The CorwinLaw Codex

The FTC Safeguards Rule for Automotive Dealers: A Practical Compliance Guide

Cybersecurity Is Not Merely an IT Issue

Codex Entry
014-26
Revision
1.0
Practice Area
Automotive Franchise Law
Last Reviewed
August 2026

Current through August 11, 2026

Automotive dealerships collect some of the most sensitive information a consumer may provide outside a bank or medical office. A single transaction may involve a driver’s license, Social Security number, credit report, employment history, income, bank information, insurance information, electronic signature, and financing records. That information may pass through sales, F&I, accounting, lender portals, a dealer management system, a customer relationship platform, email, scanners, cloud storage, and outside vendors, sometimes within minutes.

Most dealers know they have cybersecurity responsibilities. Fewer can identify exactly what the Federal Trade Commission’s Safeguards Rule requires, who is responsible, which systems and vendors are covered, how compliance must be documented, or when a cybersecurity incident must be reported to the FTC.

The FTC Safeguards Rule, codified at 16 C.F.R. Part 314, requires covered financial institutions, including most dealerships that regularly arrange financing or enter into qualifying leases, to develop, implement, and maintain a written information-security program. The program must contain administrative, technical, and physical safeguards appropriate to the business, its activities, and the sensitivity of the customer information involved.

This is not satisfied merely because the dealership:

  • Uses antivirus software;
  • Has cyber insurance;
  • Employs an outside IT company;
  • Stores information in a well-known DMS;
  • Requires MFA for email;
  • Purchased a generic compliance package; or
  • Has never experienced a known breach.

Compliance is an ongoing management responsibility. It requires risk assessment, accountable leadership, appropriate technical controls, employee training, service-provider oversight, testing, incident planning, record retention and disposal practices, and in qualifying cases, notification to the FTC.


Dealer takeaway: Outsourcing technology does not outsource the dealership’s legal responsibility. A dealership must be able to explain and document how its program protects customer information in its actual operating environment.

Important Notice

This Codex provides general information about the federal FTC Safeguards Rule. It does not provide a state-by-state privacy or breach-notification survey and is not a substitute for legal advice, a dealership-specific risk assessment, manufacturer requirements, lender obligations, insurance conditions, or technical guidance from qualified cybersecurity professionals. Federal and state requirements may overlap, and the law may change after the date shown above. Contact CorwinLaw to further assess your specific dealership needs.

1. Why Is a Dealership Treated as a Financial Institution?

The phrase “financial institution” is broader under the Gramm-Leach-Bliley Act framework than it sounds in ordinary conversation. A business need not be a bank. A dealership may be covered when, as a regular part of its business, it:

  • Extends credit to consumers;
  • Arranges or facilitates consumer financing;
  • Accepts and processes credit applications;
  • Communicates customer financial information to prospective lenders; or
  • Enters into nonoperating consumer leases exceeding 90 days.

For that reason, most franchised automobile dealerships, and many independent dealerships, are likely covered. The FTC’s dealer-specific guidance explains that most dealers that finance, facilitate financing, or lease automobiles are subject to the Rule. See Automobile Dealers and the FTC’s Safeguards Rule—Frequently Asked Questions.

Coverage depends on what the legal entity actually does, not simply how it describes itself. Dealer groups should not assume that every affiliate has the same status. Cash-only sales operations, wholesale businesses, rental entities, service-only facilities, and related real-estate or management companies may require separate analysis.

Questions that may require individual review

  • Does the dealer merely provide a lender’s contact information, or does it participate in arranging financing?
  • Does a separate entity process the applications?
  • Are commercial transactions handled differently from consumer transactions?
  • Does a service-only location have access to financing information held in a shared system?
  • Do several rooftops share one DMS, CRM, server, or accounting department?
  • Does the entity maintain historical customer information even if it no longer originates or arranges financing?

The safest starting point is not “Are we a bank?” It is: What financial activities do we conduct, and what consumer financial information do we receive or maintain because of those activities?

2. What Is “Customer Information”?

The Rule protects customer information: records containing nonpublic personal information about a customer of a financial institution, whether maintained in paper, electronic, or another form.

In a dealership, covered information may include:

  • Credit applications;
  • Social Security and taxpayer-identification numbers;
  • Driver’s-license data;
  • Dates of birth;
  • Credit reports and credit scores;
  • Income, employment, and housing information;
  • Bank-account and payment information;
  • Financing and leasing terms;
  • Electronic signatures;
  • Documents uploaded through digital-retail portals;
  • Information received from lenders;
  • Adverse-action and declined-application records; and
  • Information derived from the financing or leasing relationship.

Not every name and address is automatically customer information

The FTC’s dealer FAQs recognize an important distinction. A general list containing only the names and addresses of persons who bought vehicles may not be customer information if it does not reveal financing or leasing and contains no other nonpublic personal information. However, context matters. A database entry showing that the person applied for or received financing may reveal a financial relationship.

Moreover, placing covered and noncovered information in a commingled database does not remove the covered information, or connected systems, from the dealership’s security analysis. Dealers should not assume that an entire CRM, DMS, or marketing database is outside the Rule merely because some records relate to cash buyers or ordinary service customers.

Consumer, customer, and prospect are not always identical

The regulatory definitions can distinguish between a consumer who seeks a financial product and a customer with a continuing relationship. But information that falls outside a particular Safeguards Rule definition may still be protected by another federal or state law, a contract, an insurer requirement, or the dealership’s own privacy representation.


