Skip to main content
Dealership leaders inspect a chain of locked customer-information handoffs across sales, financing, scanning, and technology operations.
One new lock cannot secure a broken chain of responsibility.

Business technology resource

What the FTC Safeguards Rule Means for an Auto Dealer’s Technology Operations

For a covered auto dealer, the Safeguards Rule is an operating program involving customer information, written responsibilities, technical safeguards, service providers, monitoring, testing, response, and ongoing review.

Short answer

Most automobile dealers that finance or facilitate consumer financing, or lease vehicles for longer than 90 days, are treated as financial institutions for the FTC Safeguards Rule. A covered dealer must develop, implement, and maintain a written information security program appropriate to its customer information and operations. Leadership should obtain legal or compliance guidance for applicability and interpretation.

Technology operations should make the approved program inspectable. The dealer needs to know where covered information resides, who can access it, which safeguards and providers protect it, how those safeguards are tested, how incidents are handled, and what evidence leadership retains. Buying a security product or receiving an MSP report does not replace the dealer’s program ownership.

Frame the decision around the operating condition

Start with the work the organization must perform, the information it depends on, and the consequence when a handoff fails. Document the current condition before prescribing a replacement, integration, automation, control, or subscription.

Leadership needs evidence of reliable use, controlled access, accountable ownership, recoverable information, supportable change, and a path for exceptions. Use these decision factors:

  • The activities and customer information qualified advisers determine are within the dealer’s approved program scope.
  • DMS, CRM, desking, F&I, lender, document, email, file, scanner, payment, and export paths containing relevant information.
  • Employee, contractor, OEM, lender, marketing, software, support, disposal, and other service-provider access.
  • Written risk decisions and the technical, physical, and administrative safeguards selected for the environment.
  • Monitoring, testing, vulnerability, change, training, incident, notification, backup, and recovery evidence.
  • The qualified individual, leadership reporting, service-provider oversight, review cadence, and change triggers.

Make responsibilities explicit

Industry platforms depend on business owners, employees, vendors, Microsoft 365, devices, networks, identity, integrations, and recovery services. Product contracts do not necessarily assign every operating responsibility.

Before making changes, name who approves the outcome, performs the work, and sustains it. Shared participation is normal; accountability still needs a named owner.

A responsibility map should connect each role to evidence the organization can inspect.
RolePrimary responsibilityEvidence to retain
Dealer leadershipApprove the program, resources, risk decisions, providers, and accountable oversightWritten program, approvals, reports, contracts, and review record
Qualified individualCoordinate the program, assessment, safeguards, testing, response, and reportingRisk assessment, action register, test evidence, and written reports
Technology and service providersPerform contracted safeguards, operations, support, monitoring, and incident dutiesResponsibility matrix, service evidence, access review, and escalation record
Employees and contractorsFollow approved access, handling, authentication, training, and reporting practicesTraining completion, access record, acknowledgments, and issue reports

Recognize warning signs before they become urgent

Treat these signals as questions to investigate, not proof that a product or provider failed. Preserve examples, dates, affected workflows, and business consequences so the decision rests on evidence.

  • The dealer cannot separate covered customer information from general customer, vehicle, sales, or marketing data.
  • One combined database is assumed to place every record inside or outside scope without a documented analysis.
  • Service providers can access customer information without current contracts, oversight, access review, or removal procedures.
  • The written program lists controls that cannot be tied to configuration, monitoring, testing, or current ownership.
  • DMS, email, document, device, lender, OEM, camera, network, and backup responsibilities are fragmented.
  • Incident procedures do not address evidence, internal authority, qualified advice, provider coordination, and notification decisions.

What to verify before buying or changing technology

Verify requirements, current capability, ownership, and transition consequences before selecting a tool. Ask vendors to distinguish included features, licensed modules, supported integrations, services, and customer responsibilities.

Test representative workflows and exceptions. Record the evidence, open assumptions, acceptance owner, and post-launch measures. Leadership should answer these questions:

  • Which dealership activities and information has qualified counsel determined are covered?
  • Can the dealer map covered information across systems, integrations, exports, devices, vendors, and retention paths?
  • Who is the qualified individual, and what current evidence supports leadership reporting and program decisions?
  • What safeguards are required, who operates them, how are they tested, and how are exceptions resolved?
  • Which providers receive or can access customer information, and how does the dealer oversee them?
  • How will the dealer identify, investigate, escalate, recover from, and evaluate notification for an incident?

Use a bounded improvement sequence

Evidence may support retaining the current system, improving configuration, clarifying ownership, connecting a handoff, adding a recovery control, or replacing only a justified gap. Sequence the smallest useful change.

Define success before implementation and schedule a review. Show what changed, what remains unresolved, who operates the result, and when the decision returns to leadership.

Move from evidence to action without turning an assessment into a predetermined sale.
StagePractical actionDecision produced
ConfirmObtain qualified applicability and requirement decisions and define customer-information scopeEstablish the governed program boundary
MapDocument systems, information, users, providers, safeguards, incidents, and recovery dependenciesCreate an evidence-based current state
ImprovePrioritize missing ownership, safeguards, provider controls, tests, and recordsAuthorize bounded remediation
GovernReview reports, incidents, changes, providers, tests, and program effectivenessMaintain or revise the program

Related next steps

Related articles

Sources and further reading

This resource provides general business-technology guidance. Engagement scope, evidence, and recommendations depend on the organization’s actual condition.

A practical next step

Connect the dealership’s written program to current technology evidence.

Explore the cybersecurity and continuity assessment