The FTC Safeguards Rule: What Dealers Keep Getting Wrong

July 1, 2026

Executive Summary

The FTC Safeguards Rule has been in full effect for over two years, yet many auto dealerships are still operating with security gaps that would fail an audit today. The rule treats dealerships as financial institutions, which means the compliance bar is higher than most owners realize. If your dealership arranges financing or leases vehicles, this rule applies to you and the FTC is actively enforcing it.

Why It Matters

The FTC Safeguards Rule was updated in 2023 with significantly expanded requirements for any business that qualifies as a "financial institution" under the Gramm-Leach-Bliley Act. Auto dealerships that finance or lease vehicles fall squarely into that category.

For years, the rule existed mostly as a background obligation. That changed. The FTC has grown more aggressive in enforcement, warning letters have gone out to hundreds of dealerships in recent months, and major lenders are now embedding Safeguards compliance addendums directly into dealer agreements. A gap in your security program is no longer just a regulatory risk. It can affect your ability to do business with the lenders you depend on.

The penalty structure reflects how seriously the FTC takes this. Violations can carry fines up to $50,120 per day per violation. That is not a one-time fine for getting caught. It accumulates. A dealership that discovers a gap in June and does not resolve it until September has been accruing penalties the entire time.

There is also a breach notification requirement added in 2024: if unauthorized parties gain access to unencrypted customer data for 500 or more individuals, the dealership must notify the FTC within 30 days. That is a tight window when most dealerships do not have a tested incident response process.

How It Impacts Dealerships

The customers who walk through your showroom leave behind significant financial data. Credit applications, income verification, Social Security numbers, banking history. The same is true for customers who finance parts or accessories purchases. That data sits in your DMS, your CRM, your email system, and in the systems of every vendor who touches your deal flow.

The Safeguards Rule does not just require that you secure your own systems. It requires that you verify your vendors are doing the same.

Dealerships with multiple locations, layered software systems, and years of accumulated vendor relationships often discover during an assessment that no one has a complete picture of where customer data actually lives. That is not a technology failure. It is a governance failure, and it is exactly the kind of gap that makes an audit painful.

The compliance failures that tend to catch dealerships off guard are rarely obvious. They are quiet ones: shared admin accounts that were never cleaned up, a DMS vendor that has not been audited in three years, MFA that was turned on for some systems but not all, and an incident response plan that exists as a document but has never been tested.

Leadership often believes the dealership is in better shape than it is, because the IT provider they use has not surfaced these issues clearly.

For more on consolidating the technology environment your dealership depends on, see Is Tech Sprawl Slowing Down Your Dealership?

What Steps Companies Can Take

Getting into real compliance is not a one-day project, but the starting point is simpler than most dealerships expect: an honest assessment of where you actually stand.

The rule requires a written information security program that covers seven key areas. Most dealerships have documentation somewhere, but it is often out of date, incomplete, or written in a way that does not reflect how the dealership actually operates.

Here is what a genuine compliance review needs to cover:

Qualified Individual. You must designate someone with authority and accountability for the security program. This person must report at least annually to senior leadership or the board. If your current IT support handles this role informally without a defined structure, that does not satisfy the requirement.

Risk Assessment. A documented assessment of where customer data exists, who has access to it, and what the realistic threats are. This is not a checkbox. The FTC expects this to be updated when significant changes happen, such as a new DMS system or a new vendor relationship.

Access Controls. Access to systems containing customer NPI should be limited to people who need it for their specific role. Shared accounts and lingering access from former employees are common findings.

Encryption. Customer data must be encrypted in transit and at rest. This includes data on laptops, in email, and across third-party systems.

Multi-Factor Authentication. MFA is mandatory for anyone accessing systems that hold customer NPI. That includes employees, vendors, and contractors. No exceptions under the rule.

Vendor Oversight. Every service provider with access to customer data needs a security review and a contract that includes data security provisions, breach notification language, and audit rights. Many dealerships have not revisited their vendor agreements since before the 2023 updates.