Practical rule: Classify information by its content, context, source, use, and relationship to financing or leasing—not merely by the department in which it is found.

3. Where Does Customer Information Live?

A dealership cannot protect information it has not identified. A useful compliance program maps where information enters, where it travels, who can access it, and when it should be removed.

Customer information may reside in or pass through:

  • The dealer management system;
  • The customer relationship management system;
  • Digital-retail and online credit-application platforms;
  • Desking and F&I software;
  • Lender and finance-source portals;
  • OEM portals and applications;
  • Accounting, payroll, and document-management platforms;
  • Service scheduling and repair-order systems;
  • Email, text-messaging, and chat platforms;
  • Shared network drives and cloud-storage accounts;
  • Local computer folders and employee-created spreadsheets;
  • Desktop scanners and multifunction printers;
  • Temporary scan folders;
  • Employee laptops, tablets, and phones;
  • Paper deal jackets and archived records;
  • Backup systems and disaster-recovery copies;
  • Vendor support tools and remote-access utilities; and
  • Former or disconnected systems retained after a migration.

Data mapping should also identify integrations. A dealership may enter information in one application while copies automatically flow to a DMS, CRM, lender, OEM, analytics provider, marketing vendor, call center, or cloud service.

A diagram need not be technically elaborate. It should be accurate enough for the dealership to answer:

  1. What information do we collect?
  2. Why do we collect it?
  3. Where is it stored?
  4. Who can access it?
  5. With whom is it shared?
  6. How is it protected?
  7. How long is it retained?
  8. How is it securely disposed of?

4. The Written Information-Security Program

A covered dealership must develop, implement, and maintain a written information-security program containing safeguards appropriate to its size and complexity, the nature and scope of its activities, and the sensitivity of the customer information at issue.

The word “written” should not obscure the operational requirement. A downloaded policy that does not match the dealership’s systems, personnel, vendors, and practices may create a false sense of security. The program should identify responsible persons, describe the dealership’s controls, incorporate the risk assessment, and establish how the program will be reviewed and updated.

A functioning program ordinarily brings together:

  • Governance and accountability;
  • Risk assessment;
  • System, device, data, and vendor inventories;
  • Access controls;
  • Encryption;
  • Multi-factor authentication;
  • Secure software and application practices;
  • Data-retention and disposal procedures;
  • Change management;
  • Logging and user monitoring;
  • Security testing;
  • Personnel training;
  • Service-provider oversight;
  • Incident response; and
  • Management or governing-body reporting where required.

The requirements are summarized here, but the dealership’s program must be tailored. A single-rooftop dealer and a multistate group may implement different programs while remaining subject to the same fundamental standard.

5. Designating the Qualified Individual

The Rule requires designation of a Qualified Individual responsible for overseeing, implementing, and enforcing the information-security program.

The Qualified Individual may be:

  • A dealership employee;
  • An employee of an affiliate;
  • An outside consultant; or
  • A service provider.

The Rule does not require a particular degree, certification, or job title. But the individual must have knowledge and capability appropriate to the dealership’s systems, risks, and program.

Outsourcing does not transfer responsibility

If an affiliate or service provider supplies the Qualified Individual, the dealership must still:

  • Retain responsibility for compliance;
  • Designate a senior member of dealership personnel to direct and oversee the Qualified Individual; and
  • Require the affiliate or service provider to maintain an appropriate information-security program protecting the dealership.

The general manager should therefore not assume that naming the IT vendor’s employee on a form completes the requirement. The dealership should define authority, reporting lines, access to management, documentation duties, escalation procedures, and the resources available to the Qualified Individual.

Questions management should ask

  • Who is the Qualified Individual?
  • Is the designation written and current?
  • Does the person understand dealership operations as well as technology?
  • Can the person obtain information from every relevant department?
  • Who acts when that person is unavailable?
  • Who within dealership management oversees an outside Qualified Individual?
  • How are unresolved risks presented to ownership or senior management?

6. The Risk Assessment: The Foundation of the Program

The Rule requires the information-security program to be based on an assessment of reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information, together with an assessment of whether existing safeguards adequately control those risks.

For institutions subject to the full written-risk-assessment requirements, the assessment must include criteria for evaluating and categorizing risks, assessing confidentiality, integrity, availability, and existing controls, and explaining how identified risks will be mitigated or accepted.

A dealership risk assessment should address realities such as:

  • Phishing and credential theft;
  • Business-email compromise;
  • Fake lender, OEM, executive, or vendor messages;
  • Ransomware;
  • Shared usernames and weak passwords;
  • Missing MFA;
  • Excessive access privileges;
  • Former employees retaining access;
  • Remote-access software;
  • Unmanaged personal devices;
  • Unencrypted laptops, backups, files, or transmissions;
  • Paper records left on desks or in open storage;
  • Publicly accessible scanner folders;
  • Unpatched systems and unsupported software;
  • Misconfigured cloud storage;
  • Vendor integrations and support accounts;
  • Dealership acquisitions and data migrations;
  • Inadequate backups or restoration testing;
  • Insider misuse;
  • Physical theft; and
  • Failure to recognize and escalate a security event.

Risk acceptance should be a decision—not an accident

Not every risk can be eliminated immediately. When management accepts a risk, the decision should be informed, documented, time-limited where appropriate, and revisited. “We have always done it that way” is not a risk-management rationale.

