Who is the 'qualified individual' under the FTC Safeguards Rule?
The single named person responsible for overseeing, implementing and enforcing the dealership's information security program. The role can be held by an employee or supplied by a service provider, but accountability stays with the dealership and the person must be identified rather than implied. This is issue-spotting information and not legal advice.
It is a named role, not a committee
The requirement is a designated individual. Where an outside provider supplies the function, the dealership still needs a named person responsible for direction and oversight of that provider.
Reporting obligation
The role includes reporting to the governing body on the program's status, risks and incidents. Build that reporting into an existing management cadence rather than treating it as an annual document.
Vendor oversight sits here
Selecting service providers capable of safeguarding information, requiring safeguards contractually and monitoring them belongs to this role — which is why the person should see software purchases before they are signed.
Document the decisions
Risk assessments, testing results and remediation decisions are the evidence that a program exists in practice. Keep them where they can be produced.
What to verify
Name one individual, even if a provider supplies the function
Build the reporting obligation into an existing cadence
Route software purchases through this role before signature
Keep risk assessments and testing results producible
Continue the research
Fraud & cybersecurity
Identity verification, endpoint security, backup, monitoring and incident readiness.
Compare providers →Credit, identity & compliance
Credit applications, bureaus, adverse action, red flags and fraud prevention.
Compare providers →Dealer IT & managed services
Networks, endpoints, telecom, help desk, compliance and continuity.
Compare providers →Related dealership technology questions
What should a dealer ask before signing a software contract?
Confirm the exact products, implementation, service levels, data rights, security obligations, fees, renewal mechanics, price changes, termination, transition support and order-of-precedence across every incorporated document. Obtain qualified legal review for the dealer’s situation.
Vendor security reviewWhat security questions should dealerships ask software vendors?
Ask about governance, independent assessments, access control, encryption, logging, vulnerability management, incident response, resilience, data retention, subprocessors and contract obligations. Scope the review to the actual service and data involved.
Digital retailing definitionWhat is automotive digital retailing?
Automotive digital retailing supports some or all of the shopping and deal process online, such as payments, trade, credit, protection products, documents and handoff to the showroom. The term does not guarantee an end-to-end transaction or identical online and in-store terms.
Vendor acquisition diligenceWhat should dealers do when a software vendor is acquired or rebranded?
Confirm the legal contracting entity, product roadmap, support organization, data practices, integrations, pricing, renewal terms, account ownership and any required consent. A rebrand may be cosmetic; an acquisition may change dependencies or commercial terms, but neither should be assumed.