
The FTC sent warning letters to 97 dealer groups in March 2026 and published their names on May 28. In April it settled with Lindsay Automotive Group for a $3.1 million civil penalty plus more than $75 million in customer restitution. Every one of those actions was about advertised pricing. But a second FTC rule already applies to your dealership — and it is enforced by the same people.
If your dealership finances or leases vehicles, you are a “financial institution” under the FTC Safeguards Rule. Since June 9, 2023 you have been required to run a written information security program built on nine specific elements, and since May 2024 to report breaches touching 500 or more consumers within 30 days.
That is not an advertising problem or an F&I problem. The FTC Safeguards Rule for car dealerships is an IT problem — and it is the half of FTC dealer enforcement almost nobody is writing about.
Why dealerships are back on the FTC’s radar
The pricing enforcement is real and it is escalating. The FTC’s Bureau of Consumer Protection cited Section 5 of the FTC Act in warning letters covering six categories of conduct: advertising prices that exclude mandatory fees, promoting rebates unavailable to all buyers, omitting required down-payment disclosures, conditioning advertised prices on dealer financing, requiring add-ons, and advertising vehicles that aren’t available.
The CARS Rule — the dealer-specific rule that would have codified much of this — was vacated on procedural grounds in January 2025. That was widely read in the industry as the pressure coming off. It wasn’t. The court did not find that the conduct the rule targeted was lawful; the FTC simply went back to Section 5, which it has always had.
Here is the part worth sitting with. The Bureau of Consumer Protection enforces deceptive pricing. The Bureau of Consumer Protection also enforces the Safeguards Rule. The FTC’s investigative authority runs to the matters under investigation — and the agency, not the dealer, decides what those are.
To be straight with you: we could not find a published case where the FTC turned a dealer pricing investigation into a Safeguards Rule action. Anyone telling you that is a documented pattern is overselling it. What is documented is that 97 dealer groups are now on the FTC’s radar by name, that the Safeguards Rule has been mandatory for three years, and that most dealerships could not demonstrate compliance with it today. Draw your own conclusion about what happens if someone looks.
Does the FTC Safeguards Rule for car dealerships apply to you?
Almost certainly yes, and the test is narrower than most dealers assume.
Per the FTC’s own dealer FAQ, you are a financial institution if you finance or facilitate the financing of vehicles for consumers — because lending money is a financial activity under federal law. You also qualify if you lease vehicles for longer than 90 days.
What matters is the activity, not how you describe yourself. A dealership that thinks of itself as “a car lot, not a bank” is still covered the moment it arranges financing.
But the rule does not cover everyone who walks in. These people never become customers under the rule:
- Someone who pays cash and finances nothing
- Someone who arranges financing elsewhere and brings their own
- Someone who asks general questions about financing without applying
- Someone who simply expresses interest in a vehicle
And these records are not customer information unless you combine them with data that is:
- Names and addresses collected from every buyer regardless of financing — for example, the list you send an OEM for recall notices
- Aggregate sales reports not derived from how vehicles were financed
- Service and maintenance records for vehicles you sold or serviced
We point this out because the compliance-vendor pitch usually implies everything you hold is in scope. It isn’t, and a dealer who believes it is will buy more than they need.
The rule scopes to your network, not your F&I office
This is the most important line in the FTC’s dealer guidance, and it is the reason Safeguards is an infrastructure project rather than a paperwork project:
“unless you maintain two separate networks that are not connected, the protections that you need to provide for customer information on your network will also protect other information on your network”
Read that again. The rule requires you to secure systems containing customer information and systems connected to them. On a typical dealership network — one flat segment carrying the DMS, the service department, the sales floor, the parts counter, the manager’s laptop, and the showroom Wi-Fi — that is everything.
You cannot satisfy this rule by locking a filing cabinet in F&I. Either you segment the network so customer data lives somewhere defensible, or the whole dealership is in scope. That decision gets made in the server room, not the finance office — which is why it usually lands on whoever handles your security administration.