The assessment should also be repeated periodically and when material changes occur; for example, a new DMS, acquisition, new digital-retail platform, major integration, facility move, change in remote access, significant incident, or discovery of a new threat.

7. Access Controls and the Employee Lifecycle

Access should be limited to authorized users and to the customer information each person needs to perform assigned duties. This is the principle of least privilege.

Dealer-specific controls should address:

  • Unique user credentials;
  • Role-based permissions;
  • Separate administrator accounts;
  • Approval of elevated access;
  • Periodic access reviews;
  • Prompt removal of terminated users;
  • Changes when an employee transfers departments;
  • Temporary employees and outside contractors;
  • Vendor and OEM support accounts;
  • Remote access;
  • Shared workstations;
  • Physical access to records and server areas; and
  • Emergency or break-glass access.

Shared accounts undermine accountability and may make it difficult to determine who viewed, changed, exported, or deleted information. A dealer should also coordinate HR, department management, and IT so that access changes occur promptly, not days or weeks after a departure.

Department does not equal entitlement

An employee’s ability to view information should be based on job duties. A salesperson may not need the same access as an F&I manager. A service advisor may need customer contact and vehicle data without needing a Social Security number or credit report. A marketing vendor may need a limited audience list without needing access to the DMS.

8. Multi-Factor Authentication

The Rule generally requires multi-factor authentication for any individual accessing an information system unless the Qualified Individual approves in writing the use of reasonably equivalent or more secure controls.

MFA requires more than a password. It uses at least two different categories of authentication, such as something the user knows, possesses, or is. A password followed by another knowledge-based question may not provide the protection management assumes.

Dealers should evaluate MFA across:

  • Email;
  • DMS and CRM accounts;
  • Lender portals;
  • Cloud storage;
  • Remote access;
  • Administrator accounts;
  • OEM platforms;
  • Accounting systems;
  • Vendor support tools; and
  • Other systems that provide direct or indirect access to customer information.

MFA on email alone does not establish full compliance. Legacy applications, generic accounts, automated integrations, and vendor-controlled platforms require documented analysis. If a system cannot support MFA, the dealership should not simply ignore the gap. The Qualified Individual must evaluate and approve any reasonably equivalent or stronger alternative in writing.

Dealers should also train employees never to approve an unexpected authentication prompt. MFA fatigue attacks can succeed when a user repeatedly receives requests and eventually presses “approve.”

9. Encryption

The Rule requires customer information held or transmitted by the dealership to be protected by encryption both:

  • In transit over external networks; and
  • At rest.

If encryption is infeasible, effective compensating controls must be reviewed and approved by the Qualified Individual.

Encryption questions may arise when customer information is:

  • Stored on servers or workstations;
  • Saved on laptops or removable media;
  • Included in backups;
  • Sent by email;
  • Uploaded to a lender or OEM portal;
  • Downloaded from an application;
  • Shared with an attorney, accountant, vendor, or customer;
  • Stored in a scanner or printer; or
  • Exported into a spreadsheet.

Password protection is not necessarily encryption. Nor should the dealer assume that every cloud platform or portal encrypts information in every relevant state. The dealership should obtain and retain reliable documentation concerning how data is protected.

Encryption keys matter

For purposes of the FTC notification provision, information may be treated as unencrypted if the encryption key was accessed by an unauthorized person. Therefore, key management and credential security can be as important as the encryption technology itself.

10. Secure Applications, Change Management, Logging, and Monitoring

Dealerships often depend on externally developed applications and integrations. The Rule requires secure development practices for in-house applications handling customer information and procedures for evaluating or testing externally developed applications.

Dealers should maintain a controlled process for:

  • Introducing new software;
  • Activating integrations;
  • Changing security configurations;
  • Approving remote access;
  • Applying updates and patches;
  • Adding or replacing vendors;
  • Migrating data;
  • Changing retention settings; and
  • Decommissioning systems.

A new application should not enter the dealership because an employee found it convenient and created an account with a company credit card. Unapproved “shadow IT” can create unmanaged data flows and unknown contractual obligations.

The dealership must also implement controls designed to monitor and log authorized-user activity and detect unauthorized access, misuse, or tampering. Logs are valuable only if they are appropriately retained, protected, and reviewed or connected to an effective alerting process.

11. Testing and Vulnerability Management

The full Rule requires regular testing or monitoring of key safeguards, including systems and controls designed to detect actual and attempted attacks.

For relevant information systems, the Rule calls for effective continuous monitoring or, absent such monitoring:

  • Annual penetration testing, based on identified risks; and
  • Vulnerability assessments at least every six months, as well as after material changes or when circumstances may materially affect the program.

These terms should not be treated as interchangeable:

  • Antivirus detects certain malicious software.
  • A vulnerability scan identifies known weaknesses.
  • A penetration test attempts to exploit weaknesses within an authorized scope.
  • Continuous monitoring identifies relevant activity or changes on an ongoing basis.
  • A compliance review evaluates whether required processes and controls exist.

A dealer should verify exactly what a vendor is providing, what systems are included, what is excluded, how findings are prioritized, and whether remediation is documented and retested.

12. Employee Security Awareness and Training

Technology cannot compensate for employees who do not recognize or report threats. Training should be updated to reflect the dealership’s current risks and should be relevant to actual job functions.

