If your dealership finances or arranges financing or leasing, the FTC considers you a financial institution, and the Safeguards Rule has been fully mandatory since June 9, 2023. Here is the entire rule, translated into the ten things your store must do, what each one takes, and how to prove it is done.
By DealSafe | Reading time: 6 minutes | Last reviewed: September 2026. This article is information, not legal advice.
Almost certainly, yes. The FTC's own dealer-specific FAQ says it directly: most automobile dealers who finance or lease automobiles are financial institutions under the Safeguards Rule. If your F&I office sends deals to lenders, you are covered. If you are a Buy Here Pay Here store extending the credit yourself, you are covered twice over: as a financial institution under Safeguards and as a creditor under the Red Flags Rule.
There is one partial exemption. Dealerships holding customer information on fewer than 5,000 consumers are excused from four requirements: the written risk assessment, monitoring and testing, the written incident response plan, and the annual board report. Everything else (the Qualified Individual, access controls, encryption, multi-factor authentication, training, and vendor oversight) still applies.
Violations of FTC rules carry civil penalties of up to $53,088 per violation, the inflation-adjusted figure effective January 17, 2025. Violations can be counted per affected consumer.
There is also a newer exposure many dealers miss. Since May 13, 2024, you must notify the FTC as soon as possible, and no later than 30 days after discovery, of any breach involving unencrypted customer information of 500 or more consumers. Reports go through an FTC online form and are posted in a public database. Unauthorized access is presumed to be acquisition unless you have reliable evidence otherwise.
That is the risk. Here is the checklist that closes it.
Compliance is not the activity. It is the proof of the activity. Accountants who work dealer audits call the assembled record your Book of Evidence: signed program documents, the current risk assessment, training logs for every employee, access reviews, vendor contracts, testing results, the incident plan, and the board report.
After an incident, that file is often the difference between the FTC reading your store as negligent versus grossly negligent. Build it as a byproduct of running the program, not as a scramble when someone asks. A good standard: be able to produce the whole book within 48 hours of being asked.
Two things worth knowing. First, the FTC's CARS Rule, the separate retail rule covering advertising and add-ons, was vacated by the Fifth Circuit in January 2025 and formally withdrawn in February 2026. The court ruled on procedure only; it never said the targeted conduct was lawful, and the FTC continues to enforce the same principles under Section 5 of the FTC Act, case by case. In March 2026 the agency put 97 dealer groups on written notice over advertised pricing.
Second, enforcement against dealers is real and recent: a $20 million judgment against Leader Automotive Group in December 2024, and in April 2026 an agreement with Lindsay Automotive covering refunds on more than $75 million in consumer charges plus a $3.1 million civil penalty. The Safeguards Rule itself is enforced the same way, through consent orders and penalties, and every public breach report invites scrutiny of the whole program.
Print the ten items above. For each one, ask a single question: if an examiner asked tomorrow, could I hand over dated proof this is done? Every "no" is a gap. Every gap has an owner, a cost, and a fix.
If you want a second set of eyes, DealSafe offers a free gap assessment: a 30-minute working session that maps your store against this exact checklist, with the findings in writing whether or not you ever become a customer. You can also see how our Safeguards program handles each requirement, or check our published per-rooftop pricing.
It applies to dealers that finance or arrange financing or leasing for consumers, which covers most dealerships. The FTC's dealer FAQ says so explicitly. Dealers holding customer information on fewer than 5,000 consumers are exempt from four of the ten requirements, but not from the Qualified Individual, access controls, encryption, MFA, training, or vendor oversight.
Civil penalties run up to $53,088 per violation under FTC Act Section 5(m)(1)(A), effective January 17, 2025. Violations can be counted per affected consumer, so exposure compounds quickly across a customer database.
The amended rule's prescriptive provisions took effect June 9, 2023. The breach-notification requirement followed on May 13, 2024: report any breach of unencrypted information of 500 or more consumers to the FTC within 30 days of discovery.
An employee, someone at an affiliate, or a service provider. Many smaller stores assign the role to the GM or controller with outside support. The dealership keeps responsibility regardless of who holds the title.
No. The rule requires a running program: current risk assessment, monitored controls, MFA, training with logs, vendor contracts and reviews, an incident response plan, and an annual written board report. A binder alone is a snapshot, not a program.
Red Flags & ID verification for dealers · The Red Flags Rule for Auto Dealers