Mon - Sat: 9:00 AM - 6:00 PM
Call: 844-376-2274
F&I & Compliance
FTC Safeguards Rule Compliance for Car Dealerships
No vendor can make you compliant. Some of them can stop your customers' information from sitting on a desk in the first place.
Why the rule applies to a car dealership at all
Plenty of dealers are still surprised by this, so it is worth saying without jargon. Under the Gramm Leach Bliley Act, a business that arranges or extends credit to consumers is treated as a financial institution. A store that takes credit applications and sends them anywhere is in that category, whether it thinks of itself that way or not. Buy here pay here operations, independents and franchise points are all in scope.
The Safeguards Rule is the part of that framework that governs how you protect customer information. The Federal Trade Commission amended it, with the main compliance date landing in June 2023, and the amended version is far more prescriptive than what came before. It stopped being a general instruction to be careful and became a list of things you must have.
Two honest cautions before anything else on this page. Nothing here is legal advice, and we are a software company rather than your counsel or your auditor. Requirements, guidance and enforcement posture change, so verify the current text of the rule and your own obligations with a qualified attorney or compliance professional rather than with any vendor page, including this one.
What the rule actually asks for
Stripped to plain language, the amended rule expects a written information security program with roughly these components. Read them as a checklist for a conversation with counsel rather than as a substitute for the rule itself.
- A named person in charge. A qualified individual responsible for the program. One human, by name, not a committee and not a general instruction to the IT vendor.
- A written risk assessment. Where customer information lives, what could go wrong, and what you are doing about each risk.
- Safeguards. Access controls limited to who needs the information, an inventory of the systems holding it, encryption of customer information, multi factor authentication for people accessing it, secure disposal, change management, and logging of authorized user activity.
- Testing. Either continuous monitoring, or periodic penetration testing and vulnerability assessment on a defined schedule.
- Training. Security awareness for your staff, refreshed rather than done once at hire.
- Vendor oversight. Selecting service providers capable of protecting the information, requiring it by contract, and reassessing them.
- A written incident response plan. What happens, who acts, and in what order.
- An annual written report from the qualified individual to your board or a senior officer.
Smaller operations holding information on fewer consumers get relief from some of these obligations, and there is a threshold in the rule. Do not assume you are under it based on your monthly volume. The count is about customer information you maintain, which for most stores includes years of history rather than this month's deals.
Where the leaks actually are in a dealership
Enforcement conversations and breach stories in retail automotive rarely involve exotic attacks. They involve ordinary process, and every store recognizes at least two of these.
A paper credit application filled out at a desk, then photocopied, then left in a folder in an unlocked drawer overnight. A customer texting a photo of their driver licence and social security card to a salesperson's personal phone, where it stays for years. Applications arriving in a shared email inbox that six people can read and nobody administers. A fax machine in an open hallway. A shared login used by whoever is on the desk, so the activity log says nothing useful. Former employees whose access was never removed because nobody owned the offboarding step.
None of that is a technology failure in the interesting sense. It is a design failure, and it is the part software can genuinely change, because the fix is to make the secure path the convenient one. If applying privately on a phone is easier than filling in paper at a desk, the paper problem shrinks on its own.
What SecureWebX contributes, precisely
Being specific rather than waving at compliance, because the difference matters when you are documenting a program.
Secure online credit applications and apply links. An apply link is a shareable application URL you can text to a customer or place on a landing page. The customer completes it on their own device and it lands in an application inbox tied to your company rather than in a person's email. That single change removes the paper copy, the texted photo of a social security card and the shared inbox at the same time.
Document collection at intake. Proof of income, proof of residence and identification arrive attached to the application. Document reading assists capture from a phone camera, so a licence or insurance card does not need a copier or a personal phone.
Identity verification at intake, recorded with the application rather than remembered by whoever was on the desk.
A compliance module and a versioned consent gate. Versioning is the part people underestimate. When your disclosure language changes you need to know which version a specific customer accepted and when, not merely that they accepted something at some point. A system that overwrites its own terms cannot answer that question a year later.
Access control and logging. User management with role based permissions on both the CRM and SecureWebX sides, plus a login log recording who was in the system and when. On the CRM side, customer profiles hold personally identifiable information encrypted, and customer facing deal pages use opaque tokens rather than guessable record numbers.
eFax on the admin side, which retires the machine in the hallway.
What no software can do for you
Anyone selling you Safeguards compliance in a box is selling you a feeling. Here is what stays yours no matter which vendors you use.
Naming your qualified individual. Writing and maintaining the risk assessment. Deciding retention, meaning how long you keep customer information and how you dispose of it. Training your staff and doing it again next year. Testing, whether that is continuous monitoring or scheduled penetration testing and vulnerability assessment. Writing the incident response plan and rehearsing it. Producing the annual written report to your board or senior officer. Controlling access to every system you use, including the dealer management system you run, your email, your phones and your physical files.
