Most dealership owners we talk to know the FTC Safeguards Rule exists. Far fewer can name the Qualified Individual on their written information security program, produce the last penetration test report, or say when their vendor list was last reviewed. That gap is the problem, because the rule has been fully enforceable since June 9, 2023, and since May 2024 a qualifying breach has to be reported to the FTC within 30 days and lands in a public database.

This post covers why the FTC treats dealerships as financial institutions, what the rule actually requires, where dealerships most often fall short, and what non-compliance costs when something goes wrong. The uncomfortable part is that the FTC penalty is rarely the largest number on the page.

Why a car dealership is a "financial institution"

Dealerships get caught by the Safeguards Rule because of the F&I office, not the service bay. The Gramm-Leach-Bliley Act defines a financial institution as any business "significantly engaged" in financial activities. When your store arranges financing, originates a lease, or brokers a loan through a captive or a credit union, you are engaged in a financial activity, and the customer information you collect to do it is regulated.

Under Section 1029 of the Dodd-Frank Act, the Consumer Financial Protection Bureau was denied authority over most auto dealers. That authority stayed with the Federal Trade Commission. So dealerships answer to the FTC on data security, and the FTC's implementing regulation is the Safeguards Rule at 16 CFR Part 314.

The scope of the covered data is broader than most stores assume. A credit application is obviously covered. So is the driver's license scan taken before a test drive, the trade-in payoff quote, the deal jacket sitting in a filing cabinet, the DMS record, and the customer list your CRM vendor holds on your behalf. A "buy here, pay here" store or a dealership doing its own in-house financing sits even deeper inside the rule.

What the rule actually requires

The 2021 amendments turned the Safeguards Rule from a general "have a reasonable program" standard into a specific checklist. Your written information security program has to include nine things.

  • A Qualified Individual. One named person responsible for the program. They can be an employee or supplied by a service provider, but if they come from outside, a senior member of your staff still has to oversee them, and the responsibility stays with the dealership.
  • A written risk assessment. Periodic, documented, and specific enough to actually drive your safeguards. A generic template with your name at the top is not a risk assessment.
  • Specific technical safeguards. Access controls, a current inventory of the data and systems you hold, encryption of customer information in transit and at rest, secure development practices for any app you build, multifactor authentication for anyone accessing an information system holding customer information, secure disposal of customer information no later than two years after the last use, change management, and logging of authorized user activity.
  • Continuous monitoring, or testing. Either continuous monitoring of your systems, or annual penetration testing plus vulnerability assessments at least every six months. Most dealerships choose the second option and then only do half of it.
  • Security awareness training. For all staff, plus verification that your security personnel maintain current knowledge.
  • Service provider oversight. You must select vendors capable of protecting the data, require safeguards by contract, and periodically assess them. Your DMS, CRM, lead aggregator, and payment processor all sit here.
  • Program evaluation and adjustment. The program has to change when your environment, systems, or threat landscape change.
  • A written incident response plan. Covering goals, roles, internal processes, communication, remediation, documentation, and post-incident revision.
  • An annual written report. The Qualified Individual reports at least annually, in writing, to your board of directors or a senior officer.

Read that list against your store honestly. Most dealerships we assess have some version of items one, three, and five, and nothing written down for the rest.

The 5,000-consumer exemption trap

The rule includes a partial exemption for businesses that maintain customer information on fewer than 5,000 consumers. Those businesses are excused from the written risk assessment, the continuous monitoring or annual pen-testing requirement, the written incident response plan, and the annual written report.

Two things go wrong with this exemption in practice.

First, the count is not your annual unit sales. It is every consumer whose information you maintain, including service customers, past buyers, and anyone whose credit you pulled on a deal that never closed. A single-rooftop store that has been open five years is almost certainly past 5,000. Most dealers who believe they are exempt have never actually counted.

Second, the exemption removes the paperwork, not the safeguards. Encryption, MFA, access controls, secure disposal, and vendor oversight still apply at any size. An exempt dealership that skipped MFA is still in violation.

The 30-day clock, and the public database

The amendment that changed the risk calculus took effect on May 13, 2024. If you discover a security event involving the unencrypted customer information of 500 or more consumers, you must notify the FTC as soon as possible and no later than 30 days after discovery.

The notification goes into a database the FTC publishes. Your dealership's name, the date, the number of consumers affected, and a description of the event become searchable by anyone: local news, plaintiffs' attorneys, your OEM, your floor plan lender, and the customer deciding between you and the store across town.

Note the word "unencrypted." Encryption at rest is what keeps a stolen database from becoming a reportable event in the first place. It is one of the highest-leverage controls in the entire rule, and it is one of the most commonly missing.

What non-compliance actually costs

Dealers usually ask about the FTC fine first. It is the wrong thing to worry about first.

The FTC consent order is the real regulatory penalty. FTC data security enforcement typically ends in a consent order running twenty years, requiring a mandated security program, biennial assessments by an approved third-party assessor, ongoing recordkeeping, and compliance reporting. In 2019 the FTC brought an action against LightYear Dealer Technologies, the operator of the DealerBuilt dealer management system, after an unsecured backup device exposed data belonging to millions of consumers across its dealership customers. The resulting order imposed exactly that kind of long-term obligation. Twenty years of audited compliance is more expensive, and more disruptive, than any single check you write.

