
If your dealership finances or leases vehicles, the FTC treats you like a bank, and its Safeguards Rule has been fully enforceable since June 2023. That means a written security program, multi-factor authentication, encryption, and one named person on the hook for all of it. Ignore it and you're facing FTC enforcement on top of a breach you may not recover from cleanly.
By Joel Baum, The NetSys Group
Does the FTC Safeguards Rule apply to my dealership?
Almost certainly, yes. Any dealer that arranges financing or leasing counts as a "financial institution" under the Gramm-Leach-Bliley Act, which puts you squarely inside the FTC Safeguards Rule. Buy-here-pay-here lots, franchise stores, and independents all qualify. The rule covers customer names, Social Security numbers, credit applications, and driver's license data.
What does the Safeguards Rule actually require?
A written information security program with nine parts. The FTC spells them out, and they're not optional:
- Designate a qualified individual to run the program
- Base it on a written risk assessment
- Design safeguards to control the risks you find
- Regularly monitor and test those safeguards
- Train your staff on the program
- Oversee your service providers
- Keep the program current as your risks change
- Write an incident response plan
- Have the qualified individual report to ownership or your board
The "qualified individual" part trips up most stores. It can be an employee or an outside partner, but someone's name goes on the program, and that person answers for it. If nobody owns it, you don't have a program.
What are the technical controls?
Three requirements have teeth: MFA, encryption, and regular testing.
Multi-factor authentication is required for anyone who touches your systems, not just the F&I manager. If a salesperson can log into the DMS from a phone, that login needs a second factor. This is the single control that stops most stolen-password attacks, and it's the one auditors check first.
Encryption is required for customer data both at rest and in transit. That covers the credit apps sitting on your server and the files you email to a lender.
Testing is required on a schedule. If you don't run continuous monitoring, the FTC wants annual penetration testing plus vulnerability assessments at least every six months. If you're not sure of the difference, we break it down in penetration testing vs. vulnerability scanning.
What changed with breach reporting in 2024?
Since May 2024, you have to tell the FTC when a breach hits 500 or more people. The clock is 30 days from discovery, and the notice goes into a public FTC database. There's no "we handled it quietly" option anymore.
That reporting line matters because breaches in this sector are expensive. IBM put the global average cost of a data breach at $4.44 million in 2025. A dealership doesn't need to hit that average to be badly hurt; a week of downtime during month-end and a wave of angry customers is enough.
Do smaller dealers get a break?
Some. If you keep information on fewer than 5,000 consumers, you're exempt from four of the heavier requirements: the written risk assessment, continuous monitoring or the pen-test-and-scan schedule, the written incident response plan, and the annual report to ownership. Everything else still applies, including MFA and encryption.
Read that threshold carefully. It counts total consumers in your records, not last month's sales. Most stores with any history blow past 5,000 fast, so don't assume the exemption covers you.
What happens if you ignore it?
The FTC has stopped waiting. Its consent orders in data-security cases are long-running and force third-party audits and system overhauls, which is a heavier lift than getting compliant in the first place. State attorneys general and your lenders are watching too, and captive finance arms increasingly expect Safeguards compliance from the stores whose paper they buy.
How does a dealership actually get compliant?
Start with the risk assessment, because everything else flows from it. You can't secure data you haven't mapped.
Name your qualified individual next, whether that's an internal manager or a managed security partner. Then close the obvious gaps: turn on MFA everywhere, encrypt customer data, lock down who can reach the DMS, and write the incident response plan. A written information security plan ties it together, and vendor oversight matters more than most stores think, since your DMS provider, your website host, and your marketing vendor all touch customer data. We cover that exposure in vendor risk management.
None of this is a one-time project. The rule expects you to keep it current, test it, and prove it. That's the part a managed IT and security partner handles day to day.
Frequently asked questions
Is the Safeguards Rule the same as PCI compliance?
No. PCI DSS protects cardholder payment data and comes from the card brands. The Safeguards Rule protects all nonpublic customer information and comes from the FTC. A dealership that takes card payments and arranges financing has to meet both. They overlap on controls like encryption but are separate obligations.
Can my DMS vendor make me compliant?
No single vendor can. Your DMS handles part of the picture, but the rule covers your whole environment: email, endpoints, staff access, and every other vendor. You still need your own program, your own qualified individual, and oversight of the DMS provider itself as a service provider.
How long does it take to get compliant?
The high-impact basics, MFA and encryption, can be in place within a few weeks. A full program with risk assessment, incident response plan, and vendor oversight typically takes a quarter to stand up and then runs continuously. Waiting for an FTC letter is the expensive way to start.
What counts as a reportable breach?
Unauthorized acquisition of unencrypted customer information affecting at least 500 people. You have 30 days from discovery to notify the FTC. Encryption matters here too: properly encrypted data that's stolen but unreadable generally doesn't trigger the reporting requirement.
Not sure where your store stands against the Safeguards Rule? The NetSys Group can assess your current setup, name the gaps, and build the program the FTC expects. Book a complimentary security assessment or see our managed IT and security services.
The NetSys Group has delivered managed IT, cybersecurity, and cloud services since 1998. Our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



