Celebrating 26 years as a car dealership marketing company.

1-888-524-4563
Blog

The FTC Safeguards Rule and Your Marketing Vendors

By September 18, 20269 min read
The FTC Safeguards Rule and Your Marketing Vendors

The FTC Safeguards Rule (16 C.F.R. Part 314) treats an auto dealer as a financial institution, and its requirements reach every vendor you hand customer information to — mail houses, lead providers, BDC vendors, CRM and DMS integrators. Section 314.4(f) requires you to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess them. Section 314.4(j) requires notifying the FTC as soon as possible and no later than 30 days after discovering a notification event involving the unencrypted customer information of at least 500 consumers. The key provisions became mandatory on June 9, 2023 and the notification requirement took effect May 13, 2024. Cited against the Code of Federal Regulations in September 2026.

Stated at the top rather than in small print at the bottom. This is general information written to help a dealership manager ask better questions of their own counsel and their own IT people. It is not legal advice, it creates no advisory relationship, and it cannot account for your state, your vendor contracts or how your store actually moves data.

Every requirement below is cited to the regulation so you can read the text yourself rather than take our summary of it.

Why This Applies To a Car Dealership At All

The objection we hear most is that the Safeguards Rule is a banking rule. It is not. It sits under the Gramm-Leach-Bliley Act, and GLBA’s definition of a financial institution turns on activities rather than signage. A dealership that arranges or facilitates financing or leasing — which is very nearly all of them — is doing an activity that brings it inside the definition. Selling the contract to a lender the same afternoon does not remove you from scope, because you collected and held the information to arrange the deal.

The FTC has published dealer-specific guidance precisely because this keeps being misread. If your store takes a credit application, runs a bureau pull, or holds a completed deal jacket, the rule is addressed to you.

What Counts As Customer Information

This is where marketing gets pulled in, and it is the part most stores have not mapped. Customer information is nonpublic personally identifiable financial information about a customer, in any form, that you handle or maintain. A credit application obviously qualifies. So does the fact that a named individual applied for financing, which is exactly the fact a prescreened or credit-qualified mailing list conveys.

So the question to ask of your marketing is not “is this a financial record” but “does this file identify a person and say something about their financial circumstances”. A list of last month’s buyers with payoff amounts does. An equity-mining pull does. A bankruptcy or credit-challenged list does — the list itself is the financial fact. A prospect file of names and addresses bought on geography alone generally does not, which is a real and useful distinction when you are deciding how carefully a given file has to be handled.

The Program You Are Required To Have

Section 314.4 sets out the elements. In the order the regulation gives them:

  • A qualified individual. You must designate one person responsible for overseeing and implementing the program. It can be an employee or an affiliate or a service provider, but if it is an outside party the store still owns the responsibility and must designate someone senior to direct them.
  • A written risk assessment. Not a conversation. The regulation requires it in writing, requires it to identify reasonably foreseeable internal and external threats, and requires it to be updated periodically.
  • Safeguards that follow from it — access controls limited to what a role actually needs, an inventory of where data lives, encryption of customer information both in transit over external networks and at rest, secure development practices, multi-factor authentication for any individual accessing any information system, secure disposal, change management, and logging of authorised user activity.
  • Testing. Continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months.
  • Training. Security awareness training for personnel, kept current.
  • Service provider oversight. Covered in its own section below, because for marketing it is the whole ballgame.
  • A written incident response plan.
  • An annual written report from the qualified individual to your board or equivalent governing body.

Two of these are the ones stores skip and investigators ask for immediately: the written risk assessment and the annual report. They are cheap to produce and conspicuous by their absence.

The Vendor Clause That Actually Matters

Section 314.4(f) is the provision every marketing decision runs into. It requires you to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess your providers based on the risk they present and the adequacy of their safeguards.

Read that as three separate duties, because it is three separate duties. Choosing a competent vendor is not enough if the contract is silent. A contract with a security clause is not enough if you never look again. And “periodically assess” means you need something on file — a questionnaire, an attestation, a report — with a date on it.

In practice, for a dealership, the vendors in scope usually include the DMS and CRM, any lead provider, any equity-mining or data-append service, the mail house, any outsourced BDC or call centre, any texting platform, and whoever disposes of your paper. If a file with names and financial facts reaches them, they are in scope.

