. This involves due diligence, contractual requirements, and periodic assessments. This is why we have a careful vetting process for all our vendors.
  • Create a Written Incident Response Plan: You must have a plan in place for what to do in the event of a data breach or other security incident. This written plan should outline the steps for responding to, investigating, and mitigating the impact of an incident, as well as notifying affected customers and regulatory bodies.
  • Regular Reporting to Your Board: The Qualified Individual must provide regular written reports to the dealership’s board of directors or equivalent governing body. These reports must detail the status of the information security program and any significant security events.

What Compliance Looks Like in Practice

Moving from a checklist to real-world application is the most significant challenge for dealerships. In practical terms, compliance means transforming how you handle data at every stage of the customer journey, from their first visit to our used inventory page to the final signature on a sales contract. It involves securing your physical files in locked cabinets, controlling who can access your computer systems, and ensuring that any data transmitted electronically is encrypted. It means a cultural shift where every team member, from sales to finance to service, understands they play a role in protecting customer information. By embracing these principles, we not only comply with the law but also reinforce the core values you can read about on our about us page.

The High Cost of Non-Compliance

Ignoring the FTC Safeguards Rule can have devastating consequences. The FTC can impose fines of over $40,000 per violation, and each affected customer record can be considered a separate violation. Beyond federal penalties, dealerships may face lawsuits from affected customers and investigations from state attorneys general. Perhaps the most damaging consequence is the loss of customer trust. A data breach can permanently tarnish a dealership's reputation, driving customers to competitors and making it difficult to attract new business. The investment in a strong, compliant security program is small compared to the potential financial and reputational costs of a security failure. If you have any questions about our processes, please do not hesitate to contact us.

What is the deadline for complying with the updated FTC Safeguards Rule?

The Federal Trade Commission extended the deadline for some of the updated provisions to June 9, 2023. As of that date, all covered financial institutions, including auto dealerships, are expected to be in full compliance with all aspects of the amended rule.

Does the rule apply if we only use a third-party lender for financing?

Yes, it still applies. If your dealership collects, handles, and transmits nonpublic personal information to a lender as part of the financing process, you are considered a financial institution under the rule. Your responsibility is to safeguard that data while it is in your possession, before and during its transmission to the lender.

What kind of employee training is required?

The rule requires regular security awareness training for all employees. This should cover the dealership's specific security policies, how to identify and report potential threats like phishing emails, the importance of strong passwords and multi-factor authentication, and procedures for handling sensitive customer information securely.

Is hiring a new "Qualified Individual" mandatory for small dealerships?

You do not necessarily need to hire a new person. A current employee can be designated as the Qualified Individual, provided they have the expertise and authority to manage the security program. Small dealerships can also hire an external third-party service to act as their Qualified Individual and manage their program.

What are examples of "customer information" that need protection?

Customer information, or nonpublic personal information (NPI), includes any personally identifiable financial information. This covers names, addresses, phone numbers, Social Security numbers, driver's license numbers, credit history, bank account numbers, income details, and any other information collected on a credit application or from a consumer report.