Dealer training should address:

  • Phishing and malicious links;
  • Fake lender, OEM, vendor, customer, and executive messages;
  • Business-email compromise;
  • MFA prompt attacks;
  • Password and account security;
  • Social engineering and caller verification;
  • Fraudulent payment or bank-change instructions;
  • Customer identity verification;
  • Secure handling of credit applications and identification;
  • Paper-record security;
  • Personal email and device restrictions;
  • Remote-work practices;
  • Reporting lost devices or misdirected email;
  • Incident escalation; and
  • Consequences of bypassing safeguards.

Annual training may be useful, but the program should also include onboarding, role-specific instruction, periodic reminders, simulated exercises where appropriate, and prompt updates after significant threats or incidents.

Management should retain evidence of attendance, content, dates, and follow-up, not merely a statement that training occurred.

13. OEMs, DMS Providers, and Other Service Providers

Dealer data routinely flows to organizations outside the dealership. Those relationships require classification and oversight, not assumptions.

An OEM is not automatically a service provider

The FTC’s dealer FAQs explain that an OEM does not become a Safeguards Rule service provider merely because the dealership shares information with it. The OEM must be providing a service to the dealer that involves access to customer information.

For example, an OEM receiving names and addresses so it can send recall notices may not occupy the same role as an OEM-controlled platform that hosts, processes, or analyzes dealership customer information. The answer depends on the function performed and the reason for access.

Questions should include:

  • What information does the OEM receive?
  • Why does it receive the information?
  • Is it providing the dealership a service?
  • Does it use information for its own purposes?
  • Which systems or integrations transmit the data?
  • Who controls access and retention?
  • Who investigates and reports an incident?
  • What contractual or program terms apply?

DMS and cloud providers do not absorb the dealer’s duties

A DMS provider, CRM company, digital-retail vendor, managed-service provider, cloud host, document-storage company, or cybersecurity vendor may supply important safeguards. The dealership nevertheless retains responsibility for reasonable selection, contracting, and periodic assessment.

The Rule requires covered dealers to:

  1. Take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards;
  2. Require service providers by contract to implement and maintain appropriate safeguards; and
  3. Periodically assess providers based on the risks presented and the continued adequacy of their safeguards.

Vendor contract topics

Depending on the service and risk, contracts should address:

  • Permitted use of customer information;
  • Appropriate administrative, technical, and physical safeguards;
  • Access controls and personnel obligations;
  • Encryption and secure transmission;
  • Incident notification deadlines;
  • Cooperation with investigations and regulatory analysis;
  • Preservation of evidence;
  • Subcontractors;
  • Data location and remote access;
  • Business continuity and backups;
  • Return or deletion of data;
  • Audit reports, certifications, or assessments;
  • Cyber-insurance;
  • Indemnification and limitations of liability;
  • Termination assistance; and
  • Allocation of responsibility for customer and regulatory communications.

The safeguards appropriate for a marketing vendor receiving a limited list may differ from those required of a DMS provider hosting financing records. The analysis should be risk-based, but it should be documented.

14. The Limited Exception for Fewer Than 5,000 Consumers

One of the most dangerous misconceptions is: “We have fewer than 5,000 customers, so we are exempt.”

The Rule provides limited relief to a financial institution that maintains customer information concerning fewer than 5,000 consumers. It removes only specified requirements, including certain provisions governing:

  • The prescribed content of the written risk assessment;
  • Continuous monitoring, penetration testing, and vulnerability assessments;
  • The written incident-response plan; and
  • Annual reporting to the board or senior officer.

It is not a blanket exemption from the Safeguards Rule.

A qualifying dealership generally remains subject to other requirements, including those concerning:

  • A Qualified Individual;
  • An information-security program based on risk assessment;
  • Access controls;
  • System and data management;
  • Encryption;
  • Secure application practices;
  • MFA or approved equivalent controls;
  • Retention and disposal;
  • Change management;
  • Logging and monitoring;
  • Employee training;
  • Service-provider oversight;
  • Program adjustment; and
  • FTC notification of qualifying events.

Count carefully

The relevant concept is customer information maintained concerning fewer than 5,000 consumers. It is not necessarily limited to:

  • Current-year sales;
  • Active customers;
  • One rooftop’s recent transactions; or
  • Consumers in the primary DMS.

Historical records, archives, backups, acquired databases, and shared systems may affect the count. A dealer should document the methodology and revisit it as records and operations change.

Even where the exception technically applies, a written incident-response plan, periodic testing, and senior-management reporting may remain sound business practices or may be required by insurers, lenders, OEMs, contracts, or other laws.

15. Retention and Secure Disposal

Keeping information indefinitely can increase cost and risk. The Rule requires procedures for secure disposal of customer information in any format no later than two years after the last date it is used in connection with the relevant product or service, unless:

  • The information is necessary for business operations;
  • It is needed for another legitimate business purpose;
  • Retention is required by law or regulation; or
  • Targeted disposal is not reasonably feasible because of the manner in which the information is maintained.

The dealership must also periodically review its retention policy to minimize unnecessary retention.

Two years is not a universal destruction date

The Rule does not simply require destruction two years after a document is created. The analysis concerns the last relevant use and recognizes legitimate exceptions. Other laws, litigation holds, contracts, audits, tax obligations, warranty matters, and operational needs may require longer retention.

The dealer should harmonize those obligations rather than adopting an arbitrary delete-everything rule.