California adds a second layer with teeth. For a California dealership, the FTC is not the biggest exposure. The California Consumer Privacy Act gives consumers a private right of action when unencrypted, unredacted personal information is exposed through a business's failure to maintain reasonable security. Statutory damages run $100 to $750 per consumer per incident, and the consumer does not have to prove they were harmed. Do the arithmetic on a store holding records for 20,000 customers and the range lands between $2 million and $15 million before anyone argues about actual damages. Class action firms watch the FTC's public breach database for exactly this reason. The California Attorney General and the California Privacy Protection Agency can also act independently of anything the FTC does.

Your cyber insurance may not respond. Current cyber applications ask specific questions about MFA coverage, backup immutability, EDR deployment, and incident response testing. If you attested to controls you do not have, the carrier can rescind the policy after a claim, meaning it is treated as never having existed. We covered how that plays out in How to Answer Cyber Insurance Renewal Questions. A Safeguards Rule gap and an insurance misrepresentation are frequently the same gap, discovered on the same bad day.

Your OEM and your floor plan lender have contractual rights. Manufacturer agreements and floor plan financing agreements increasingly carry data security and breach notification obligations. A breach can trigger notice requirements, audits, remediation demands, and in serious cases affect your standing with the captive.

And then there is downtime. In June 2024, the ransomware attack on CDK Global took dealer management systems offline for roughly 15,000 North American dealerships. Stores went back to paper deals for weeks. The Anderson Economic Group estimated direct losses to affected dealers at roughly $1 billion over about three weeks. Most of those dealerships did nothing wrong themselves, which is precisely the point of the rule's service provider oversight requirement. You are responsible for knowing what happens to your data inside your vendors' systems, and for having an incident response plan that assumes a vendor outage rather than only an attack on your own network.

Where dealerships actually fall short

Across the assessments we run, the same gaps repeat.

  • MFA is enabled on email but not on the DMS, the CRM, remote access, or administrator accounts.
  • Customer information is encrypted in transit and not at rest, which is what determines whether a breach is reportable.
  • Nobody is formally named as the Qualified Individual, so no one owns the program.
  • Terminated employees keep DMS access for weeks. Sales turnover makes this the single most common access control failure in the industry.
  • Deal jackets with credit applications sit in unlocked storage past the two-year disposal window.
  • Vendor contracts have no security terms, and no one has ever requested a SOC 2 report from the DMS provider.
  • The incident response plan does not exist, or exists as a document nobody has read since it was written.

None of these require a large budget to fix. They require someone to own them.

A 90-day path to compliance

Days 1 to 15. Name your Qualified Individual in writing. Count the consumers whose information you maintain so you know whether the partial exemption applies. Inventory every system holding customer information, including anything a vendor holds for you.

Days 15 to 45. Turn on MFA everywhere customer information can be reached, not just email. Verify encryption at rest on the DMS, CRM, file servers, and backups. Audit every active user account against your current employee roster and revoke what should not be there.

Days 45 to 70. Write the risk assessment and the incident response plan. Keep both short enough that someone will actually use them. Run a 60-minute tabletop exercise covering a DMS vendor outage and a ransomware event, and keep the notes as evidence of testing.

Days 70 to 90. Request SOC 2 reports or equivalent attestations from your DMS, CRM, and lead vendors, and document who responded. Schedule your penetration test and your six-month vulnerability assessments. Deliver the Qualified Individual's first written report to your dealer principal or board, and calendar it annually.

If your store cannot produce a written information security program today, start with the Qualified Individual and the system inventory. Everything else in the rule depends on knowing who owns the program and where the data lives.

Frequently asked questions

Does the FTC Safeguards Rule apply to my dealership?

If your store arranges financing or leasing for customers, yes. That activity makes the dealership a financial institution under the Gramm-Leach-Bliley Act, and the FTC retained enforcement authority over auto dealers under Section 1029 of the Dodd-Frank Act. Compliance has been mandatory since June 9, 2023.

What counts as customer information at a dealership?

Any nonpublic personal information you obtain in connection with providing a financial product or service. That includes credit applications, driver's license scans, Social Security numbers, bank and payoff details, deal jackets, DMS and CRM records, and data your vendors hold on your behalf.

Do I have to report a data breach to the FTC?

Since May 13, 2024, yes. If a security event involves the unencrypted customer information of 500 or more consumers, you must notify the FTC as soon as possible and no later than 30 days after discovery. The FTC publishes those notifications in a public database.

Is my dealership exempt if we have fewer than 5,000 customers?

The partial exemption removes four documentation requirements: the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan, and the annual written report. The technical safeguards, including MFA, encryption, access controls, and secure disposal, still apply. The 5,000 count covers everyone whose information you maintain, not just this year's buyers.

What happens if my dealership is not compliant?

FTC enforcement typically results in a consent order carrying twenty years of mandated security program requirements and third-party assessments. In California, a breach involving unencrypted personal information can also trigger private lawsuits with statutory damages of $100 to $750 per consumer per incident under the CCPA, plus state Attorney General action. Contractual consequences with your OEM and floor plan lender, and a cyber insurance claim denial, often follow the same incident.

Who can serve as our Qualified Individual?

Either an employee or a person supplied by a service provider such as a managed IT or managed security provider. If the role is outsourced, a senior member of your dealership's staff must oversee that provider, and legal responsibility for the program remains with the dealership.

ShadowEdge helps Northern California dealerships build and document Safeguards Rule programs, from the initial risk assessment through MFA rollout, vendor oversight, and the annual report. If you are not sure where your store stands, get in touch and we will walk the nine requirements with you.