Skip to content
(888) 538-6881Client Portal
The Network Gurus

Blog

What the FTC Safeguards Rule means for your dealership

Nine requirements, what each one actually asks of your IT, and the questions to put to your current provider this week.

A car dealership showroom

October 7, 2026 · The Network Gurus

If your dealership arranges financing, you're a financial institution in the eyes of the Federal Trade Commission, and the Safeguards Rule applies to you. The amended rule has been fully in effect since June 2023, and the FTC added a breach-notification requirement in 2024. Most dealerships we assess have done some of it. Very few have done all of it.

Here are the nine elements the rule requires, what each means for your IT, and what your provider should already have in place.

1. A qualified individual

Someone at the dealership, or a contracted provider, has to own the information security program. The FTC doesn't require a title, but it does require a name. If nobody at your store can say who that is, start there.

What IT should do: support that person with the documentation and reporting below.

2. A written risk assessment

You have to identify where customer financial data lives, what could go wrong, and how likely it is. In a dealership, that data is in the DMS, the F&I desk, credit application portals, email, scanned documents on shared drives, and often on paper.

What IT should do: inventory every system touching customer data, document the risks, and update it annually.

3. Safeguards to control the risks

This is the bulk of the technical work, and the rule is specific:

  • Access controls. Only people who need customer financial data can reach it. Shared logins at the F&I desk fail this test.
  • Data inventory. Know what you hold and where.
  • Encryption of customer information at rest and in transit.
  • Secure development for any apps you build (rare for dealerships, but it applies to custom integrations).
  • Multi-factor authentication for anyone accessing customer information. This one is explicit in the rule.
  • Secure disposal of customer data within two years of last use, unless there's a business reason to keep it.
  • Change management so system changes don't quietly open holes.
  • Activity monitoring and logging of who accessed what.

What IT should do: all of it, and be able to show evidence for each.

4. Regular testing

Either continuous monitoring or annual penetration testing plus vulnerability assessments every six months.

What IT should do: run continuous monitoring on every endpoint and server, scan for vulnerabilities, and arrange third-party penetration testing when your insurer or auditor requires it.

5. Staff training

Everyone who touches customer data needs security awareness training, and the people running the program need to stay current.

What IT should do: deliver training and phishing simulations and keep the completion records.

6. Oversight of service providers

Your DMS vendor, your credit portal, your marketing company, and your IT provider all have to be vetted and contractually bound to protect the data.

What IT should do: document which vendors have access and help you review their agreements.

7. Keep the program current

The program has to change when your business changes: a new location, a new DMS, a new lender integration.

8. An incident response plan

A written plan that says what happens when something goes wrong: who's called, what's contained, how customers are notified.

What IT should do: write and test it with you.

9. Annual reporting

The qualified individual reports to ownership or the board at least once a year on the program's status.

What IT should do: produce the report's technical content.

Questions to ask your current provider this week

  1. Is MFA enforced on every account that can reach the DMS or F&I systems?
  2. Can you show me the log of who accessed customer financial data last month?
  3. When was our last vulnerability scan, and what did it find?
  4. Where is our written incident response plan?
  5. Which of our vendors have you documented as having access to customer data?

If the answers are vague, the gap is real. Here's exactly what we do for dealerships, and a free assessment will map your current setup against the rule in writing.

Keep reading

More from the blog

Questions we hear

Frequently asked questions

Don’t see your question? Call us and a real person will answer.

Does the Safeguards Rule apply to my dealership?

If you arrange financing or leasing, yes. The rule covers any business that's a 'financial institution' under GLBA, and dealerships that handle credit applications qualify.

What are the penalties?

The FTC can seek civil penalties per violation, and a breach involving 500 or more consumers must be reported to the FTC within 30 days. The larger cost is usually the breach itself: downtime, forensics, notification, and lost deals.

Free IT assessment

Know where you stand before something breaks

A plain-English review of your security, backups, and support experience. No cost, no obligation, and the report is yours to keep.

What the FTC Safeguards Rule Means for Your Dealership | The Network Gurus