← Back to Compliance Insights

September 5, 2026  ·  Jonah Gobah

The FTC's 30-Day Breach Notification Requirement: What Dealers Need to Know

Short answer: Since May 13, 2024, the FTC Safeguards Rule has required financial institutions — including independent auto dealerships — to notify the FTC directly, no later than 30 days after discovery, of any breach involving the unauthorized acquisition of at least 500 consumers' unencrypted information. This is a specific, standalone requirement (Section 314.4(j) of the Rule) separate from your general incident response obligations, and it does not require notifying the affected customers directly — only the FTC.

Why this is easy to miss

A lot of dealership compliance conversation still treats "have an incident response plan" as the complete answer to breach obligations. That was closer to accurate under the original Safeguards Rule. Since the 2023 amendment took effect in 2024, there's now a specific, dated, numeric reporting requirement layered on top — and it's easy for a dealer whose compliance program predates the amendment to have never updated their incident response plan to actually include this step.

What triggers the requirement

The rule calls this a "notification event": the unauthorized acquisition of at least 500 consumers' unencrypted customer information. A few specific details matter here:

  • The threshold is 500 consumers, not 500 records or 500 accounts — the FTC lowered this from an initially proposed 1,000 down to 500 in the final rule.
  • "Unencrypted" has a specific meaning. Information is treated as unencrypted for this purpose even if it was technically encrypted, if the encryption key was also accessed by the unauthorized person. Properly encrypted data where the key stayed secure generally doesn't trigger this requirement.
  • Unauthorized access is presumed to include acquisition, unless you have reliable evidence showing the information wasn't actually acquired. This shifts the burden toward the dealer to demonstrate a breach didn't rise to this level, rather than the FTC needing to prove it did.

What you actually have to do

If a notification event occurs, you must notify the FTC as soon as possible, and no later than 30 days after discovery, through the FTC's online Security Event Reporting Form. The notice needs to include specific information about the event, including the number of consumers affected or potentially affected.

Importantly, this FTC notification requirement is separate from and doesn't replace any state breach notification laws requiring you to notify affected customers directly — those obligations exist independently and typically still apply.

Why the FTC made this change

Regulators wanted covered financial institutions to be transparent about breaches, both to inform the FTC's own oversight and because the agency has stated it intends to publish notices it receives. That means a reported breach becomes a matter of public record with the FTC, not something that stays entirely internal to your dealership.

What this means for your incident response plan

If your written incident response plan doesn't specifically reference this 30-day, 500-consumer FTC reporting requirement, it's out of date relative to the current rule, regardless of how solid the rest of the plan is. The "identification" phase of your incident response process specifically needs to include a step for determining whether an incident meets this reporting threshold, not just whether it's serious in a general sense.

Getting your incident response plan current

This is exactly the kind of specific regulatory detail that's easy to miss if your compliance documentation hasn't been reviewed since before 2024. Sterling Safeguard's incident response planning is built around the current rule, including this specific FTC notification requirement, not just general breach response best practices.

Run the free FTC Safeguards Rule risk assessment →

FREE DOWNLOAD

FTC Safeguards Rule Readiness Checklist

The 9-point checklist every dealer needs. Delivered instantly to your inbox.

Sterling Safeguard

Ready to get your dealership FTC compliant?

Sterling Safeguard gives you everything you need — written security program, risk assessments, employee training, and the Verified™ seal — without hiring a consultant or a law firm.

Get Started →More Articles