Places forgotten data may remain

  • Paper deal jackets;
  • Declined or abandoned applications;
  • Email attachments;
  • Downloads from lender portals;
  • Local desktop folders;
  • Shared drives;
  • Temporary scanner folders;
  • Photocopier and printer memory;
  • Employee-created spreadsheets;
  • Old laptops and portable drives;
  • Cloud backups;
  • Vendor-hosted archives;
  • Former DMS or CRM platforms; and
  • Data inherited in an acquisition.

Secure disposal should render the information unreadable and unrecoverable as appropriate to the medium. Throwing documents into ordinary trash or deleting a file while recoverable copies remain elsewhere may not accomplish that purpose.

16. Incident Response: Prepare Before the Crisis

For institutions subject to the full requirement, the Rule requires a written incident-response plan designed to respond to and recover from security events materially affecting the confidentiality, integrity, or availability of customer information.

The plan must address:

  • Its goals;
  • Internal response processes;
  • Clear roles, responsibilities, and decision-making authority;
  • Internal and external communications;
  • Remediation of identified weaknesses;
  • Documentation and reporting; and
  • Evaluation and revision after a security event.

A useful dealership plan should answer practical questions:

  • Who receives the first report?
  • Who has authority to disconnect systems or disable accounts?
  • Who contacts counsel and the cyber insurer?
  • Who retains a forensic investigator?
  • Who contacts the DMS, OEM, lender, or affected vendor?
  • Who preserves logs, emails, devices, and other evidence?
  • Who determines the discovery date?
  • Who evaluates FTC and state reporting duties?
  • Who approves communications with employees, customers, media, and regulators?
  • How will the dealership operate if core systems are unavailable?

Do not destroy evidence while trying to contain the incident

Well-intentioned actions, reimaging a device, deleting messages, resetting accounts without preserving logs, or allowing a vendor to overwrite data, can impair the investigation. Containment and preservation should be coordinated.

Practice the plan

A tabletop exercise can reveal missing contacts, unclear authority, unavailable backups, incompatible vendor procedures, and uncertainty concerning legal notification. The time to learn that no one has the insurer’s hotline or the DMS escalation contact is not during a ransomware event.

17. FTC Notification: The Requirement Effective May 13, 2024

The FTC notification provision became effective on May 13, 2024. A covered financial institution must notify the FTC as soon as possible and no later than 30 days after discovery of a notification event involving the information of at least 500 consumers. See 16 C.F.R. § 314.4(j) and the FTC’s notification guidance.

What is a notification event?

A notification event involves unauthorized acquisition of unencrypted customer information. Information is treated as unencrypted if an unauthorized person accessed the encryption key.

Unauthorized acquisition is presumed when there has been unauthorized access to unencrypted customer information unless reliable evidence demonstrates that unauthorized acquisition did not or could not reasonably have occurred.

This means “we cannot prove the attacker downloaded it” may not end the analysis. Logs, forensic evidence, system architecture, access duration, and the nature of the compromise may become critical.

When is an event discovered?

An event is treated as discovered on the first day it is known to the institution. Knowledge may be attributed to the dealership when the event is known to an employee, officer, or other agent other than the person committing the breach.

Dealers should not assume that the 30-day period begins only when:

  • The general manager learns of the incident;
  • A forensic report is complete;
  • The dealer confirms data exfiltration;
  • The insurer approves counsel; or
  • The total number of affected consumers is finally known.

Prompt internal escalation and careful documentation of the earliest known facts are essential.

What must the notice contain?

The FTC notice must include specified information, including:

  • The institution’s name and contact information;
  • The types of information involved;
  • The date or date range, if reasonably determinable;
  • The number of consumers affected or potentially affected;
  • A general description of the event; and
  • Information concerning any qualifying written law-enforcement determination requesting delay.

Law-enforcement delay

A law-enforcement official may request an initial delay of up to 30 days after notice is provided to the FTC. A written request may support an extension of up to 60 additional days. Further delay requires an FTC staff determination that public disclosure would continue to impede a criminal investigation or damage national security.

The dealership should not assume that an informal conversation with law enforcement suspends its obligations.

FTC notification is not the entire breach analysis

A security event may also trigger:

  • State breach-notification laws;
  • Consumer notice;
  • Notice to state regulators or attorneys general;
  • Cyber-insurance requirements;
  • Contractual notice to lenders, OEMs, vendors, or payment processors;
  • Law-enforcement contact;
  • Payment-card obligations; and
  • Other federal requirements.

Conversely, an event falling below the FTC’s 500-consumer threshold may still trigger other legal or contractual duties.

A practical decision path

When an incident occurs, ask promptly:

  1. Does the event involve customer information?
  2. Was there unauthorized access or acquisition?
  3. Was the information encrypted?
  4. Was an encryption key compromised?
  5. Is unauthorized acquisition presumed?
  6. How many consumers are affected or potentially affected?
  7. What is the earliest defensible discovery date?
  8. Does FTC notification apply?
  9. What other federal, state, contractual, and insurance notices must be evaluated?

These decisions should be made with qualified legal and forensic assistance, not by guesswork.

18. The Privacy Rule, Disposal Duties, Red Flags, and Other Overlaps

The Safeguards Rule does not stand alone. A dealer may comply with one framework while failing another.

