What is the FTC Safeguards Rule for dealerships?
Because dealerships arrange financing and leasing, they are treated as financial institutions under the Gramm-Leach-Bliley Act and fall under the FTC's Safeguards Rule. The Rule requires a written information security program with named elements — including a designated qualified individual, a written risk assessment, encryption, multi-factor authentication and vendor oversight. The amended requirements became mandatory on June 9, 2023. This is issue-spotting information, not legal advice.
Why dealers are in scope
The obligation follows from arranging credit, not from selling vehicles. A store that facilitates financing or leasing is handling customer financial information and is treated accordingly, whether it is franchised or independent.
The vendor-oversight element is the one that touches procurement
The program has to address service providers: selecting them on their ability to safeguard information, requiring safeguards by contract, and monitoring them. That turns security diligence into a purchasing step rather than an IT afterthought — which is why security questions belong in the RFP.
A document is not a program
Written policy that is not implemented, tested and evidenced does not demonstrate compliance. Keep the risk assessment current, keep records of testing, and be able to show what you actually do.
What to ask a software vendor
Where data is stored and processed, who can access it, what encryption applies in transit and at rest, how access is authenticated, which subprocessors are involved, what the incident-notification commitment is, and what independent assessment exists. Ask for the answers in the contract, not in a sales deck.
What to verify
Confirm a qualified individual is named and documented
Keep the written risk assessment current and evidenced
Put vendor security requirements in the contract, not the deck
Record testing and remediation so the program can be demonstrated
Continue the research
Fraud & cybersecurity
Identity verification, endpoint security, backup, monitoring and incident readiness.
Compare providers →Credit, identity & compliance
Credit applications, bureaus, adverse action, red flags and fraud prevention.
Compare providers →Dealer IT & managed services
Networks, endpoints, telecom, help desk, compliance and continuity.
Compare providers →Related dealership technology questions
What should a dealer ask before signing a software contract?
Confirm the exact products, implementation, service levels, data rights, security obligations, fees, renewal mechanics, price changes, termination, transition support and order-of-precedence across every incorporated document. Obtain qualified legal review for the dealer’s situation.
Vendor security reviewWhat security questions should dealerships ask software vendors?
Ask about governance, independent assessments, access control, encryption, logging, vulnerability management, incident response, resilience, data retention, subprocessors and contract obligations. Scope the review to the actual service and data involved.
Digital retailing definitionWhat is automotive digital retailing?
Automotive digital retailing supports some or all of the shopping and deal process online, such as payments, trade, credit, protection products, documents and handoff to the showroom. The term does not guarantee an end-to-end transaction or identical online and in-store terms.
Vendor acquisition diligenceWhat should dealers do when a software vendor is acquired or rebranded?
Confirm the legal contracting entity, product roadmap, support organization, data practices, integrations, pricing, renewal terms, account ownership and any required consent. A rebrand may be cosmetic; an acquisition may change dependencies or commercial terms, but neither should be assumed.