Your dealership arranges financing. That makes it a financial institution, and the only kind the FTC regulates under two rules.
The F&I desk did this. A dealership lands inside the FTC Safeguards Rule by two independent routes, financing and leasing, and it then carries a second FTC rule that reaches no other kind of financial institution. Most dealer coverage stops at "you need a written plan." The sentences that decide what is actually in scope are further down.
- Financing or arranging financing makes you covered, on its own
- Leasing longer than 90 days makes you covered, separately
- Ten elements, one written program, and a 30 day FTC notice once an event qualifies
Is a car dealership a financial institution under the FTC Safeguards Rule?
Yes, and there are two independent ways in. Most articles quote one of them. The one they usually quote is the narrower of the two.
The first door is financing. The FTC says it plainly in guidance written specifically for dealers:
Automobile dealers who finance (or facilitate the financing of) automobiles for consumers are financial institutions for purposes of the Safeguards Rule, since lending money is considered a financial activity under the relevant federal law.
FTC, Automobile Dealers and the FTC's Safeguards Rule FAQs, June 2025
Read the parenthesis, because it is the whole ballgame. Facilitate the financing. You do not have to lend the money. Walking a buyer's credit application over to a captive or a credit union puts you inside the definition on the same footing as a lender.
The second door is leasing, and this is the one that gets quoted because it is printed in the regulation itself:
An automobile dealership that, as a usual part of its business, leases automobiles on a nonoperating basis for longer than 90 days is a financial institution with respect to its leasing business.
16 CFR 314.2(h)(2)(ii)
A rooftop that does no leasing at all reads that sentence, decides it is about somebody else, and stops reading. The financing door was open the entire time.
Neither door has a revenue threshold, an employee count, or a carve out for stores that consider themselves too small to be regulated. A single point family store and a hundred rooftop group are financial institutions on identical grounds. Size changes four obligations further into the rule, which this page gets to below, and it changes nothing about whether the rule applies.
The FTC's own summary of scope: the Safeguards Rule "applies to financial institutions subject to the FTC's authority. That includes most automobile dealers who finance or lease automobiles."
Why the FTC, when nobody examines a dealership
Banks and credit unions get examined on a cycle. Somebody walks in, asks for the information security program, and reads it. Dealerships have no equivalent, which is exactly why the obligation is easy to carry for years without ever being tested.
The reason the FTC holds this and not the Consumer Financial Protection Bureau is statutory, and it is worth knowing because it answers the first objection most dealer principals raise. Congress wrote the carve out into Dodd-Frank:
the Bureau may not exercise any rulemaking, supervisory, enforcement or any other authority, including any authority to order assessments, over a motor vehicle dealer that is predominantly engaged in the sale and servicing of motor vehicles, the leasing and servicing of motor vehicles, or both.
12 U.S.C. 5519(a)
The dealer lobby won that exclusion. What it did not do, and what is written into the same section at subsection (d), is remove the FTC. The Commission keeps its rulemaking authority over dealers, and the Safeguards Rule is one of the rules it wrote with it. So the industry that successfully argued its way out of one regulator ended up with a federal data security obligation and no examiner to tell it how it is doing.
That is the honest reason to read the rule rather than wait for someone to ask about it. The absence of an examination cycle is not the absence of a duty. It only means the first time anyone reads your program closely, it will probably be after something has already gone wrong.
Dealers are the only financial institution the FTC covers under two rules
This is the part almost no dealer content mentions, and it comes from the FTC's own staff:
auto dealers are the only financial institutions who also fall under the FTC's Privacy Rule.
FTC Bureau of Consumer Protection staff, August 13, 2025
Tax preparers, title agencies, appraisers, collection agencies, mortgage brokers: all covered by the Safeguards Rule, none of them carrying the Privacy Rule as well. Dealers carry both. They are separate rules, with separate triggers, and they answer different questions.
The Safeguards Rule, 16 CFR Part 314
- Question it answers: how do you protect the information you hold?
- Trigger: a continuing relationship. The person became your customer.
- Output: a written information security program with ten elements.
- Scope: customer information only, but every copy of it, in any format.
The Privacy Rule, 16 CFR Part 313
- Question it answers: what do you tell people, and what may you share?