FTC Privacy Rule

The Privacy Rule addresses privacy notices and certain disclosures of nonpublic personal information. The Safeguards Rule addresses protection of customer information. Their subject matter overlaps, but compliance with a privacy-notice requirement does not establish that the dealership has implemented the required security program. See FTC’s Privacy Rule and Auto Dealers: FAQs.

Disposal obligations

Secure disposal appears within the Safeguards Rule and may also be affected by other legal requirements. A retention schedule should identify both minimum retention obligations and the point at which continued storage becomes unnecessary.

Red Flags Rule

Where applicable, the Red Flags Rule concerns identity-theft prevention. A dealer may need both an identity-theft prevention program and a Safeguards Rule information-security program. One should not be relabeled as the other.

State laws and contracts

State data-breach, cybersecurity, privacy, recording, biometric, consumer-protection, and records laws may impose additional obligations. Lenders, OEMs, payment processors, insurers, and vendors may impose contractual requirements that are more specific or operate on different timelines.

This Codex focuses on the federal FTC framework. A dealership’s complete compliance analysis must account for the jurisdictions in which it operates and the individuals whose information it maintains.

19. Dealer Groups, Shared Systems, and Acquisitions

Centralized compliance can create efficiencies, but it does not make legal entities or risks disappear.

A dealer group should consider:

  • Which entities are covered financial institutions;
  • Whether customer information is shared across entities;
  • Whether rooftops share a DMS, CRM, network, accounting department, or Qualified Individual;
  • Which entity contracts with each provider;
  • Whether one written program accurately addresses each operation;
  • How incidents are escalated across the group;
  • Which board, governing body, owner, or senior officer receives required reporting; and
  • Whether each entity can produce evidence of its compliance.

Acquisitions create elevated risk

A dealership acquisition may introduce:

  • Unknown legacy credentials;
  • Former employees with active access;
  • Unsupported software;
  • Old remote-access tools;
  • Unidentified vendor integrations;
  • Historical customer databases;
  • Inadequate backups;
  • Data-retention problems;
  • Unreported prior incidents;
  • Conflicting policies; and
  • Unclear responsibility during transition.

Cybersecurity diligence should begin before closing when practicable. Post-closing integration should include credential resets, access review, system inventory, vendor review, risk reassessment, retention analysis, and documentation of data migration.

20. Annual Reporting and Management Accountability

For institutions not within the limited exception, the Qualified Individual must report in writing, regularly and at least annually, to the board of directors or equivalent governing body. If none exists, the report must be presented to a senior officer responsible for the information-security program.

The report must address:

  • The overall status of the program;
  • Compliance with the Rule; and
  • Material matters such as risk assessment, control decisions, service-provider arrangements, testing results, security events or violations, management responses, and recommendations for change.

For a closely held dealer, “we do not have a formal corporate board meeting” does not make the requirement disappear. The dealership should identify the equivalent governing body or responsible senior officer and establish a repeatable reporting process.

A useful report does more than say “compliant.” It identifies important risks, unresolved remediation, incidents, vendor concerns, testing results, resource needs, and decisions required from management.

21. Myth Versus Reality

MythReality
“We sell cars, not financial products.”A dealer that regularly extends credit, arranges financing, or enters into qualifying leases may be a financial institution under the Rule.
“Our IT company handles compliance.”A service provider may perform important work, but the dealership retains responsibility.
“We have fewer than 5,000 customers, so the Rule does not apply.”The limited exception removes only specified requirements, and the count concerns customer information maintained.
“MFA on email is enough.”MFA must be evaluated across information systems, subject to the Rule’s written-equivalent-control provision.
“The DMS provider owns the security problem.”The dealer must reasonably select, contract with, and periodically assess service providers.
“An OEM is always our service provider.”The role depends on whether the OEM provides the dealer a service involving access to customer information.
“Cyber insurance proves compliance.”Insurance may support response and risk transfer, but it does not establish compliance with the Rule.
“Our privacy notice satisfies the Safeguards Rule.”Privacy notices and information-security safeguards are separate obligations.
“Only F&I records count.”Customer information may be copied into email, shared drives, scanners, accounting systems, backups, vendor platforms, and other departments.
“Encrypted information never requires analysis.”The encryption key may be compromised, and other legal or contractual notice duties may apply.
“The 30-day period starts after forensics confirms a breach.”Discovery may occur when an employee, officer, or agent first knows of the event.
“No download means no notification event.”Unauthorized acquisition may be presumed from unauthorized access to unencrypted customer information unless reliable evidence rebuts the presumption.
“We can keep records forever because storage is inexpensive.”The Rule requires disposal procedures and periodic review to minimize unnecessary retention, subject to recognized exceptions.
“We bought a policy template, so we are finished.”The program must be implemented, tested, adjusted, supervised, and supported by documentation.

22. Department-Specific Checklists

Dealer principal, ownership, and senior management

  • Confirm which entities and operations are covered.
  • Designate and empower the Qualified Individual.
  • Allocate adequate personnel and resources.
  • Review material risks and unresolved remediation.
  • Receive the required written report where applicable.
  • Ensure cyber insurance, contracts, and response procedures are coordinated.
  • Avoid treating cybersecurity as solely an IT expense.

Qualified Individual

  • Maintain the written information-security program.
  • Keep the risk assessment current.
  • Maintain data, system, device, user, and vendor inventories.
  • Document compensating controls and risk acceptance.
  • Coordinate access reviews, testing, training, and remediation.
  • Monitor material operational and threat changes.
  • Maintain incident-response readiness.
  • Prepare governing-body or senior-officer reports where required.