What To Put In a Marketing Vendor Contract

We are one of these vendors, so take this as a description of what a dealer should require of us and of anyone else, rather than as a sales point:

  • A definition of customer information that matches the rule, not a narrower one.
  • An undertaking to implement and maintain safeguards appropriate to the data, with encryption in transit and at rest named specifically.
  • Purpose limitation — the file is used for the campaign and nothing else, and is not resold, appended or retained for other clients.
  • A retention and deletion term with an actual period, and certified deletion on request.
  • Subcontractor flow-down, because your mail house has a printer and your BDC vendor has a dialer.
  • An obligation to notify you of a security event promptly and in any case fast enough that you can still meet your own 30-day clock.
  • A right to assess — questionnaire, evidence, or audit — so that “periodically assess” is something you are contractually able to do.

The Notification Requirement, and the Clock

Section 314.4(j) requires notifying the Federal Trade Commission of a notification event involving the information of at least 500 consumers, as soon as possible and no later than 30 days after discovery. The trigger is unauthorised acquisition of unencrypted customer information. Notification is made through a form on the FTC’s website, and the entries are published.

Two practical points. First, encryption is doing real work here — it is the difference between an event you report and one you may not have to. Second, the clock runs from discovery, and discovery includes what your vendor discovered, which is why the contractual notice obligation above matters so much. A mail house that tells you three weeks late has spent most of your window.

This is separate from your state’s breach notification statute, which has its own triggers, its own deadlines and its own definition of personal information. Both can apply to the same incident.

A Practical Checklist

  1. Name the qualified individual in writing and put a date on it.
  2. List every system and every vendor that touches customer information. Most stores find more than they expected.
  3. Write the risk assessment. It does not need to be long. It needs to exist, be specific to your store, and be dated.
  4. Turn on multi-factor authentication for every system holding customer information, including the ones only one manager uses.
  5. Pull your marketing vendor contracts and check them against the seven clauses above. Amend the ones that fail.
  6. Get a dated security attestation from each vendor and diarise the next one.
  7. Write the incident response plan and make sure it names who calls whom at 6 p.m. on a Friday.
  8. Produce the annual report to your governing body.

Frequently Asked Questions

Does the Safeguards Rule apply if we never hold the contract?

Yes. The rule follows the activity of arranging or facilitating financing and the information you collect to do it, not whether the paper stays with you. Assigning the contract to a lender the same day does not put you outside the definition.

Are we exempt because we are small?

Partially, and less than most people hope. A financial institution that maintains customer information concerning fewer than five thousand consumers is exempt from some specific requirements — the written risk assessment, continuous monitoring or annual penetration testing, the incident response plan and the annual written report. The rest of § 314.4, including the vendor obligations in (f), still applies. Count the consumers you maintain information about, not the cars you sell.

Is a plain prospect mailing list in scope?

Usually not, if it is names and addresses selected on geography or vehicle ownership with nothing financial attached. It changes the moment the selection itself conveys a financial fact — credit-qualified, prescreened, in-equity, lease-end, bankruptcy. Then the list is the financial information, and it should be handled and contracted for accordingly.

Who has to report a breach at the mail house, them or us?

Your obligation under § 314.4(j) is your own. Their contract should require them to tell you quickly enough that you can meet it, and it should say so in days. The parallel obligations on how you may then contact those people are covered in TCPA and dealer outreach compliance. Do not assume a vendor notification discharges your duty to notify the FTC.

Summary

The Safeguards Rule reaches dealership marketing because dealership marketing runs on customer information. The obligations that bite are the unglamorous ones: a named qualified individual, a written and dated risk assessment, multi-factor authentication, encryption, a written incident response plan, an annual report, and — for anyone sending files to a mail house, a lead vendor or an outsourced BDC — the three duties in § 314.4(f) to select carefully, require safeguards by contract and reassess on a schedule. Add the 30-day notification clock in § 314.4(j) and the fact that it starts at discovery, including your vendor’s. All of it was cited against 16 C.F.R. Part 314 in September 2026, and none of it substitutes for advice from your own attorney.

Ready when you are

Let's grow your dealership.

Tell us about your store and our team will be in touch — or .

What are you interested in? (select all that apply)
Call