← Back to Compliance Insights

August 11, 2026  ·  Jonah Gobah

Does the FTC Safeguards Rule Apply to My Auto Dealership?

If you own or manage an auto dealership, you probably think of yourself as being in the business of selling cars.

The Federal Trade Commission may look at your business a little differently.

If your dealership finances vehicles, helps customers obtain financing, or leases vehicles for more than 90 days, you may be considered a financial institution under the FTC's Safeguards Rule.

That means your dealership may have responsibilities that go well beyond selling vehicles and maintaining customer records. You may be required to have a written information security program designed to protect sensitive customer information.

And this is where many independent dealerships have a problem. They may have antivirus software. They may have an IT company. They may use Microsoft 365, a dealership management system, a CRM, and other security tools. But having technology is not the same thing as having a documented and maintained compliance program.

So, does the Safeguards Rule apply to your dealership?

The short answer is: if your dealership finances or facilitates financing for consumers, the answer is generally yes.

The FTC specifically states that automobile dealers who finance or facilitate financing for consumers are considered financial institutions for purposes of the Safeguards Rule. Dealers that lease automobiles for more than 90 days can also fall within the definition because leasing is considered a financial activity.

This catches some dealers by surprise. You don't have to think of yourself as a bank. You don't have to call yourself a financial institution. What matters is what your dealership actually does.

For example, if your dealership collects information from a customer to determine whether that customer qualifies for financing, that activity can bring the dealership within the scope of the Safeguards Rule.

And the information involved can be extremely sensitive. Think about what is typically sitting inside a dealership's finance office:

  • Names and addresses
  • Social Security numbers
  • Driver's license information
  • Income information
  • Employment information
  • Financial account information
  • Credit application information
  • Financing and leasing records
  • Other nonpublic personal information

The FTC specifically identifies financing applications and certain customer lists as examples of customer information that dealerships need to protect. That is a lot of valuable information sitting inside a business that, on the surface, is simply selling cars.

"But we already have an IT company"

This is one of the biggest misunderstandings. Having an MSP, antivirus software, a firewall, endpoint protection, or Microsoft 365 does not automatically mean your dealership is compliant with the Safeguards Rule.

Cybersecurity technology is important. But the FTC's requirements go beyond technology. A covered dealership is expected to develop, implement, and maintain a comprehensive written information security program appropriate to the dealership's size, complexity, activities, and the sensitivity of the information it handles.

That means you need to be able to answer questions such as: What customer information do we have? Where is it stored? Who has access to it? What could go wrong? What safeguards do we have in place? How do we know those safeguards are working? What happens when an employee leaves? How do we manage our vendors? What happens if we experience a security incident? Where is all of this documented?

Those are compliance questions — not just IT questions.

What does the FTC expect?

The Safeguards Rule requires a covered dealership to maintain an information security program with administrative, technical, and physical safeguards designed to protect customer information. The FTC's auto-dealer guidance points to several important elements.

1. A Qualified Individual

Your dealership needs someone responsible for overseeing and implementing the information security program. That person could be an employee, an affiliate, or an appropriate service provider.

2. A written risk assessment

You need to understand the reasonably foreseeable risks to your customer information and evaluate the safeguards you have in place. This shouldn't be a document that gets created once and forgotten. Your risks and systems change. Your assessment should change with them.

3. Appropriate security safeguards

The FTC's guidance includes safeguards such as access controls, encryption, multifactor authentication, logging, and monitoring. The specific controls should be appropriate for the dealership and the risks involved.

4. Testing and monitoring

Security controls need to be monitored and tested. The goal isn't simply to say, "We have a firewall." The better question is: can we demonstrate that our security controls are working? The FTC guidance addresses continuous monitoring and, where continuous monitoring isn't used, vulnerability assessments and penetration testing requirements.

5. Employee training

Your employees are part of your security program. Salespeople, F&I personnel, accounting staff, managers, and other employees may interact with customer information every day. They need to understand their responsibilities.

6. Vendor oversight

This is another area dealerships shouldn't overlook. Your dealership may rely on a CRM provider, DMS provider, managed service provider, cloud storage provider, payment processor, marketing company, or other third-party service providers. The FTC expects covered financial institutions to take reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards, and to address security obligations contractually and through ongoing oversight.

7. Incident response

What happens if someone clicks a malicious link? What happens if a laptop containing customer information disappears? What happens if someone gains unauthorized access to your systems?

A dealership should not be trying to answer those questions for the first time after an incident occurs. The FTC's 2023 amendment also created notification requirements for certain security incidents involving customer information, with those requirements taking effect in May 2024.

What about a small independent dealership?