Sales and F&I

  • Collect only information needed for authorized purposes.
  • Avoid leaving applications and identification unattended.
  • Use approved systems and secure transmission methods.
  • Do not send customer information through personal email or unapproved messaging.
  • Verify recipients before transmitting documents.
  • Report misdirected emails, lost paperwork, suspicious activity, and account prompts immediately.
  • Do not share credentials.
  • Follow approved customer-identity verification procedures.

Accounting

  • Verify payment and bank-change instructions through an independent channel.
  • Restrict access to financial and customer records.
  • Use approved secure transmission methods.
  • Recognize executive and vendor impersonation.
  • Coordinate incident escalation for fraudulent payments and compromised email.
  • Review access after staffing changes.

Service and parts

  • Understand which customer information appears in scheduling, repair-order, loaner, payment, and manufacturer systems.
  • Protect printed repair orders and identification.
  • Avoid unnecessary access to financing information.
  • Use approved payment and communication systems.
  • Secure shared workstations and tablets.
  • Escalate suspicious links, account behavior, or vendor requests.

Human resources

  • Coordinate onboarding, transfer, leave, and termination access changes.
  • Maintain current confidentiality and acceptable-use policies.
  • Track security training.
  • Notify responsible personnel promptly of departures.
  • Protect employee information under applicable requirements even when it is outside the Safeguards Rule.

IT and managed-service providers

  • Maintain inventories and secure configurations.
  • Implement MFA, encryption, logging, patching, backups, and access controls.
  • Restrict and monitor remote access.
  • Preserve evidence during incidents.
  • Document testing, findings, remediation, and retesting.
  • Coordinate with the Qualified Individual rather than making undocumented compliance assumptions.

Vendor management

  • Classify vendors by data access and operational risk.
  • Perform risk-appropriate diligence.
  • Maintain security contract provisions.
  • Track incident contacts and notice terms.
  • Periodically reassess safeguards.
  • Remove access and confirm data disposition at termination.

Used-vehicle and acquisition teams

  • Identify legacy systems and inherited data.
  • Reset access and remove former users.
  • Review old vendor integrations.
  • Securely migrate or dispose of records.
  • Confirm responsibility during transition.
  • Include cybersecurity in acquisition diligence and integration planning.

23. The First 24 Hours After a Suspected Security Event

The appropriate response depends on the event, but the dealership should be prepared to:

  1. Escalate immediately. Notify the designated internal response team, Qualified Individual, management, and counsel as appropriate.
  2. Record the timeline. Document who learned what, when, and from whom. The discovery date may affect legal deadlines.
  3. Contain carefully. Limit ongoing harm without unnecessarily destroying logs, devices, messages, or other evidence.
  4. Preserve evidence. Coordinate preservation of affected systems, emails, access logs, alerts, and relevant communications.
  5. Contact the cyber insurer. Follow policy requirements before retaining vendors when practicable.
  6. Engage qualified assistance. Legal and forensic support may be necessary to determine scope, privilege, and notification obligations.
  7. Coordinate with providers. Contact affected DMS, cloud, OEM, lender, payment, or technology providers through established escalation channels.
  8. Identify affected information. Determine what systems, data categories, and consumers may be involved.
  9. Assess encryption and keys. Determine whether data was encrypted and whether keys or credentials were compromised.
  10. Evaluate notices. Calendar the FTC deadline if potentially applicable and analyze state, contractual, insurance, and other duties.
  11. Control communications. Use approved internal and external communications. Avoid unsupported assurances or speculation.
  12. Maintain operations safely. Activate business-continuity procedures without reconnecting compromised systems prematurely.


Do not wait for perfect information before escalating. Early uncertainty is normal. The response process should gather and refine facts while preserving deadlines and evidence.

24. A 30/60/90-Day Compliance Roadmap

First 30 days: establish responsibility and visibility

  • Confirm coverage and relevant legal entities.
  • Designate or reconfirm the Qualified Individual.
  • Identify internal senior oversight.
  • Inventory systems, devices, data repositories, and critical integrations.
  • Inventory vendors with access to customer information.
  • Identify immediate MFA, encryption, terminated-user, remote-access, and backup gaps.
  • Locate existing policies, assessments, contracts, tests, and training records.
  • Confirm incident contacts for counsel, insurer, forensics, DMS, OEMs, and critical providers.

By 60 days: assess and address priority risk

  • Complete or update the risk assessment.
  • Categorize findings and assign remediation owners and deadlines.
  • Review access by role and remove unnecessary accounts.
  • Confirm encryption and MFA coverage or document approved alternatives.
  • Review high-risk vendor contracts and diligence.
  • Update retention and secure-disposal procedures.
  • Draft or update incident-response materials.
  • Deliver targeted employee training.

By 90 days: test, document, and establish recurring governance

  • Complete required vulnerability assessments or penetration testing as applicable.
  • Test backups and restoration.
  • Conduct an incident-response tabletop exercise.
  • Remediate and retest priority findings.
  • Complete required management or governing-body reporting.
  • Establish recurring access reviews, vendor assessments, training, testing, and policy updates.
  • Document risk acceptance and compensating controls.
  • Confirm how regulatory and contractual developments will be monitored.

This roadmap is a starting framework, not a guarantee of compliance. Critical risks should not wait for a later milestone merely because they appear in a 60- or 90-day category.