- Trigger: wider. It reaches a consumer who never filled out a formal application.
- Output: privacy notices and an opt out before sharing with unaffiliated third parties.
- Scope: collection and sharing practices rather than protection.
The practical consequence is that a store can be genuinely compliant with one and untouched by the other, and many are. Dealers have handled Privacy Rule notices since 2000 and the paperwork is routine. The Safeguards Rule asks a different question, and handing a buyer a privacy notice answers none of it.
The Privacy Rule also reaches further up the funnel. Per the FTC's dealer guidance it applies even when someone gives you personal information about potential financing and never fills out a formal application. It does not apply to a walk in who asks general questions about financing, buys with cash, or arranges financing elsewhere, because that person never becomes a consumer under the rule at all.
What most stores believe, and what the regulation says
Each row on the right cites the paragraph of the regulation, or the FTC staff guidance, it comes from. Where the source is the staff FAQs rather than the rule text, that guidance is the FTC's view and is not binding on the Commission.
| The common assumption | What it gets wrong | What the rule and the FTC's dealer guidance say |
|---|---|---|
| "We sell cars. We are not a financial institution." | Uses the conversational meaning of the phrase | Dealers who finance or facilitate financing are financial institutions, and leasing beyond 90 days is a separate route in. FTC Automobile Dealers Safeguards Rule FAQs, and 16 CFR 314.2(h)(2)(ii) |
| "The lender holds the paper, so the obligation is theirs." | Assumes the customer relationship follows the note | Arranging or brokering the loan creates a continuing relationship with you, and the duty survives after you no longer hold the note. FTC Automobile Dealers Safeguards Rule FAQs |
| "We are under the threshold, so we are exempt." | Reads a partial exception as a full exemption | Below five thousand consumers, exactly four paragraphs stop applying. Encryption, multifactor authentication, and the written program itself still bind. 16 CFR 314.6 |
| "Our DMS vendor handles security." | Assumes outsourcing transfers accountability | You must select capable providers, require safeguards by contract, and periodically assess them. The duty is yours. 16 CFR 314.4(f) |
| "We turned on multifactor authentication for the sales floor." | Scopes the requirement to employees and to email | Multifactor authentication for any individual accessing any information system, unless equivalent or stronger controls are approved in writing. 16 CFR 314.4(c)(5) |
| "Everything in the DMS is customer information." | Over-scopes, then gives up on the whole problem | Name and address alone are not. Service records are not. The line is whether the record shows the person sought or obtained financing. FTC Automobile Dealers Safeguards Rule FAQs |
| "None of it is customer information, so the database is out of scope." | Under-scopes a commingled system | Once the database contains customer information you must protect it and control access to it, whatever else is in there. FTC Automobile Dealers Safeguards Rule FAQs |
| "We use Microsoft 365, so encryption is handled." | Confuses a licence with a configuration | Encrypt customer information in transit over external networks and at rest, or document compensating controls approved in writing by your Qualified Individual. 16 CFR 314.4(c)(3) |
| "We have a WISP template from a vendor, so we are done." | Treats a document as the program | The program must be written, and it must be implemented, maintained, monitored, tested, and reported on annually. 16 CFR 314.3(a) and 314.4(d), (g), (i) |
The FTC Automobile Dealers Safeguards Rule FAQs referenced above is the FTC publication Automobile Dealers and the FTC's Safeguards Rule Frequently Asked Questions, published June 2025 and linked in full below. The FAQs represent the views of FTC staff and are not binding on the Commission.
Find out what your systems can honestly claim
Our engineers read your Microsoft 365 tenant and report what is switched on, what is not, and which element of the rule each finding belongs to. No cost, no obligation.
The ten elements, and where Microsoft 365 carries the weight
16 CFR 314.4 runs from paragraph (a) to paragraph (j). Paragraph (j) is the newest, and 16 CFR 314.5 fixes its effective date at May 13, 2024, which is why older material still counts nine.
Eight of the ten are organizational rather than technical. Naming a Qualified Individual, writing a risk assessment, training staff, overseeing service providers, evaluating and adjusting the program, keeping an incident response plan, reporting to ownership at least annually, and notifying the FTC when something qualifies. No product does any of those for you, and any vendor that says otherwise is selling you a document.