Also yours: everything outside the systems a vendor touches. The most common gap we see is not the CRM at all, it is a folder of scanned deal jackets on a shared drive that has been open to the whole store since 2019. A vendor page will never find that. A risk assessment will.
Related obligations sit alongside this one and are not the same thing. Red Flags identity theft prevention and OFAC screening are separate programs with separate requirements. See Red Flags Rule compliance and OFAC compliance software.
Vendor oversight is the element stores skip
Of the eight components, vendor oversight is the one most likely to be missing when someone looks closely, because it requires work with third parties rather than inside your own building.
Make a list of every vendor that holds or can reach customer information. It is longer than you think: CRM, website provider, chat vendor, lead providers, phone system, document scanning, marketing agency, the dealer management system you run, payment processing, and whoever administers your network. For each one, you need to know what information they hold, what security commitments exist in the contract, and how you would find out if something went wrong at their end.
Then ask each of them a short set of questions and keep the answers. How is customer information encrypted at rest and in transit? Is multi factor authentication available and enforced for our users? Can we control access by role and remove a user immediately? Is there an activity log we can review? What is your breach notification commitment to us, and in what time frame? Who is your subprocessor list? Can we export our data and in what format?
Ask us those questions too, in writing, and hold the answers with the rest. A vendor that will not answer in writing has told you something.
Incident response and the notification clock
The amended rule added a reporting obligation for certain security events affecting customer information above a defined threshold, on a short clock measured in days rather than months. Confirm the current threshold and timing with counsel, because this is exactly the kind of detail that changes and exactly the kind you cannot afford to get wrong in the week it applies.
What matters operationally is that a clock that short cannot be met by a plan you write after the event. Before anything happens you need to know who declares an incident, who they call first, which systems get isolated, who talks to customers, who talks to the manufacturer if you are a franchise point, and who assembles the facts for a report. Write it down, put names in it, and put a copy somewhere that does not depend on the network being available.
Then rehearse it once. A thirty minute tabletop where you walk through a plausible scenario will find more gaps than another software purchase, and it costs nothing but the meeting.
A practical order of operations
Most stores stall because the whole program looks like a project nobody has time for. Sequence it and it becomes a series of afternoons.
Start by naming the qualified individual, because nothing else moves without an owner. Then inventory where customer information lives, including the paper and the shared drive, not just the software. Then close the two or three obvious leaks you already know about, which for most stores means retiring paper applications, ending the practice of customers texting documents to personal phones, and cleaning up user accounts for people who no longer work there.
Only then buy anything. A store that has done those three things has a far better idea of what it actually needs, and a much shorter vendor list.
If moving the application off the desk is the piece you want to solve first, that is the fastest one to change and the one customers notice most. Our page on the digital F&I platform covers how apply links work in practice, and compliance document management covers keeping the records afterward.
What this costs and where to start with us
Pricing is month to month with no long term contract. CRM Only starts at $199 a month and plans that include exclusive local leads start at $799, with combined buyer and seller programs from $1,599. Detail is on the pricing page. Nothing about the secure application intake requires a DMS integration or an inventory feed, which matters here because fewer connections means fewer vendors in your oversight list.
The honest summary: we can take the credit application off your desk, put identity and consent capture behind a versioned record, control who sees what, and log it. That is a real contribution to several elements of your program and it is not the program. Anyone who tells you their product makes you compliant with the Safeguards Rule has just told you how carefully they read it.
If you want to talk through where your intake process leaks before buying anything, tell us what happens today and we will give you a straight answer about whether we are the right fix.
Frequently Asked Questions
Does the Safeguards Rule really apply to independent dealers?
If you arrange or extend credit to consumers, you are generally treated as a financial institution under GLBA regardless of size or franchise status. Confirm your specific obligations with counsel rather than assuming your volume puts you outside the rule.
Can any software make our store compliant?
No. Compliance is a written program with a named owner, a risk assessment, training, testing, vendor oversight, incident response and an annual report. Software can secure and document parts of it. Any vendor claiming to deliver compliance in a box is overselling.
How do apply links help with this?
They remove the paper application, the photographed social security card in a salesperson's phone and the shared email inbox in one move. The customer applies privately on their own device and it lands in an application inbox tied to your company with role based access.
Why does consent versioning matter for compliance?
Because the question a year later is not whether the customer agreed but which version of your language they agreed to and when. A system that overwrites its terms cannot answer that. SecureWebX keeps a versioned consent record.
What should we ask our other vendors?
How customer information is encrypted, whether multi factor authentication is enforced, whether access is controlled by role and can be revoked immediately, whether there is an activity log, and what their breach notification commitment to you is. Keep the answers in writing.
Is this legal advice?
No. This page is written to help you have a better conversation with counsel. The rule and its guidance change, so verify current requirements with a qualified attorney or compliance professional before relying on anything here.
Get the credit application off your desk this month
See a secure apply link go out by text and come back with documents, identity capture and a versioned consent record attached. Month to month, no long term contract.


LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.
Answers to your questions:
LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.
LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.
Answers to your questions:
LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.