25. What Evidence Should the Dealership Be Able to Produce?

A compliant program should leave a record. Depending on the dealership and applicable requirements, useful evidence may include:

  • The written information-security program;
  • Written designation of the Qualified Individual;
  • Internal oversight documentation;
  • Current and prior risk assessments;
  • Data, system, device, application, and vendor inventories;
  • Data-flow maps;
  • User-access approvals and periodic reviews;
  • Termination and transfer records;
  • MFA and encryption documentation;
  • Written alternative-control approvals;
  • Security configurations and change records;
  • Training materials and attendance records;
  • Vulnerability assessments and penetration-test reports;
  • Remediation plans and retesting results;
  • Vendor diligence and contracts;
  • Incident-response plans and exercise records;
  • Security-event logs and response documentation;
  • Retention schedules and disposal records;
  • Backup and restoration-test records; and
  • Annual reports to the board, equivalent governing body, or senior officer where required.

Documentation should be accurate. Creating backdated, generic, or misleading records after an incident can worsen the dealership’s position. The objective is to show a living program in which risks are identified, decisions are made, safeguards are implemented, and deficiencies are addressed.

26. Questions a Dealer Should Ask Its IT or Compliance Provider

  • Are you serving as our Qualified Individual, or merely providing technical support?
  • Which Safeguards Rule obligations do you perform, and which remain with us?
  • Do we have a current written risk assessment specific to our dealership?
  • Which systems containing customer information lack MFA?
  • Where is customer information not encrypted at rest or in transit?
  • How are administrator, vendor, and remote-access accounts controlled?
  • How quickly are terminated users disabled?
  • What logs are collected, how long are they retained, and who reviews alerts?
  • Do we have continuous monitoring? If not, when were the last penetration test and vulnerability assessments?
  • Which systems were excluded from testing?
  • How are critical findings tracked and retested?
  • When were backups last restored successfully?
  • Which vendors have access to customer information?
  • Do their contracts require appropriate safeguards and prompt incident notice?
  • What happens if our DMS, internet, email, or identity system is unavailable?
  • Who will preserve evidence and coordinate forensics after an incident?
  • How will we determine whether 500 consumers may be affected?
  • Who calendars and evaluates the FTC’s 30-day notification deadline?
  • What evidence can we produce today to demonstrate implementation?

A provider should be able to explain limitations and assumptions. A confident “you are fully compliant” without a dealership-specific review should invite more questions, not fewer.

27. Key Takeaways

  • Most dealers that finance, facilitate financing, or enter into qualifying leases are likely covered financial institutions.
  • The Safeguards Rule requires a written, implemented, and maintained information-security program—not merely a policy binder.
  • A Qualified Individual must oversee and enforce the program.
  • Outsourcing IT or the Qualified Individual role does not transfer responsibility away from the dealership.
  • The program must be based on actual dealership risks and actual data flows.
  • Customer information may exist far beyond the F&I office.
  • Access controls, encryption, MFA, secure disposal, change management, logging, training, and vendor oversight are central requirements.
  • OEM status must be evaluated by function; an OEM is not automatically a service provider.
  • The fewer-than-5,000-consumers provision is a limited exception from specified requirements, not a wholesale exemption.
  • The Rule generally calls for disposal procedures no later than two years after the last relevant use, subject to legitimate exceptions.
  • A qualifying notification event involving at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery.
  • Discovery may be attributed when an employee, officer, or agent learns of the event.
  • FTC notification does not replace state, consumer, insurer, lender, OEM, payment-card, or contractual analysis.
  • Documentation is essential to demonstrating that the program exists in practice.

Conclusion

For automotive dealerships, cybersecurity compliance is not an abstract technical exercise. It is a business-governance obligation tied directly to the way customer information moves through sales, F&I, accounting, service, online retail, lender relationships, OEM systems, vendors, and dealer-group infrastructure.

The FTC Safeguards Rule does not demand identical technology from every dealership. It does require each covered dealer to understand its information environment, evaluate foreseeable risks, implement required and appropriate safeguards, supervise service providers, prepare for incidents, and adjust the program as threats and operations change.

The dealerships best positioned to respond will not be those with the longest policy manual. They will be those that can answer basic operational questions with evidence: Who is responsible? What information do we maintain? Where is it? Who has access? How is it protected? Which vendors receive it? When is it deleted? What happens when a control fails? Who decides whether notice is required?

A dealer that cannot answer those questions should not wait for an incident, an insurer inquiry, a lender review, or an FTC investigation to begin.

For assistance evaluating Safeguards Rule coverage, dealership information-security programs, risk assessments, vendor agreements, OEM relationships, retention policies, incident-response procedures, or customer and regulatory notification obligations, contact CorwinLaw:

https://www.corwinlaw.net

The CorwinLaw Codex

This Codex is provided by CorwinLaw, www.corwinlaw.net, for general educational and informational purposes only. It is not legal, accounting, financial, tax, or privacy specific advice. Reading this Codex, visiting a website, or contacting CorwinLaw does not create an attorney-client relationship. An attorney-client relationship should arise only through a written engagement agreement accepted by CorwinLaw and the client. Do not send confidential or time-sensitive information unless and until CorwinLaw confirms that it represents you in the matter.

Explore additional legal guides, practical resources, and practice-area reference materials at:

https://www.corwinlaw.net