The technical work concentrates in a single element, paragraph (c), plus the testing choice in paragraph (d). Paragraph (c) is also the longest element in the rule, and these three of its sub-requirements are the ones most likely to be wrong in a dealership right now:
Multifactor authentication
For any individual accessing any information system, not just email and not just employees. Microsoft Entra ID is where that gets enforced and where the gaps are visible.
16 CFR 314.4(c)(5)Encryption in transit and at rest
Or compensating controls your Qualified Individual approves in writing. Microsoft Purview is where classification and protection of customer information get applied and evidenced.
16 CFR 314.4(c)(3)Logging and monitoring
Policies and controls that monitor and log authorized user activity and detect unauthorized access or tampering. Microsoft Defender and Microsoft Intune carry this on the endpoint and identity side.
16 CFR 314.4(c)(8)Two more technical requirements sit inside paragraph (c) and get missed constantly. Access has to be limited to the customer information a person needs to do their job, at 314.4(c)(1)(ii), which is a real problem in a store where the whole floor can pull any deal jacket. And secure disposal is on a clock: procedures to dispose of customer information no later than two years after the last time it was used for that customer, unless you have a legitimate business or legal reason to keep it, at 314.4(c)(6)(i).
On testing, paragraph (d)(2) gives a choice rather than a mandate. Run continuous monitoring, or run annual penetration testing plus vulnerability assessments at least every six months. Most stores have neither, and the second option is the expensive one.
Which of your records are actually covered, and which are not
This is the most useful section of the FTC's dealer guidance and the part almost nothing else repeats. The Safeguards Rule does not cover everything in a dealership. It covers customer information, and the FTC draws the line in a way that is genuinely workable.
The line is financing. A record is customer information when it shows that a particular person sought or obtained financing or leasing from you. A record that does not show that, and contains nothing else sensitive, is not customer information on its own.
Customer information
- Approved financing and lease applications, with the name, address, Social Security number, and account details on them
- A spreadsheet of the names and addresses of people who financed or leased from you
- Financial information about individual consumers who financed or leased
- Anything derived from that information, including a list identifying who financed with you
Not customer information on its own
- Names and addresses collected from every buyer, where nothing indicates how they paid
- Retail Delivery Reports carrying name, address, and VIN
- General sales data and aggregate reports not derived from how vehicles were financed
- Service and maintenance records for vehicles you sold, leased, or serviced
Two qualifications keep this from being a loophole, and both matter more than the list does.
Combine the two categories and the whole thing is covered
Name and address alone are outside. Name and address next to anything showing the person applied for or received financing is inside. The FTC is explicit: if a document indicates whether those individuals obtained financing from you, that information is customer information and you have an obligation to protect it. Most dealership records do not stay in one category for long.
A commingled database is covered as a whole
Almost every store keeps everything in one system: shoppers who kicked tires, people who applied, people who bought, with Social Security numbers and financial detail sitting alongside service history. The FTC addresses that directly. Because the database includes customer information, you are obligated to protect it, and, in the Commission staff's words, that means you should control access to it.
A list you pull out of that database is judged separately. A list of everyone who bought a vehicle is not customer information, even though it came from a covered system, as long as it does not indicate who financed or leased and carries nothing else sensitive.
The network protection obligation is broader than the records obligation
Even where a particular record is not customer information, the rule requires you to secure information systems that contain customer information and those connected to a system containing it. Unless you run two genuinely separate networks, protecting the covered files protects everything on the same wire. This is the reason scoping arguments rarely reduce the work as much as people hope.
The sentence that makes your DMS vendor's security your problem
A dealership runs on other people's systems. The DMS, the CRM, the credit aggregation portal, the desking tool, the equity mining vendor, the marketing company pulling lists, the shredding service, the IT provider with a remote session open to the back office. Most of them touch customer information and several of them have direct access to the network.
Paragraph (f) of the rule turns that into three specific duties, and it is worth reading them as three rather than as a vague expectation:
Select and retain providers capable of protecting the information
Reasonable steps to pick vendors that can maintain appropriate safeguards for the customer information at issue. Not a promise on a website. Something you looked at before you signed.
