Qualified Individual
16 CFR 314.4(a)
Name one person accountable for coordinating your information security program.
If your dealership arranges customer financing, the FTC treats you as a financial institution, and the Safeguards Rule is the law. It requires a written information security program with nine specific parts. This page explains what the Rule asks of a dealership, who it covers, what ignoring it costs, and the fastest honest path to compliance.
Or call (434) 317-6669 to talk to a compliance specialist.
The Safeguards Rule sits under the Gramm-Leach-Bliley Act, which defines a "financial institution" broadly. A dealership that arranges or brokers financing or leasing for its customers is significantly engaged in a financial activity, which brings it inside the Rule. That covers franchised new-car stores, independent used-car lots, and buy-here-pay-here operations that handle customer credit applications, Social Security numbers, and bank details.
In June 2025 the FTC published its first dealer-specific Safeguards FAQs, which settled the "does this apply to us" question and spelled out where vendor and OEM responsibility sits. If you take credit apps, the Rule applies to you.
Every covered dealership must satisfy all nine elements of 16 CFR 314.4 and keep the evidence to prove it. Here is the short version; the pillar guide breaks each one down in plain English.
16 CFR 314.4(a)
Name one person accountable for coordinating your information security program.
16 CFR 314.4(b)
Identify and document internal and external risks to customer financial data.
16 CFR 314.4(c)
Implement access controls, encryption, and multi-factor authentication to control those risks.
16 CFR 314.4(d)
Regularly test or monitor the effectiveness of your key controls.
16 CFR 314.4(e)
Train every employee who touches customer data, including F&I, sales, and service.
16 CFR 314.4(f)
Vet and monitor the DMS, CRM, and finance vendors that handle your customer data.
16 CFR 314.4(g)
Update the program as your systems, risks, and the Rule change.
16 CFR 314.4(h)
Have a written plan for responding to a security event before one happens.
16 CFR 314.4(i)
Report on the program in writing to your board or dealer principal every year.
Read the full guide: the 9 FTC Safeguards Rule requirements in plain English
Civil penalties run up to $53,088 per violation, the current 2026 federal maximum.
Owners, GMs, and officers can be held personally responsible for compliance failures.
A breach at a non-compliant dealership opens the door to class-action litigation.
Carriers increasingly deny cyber claims from businesses with no documented program.
The ground keeps shifting, and each change widened what applies to dealers. On May 13, 2024, breach notification went live: a notification event involving the unauthorized acquisition of unencrypted information of 500 or more consumers must be reported to the FTC no later than 30 days after discovery (16 CFR 314.4(j)). In June 2025 the FTC published its dealer-specific FAQs. On January 1, 2026 new state privacy laws took effect in Kentucky, Indiana, and Rhode Island, and on July 1 Connecticut's law began applying to dealerships operating there after the state removed the GLBA exemption that used to keep many dealers out.
SaferDealer works only with dealerships. We build the written program, train your people, vet your vendors, and hand you the documentation an examiner asks for, then keep it current.
Get a no-obligation gap assessment, free for qualifying dealerships. We show you which of the nine requirements you meet and which need work, then recommend only what closes the gap.