← Back to Compliance Insights

September 5, 2026  ·  Jonah Gobah

What Should You Do If Your Dealership Has a Data Breach?

Short answer: Contain the breach immediately, document everything as you go, notify your designated Qualified Individual, assess what data was exposed, determine your legal notification obligations (which vary by state and by what data was involved), and execute your written incident response plan. If you don't have a written incident response plan already, that gap becomes obvious immediately — which is exactly why the FTC Safeguards Rule requires one in advance, not improvised in the moment.

Why the first hours matter more than they seem to

When a breach is discovered, the instinct is often to figure out the full scope before doing anything else. That instinct costs time you don't have. Containing further exposure and beginning documentation should start immediately, in parallel with figuring out scope — not after.

Step by step: what to actually do

1. Contain it. Isolate affected systems, revoke compromised credentials, and stop the active exposure before anything else. Don't wait until you understand the full picture to start containing it.

2. Notify your Qualified Individual. This is precisely why the rule requires someone specifically designated for this responsibility — there should be no ambiguity about who takes point.

3. Document everything, starting now. What was discovered, when, by whom, and what actions were taken and at what time. This documentation matters for your own response and for any regulatory or legal review that follows.

4. Assess what data was actually exposed. Customer names, financial information, SSNs, credit application details — the specific data involved determines your notification obligations and their urgency.

5. Determine your legal notification requirements. Most states have data breach notification laws, and requirements vary by what data was exposed and how many people were affected. This is a point where legal counsel familiar with your state's specific requirements is worth involving quickly.

6. Execute your written incident response plan. If you have one, this is the moment it's supposed to guide your specific next steps — who gets notified internally, what external parties need informing, what remediation happens.

7. Notify affected customers, and any required regulators, within the legally required window. Delayed notification, beyond adding to the underlying harm, can become its own separate compliance problem.

8. After the immediate response, update your risk assessment. A breach is a very specific and clear signal about where your risk assessment had a gap. Update it to reflect what actually happened, not just what you assumed could happen.

Why this is so much harder without a plan already in place

Every one of these steps takes longer and is more error-prone when you're deciding what to do for the first time in the middle of an actual crisis. This is the entire reason the Safeguards Rule requires a written incident response plan before anything happens — the plan's value isn't in having a document, it's in not having to make these decisions from scratch under pressure.

If you don't have a plan yet

If you're reading this because something has already happened, get your Qualified Individual and legal counsel involved immediately — this article isn't a substitute for either. If nothing has happened yet and you're reading this because you realized you don't have a plan, that's the more fortunate position to be in, and the moment to fix it.

Run the free FTC Safeguards Rule risk assessment →

FREE DOWNLOAD

FTC Safeguards Rule Readiness Checklist

The 9-point checklist every dealer needs. Delivered instantly to your inbox.

Sterling Safeguard

Ready to get your dealership FTC compliant?

Sterling Safeguard gives you everything you need — written security program, risk assessments, employee training, and the Verified™ seal — without hiring a consultant or a law firm.

Get Started →More Articles