Published October 12, 2025 · Updated July 25, 2026

FTC Safeguards Rule Requirements: All 10, Explained for Dealers

If your dealership arranges financing or leases vehicles for 90 days or more, you are a financial institution under federal law, and the FTC Safeguards Rule applies to you. The Rule requires a written information security program built on nine required elements, listed at 16 C.F.R. §314.4. A tenth obligation, breach notification, was added in 2023 and is now in effect.

This page explains every requirement: the section of the Rule it comes from, what it actually looks like inside a store, and the fastest way to close it. The primary sources are the FTC’s own guidance, What Your Business Needs to Know and the Automobile Dealer FAQs. Note that the FTC’s dealer-specific FAQs count ten elements rather than nine, because they fold in the breach notification obligation that the general business guidance handles separately.

Want the short version to walk the store with? The FTC Safeguards Rule compliance checklist condenses all of this to a one-page PDF you can hand to a manager.

The deadlines that already passed

Nothing here is upcoming. Every date below is in force today.

  • June 9, 2023. The compliance deadline for the amended provisions, including designating a Qualified Individual and implementing multi-factor authentication, after the FTC granted a six-month extension from the original date.
  • May 13, 2024. The breach notification requirement took effect. Covered institutions must notify the FTC within 30 days of discovering unauthorized acquisition of unencrypted customer information affecting 500 or more consumers. See the FTC’s notice.

If your store has no written program, no named Qualified Individual, or no MFA on the systems holding customer data, you are not behind schedule. You are past the deadline.

All ten requirements at a glance

#RequirementRuleWhat it means in your store
1Designate a Qualified Individual§314.4(a)One named person owns the program and reports to ownership
2Write a risk assessment§314.4(b)A document mapping where customer data lives and what could go wrong
3Implement safeguards§314.4(c)MFA, encryption, access control, inventory, secure disposal, logging
4Monitor and test§314.4(d)Continuous monitoring, or annual pen test plus twice-yearly vulnerability scans
5Train your staff§314.4(e)Role-appropriate training, deeper training for the people running the program
6Oversee service providers§314.4(f)Vet vendors, put security terms in contracts, reassess them
7Keep the program current§314.4(g)Update as systems, staff and threats change
8Written incident response plan§314.4(h)Roles, containment, notification and lessons learned, on paper
9Report to owners or the Board§314.4(i)At least one written report a year from the Qualified Individual
10Notify the FTC of qualifying breaches§314.4(j)30 days, 500 or more consumers, added 2023 and now in effect

1. Designate a Qualified Individual

The requirement. Name one individual with the authority to run the information security program and to report to leadership. You may outsource the work to a service provider, but the dealership stays accountable for it. §314.4(a)

What it looks like in a store. Security tasks are usually spread across IT, F&I and a couple of vendors, so nothing is owned end to end. The Qualified Individual does not have to be a security specialist. Plenty of stores use a controller, an IT manager, or a managed security provider. What matters is that one person can answer the regulator’s question, which is always some version of “who decided this, and what did you do about it?”

Fast actions. Give the role written authority. Set a reporting rhythm to the GM or the owners. Define a 90-day roadmap so the appointment produces work and not just a title.

Go deeper: start by putting someone in charge, and for groups, what a Qualified Individual actually does across 5 to 10 rooftops.

2. Conduct a written risk assessment

The requirement. A documented risk assessment with written criteria, identified risks and planned mitigations, kept current as conditions change. §314.4(b)

What it looks like in a store. Most dealerships have never mapped where customer information actually sits. It is in the DMS and the CRM, in lender portals, in email attachments, on the scan station, in the deal jackets in the filing cabinet, and on somebody’s desktop as a PDF export. Until that map exists on paper, every other control is a guess. The most common finding is mundane and expensive: credit applications sitting on an open office computer that half the store can reach.

Fast actions. Inventory the systems and data flows behind credit applications and scanned IDs. Rank the risks. Tie every risk to a named control and an owner.

Go deeper: know what you have, conduct a written risk assessment.

3. Design and implement safeguards

The requirement. Put controls in place to address the risks you identified: access controls, a data and asset inventory, encryption in transit and at rest, secure development practices, multi-factor authentication, secure disposal, change management, and logging or monitoring of authorized user activity. §314.4(c)

What it looks like in a store. Shared logins at the service lane and the parts counter. Former employees whose CRM access still works. Vendor helper accounts created once and never removed. Those are the openings that get used, and they are all cheap to close. Encryption of customer information in transit and at rest is expected. Where it is not feasible, the Rule allows effective alternative compensating controls reviewed and approved by your Qualified Individual. The MFA requirement has a similar escape hatch at §314.4(c)(5), but a stricter one: there, the Qualified Individual has to approve the equivalent access controls in writing.