Require those safeguards by contract
In writing, in the agreement. The FTC is clear that this does not mean forcing every vendor to meet every obligation that binds you. The steps required depend on your size and complexity and on the nature of the service. A shredding company that never touches your network is not held to the same network security terms as a marketing firm you gave a login to.
Periodically assess them, based on the risk they present
An ongoing duty rather than a one time diligence exercise. The FTC ties the reason to two failure paths: poor security at the vendor can expose your customer information sitting on their system, and a vendor with direct access to your network can be the route a bad actor walks in through.
Two consequences of paragraph (f) are worth stating in plain terms, because they change what a dealership actually does on Monday.
A vendor with direct network access falls inside the multifactor requirement. The FTC gets there through the same paragraph that governs your own staff. Paragraph (c)(5) requires multifactor authentication for any individual accessing any information system, and the FTC applies that to vendors in these words: if you give a service provider direct access to your network, they should be required to use multifactor authentication for that access, because they are individuals accessing your information systems. Every standing remote session into the back office is inside that sentence. So is every shared login a vendor has been using since 2019 because rotating it was inconvenient.
Sharing information with a company does not make them your service provider. This one cuts in your favor and it is worth knowing. Per the FTC's dealer guidance an OEM does not become a service provider just because you sent them data. If they are not providing you a service, you have no obligation under the Safeguards Rule to oversee their safeguards. A company that collects customer names and addresses from you to use in future recall notices is not providing you a service and is not a service provider for that activity. The Privacy Rule analysis for that same disclosure is separate, and it is the one to actually check.
The same logic applies to a nonaffiliated company you share customer information with under a consent exception, to let a customer claim a rebate or a tax credit. If they are not a service provider, the ongoing oversight duty does not attach, even though the information you sent was customer information.
We are under five thousand consumers. Does the rule still apply?
Yes. The rule still applies, subject to four specific exceptions. Two of them are whole elements and two are subparagraphs inside a larger element, and the whole exception is written narrowly enough to quote in one line:
Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.
16 CFR 314.6
Those four are the written risk assessment at 314.4(b)(1), the continuous monitoring or penetration testing and vulnerability assessment requirement at 314.4(d)(2), the written incident response plan at 314.4(h), and the annual written report to your board or a senior officer at 314.4(i). Note the shape of that list: (h) and (i) are whole elements, while (b)(1) and (d)(2) are subparagraphs, so the rest of elements (b) and (d) still binds. Real relief, and for a small store it removes the most expensive items on the list.
Here is what the exception does not touch, and this is the part that gets misread:
The written program itself still binds
16 CFR 314.3(a) requires a comprehensive information security program, written in one or more readily accessible parts. The threshold does not lift it. A store under five thousand consumers still owes a written program, it just contains fewer required parts.
Every technical safeguard still binds
All of paragraph (c) survives. Access controls, encryption at rest and in transit, multifactor authentication for anyone accessing any information system, secure disposal, change management, logging and monitoring. Nothing in the threshold reduces the technical work.
The Qualified Individual, training, and vendor oversight still bind
Paragraphs (a), (e), and (f) are not in the list of exceptions. You still designate someone accountable, you still train staff, and you still oversee your service providers.
FTC breach notification still binds
Paragraph (j) is not excepted either. A store under the threshold that suffers a qualifying event still notifies the Commission on the same 30 day clock as everyone else.
There is a counting question hiding in the threshold too. It is consumers whose information you maintain, not deals you wrote this year. Prior years stay in the count for as long as the records are still in your possession, which is one of the practical arguments for taking the two year disposal clock in 314.4(c)(6)(i) seriously. Stores that have never disposed of anything are usually further over five thousand than they assume.
You do not hold the paper. You are still holding the file.
Ask a dealer principal why the Safeguards Rule is somebody else's problem and this is usually the answer. The credit union funded it. The captive holds the note. The store took a flat and moved on. The file left with the lender.
The file did not leave. The FTC addressed this exact question in the dealer guidance, and the answer runs the other way in two separate steps.