What the nine required elements actually are
Section 314.4 of the rule specifies nine elements. The FTC’s dealer FAQ counts the breach-notification duty as a tenth. Here they are in plain English, with who realistically owns each one.
| Requirement | What it means in a dealership | Typically owned by |
|---|---|---|
| 1. Qualified Individual | One named person accountable for the program. Can be your employee or your service provider — but if it’s a provider, you must still designate a senior employee to supervise them. | Dealer + MSP |
| 2. Written risk assessment | Inventory what customer data you hold and where, then assess threats in writing with stated criteria. Reassess periodically. | MSP |
| 3. Safeguards to control those risks | Access controls, data inventory, encryption at rest and in transit, app security review, MFA for anyone accessing customer information, secure disposal within two years of last use, change management, and activity logging. | MSP |
| 4. Monitor and test | Continuous monitoring — or, if you don’t have it, annual penetration testing plus vulnerability assessments every six months. | MSP |
| 5. Train your staff | Security awareness training for everyone, plus specialized training for whoever runs the program. | Dealer + MSP |
| 6. Oversee service providers | Select providers capable of protecting the data, put the security expectations in the contract, and reassess them periodically. Your DMS vendor is in scope. | Dealer (MSP advises) |
| 7. Keep the program current | Update it as your operations, threats, and staff change. | MSP |
| 8. Written incident response plan | Seven specified contents — goals, internal processes, roles and decision authority, communications, remediation, documentation and reporting, and a post-mortem that feeds back into the program. | MSP |
| 9. Annual written report | The Qualified Individual reports in writing, at least annually, to your board or governing body — or a senior officer if you have neither. | MSP drafts, dealer owns |
| 10. Breach notification | Report qualifying breaches to the FTC within 30 days. See below. | Dealer + MSP |
Two of these catch dealerships out more than the rest. MFA is not “MFA on email” — the rule says multi-factor for anyone accessing customer information on your system, and the only exception is a written approval from your Qualified Individual for equivalent controls. And the annual written report is the one nobody has, because it’s the only element that produces no visible IT benefit — which also makes it the fastest way for an investigator to establish that no real program exists.
What if we have fewer than 5,000 customers?
Then you get a genuine break, and it is bigger than most compliance vendors will tell you.
16 C.F.R. § 314.6 exempts financial institutions maintaining customer information on fewer than five thousand consumers from four requirements. In plain terms:
- The written risk assessment
- Continuous monitoring, annual penetration testing, and semi-annual vulnerability assessments
- The written incident response plan
- The annual written report to your board
That is the four most expensive line items on the list. A single-rooftop dealership under that threshold has a materially smaller job than a ten-store group.
Read the threshold carefully, though. It is customer information you maintain — not units sold last year. Financing records you have held since 2019 still count toward it. Most dealerships cross 5,000 faster than they expect, and the exemption evaporates quietly when they do.
The 30-day breach clock
Since May 2024, a “notification event” — a breach involving unauthorized acquisition of at least 500 consumers’ unencrypted information — must be reported to the FTC as soon as possible and no later than 30 days after discovery.
Three details change how you should prepare:
- Unauthorized acquisition is presumed. If unencrypted customer information was accessed without authorization, the rule assumes it was acquired unless you hold reliable evidence it wasn’t. That evidence is logging — which you either had running before the incident or you don’t have at all.
- Encrypted data counts as unencrypted if the key was taken. Encryption is not a blanket exemption from reporting.
- Your report may be made public. The FTC states it may appear in a public listing or a FOIA response. The 30-day clock and the disclosure risk are why an untested incident response plan is worth roughly nothing.
We won’t quote you a per-day penalty figure, because the ones circulating in dealer-marketing content don’t trace back to a statute. The consequence that is well documented is the shape of FTC data-security consent orders: multi-year compliance regimes with recurring third-party assessments. A fine is an event you write a check for. A consent order is someone auditing your dealership for years.
