Short answer: Under the FTC Safeguards Rule, customer information means any record containing nonpublic personal information about a customer, whether in electronic or paper form, that a dealership collects or handles in the course of offering a financial product or service — most commonly, credit applications, financing terms, trade-in valuations tied to a specific customer, and similar records connected to arranging or extending credit. It's broader than just "the credit application" alone, and it applies regardless of whether the information is stored digitally or on paper.
Why this definition matters
Dealers sometimes assume Safeguards Rule protections apply narrowly to whatever's stored in their F&I software, and treat everything else as outside scope. The actual definition is broader than that. Understanding exactly what counts as customer information is the foundation of your risk assessment — if you're not accounting for everywhere this information actually exists, your risk assessment has a blind spot before it even starts.
What clearly counts as customer information
- Credit applications and any information collected on them (income, employment, SSN, credit history)
- Financing and lease agreement terms tied to a specific customer
- Trade-in valuation records connected to a customer's identity
- Bank account or payment information used for financing or purchase transactions
- Any customer financial information shared with or received from a third-party lender as part of arranging financing
What's easy to overlook
Paper records. The rule doesn't only apply to digital systems. A physical filing cabinet of credit applications is covered exactly the same as a digital database, and physical security (locking cabinets, controlling who has keys) is part of your obligation.
Information you received but didn't directly collect. If a customer's financial information came to you through a co-buyer, a trade-in appraisal service, or from a lender processing an application, it's still customer information under the rule once it's in your possession.
Information about customers who didn't ultimately buy. A credit application submitted by a customer who ended up not purchasing a vehicle is still customer information — the obligation doesn't depend on whether the sale was completed.
Backup copies and old records. Customer information sitting in an old backup, an archived system, or a retired piece of software is still covered. It doesn't stop being in scope just because it's not part of your active, current systems.
Marketing lists derived from customer records. If a marketing list was built using information originally collected as customer information — names and financial profile details pulled from past credit applications, for example — that derived list can still carry the same protection obligations.
What's generally NOT customer information
Aggregate or de-identified data that can't be tied back to a specific customer, and general business information unrelated to any individual customer's financial details, generally fall outside the definition. The key test is the same one that runs through this whole rule: is the information both financial in nature and tied to an identifiable customer.
Why this matters for your risk assessment specifically
A risk assessment is only as complete as your understanding of where customer information actually lives. If your assessment only accounts for your DMS and F&I platform but misses the filing cabinet of paper applications, the old backup server, or the marketing list built from historical customer data, you have a real gap in coverage — not because the assessment process failed, but because it started from an incomplete map of where customer information actually exists.
Building a complete picture
Sterling Safeguard's risk assessment specifically walks through the full range of places customer information tends to live in a dealership — digital and physical, active and archived — so your assessment reflects the actual definition the rule uses, not just the obvious systems.