Arranging the loan creates the relationship
If your dealership arranges or brokers a loan for a consumer, you are in a continuing relationship with that consumer for purposes of safeguarding the customer information they gave you. That is true whether you funded it or not. The information the customer handed over so you could arrange the financing, and the information another financial institution handed you for the same purpose, is customer information subject to the rule.
The duty outlives the relationship
It remains customer information after the customer relationship ends. In the FTC's framing, you must continue to protect customer information you obtained from a customer, even if they are no longer a customer, for as long as you have that information in your possession.
There is an exit, and it is the one nobody uses. You can securely dispose of the information at any point, and the FTC says you should, once you no longer have a business need to keep it. The obligation attaches to possession. Stop possessing it and the obligation stops.
Put those together and a pattern shows up in almost every store. The deal jackets from 2019 nobody has looked at since, the credit applications sitting in a shared mailbox, the scanned identity documents in a folder on the file server, the exports somebody pulled for a spiff contest. None of that is generating revenue. All of it is customer information you are required to protect, and all of it is counting toward your five thousand.
Disposal is the only element of the rule that makes the rest of the rule cheaper. It is also the one dealers are best positioned to act on this quarter without buying anything.
Thirty days, five hundred consumers, and the word that starts the clock
Paragraph (j) is the newest element and the one most likely to be missing from a program written before 2024. Since May 13, 2024, a covered institution must notify the FTC of a notification event involving the information of at least 500 consumers, as soon as possible and no later than 30 days after discovery. The notice is filed electronically on the FTC's website.
Three details in the text decide whether a store meets that clock or misses it.
Discovery is earlier than you think. The rule deems an event discovered on the first day it is known to you, and you are deemed to know it if it is known to any employee, officer, or other agent, other than the person who committed the breach. The clock does not start when the owner is told. It starts when a service advisor notices.
Unauthorized acquisition is presumed. The rule presumes it unless you have reliable evidence showing there has not been, or could not reasonably have been, unauthorized acquisition of the customer information. The rule does not say what reliable evidence has to be, but a store with no record of who touched what has very little to offer, which is the practical reason paragraph (c)(8) is not optional.
Encryption changes the analysis. The duty attaches to unencrypted customer information, and it reaches encrypted information as well when the encryption key was accessed. So encryption at rest can keep an event outside the notification duty, but only where the key was not also taken, and only as one condition among the three. That is still a sharper argument for 314.4(c)(3) than any compliance checklist makes.
And the filed notice includes a general description of the event and the number of consumers affected. Reports made under this paragraph can be made public. For a business whose reputation is local and whose competitors are eight minutes away, that is the part worth sitting with.
The same rule, read from the lender's side of your deals
Access Business Technologies manages Microsoft 365 for more than 750 financial institutions and hosts their Azure environments. Banks, credit unions, and mortgage companies. The people funding your paper.
One distinction inside that sentence is worth making, because it is exactly the kind an examiner notices. The FTC Safeguards Rule reaches financial institutions under the FTC's jurisdiction that are not already subject to another regulator's enforcement authority through section 505 of the Gramm-Leach-Bliley Act. ABT's non-bank mortgage clients sit under this rule, the same 16 CFR 314 this page has been quoting. The banks and credit unions ABT serves sit under separate Gramm-Leach-Bliley safeguards standards written and enforced by their own prudential regulators, which is a different regime with a different examiner.
That adjacency is the reason this page exists. ABT's Microsoft 365 security baseline runs 80 policies across 11 categories, deployed from day one, including 11 Conditional Access policies. 62 of those 80 policies are formally mapped to Gramm-Leach-Bliley Safeguards Rule subsections at 16 CFR 314.4, and the baseline covers 169 Microsoft Secure Score controls.
16 CFR 314.4 is the paragraph this whole page has been quoting. Not a bank framework adapted for retail automotive, and not a compliance overlay invented for a new market. The mapping already speaks your regulation because ABT's mortgage clients have lived under it for years, and because the baseline was written against 16 CFR 314.4 subsection by subsection rather than against a generic security framework.
A free security assessment of your Microsoft 365 tenant
Our engineers read your Microsoft 365 tenant and report what is actually configured there, with each finding tied to the element of the rule it belongs to. The review covers the tenant, not your DMS or other systems that sit outside it.
