The Rule, built for dealerships

The FTC Safeguards Rule for auto dealers.

If your dealership arranges customer financing, the FTC treats you as a financial institution, and the Safeguards Rule is the law. It requires a written information security program with nine specific parts. This page explains what the Rule asks of a dealership, who it covers, what ignoring it costs, and the fastest honest path to compliance.

Or call (434) 317-6669 to talk to a compliance specialist.

Interior of a modern car dealership showroom
Does it apply to you?

If your store arranges financing, the answer is almost certainly yes

The Safeguards Rule sits under the Gramm-Leach-Bliley Act, which defines a "financial institution" broadly. A dealership that arranges or brokers financing or leasing for its customers is significantly engaged in a financial activity, which brings it inside the Rule. That covers franchised new-car stores, independent used-car lots, and buy-here-pay-here operations that handle customer credit applications, Social Security numbers, and bank details.

In June 2025 the FTC published its first dealer-specific Safeguards FAQs, which settled the "does this apply to us" question and spelled out where vendor and OEM responsibility sits. If you take credit apps, the Rule applies to you.

Read: what the FTC answered for dealers

What the Rule requires

Nine requirements, one written program

Every covered dealership must satisfy all nine elements of 16 CFR 314.4 and keep the evidence to prove it. Here is the short version; the pillar guide breaks each one down in plain English.

1

Qualified Individual

16 CFR 314.4(a)

Name one person accountable for coordinating your information security program.

2

Written Risk Assessment

16 CFR 314.4(b)

Identify and document internal and external risks to customer financial data.

3

Safeguards and Controls

16 CFR 314.4(c)

Implement access controls, encryption, and multi-factor authentication to control those risks.

4

Testing and Monitoring

16 CFR 314.4(d)

Regularly test or monitor the effectiveness of your key controls.

5

Security Awareness Training

16 CFR 314.4(e)

Train every employee who touches customer data, including F&I, sales, and service.

6

Service Provider Oversight

16 CFR 314.4(f)

Vet and monitor the DMS, CRM, and finance vendors that handle your customer data.

7

Program Evaluation and Adjustment

16 CFR 314.4(g)

Update the program as your systems, risks, and the Rule change.

8

Written Incident Response Plan

16 CFR 314.4(h)

Have a written plan for responding to a security event before one happens.

9

Annual Report to Leadership

16 CFR 314.4(i)

Report on the program in writing to your board or dealer principal every year.

Read the full guide: the 9 FTC Safeguards Rule requirements in plain English

The cost of ignoring it

Non-compliance is not a paperwork problem

$53,088

Per violation

Civil penalties run up to $53,088 per violation, the current 2026 federal maximum.

Personal

Owner liability

Owners, GMs, and officers can be held personally responsible for compliance failures.

Class-action

Customer lawsuits

A breach at a non-compliant dealership opens the door to class-action litigation.

Denied

Insurance claims

Carriers increasingly deny cyber claims from businesses with no documented program.

What changed for dealerships, 2024 to 2026

The ground keeps shifting, and each change widened what applies to dealers. On May 13, 2024, breach notification went live: a notification event involving the unauthorized acquisition of unencrypted information of 500 or more consumers must be reported to the FTC no later than 30 days after discovery (16 CFR 314.4(j)). In June 2025 the FTC published its dealer-specific FAQs. On January 1, 2026 new state privacy laws took effect in Kentucky, Indiana, and Rhode Island, and on July 1 Connecticut's law began applying to dealerships operating there after the state removed the GLBA exemption that used to keep many dealers out.

Read: how state privacy laws are closing the GLBA loophole

How we help

From uncertain to auditable in 60 to 90 days

SaferDealer works only with dealerships. We build the written program, train your people, vet your vendors, and hand you the documentation an examiner asks for, then keep it current.

  1. Day 0 Free Gap Assessment
  2. Days 1 to 45 Build Your Program
  3. Day 60 to 90 Maintain and Report

See all six compliance services and what each includes

Find out exactly where your dealership stands

Get a no-obligation gap assessment, free for qualifying dealerships. We show you which of the nine requirements you meet and which need work, then recommend only what closes the gap.

Get your free gap assessment