This is where many dealers have an understandable concern: does this mean I need to build a giant cybersecurity department?

No. The FTC recognizes that information security programs should be appropriate to the size and complexity of the business, the nature and scope of its activities, and the sensitivity of the information involved. A five-person dealership and a 500-person dealership aren't going to have identical security programs.

But being small doesn't mean being exempt. In fact, smaller dealerships may have an even greater need for a practical way to organize their compliance responsibilities. You don't necessarily need more complexity. You need visibility, accountability, documentation, and consistency.

The difference between having policies and being ready

Here's a scenario that happens more often than it should.

A dealership has a WISP. It has an employee security policy. It has an IT company. It has antivirus software. It has MFA. It has vendor contracts. Everything looks good.

Then someone asks: "Show me your risk assessment." The dealership can't find it. "Show me your employee training records." They're scattered across emails. "Show me your vendor reviews." Nobody knows who was responsible for them. "Show me what changed in your security program over the past year." There is no record.

This is where compliance becomes difficult. Having a policy is not the same as being able to demonstrate that the policy is being implemented. That distinction matters.

FTC compliance should be a living process

Your dealership doesn't become secure because someone created a WISP in January. Compliance needs to be maintained.

Employees come and go. Vendors change. Software changes. New systems are introduced. Threats evolve. Customer information moves between systems. Your dealership grows. Your compliance program needs to keep up.

That is why an effective FTC compliance program should operate more like a living management system than a folder sitting on someone's computer.

Where Sterling Safeguard fits

This is exactly the problem we built Sterling Safeguard to address. Sterling Safeguard is designed specifically for independent auto dealerships that need a practical way to manage their FTC Safeguards Rule compliance program.

Instead of keeping your compliance activities scattered across spreadsheets, email threads, shared folders, and disconnected documents, Sterling Safeguard brings the major pieces together in one place. With Sterling Safeguard, dealerships can:

Assess their risk — Use a structured FTC-mapped risk assessment to understand their current compliance posture and identify gaps.

Build and maintain their WISP — Create a written information security program that can evolve as the dealership's environment changes.

Organize compliance evidence — Store important policies, assessments, training records, vendor documentation, and other evidence in a centralized Evidence Vault.

Manage vendors — Track vendors, risk levels, contracts, renewals, and access to customer information.

Track employee training — Maintain training records and certificates instead of trying to reconstruct them later.

Manage compliance activities — Use a compliance calendar and audit timeline to keep important activities from falling through the cracks.

Monitor compliance readiness — Use the Sterling Safeguard compliance dashboard and FTC Audit Readiness Score™ to get a clearer picture of where the dealership stands.

The objective isn't to make compliance complicated. It is to make it manageable.

A simple question every dealer should ask

If you're a dealer principal, general manager, controller, or compliance leader, ask yourself these five questions:

  1. Do we know exactly what customer information we collect and where it is stored?
  2. Do we have a current written information security program?
  3. Have we completed and documented a current risk assessment?
  4. Can we demonstrate that our employees and vendors are being managed appropriately?
  5. If someone asked us tomorrow to demonstrate our compliance program, could we do it?

If you answered "no" or "I'm not sure" to several of these questions, that doesn't mean your dealership has failed. It means you have an opportunity to get organized.

Compliance doesn't have to be overwhelming

The FTC Safeguards Rule can sound intimidating when you first read through it. But when you break it down, the underlying idea is straightforward: know what information you have, understand the risks, put appropriate safeguards in place, train your people, manage your vendors, document what you do, and keep the program current.

For an independent dealership, the challenge is often not understanding that cybersecurity matters. The challenge is having a practical system for managing all of it. That's where technology can help.

Is your dealership FTC audit ready?

Sterling Safeguard was built to help independent auto dealerships move from "we think we're compliant" to "we can demonstrate what we're doing."

Now, if you're not sure where your dealership stands, start with an assessment. Evaluate your FTC compliance posture. Identify your gaps. Build your program. Keep your evidence organized.

And most importantly, don't wait until there's an incident — or someone asks for the documentation — to find out where you stand.

Sterling Safeguard FTC Safeguards Rule Compliance for Independent Auto Dealerships

This article is provided for educational purposes and is not legal advice. Dealerships should consult qualified legal or compliance professionals regarding their specific obligations.

FREE DOWNLOAD

FTC Safeguards Rule Readiness Checklist

The 9-point checklist every dealer needs. Delivered instantly to your inbox.

Sterling Safeguard

Ready to get your dealership FTC compliant?

Sterling Safeguard gives you everything you need — written security program, risk assessments, employee training, and the Verified™ seal — without hiring a consultant or a law firm.

Get Started →More Articles