- Multifactor authentication coverage across your Microsoft 365 tenant, by user and by application, including vendor and guest accounts that sign in through it, against 16 CFR 314.4(c)(5)
- Encryption posture for information in transit and at rest, against 314.4(c)(3)
- Access controls, and whether the sales floor can reach files their duties do not require, against 314.4(c)(1)(ii)
- Audit logging and retention, which is what a store draws on if it ever has to rebut the presumption in 314.4(j)(2)
- Where deal jackets and credit applications have ended up inside your Microsoft 365 tenant, including the copies in mailboxes, Teams, and SharePoint
- A plain reading of what your written program can honestly claim today
The assessment is a technical review of your Microsoft 365 configuration. It is not legal advice and not a determination of regulatory compliance. Whether your store is covered, and whether your program satisfies the rule, are questions for your counsel.
If the review turns up work worth doing, one thing is worth knowing before you ask. ABT publishes a single price list and it has no industry dimension anywhere in it. A dealership sees the same numbers a community bank sees, because there is only one set of numbers. That is a fact about the catalog rather than a discount or a match. Guardian Foundation, a hardened tenant with Guardian Security Insights, is included at no additional charge with Microsoft licensing through ABT, and the managed tiers above it, along with their per user rates and published minimums, are listed openly on the M365 Guardian page.
ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies.
There is no obligation attached to the assessment, and plenty of businesses take the report to their existing provider. That is a fine outcome. The report is more useful than the sales conversation.
Where the facts on this page come from
Every regulatory quotation was read from the current text of the regulation, and every FTC statement from the FTC's own published page, on 29 August 2026.
- 16 CFR Part 314, the FTC Safeguards Rule, current text via the Electronic Code of Federal Regulations. Sections quoted or relied on: 314.2(h)(2)(ii), 314.3(a), 314.4(a) through (j), 314.5, and 314.6. ecfr.gov
- Federal Trade Commission, Automobile Dealers and the FTC's Safeguards Rule Frequently Asked Questions, June 2025. Source of the financing and facilitating-financing scope, the ten element count, the customer information scoping, the OEM and service provider answers, and the answer on arranging a loan you do not hold. The FAQs represent the views of FTC staff and are not binding on the Commission. ftc.gov
- Federal Trade Commission, FTC Provides Guidance on Updated Safeguards Rule, June 16, 2025, the release announcing those FAQs. ftc.gov
- Federal Trade Commission, Bureau of Consumer Protection staff, Auto Dealer? Interested in the Safeguards Rule? The FTC has some FAQs for you, August 13, 2025. Source of the statement that auto dealers are the only financial institutions who also fall under the FTC's Privacy Rule. ftc.gov
- Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know. Source of the jurisdictional scope statement, that the rule applies to financial institutions under the FTC's jurisdiction that are not subject to the enforcement authority of another regulator under section 505 of the Gramm-Leach-Bliley Act, 15 U.S.C. 6805. ftc.gov
- 12 U.S.C. 5519, Exclusion for auto dealers. Source of the statement that the Consumer Financial Protection Bureau may not regulate motor vehicle dealers and that FTC authority is preserved. law.cornell.edu
- Microsoft product documentation for the capabilities named on this page: Microsoft Entra ID, Microsoft Purview, Microsoft Defender, and Microsoft Intune. learn.microsoft.com
Nothing on this page is legal advice. Whether a particular business is covered by the FTC Safeguards Rule, and whether its program satisfies the rule, are determinations for its own counsel.
More on the rule and the systems it lands on
You Might Be Running a Financial Institution. The FTC Thinks So.
The worked examples printed in the rule, and the businesses that find themselves inside a definition written for banks.
What to Ask the Vendor Holding Access to Your Tenant
The oversight questions paragraph (f) expects you to be able to answer about anyone with a login to your systems.
The Offboarding Step Almost Everyone Gets Wrong
Turnover is constant on a sales floor. Access controls under 314.4(c)(1) only hold if the leaving part actually works.
Dealership questions, answered from the rule text
Find out what your store
can honestly claim.
Tell us roughly how many people work in the store and how many consumers' information you still hold, counting prior years. Our engineers will read the tenant and come back with what is switched on, what is not, and which element of the rule each finding belongs to.

