Mon - Sat: 9:00 AM - 6:00 PM
Pacific Time (Los Angeles)
LIVEJoin Demo Call
Interactive Training Session

Glossary

What Is the GLBA Safeguards Rule?

The security rule that puts a written program behind every credit application a store takes.

The Safeguards Rule, issued under the Gramm Leach Bliley Act, requires financial institutions to develop, implement and maintain a written information security program that protects customer information. Car dealerships that arrange or extend financing are financial institutions for this purpose, so the rule reaches the credit applications, licenses and social security numbers a store handles every day.

What is the GLBA Safeguards Rule?

The Gramm Leach Bliley Act produced two rules a dealership has to know apart. The Privacy Rule is about telling customers what information is collected and shared and giving them the notices that go with it. The Safeguards Rule is about protecting that information, and it does not ask for good intentions: it asks for a written program, a person responsible for it, and evidence that the controls in it actually exist.

The rule is administered for non bank financial institutions by the Federal Trade Commission, and the definition of a financial institution is broader than most dealers expect. A store that arranges financing, leases vehicles or extends credit itself is in scope, and so is the customer information it holds: names, addresses, social security numbers, driver license images, pay stubs, bank statements and every credit application ever taken.

What action is mandated by the Safeguards Rule?

A written information security program with named elements. Designate a qualified individual to run it. Base it on a written risk assessment. Put access controls in place so people reach only the information their job requires, inventory where customer information lives, encrypt it in transit and at rest, and require multi factor authentication for anyone reaching customer information. Dispose of what is no longer needed, manage change, and log and monitor what authorized users do.

Then keep it alive. Test the controls, with continuous monitoring or with penetration testing and vulnerability assessments on the schedule the rule sets. Train the staff, because a program nobody at the desk has read is paper. Oversee service providers by selecting them for their safeguards and holding them to it by contract. Keep a written incident response plan. And report regularly to the board or to a senior officer, which is the element that turns security from a back office topic into a management one.

Questions? Request a Call Back

Leave your number and a lead specialist calls you back to answer your questions about pricing, coverage, and setup. Mon - Sat, 9:00 AM - 6:00 PM Pacific.

Ready to start? No call needed.See Pricing

Prefer to talk right now? Call or text 844-376-2274.

Why is a car dealership covered by this rule?

Because of what happens on the deal, not because of the franchise sign. A customer who applies for financing hands over exactly the information identity thieves want, in one packet, and the store keeps it. A dealership also collects that information in more places than almost any other small business: the website form, the desk, a phone call, a photo of a license, a scan of a pay stub, a text thread with a salesperson, a shared drive of deal jackets.

That is also why the program has to be written rather than assumed. A store can have a locked file room and still fail, because the copy of the application that matters is the one in an inbox, on a personal phone, or on a laptop that left with an employee nobody removed from the systems.

Where customer information leaks at a store

The usual places are ordinary. A credit application faxed to a lender and left in the tray. Scan to email, which puts a social security number in two mailboxes and a sent folder. A license photographed on a personal phone and texted to the desk. Logins shared among four people so nobody can tell who opened what. Documents stored in a folder that every user in the building can browse. A manager who left in spring and whose access stayed live all summer.

Each of those is a control failure with a boring fix: one system of record for applications and documents, individual accounts with roles, a log that shows who opened what, and a way to share a file with a lender that does not mean emailing it. Stores that make the compliant path the easy path stop relying on everyone remembering.

How LeadLocate is built for the security side

Security is part of how the credit application system is built, not an add on. Every sign in to the SecureWebX console takes two factor authentication. Application data is encrypted at rest. Users are invited individually with roles, so access follows the job, and a full audit log records who opened, changed, shared or screened a file. Uploads are virus scanned, PDFs open in a watermarked viewer with print and download gated, and the archive retains every record rather than deleting it. The credit application security page lists the controls in detail.

The paths around the application are built the same way. A lender share is code gated, expiring, revocable and watermarked, so sending a deal out is not an email attachment. The file library gives the store a tracked way to send documents, and the disclosures and privacy notice editor keeps the Privacy Rule side in one place. The store's own program, risk assessment and qualified individual stay the store's, and the Safeguards Rule compliance page covers how software evidence fits into it.

The Safeguards Rule against the Privacy Rule

Dealers mix these two constantly. The Privacy Rule is about disclosure: the initial and annual privacy notices, what is shared with whom, and the opt out where one applies. The Safeguards Rule is about protection: the program, the controls, the testing and the incident plan. A store can hand every customer a perfect privacy notice and still fail the Safeguards Rule, because the notice describes practices while the rule audits them.

Both sit alongside other obligations on the same file, including the identity theft program under the Red Flags Rule and the sanctions check a store runs before doing business. The automotive sales glossary defines those neighbors, and a store's counsel decides how its policy meets all of them.

Frequently Asked Questions

What is the primary goal of the Safeguards Rule?

To make sure the customer information a financial institution holds is protected by a written program with real controls behind it, rather than by habit. The rule names the elements: a qualified individual, a risk assessment, access controls, encryption, multi factor authentication, testing, training, vendor oversight and an incident response plan.

Does the Safeguards Rule apply to independent used car dealers?

It applies to financial institutions, and arranging or extending credit is what puts a dealership in that category, franchise or independent. A store that sells only for cash and never arranges financing is in a different position, which is a question for its counsel.

Does the rule require a written program?

Yes. A written information security program, based on a written risk assessment, with a designated qualified individual responsible for it and regular reporting to the board or a senior officer. Software provides controls and evidence; the program itself belongs to the store.

Is the Safeguards Rule the same as the FTC Safeguards Rule?

They are the same rule. The Safeguards Rule comes from the Gramm Leach Bliley Act and is enforced by the Federal Trade Commission for non bank financial institutions, which is why dealers hear it called by both names.

More Resources from LeadLocate

See where the customer information actually lives

A specialist opens an application, shows the roles, the audit trail and the watermarked viewer, then shares a file with a lender the secure way.

Have questions first? Leave your number and a lead specialist calls you back to walk through pricing, coverage, and setup.

Prefer to talk right now? Call or text 844-376-2274.

LeadLocate
Accepted credit cards: Visa, MasterCard, American Express and Discover
LeadLocate™ All rights reserved. Other product and company names mentioned herein are the property of their respective owners.

Answers to your questions:

What is LeadLocate?

LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.

Accepted credit cards: Visa, MasterCard, American Express and Discover
LeadLocate™ All rights reserved. Other product and company names mentioned herein are the property of their respective owners.

Answers to your questions:

What is LeadLocate?

LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.