Resources | DealSafe Dealership Compliance

The FTC Safeguards Rule for Auto Dealers: A Plain-English Checklist

Written by DealSafe | Sep 4, 2026, 1:48:47 AM

If your dealership finances or arranges financing or leasing, the FTC considers you a financial institution, and the Safeguards Rule has been fully mandatory since June 9, 2023. Here is the entire rule, translated into the ten things your store must do, what each one takes, and how to prove it is done.

By DealSafe | Reading time: 6 minutes | Last reviewed: September 2026. This article is information, not legal advice.

Does the Safeguards Rule apply to your dealership?

Almost certainly, yes. The FTC's own dealer-specific FAQ says it directly: most automobile dealers who finance or lease automobiles are financial institutions under the Safeguards Rule. If your F&I office sends deals to lenders, you are covered. If you are a Buy Here Pay Here store extending the credit yourself, you are covered twice over: as a financial institution under Safeguards and as a creditor under the Red Flags Rule.

There is one partial exemption. Dealerships holding customer information on fewer than 5,000 consumers are excused from four requirements: the written risk assessment, monitoring and testing, the written incident response plan, and the annual board report. Everything else (the Qualified Individual, access controls, encryption, multi-factor authentication, training, and vendor oversight) still applies.

The stakes, stated once

Violations of FTC rules carry civil penalties of up to $53,088 per violation, the inflation-adjusted figure effective January 17, 2025. Violations can be counted per affected consumer.

There is also a newer exposure many dealers miss. Since May 13, 2024, you must notify the FTC as soon as possible, and no later than 30 days after discovery, of any breach involving unencrypted customer information of 500 or more consumers. Reports go through an FTC online form and are posted in a public database. Unauthorized access is presumed to be acquisition unless you have reliable evidence otherwise.

That is the risk. Here is the checklist that closes it.

The dealership Safeguards checklist

    1. Name your Qualified Individual. One person accountable for the program. It can be your GM, your controller, or an outside service provider; the rule allows all three. Write the appointment down. Responsibility stays with the dealership either way.
    2. Write your risk assessment. Identify the reasonably foreseeable risks to customer information in your store: the showroom, the F&I office, the DMS, website leads, the service lane, shared logins on the sales floor. Record the criteria you used and how you will mitigate each risk. Reassess periodically and keep the versions.
    3. Control access. Limit customer information to people who need it for their job. Review access on a schedule. Kill shared DMS logins; five sales managers on one login is a finding waiting to happen.
    4. Encrypt customer information. At rest and in transit, or document a reasonable alternative. You cannot encrypt what you have not inventoried, so start with a list of every system that touches customer data.
    5. Turn on multi-factor authentication. MFA for anyone who accesses your information system: DMS, CRM, email, website backend. If a system genuinely cannot do MFA, the rule allows a reasonably equivalent control, but you must document the reasoning.
    6. Monitor and test. Continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months. NADA has estimated a standalone penetration test at roughly $23,000 per rooftop, which is why most stores coordinate testing through a program or their IT provider.
    7. Train everyone. Security awareness training for all staff, with specialized training for security personnel. This is where most stores quietly fail: sales consultant turnover hit 66 percent in 2024 per the NADA Dealership Workforce Study, so last year's training session no longer covers this year's sales floor. Training has to be assigned at hire and logged, or it does not count.
    8. Oversee your vendors. Choose service providers that can safeguard your data, require safeguards by contract, and reassess them periodically. Your DMS, CRM, website provider, and anyone else touching customer information belongs in the register. The DealerBuilt case is the cautionary tale: the FTC's flagship dealer-channel data-security action was against a dealership software provider whose exposed storage device compromised data on about 12.5 million consumers across 130 dealerships. It settled under a 20-year compliance order.
    9. Write the incident response plan. Roles, decision-making authority, remediation steps, documentation, and reporting procedures. Including the 30-day FTC clock from the section above. Drill it once a year. A plan nobody has opened since 2019 is a paper program, not a current one.
    10. Report to the board, annually, in writing. The Qualified Individual reports on the program's status, incidents, testing, and training at least once a year to the board or equivalent governing body. For a single-point store, "the board" can be the dealer principal, but the report must exist, in writing, dated.
    11. ol>

How to prove it: the Book of Evidence

Compliance is not the activity. It is the proof of the activity. Accountants who work dealer audits call the assembled record your Book of Evidence: signed program documents, the current risk assessment, training logs for every employee, access reviews, vendor contracts, testing results, the incident plan, and the board report.

After an incident, that file is often the difference between the FTC reading your store as negligent versus grossly negligent. Build it as a byproduct of running the program, not as a scramble when someone asks. A good standard: be able to produce the whole book within 48 hours of being asked.

What changed recently

Two things worth knowing. First, the FTC's CARS Rule, the separate retail rule covering advertising and add-ons, was vacated by the Fifth Circuit in January 2025 and formally withdrawn in February 2026. The court ruled on procedure only; it never said the targeted conduct was lawful, and the FTC continues to enforce the same principles under Section 5 of the FTC Act, case by case. In March 2026 the agency put 97 dealer groups on written notice over advertised pricing.

Second, enforcement against dealers is real and recent: a $20 million judgment against Leader Automotive Group in December 2024, and in April 2026 an agreement with Lindsay Automotive covering refunds on more than $75 million in consumer charges plus a $3.1 million civil penalty. The Safeguards Rule itself is enforced the same way, through consent orders and penalties, and every public breach report invites scrutiny of the whole program.

Where to start

Print the ten items above. For each one, ask a single question: if an examiner asked tomorrow, could I hand over dated proof this is done? Every "no" is a gap. Every gap has an owner, a cost, and a fix.

If you want a second set of eyes, DealSafe offers a free gap assessment: a 30-minute working session that maps your store against this exact checklist, with the findings in writing whether or not you ever become a customer. You can also see how our Safeguards program handles each requirement, or check our published per-rooftop pricing.

Get the free gap assessment

Frequently asked questions

Does the FTC Safeguards Rule apply to all car dealerships?

It applies to dealers that finance or arrange financing or leasing for consumers, which covers most dealerships. The FTC's dealer FAQ says so explicitly. Dealers holding customer information on fewer than 5,000 consumers are exempt from four of the ten requirements, but not from the Qualified Individual, access controls, encryption, MFA, training, or vendor oversight.

What is the penalty for violating the Safeguards Rule?

Civil penalties run up to $53,088 per violation under FTC Act Section 5(m)(1)(A), effective January 17, 2025. Violations can be counted per affected consumer, so exposure compounds quickly across a customer database.

When did the Safeguards Rule become mandatory for dealers?

The amended rule's prescriptive provisions took effect June 9, 2023. The breach-notification requirement followed on May 13, 2024: report any breach of unencrypted information of 500 or more consumers to the FTC within 30 days of discovery.

Who can be a dealership's Qualified Individual?

An employee, someone at an affiliate, or a service provider. Many smaller stores assign the role to the GM or controller with outside support. The dealership keeps responsibility regardless of who holds the title.

Is a written policy enough for Safeguards compliance?

No. The rule requires a running program: current risk assessment, monitored controls, MFA, training with logs, vendor contracts and reviews, an incident response plan, and an annual written board report. A binder alone is a snapshot, not a program.

See also

Red Flags & ID verification for dealers · The Red Flags Rule for Auto Dealers