What an MSP owns, and what stays yours
Almost everything the FTC Safeguards Rule for car dealerships requires is technical work — which is exactly where an MSP fits. We have run managed IT since 2007 and support more than 75,000 users across our customers, so let us be precise about the boundary, because it matters here more than usual.
What we do: the technical program. Network segmentation so customer data isn’t sitting on the same flat network as the showroom Wi-Fi. MFA and access control. Encryption at rest and in transit. Logging and monitoring — the thing that later tells you whether data was actually acquired. Vulnerability scanning and penetration testing on the rule’s schedule. The written incident response plan, and testing it before you need it. Serving as or supporting your Qualified Individual, and drafting the annual report. It is the same work behind our IT compliance services for other regulated industries.
What we don’t do, and won’t pretend to: we are not your lawyers, and we don’t touch the advertising and F&I side. Nothing in this article helps with the pricing conduct in those 97 warning letters — that is work for your compliance counsel and your ad agency. If someone offers you a single package covering both, ask which of the two they actually do.
What stays yours no matter who you hire: the FTC is explicit that if your Qualified Individual works for a service provider, you must still designate a senior employee to supervise them. You can outsource the work. You cannot outsource the accountability.
When you don’t need us
Some dealerships should not buy anything after reading this:
- You’re under 5,000 customer records and already have MFA, encryption, and a segmented network. You’re most of the way there. What you likely need is documentation of what you already do — a few days of work, not a monthly engagement.
- You have competent in-house IT. Then you need a gap assessment and possibly the annual penetration test, not a full managed contract. Ask us for the assessment and nothing else.
- You’re cash-only and arrange no financing or leasing. The Safeguards Rule may not apply to you at all. Confirm it with counsel and get on with your day.
The dealerships that genuinely need help are the ones running a flat network with a DMS, no MFA outside email, no logging worth the name, and nobody who could produce a written program under the FTC Safeguards Rule for car dealerships if the FTC asked tomorrow. If that’s you, the gap is real and it has been open since June 2023. Our small business cybersecurity checklist is a reasonable place to start on the technical side, and if you work in another regulated industry, the same logic drives HIPAA compliance for small medical practices.
Related: the same flat-network problem that fails Safeguards Rule segmentation is also what makes the new attack vectors AI tools create at dealerships so dangerous — AI chat tools and DMS-integrated assistants widen the attack surface across the same unsegmented network this rule requires you to secure.
Frequently asked questions
Does the Safeguards Rule apply if we only arrange financing through third-party lenders?
Yes. The FTC’s dealer FAQ covers dealers who finance or facilitate the financing of vehicles. Brokering the loan creates the continuing relationship that makes the buyer your customer, and the information they gave you to get that financing is customer information you must protect.
Is our DMS vendor responsible for our compliance?
No. Service-provider oversight is your obligation under element six — you must select providers capable of protecting customer information, require appropriate safeguards in the contract, and periodically reassess them. A vendor’s own compliance does not transfer to you; if anything, their access to your customer data is a risk you are required to manage.
We had a breach affecting 400 customers. Do we report it?
The FTC notification requirement triggers at 500 or more consumers’ unencrypted information. Below that threshold there is no FTC notification duty under this rule — but state breach-notification laws apply separately and often have lower thresholds, so this is a question for counsel, not a reason to relax.
Does the CARS Rule being vacated mean the pressure is off?
No. The CARS Rule was struck down in January 2025 on procedural grounds, and the court made no finding that the conduct it targeted was lawful. The FTC has continued enforcing under Section 5 — 97 warning letters in March 2026 and the Lindsay settlement in April. Separately, the Safeguards Rule was never part of the CARS Rule and was never affected by that ruling. The FTC’s Safeguards Rule guidance remains in force.
Not sure whether your dealership could produce a written information security program if the FTC asked? We will tell you where the real gaps are — including the ones you can close yourself. Get in touch.