Is Your Dealership Ready for the FTC Safeguards Rule?
Most car dealerships do not think of themselves as financial institutions.
But under the FTC Safeguards Rule, many dealerships are treated that way because they collect, process, finance, lease, or store sensitive customer financial information. The FTC specifically says the Rule applies to most auto dealers that finance or lease vehicles.
That means dealership IT is not just about keeping computers, phones, Wi-Fi, and printers working.
It is also about protecting customer data and being able to show that reasonable safeguards are in place.
For dealer principals, general managers, controllers, and office managers, this matters because the dealership may be responsible for more than it realizes.
Why This Matters for Dealerships
A dealership handles a large amount of sensitive information, including:
Credit applications
Driver’s licenses
Social Security numbers
Financing documents
Bank information
Insurance details
Customer contact information
Deal jackets and supporting paperwork
Employee access to dealership systems
That data may live in your DMS, CRM, email, scanned files, cloud storage, desktops, laptops, finance office systems, vendor portals, and shared drives.
If that environment is not properly managed, the risk is not just technical.
It can affect compliance, cyber insurance, customer trust, sales operations, and the ability to keep the dealership running during an incident.
The FTC Safeguards Rule in Plain English
The FTC Safeguards Rule requires covered businesses to have a written information security program designed to protect customer information. The FTC also says financial institutions must keep safeguards current as systems and networks change, and monitor authorized user activity for signs of unauthorized access.
For dealerships, that typically means having a plan for things like:
Who is responsible for the security program
What customer data the dealership stores
Who has access to that data
How user accounts are protected
How systems are monitored
How backups and recovery are handled
How vendors are managed
How employees are trained
How the dealership would respond to a security incident
This does not mean every dealership needs a large internal IT department.
It does mean someone needs to be actively managing the security controls that protect customer data.
Compliance Is Not Just a Document
A written policy is important, but the technology has to match the policy.
For example:
If your policy says MFA is required, is it actually enforced?
If your policy says former employees are removed, are they removed from every system?
If your policy says data is backed up, have you tested recovery?
If your policy says vendors are managed, do you know which vendors have access?
If your policy says systems are monitored, who is reviewing alerts?
This is where many dealerships get exposed.
They may have a policy, a checklist, or a compliance binder, but the day-to-day IT environment may not fully support what the paperwork says.
Common IT Gaps at Dealerships
1. Too Many People Have Too Much Access
Dealerships are busy. Employees change roles, vendors need temporary access, and shared logins often seem convenient.
But access control is one of the biggest parts of protecting customer data.
A dealership should know:
Who has access to customer information
Who has administrator permissions
Which vendors can access systems
Whether former employees have been fully removed
Whether shared accounts are being used
Access should be intentional, documented, and reviewed.
2. MFA Is Not Fully Enforced
Multi-factor authentication is one of the most practical ways to reduce account compromise.
But many dealerships have MFA turned on for some systems and not others.
That can leave gaps in email, cloud apps, remote access, vendor portals, CRM tools, or finance-related systems.
The question should not be, “Do we have MFA somewhere?”
The question should be, “Is MFA enforced where customer data or sensitive systems can be accessed?”
3. Backups Exist, but Recovery Is Unclear
Backups matter because dealerships cannot afford extended downtime.
If ransomware, hardware failure, vendor issues, or accidental deletion disrupts operations, leadership needs to know what can be restored and how quickly.
A backup plan should answer:
What systems are backed up?
How often do backups run?
Who monitors backup failures?
When was recovery last tested?
What happens if the DMS, email, or file storage is unavailable?
Try this: 15-Minute Test That Reveals If Your Business Could Survive a Ransomware Attack
4. Vendor Access Is Not Clearly Managed
Dealerships rely on a long list of vendors: DMS providers, CRM systems, marketing platforms, finance tools, phone providers, internet providers, payment systems, and OEM-related platforms.
Each vendor may support its own product, but no vendor is responsible for securing your entire dealership environment.
Someone still needs to know who has access, what they can access, and whether that access is still needed.
5. Security Tools Are Installed but Not Monitored
Antivirus, endpoint detection, firewalls, email filtering, and backup tools are only useful if they are properly configured and monitored.
A dealership should not assume that having tools in place means everything is covered.
The New Breach Reporting Requirement
The Safeguards Rule now includes a notification requirement. Covered financial institutions must notify the FTC as soon as possible, and no later than 30 days after discovering certain security breaches involving the unauthorized acquisition of unencrypted information of at least 500 consumers.
For dealerships, this makes preparation even more important.
If something happens, you do not want to be figuring out your systems, vendors, backups, access logs, and response plan for the first time during an emergency.
Better IT Helps the Dealership Run Better
The benefit of stronger dealership IT is not just compliance.
It can also help your team:
Reduce downtime
Protect customer trust
Improve cyber insurance readiness
Avoid last-minute compliance scrambling
Reduce vendor finger-pointing
Keep sales, finance, and service operations moving
Make technology easier for staff to use
Respond faster when something looks suspicious
Good IT should help the dealership operate with more confidence, not more confusion.
Ready to know where your dealership stands?
We’ll help identify what is already in place, what may be missing, and which IT gaps should be addressed first.