What Every Dealership Should Know About Customer Data, the Safeguards Rule, and Downtime
Every credit application is a complete identity, every payoff is a wire someone can redirect, and the whole store runs on the DMS. Here’s what the FTC actually requires of dealers, how dealerships really get hit, and what well run dealership IT looks like, in plain English.
Get the Free Dealership Technology Guide
Six plain English pages: your Safeguards obligations, the attacks, the dealership security baseline, and the questions dealer principals should ask. Instant delivery.
No spam. Unsubscribe anytime. Your information stays private.
Your Obligations, In Plain English
Because dealerships arrange financing, federal regulators treat them like financial institutions. The requirements reduce to three themes.
You're a Financial Institution
The FTC Safeguards Rule covers dealers that arrange financing or leasing. That means a written information security program: a qualified individual responsible for it, risk assessment, access controls, encryption, MFA, vendor oversight, and incident response, documented and maintained.
Customer Data Has Rules
Credit applications hold Social Security numbers, income, and everything else identity theft needs. Privacy notices, safeguarding, and proper disposal of financing paperwork are regulatory duties, and the paper in the F and I office counts as much as the data in the DMS.
Your Vendors Are Your Risk
The DMS, CRM, financing portals, and marketing tools all touch customer data, and the Safeguards Rule expects documented oversight of every one. The industry learned the hard way that a vendor outage or breach becomes every dealer’s problem at once.
How Dealerships Actually Get Hit
Dealership incidents follow the money and the systems. Four patterns cover most of the damage.
The Redirected Payoff
Attackers compromise or impersonate an inbox in the deal flow, then send updated banking details for a lien payoff, an auction payment, or a floorplan transaction. Amounts are large, timing is predictable, and the defense is procedural: banking changes verified by phone at a known number, every time.
Ransomware Meets the DMS
When the DMS goes down, sales, F and I, service, and parts stop together, and the industry saw exactly what that looks like when a major dealer software provider was taken down and thousands of stores wrote deals on paper for weeks. Your own systems and backups deserve the same scrutiny as your vendor’s.
The Phished F and I Office
Finance staff live in email and portals all day, handling the most sensitive data in the store under time pressure. One convincing email harvests a login that reads every credit application in reach. MFA and training turn the most targeted office into the strongest one.
The Disposal Pile
Printed credit applications, dead hard drives, and traded devices hold customer identities long after the deal. Documented shredding and drive destruction is a Safeguards requirement, and the cheapest one on the list.
What Well Run Dealership IT Looks Like
Whoever manages your store’s technology, this is the baseline worth reviewing together. Every item maps to a rule or an attack above.
A Safeguards Program That's Real
A written program with a named qualified individual, current risk assessment, and evidence behind every claim, ready for an FTC question or a customer’s lawyer.
MFA on Everything
Email, the DMS, CRM, financing portals, and remote access, every employee, no exceptions and no shared logins at the sales desk.
Payment Verification Procedure
Payoffs, auction payments, and any banking change confirmed by phone at a known number before funds move, written and trained.
Backups Beyond the Vendor
Daily backups of the data your store depends on, with one copy ransomware can’t reach, plus a written plan for operating when the DMS or a vendor is down.
Segmented Networks
Customer WiFi, the shop, and the business network separated, so a device in the waiting room can’t reach the F and I office.
Training, Disposal, and Monitoring
Staff phishing trained, documents and drives destroyed with documentation, and systems watched around the clock, because stores are open late and attackers are open later.
Common Questions
Does the FTC Safeguards Rule really apply to car dealerships?
Yes. Dealers that arrange or extend financing or leasing are treated as financial institutions under the Safeguards Rule. That requires a written information security program with a designated qualified individual, risk assessment, access controls, encryption, multifactor authentication, vendor oversight, employee training, and incident response, and the FTC has shown it will enforce against dealers.
Why are dealerships attractive targets?
Every deal file contains a complete identity: Social Security number, income, address, and banking details. Dealerships also move large predictable payments like lien payoffs and auction settlements, and the entire operation depends on a handful of systems, which makes ransomware pressure immediate. Attackers get identities, payment flows, and leverage in one target.
What did the big dealer software outage teach the industry?
When a major DMS provider was taken down by attackers, thousands of dealerships lost sales, F and I, service, and parts systems at once, many for weeks. The lessons: vendor risk is your risk, a written plan for operating without the DMS is not optional, and your own local systems and backups need the scrutiny you now apply to vendors.
What happens if a dealership has a data breach?
State breach notification laws apply to customer data, the Safeguards Rule expects an incident response plan and, for larger incidents, FTC notification, and customers whose identities are exposed tend to remember where they bought the car. Dealers with a written plan and documented safeguards navigate it in days. Dealers without one improvise in public.
What is in the free dealership technology guide?
A six page plain English guide covering your Safeguards Rule obligations, the four attack patterns that hit dealerships, a dealership security baseline checklist, vendor and DMS risk, and the questions dealer principals should ask about their IT.
Start With the Guide. Decide From There.
Download the Dealership Technology Guide and review the baseline with whoever runs your IT. If you’d rather have the answers verified for you, a free confidential security assessment for your store is available too.