FTC Safeguards Rule program
The FTC Safeguards Rule, translated into a program your store actually runs.
- If your dealership finances or arranges financing or leasing, the FTC considers you a financial institution.
- The Safeguards Rule has been fully mandatory since June 9, 2023.
- This page is the rule, line by line, and what DealSafe does about each line.

Every requirement. What it takes. How DealSafe handles it.
- 1. Designate a Qualified Individual. What it takes: one named person accountable for the program. It can be an employee, an affiliate, or a service provider; responsibility stays with the dealer. How DealSafe handles it: your GM or controller can hold the title. DealSafe supplies the job description, the training, the task calendar, and the expert backup so the role is real, not ceremonial.
- 2. Written risk assessment. What it takes: a written assessment of foreseeable internal and external risks to customer information, with criteria and mitigation plans, reassessed periodically. How DealSafe handles it: guided risk assessment built for dealerships (showroom, F&I office, DMS, website leads, service lane), video-led, in plain English, stored and versioned.
- 3. Access controls. What it takes: limit who can reach customer information, review access regularly, no shared logins. How DealSafe handles it: an access review workflow that flags shared DMS logins and stale accounts, with a sign-off trail per rooftop. And DealSafe enforces this one in the product: PII from the deal is visible to general managers and finance managers only. The sales floor sees deal status, never the underlying data, and every access is logged for your Book of Evidence.
- 4. Encryption. What it takes: customer information encrypted at rest and in transit, or documented alternative controls. How DealSafe handles it: a system inventory that records where customer data sits and how each system is protected, with gaps assigned and tracked to closure.
- 5. Multi-factor authentication. What it takes: MFA for anyone who accesses your information system, or a reasonably equivalent control, documented. How DealSafe handles it: an MFA rollout checklist per system (DMS, CRM, email, website backend) with verification evidence stored for the audit file.
- 6. Monitor and test. What it takes: continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months. How DealSafe handles it: a testing calendar, vendor coordination, and results logged into your evidence file. NADA has estimated a standalone penetration test at roughly $23,000; DealSafe coordinates it inside your subscription.
- 7. Employee training. What it takes: security awareness training for all staff, specialized training for security personnel, refreshed as threats change. How DealSafe handles it: short video training built for dealership roles, auto-assigned to new hires. Every completion logged. Details on the training page.
- 8. Vendor oversight. What it takes: choose capable service providers, require safeguards by contract, and reassess them periodically. How DealSafe handles it: a vendor register with contract language, outreach, and reassessment reminders. Your DMS, CRM, and website vendors, documented without the legwork.
- 9. Written incident response plan. What it takes: a written plan covering roles, decision authority, remediation, documentation, and reporting. How DealSafe handles it: a living incident response plan template, customized to your store, drilled annually, versioned, and time-stamped.
- 10. Annual board report. What it takes: the Qualified Individual reports in writing, at least annually, to the board or equivalent governing body. How DealSafe handles it: one click compiles the year's program status, incidents, testing, and training into a board-ready report.
The FTC says dealers are financial institutions. Its own FAQ says so.
This is not our interpretation. The FTC's dealer-specific FAQ states that most automobile dealers who finance or lease automobiles are financial institutions under the Safeguards Rule. BHPH stores, you are doubly covered: you extend the credit yourself.
The rule is not a policy you buy. It is a program you run, with written proof. Below is the whole requirement set. Count how many you can prove today.
Under 5,000 consumers? Four items relax. The rest do not.
Dealerships holding customer information on fewer than 5,000 consumers are exempt from four requirements only: the written risk assessment, monitoring and testing, the written incident response plan, and the annual board report. The Qualified Individual, access controls, encryption, MFA, training, and vendor oversight still apply. DealSafe scales the program to your size without letting the basics slide.
See Red Flags & ID verification · See training & audit support · Read the Safeguards checklist
A breach now comes with a deadline and a public record.
Is the Safeguards Rule actually being enforced against dealers?
The FTC's flagship dealer-channel case was against a dealer software provider (DealerBuilt, 2019) after data on about 12.5 million consumers was exposed. It settled with a 20-year compliance order. Dealer-side enforcement today runs through Section 5 actions on pricing and add-ons, and every public breach report invites a look at the whole Safeguards program. The exposure is real. It is also manageable, with a documented program.
What are the penalties?
Up to $53,088 per violation under FTC Act Section 5(m)(1)(A), the inflation-adjusted figure effective January 17, 2025. Violations can be counted per affected consumer, which is why we say "up to" once and then get to work.
Can we outsource the Qualified Individual role?
The rule allows the Qualified Individual to work for an affiliate or service provider. DealSafe supports the role either way. Responsibility for the program stays with your dealership, and we make sure you can prove it was discharged.
Does DealSafe replace my IT provider?
No. DealSafe runs the compliance program and coordinates testing. Your IT provider or MSP keeps the network running. We document what they do so it counts in an audit.
Is this legal advice?
No. DealSafe is compliance software plus specialist support, not a law firm. For legal judgment calls, we will tell you to call your counsel, and we will hand them a clean file.