Fast actions. Turn on MFA for the DMS, the CRM and email. Delete shared accounts. Encrypt endpoints. Cut vendor permissions to the minimum they need. Set a retention and destruction schedule covering paper as well as digital records.

Go deeper: from risk list to real protection, hardening Microsoft 365 for the showroom, and what to do about unsupported scan stations and lane PCs.

4. Monitor and test your controls

The requirement. Regularly test or otherwise monitor the effectiveness of your safeguards. That means either continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months, with additional testing after any material change. §314.4(d)

What it looks like in a store. Without testing, you learn about problems from a customer, a lender, or a ransom note. The classic scan finding is the forgotten wireless network that service tablets used two years ago and nobody ever turned off.

Fast actions. Centralize alerts for admin logins and bulk data exports. Book a third-party penetration test, and put both vulnerability scans on the calendar for the year rather than on somebody’s to-do list.

Go deeper: how regular testing keeps your security program honest.

5. Train your staff

The requirement. Security awareness training for personnel, plus deeper and current training for the people who run the program and anyone with security responsibilities. §314.4(e)

What it looks like in a store. Phishing, wire fraud and emailing customer documents in the clear are the three failure points that actually cost dealers money. Training has the best return of any control on this list, and it is the one most often reduced to an annual video nobody watched.

Fast actions. Quarterly micro-training plus phishing simulations. Give F&I a secure file exchange so deal packs stop riding on email. Add a rule that flags unencrypted personal information leaving the store by email.

Go deeper: how employee training protects your store, and why shared mailboxes and everyone-logs-in habits are an attacker’s shortcut.

6. Oversee your service providers

The requirement. Select and retain service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them based on the risk they present. §314.4(f)

What it looks like in a store. Your DMS, CRM, website vendor, shredding company and remote IT provider all touch customer information, and most dealer contracts say nothing about security. If a vendor is breached, the customer data is still yours, and so is the explaining. Vendor oversight is how you show you took reasonable steps in choosing who to trust.

Fast actions. Add MFA, encryption, breach notification and audit rights to contracts at renewal. Keep a vendor register with risk tiers and a review date. Review who holds remote access every quarter.

Go deeper: overseeing your service providers and grading your vendors like a pro.

7. Keep the program current

The requirement. Evaluate and adjust the program in light of testing results, material changes to operations or business arrangements, and any other circumstances that may have a material impact. §314.4(g)

What it looks like in a store. New tools arrive constantly and the policy binder never follows them. Switch CRM platforms and you have new permissions, new integrations and a new place customer data lives, all sitting outside the program you documented last year.

Fast actions. Add a security review step to software purchasing. Revisit the risk assessment quarterly and write down what changed, even when the answer is nothing.

Go deeper: why your program should always stay current.

8. Maintain a written incident response plan

The requirement. A written plan covering goals, internal response processes, roles and decision authority, internal and external communications, remediation of weaknesses, documentation and reporting, and a post-incident review. §314.4(h)

What it looks like in a store. During an incident everyone calls the GM and nobody knows the first five steps. A plan that lives in a shared drive nobody can reach during an outage is not a plan. Print it.

Fast actions. Build a one-page contact sheet with your IT provider, your insurer, your counsel and your lenders. Run a tabletop drill. Pre-draft the lender and customer notifications while nobody is panicking.

Go deeper: why every dealership needs a written plan, a 60-minute multi-store tabletop, and what to say and who to call when it happens.

9. Report to owners or the Board

The requirement. The Qualified Individual must report in writing, at least annually, to your board of directors or equivalent governing body, covering the overall status of the program, compliance with the Rule, and material matters such as risk assessment results, testing, security events and management’s responses. §314.4(i)

What it looks like in a store. Security surfaces during outages and audits and nowhere else. The annual report is the element auditors and cyber carriers ask for first, because it is the one piece of paper proving leadership was actually in the loop.

Fast actions. Put security metrics on the monthly management agenda. Have the owner sign the annual report and file it with the compliance records. Give every open remediation item a name and a due date.