Incident Response Plan. You need a written plan. The plan needs to be tested annually. If neither is true, it is a compliance gap.

For a broader look at what a compliance audit process actually looks like, see The Compliance Audit Is Coming.

How an MSP Helps

The challenge with Safeguards compliance is that it lives at the intersection of IT operations and legal obligation. Most dealerships do not have someone internally who owns both.

An MSP that understands the Safeguards Rule can help a dealership build out the required program, close gaps in existing controls, and provide the ongoing monitoring and documentation the rule demands. More importantly, they can communicate clearly to dealership leadership where the exposure actually is rather than letting problems accumulate quietly.

Vendor audits are a common weak point. Your MSP should be helping you maintain a current list of every vendor with access to customer data, reviewing those vendors’ security practices, and ensuring your contracts include the required provisions. Most dealerships have never done this systematically.

The MFA requirement is another area where partial implementation creates false confidence. Turning on MFA for email but leaving DMS access or admin accounts unprotected does not satisfy the rule. An MSP that manages your environment should be able to tell you definitively which systems are covered and which are not.

Documentation is the third gap. Even dealerships with solid security practices often fail audits because they cannot produce the records the rule requires: risk assessments, security program reviews, training logs, vendor audit records, incident response test results. A good MSP builds this documentation as part of ongoing service, not as a scramble before an audit.

Best Practices and Key Takeaways

Assign a Qualified Individual with clear authority. This role needs to be formal, documented, and reporting to leadership at least annually.

Treat vendor contracts as security documents. Revisit every third-party agreement that involves customer data. Add security provisions, breach notification language, and audit rights if they are not already there.

Test your incident response plan. A written plan that has never been exercised will not hold up in a real breach, or in an FTC inquiry about your preparedness.

Do not treat MFA as optional anywhere. If a system touches customer NPI, it needs MFA. No carve-outs.

Update your risk assessment when things change. A new DMS, a new CRM, a staff change in your IT function. Any of these should trigger a review.

Keep records. Compliance is not just about what you do. It is about being able to prove what you do. Maintain documentation of your program, your assessments, your training, and your vendor oversight activity.

Engage your IT provider directly. If your current provider cannot give you a clear, documented picture of your Safeguards compliance posture, that is a meaningful gap.

FAQ

Does the FTC Safeguards Rule apply to every auto dealership?

It applies to dealerships that arrange financing or leases, which covers the vast majority of franchise dealers and many independent lots. If your dealership collects customer financial information as part of any transaction, you are almost certainly covered. The FTC provides specific guidance for dealers at ftc.gov, and the NADA has published compliance resources as well.

What happens if a dealership is found non-compliant?

The FTC can impose fines up to $50,120 per violation per day. Beyond that, dealerships found in violation may be subject to 20-year consent decrees requiring regular third-party security audits at the dealership’s own expense. There is also exposure to lender relationship termination and reputational damage that is difficult to quantify but very real.

Our IT provider says we are compliant. How do we verify that?

Ask them to show you the documentation. A compliant Safeguards program has a written WISP, a current risk assessment, documented access controls, a vendor oversight log, MFA coverage maps, an incident response plan with a test record, and annual training records. If your IT provider cannot produce these on request, compliance has not actually been verified.

We have a small IT team and limited budget. Where do we start?

Start with the gap that creates the most exposure: MFA. If you do not have MFA enforced across all systems that hold customer data, that is the first thing to close. After that, document what you have, assign your Qualified Individual formally, and build your vendor list. A phased approach works; the key is that each phase produces documented, durable results, not just activity.

Protecting your business starts with the right partner. Core Managed helps companies secure their data, scale efficiently, and stay compliant so you can focus on running the business. Give us a call at 888-890-2673 or contact us to schedule a conversation.

For more on how MSPs turn IT challenges into competitive advantages, read our feature in the Atlanta Business Chronicle.