Short answer: In March 2026, the FTC sent warning letters to 97 auto dealership groups over deceptive pricing practices — advertised prices that didn't match what customers actually paid once mandatory fees were added. That enforcement action was about Section 5 of the FTC Act, not the Safeguards Rule. But at the FTC's own follow-up webinar with NIADA in April, the agency used the moment to also walk dealers through their separate Safeguards Rule obligations. If you run an independent dealership, that pairing is worth paying attention to.
What the warning letters were actually about
The FTC's March 2026 letters went to 97 dealer groups — covering more than 200 individual locations, from small independent lots to large public retailers — warning them that advertised prices have to be the total price a customer will actually pay, mandatory fees included. This wasn't a minor technical nitpick. The agency was explicit that the letters targeted a pattern it had already been building enforcement cases around, including a since-settled action against a Maryland dealer group that resulted in $3.1 million in penalties and an estimated $75 million in consumer restitution, with individual managers held personally liable.
That's the Section 5 UDAP side of things — unfair or deceptive advertising and pricing practices. It has nothing to do with cybersecurity, data protection, or the Safeguards Rule directly.
Where the Safeguards Rule entered the conversation
On April 21, 2026, NIADA held a webinar with the FTC's Bureau of Consumer Protection Director to walk dealers through the pricing warning letters. But that same session also included a separate segment specifically covering the Safeguards Rule — the requirement for dealers to maintain a written information security program protecting customer financial data.
The FTC didn't connect these as the same violation. They're genuinely different rules, enforced under different authority. But bundling them into the same conversation with dealers wasn't an accident either. It reflects something worth internalizing: when the FTC turns its attention to an industry, it tends to look at compliance broadly, not just the specific issue that triggered the current headline.
Why this matters even if you never got a letter
If your dealership wasn't one of the 97, it's tempting to read this as someone else's problem. That's the wrong read. A few things are true at the same time:
- The FTC has made clear this wave of pricing letters isn't a one-time event — it's described as part of an ongoing, broader price-transparency initiative touching multiple industries.
- Independent dealers who've never been audited on Safeguards Rule compliance often assume they're too small to be a target. The rule doesn't have a size exemption tied to how likely you are to get caught — it applies based on whether you handle customer financial data, full stop.
- Regulatory attention rarely stays narrowly scoped. A dealer group that ends up on the FTC's radar for one issue is more likely to face scrutiny on others, including data security.
What to actually do with this
This isn't a reason to panic. It's a reason to check, while it's front of mind, whether your dealership's Safeguards Rule documentation would actually hold up if someone asked to see it — a named Qualified Individual, a current risk assessment, training records, an incident response plan. Most independent dealers who look closely find at least one gap.
Sterling Safeguard's free risk assessment walks through exactly this, in about five minutes, and shows you precisely where those gaps are before an examiner, lender, or a wave of industry-wide scrutiny finds them for you.