Go deeper: why leadership must review and approve the annual report.

The tenth element: breach notification

The 2023 amendment added a notification duty that took effect on May 13, 2024. If unencrypted customer information affecting 500 or more consumers is acquired without authorization, you notify the FTC within 30 days of discovery through the FTC’s online form. §314.4(j)

Two details catch dealers out. The clock starts at discovery, not at containment, so the investigation and the notification run in parallel. And encryption matters here in a concrete way: information counts as unencrypted if the encryption key was also accessed by an unauthorized person. That is the clearest example on this page of a control that pays for itself.

Where dealerships actually get caught

A vendor outage. Your DMS provider has an incident. Sales and F&I slow to a crawl and you need to establish what happened and who was affected. Logging, an incident plan and real contract terms are what turn that from a guess into a documented response. During the 2024 CDK incident, dealerships across the country reverted to manual workarounds, and Anderson Economic Group estimated roughly 1.02 billion dollars in dealer losses over three weeks (AEG).

The F&I email. A finance manager emails a deal pack containing a customer’s Social Security number. Training, a secure file exchange and a basic data-loss rule would have prevented or encrypted that message.

The offboarding gap. A salesperson leaves and their CRM login stays live for months. Access controls, automated offboarding and a quarterly user audit are the answer, and all three sit under §314.4(c).

A 30-day starter plan

If you are starting from nothing, work in this order. It follows the Rule’s own logic, because each step produces the input for the next.

  1. Appoint the Qualified Individual and define how they report. §314.4(a)
  2. Complete the written risk assessment and system inventory. §314.4(b)
  3. Enforce MFA, remove shared logins, encrypt endpoints. §314.4(c)
  4. Stand up logging, book a penetration test and schedule two vulnerability scans. §314.4(d)
  5. Write the one-page incident plan and run a tabletop. §314.4(h)
  6. Update service provider contracts with security terms, breach notice and audit rights. §314.4(f)

Then write it all down in one place. The deliverable the FTC expects is a written information security program, not a folder of good intentions. If you want to know where you stand before you start, that is what a gap assessment produces.

Frequently asked questions

Are most franchised dealers covered by the Safeguards Rule?

Yes. If your store arranges financing, or leases vehicles for 90 days or more, you are a financial institution under the Rule. See the Automobile Dealer FAQs. Being small does not exempt you from the Rule. There is one narrow carve-out: under §314.6, four paragraphs do not apply to a financial institution that maintains customer information concerning fewer than 5,000 consumers, namely §314.4(b)(1), (d)(2), (h) and (i). In practice that is the written form of the risk assessment, the penetration testing and vulnerability scanning schedule, the written incident response plan and the annual report. Everything else, including MFA, encryption, training and vendor oversight, still applies.

Is it nine requirements or ten?

Nine is the standard framing, and it refers to §314.4(a) through (i), the elements of the security program itself. The 2023 amendment added notification at §314.4(j). Both are obligations. If a checklist you were handed shows nine items and no breach notification line, it predates May 2024.

Do we have to encrypt everything?

The Rule requires you to protect by encryption all customer information held or transmitted, in transit over external networks and at rest. Where you determine encryption is infeasible, §314.4(c)(3) allows effective alternative compensating controls that your Qualified Individual has reviewed and approved. Note the contrast with MFA at §314.4(c)(5), where the equivalent-controls approval must be in writing. See the FTC guide.

What if the breach happens at a vendor?

You still have to oversee your service providers under §314.4(f), and depending on what was taken and how many consumers were affected, you may still be the one notifying the FTC. Read those contracts now rather than during the incident.

Is a checklist enough to be compliant?

No, and this is where most stores lose time. The Rule asks for a program appropriate to your size, complexity and the sensitivity of the information you hold. A checklist tells you what to build. What gets judged is whether the program you built is reasonable for a dealership like yours, and whether you can prove it actually operates.

What counts as customer information in a dealership?

Nonpublic personal information you collect in connection with financing or leasing. Names and addresses can be covered when they indicate a financing relationship or are combined with other financial data. The Automobile Dealer FAQs work through the edge cases.

The through-line across all ten elements is the same: accountability, documentation and proof. Every dealership, whatever its size, has to show in writing that customer information is protected and that somebody is actively managing it.

Ready to see where your dealership stands?

A free gap assessment maps your store against all nine FTC Safeguards requirements, with a written report of every gap.

Get your free gap assessment