• Interviews
  • Business Trends
  • Sales
  • Trending
Dealership News
  • Job Board
  • Podcast
  • Technology
  • Car Humor
  • Interviews
  • Business Trends
  • Sales
  • Trending
Dealership News
  • Job Board
  • Podcast
  • Technology
  • Car Humor
Dealership News
Dealership News
  • Interviews
  • Business Trends
  • Sales
  • Trending
  • Job Board
  • Podcast
  • Tech
  • Technology
  • Dealership of the Week
  • Auto Dealer HR
  • Car Humor
© 2017–2026 DealershipNews.com. All Rights Reserved.
Home » FTC Safeguards Rule Dealership 2026: 7 Checks That Reduce Fine and Lawsuit Risk
FTC & Legal

FTC Safeguards Rule Dealership 2026: 7 Checks That Reduce Fine and Lawsuit Risk

by Michelle McLain August 19, 2026
written by Michelle McLain August 19, 2026 0 comments
Safeguards
3

One weak password exposed personal information from 12.5 million consumers in a breach tied to 130 dealerships.

FTC penalties for violating an existing order reach $53,088 per violation. The often-repeated $43,792 figure dates from 2021 and is no longer current.

Use these seven checks to find your biggest FTC Safeguards Rule gaps in ten minutes.

#1 Written Information Security Program, WISP

Fine risk: An auditor asks for your written information security program. Your team produces an insurance questionnaire, an old policy binder, or nothing.

None of those meets the requirement.

The FTC Safeguards Rule requires a written program built around your dealership’s size, operations, systems, and customer information. A downloaded template with another dealer’s name removed will fall apart once an auditor asks how the policy works inside your store.

What FTC auditors ask for:

• Who is your Qualified Individual?

• Where is your written risk assessment?

• When did senior management receive the last written security report?

Your WISP should identify where customer information enters the dealership, where staff stores customer records, who receives access, and when records get deleted. Include paper deal jackets, shared drives, desktops, cloud storage, email, CRM records, DMS records, and vendor portals.

List the person responsible for every control. “IT department” is not a person.

The FTC requires periodic risk reassessments and a written report to the board or senior officer at least once each year. Keep signed copies, meeting notes, and proof of follow-up work.

ACTION: Ask your Qualified Individual for the current WISP, risk assessment, and last management report by Friday.

#2 Multi-Factor Authentication on DMS, CRM, and Email

Fine risk: One stolen password gives a criminal access to credit applications, driver’s licenses, Social Security numbers, payroll records, and customer email.

The FTC requires multi-factor authentication for anyone accessing customer information, unless the Qualified Individual approves an equivalent control in writing.

Check every login path. Dealers often protect Microsoft 365 or Google Workspace, then leave a CRM mobile app, remote desktop account, vendor portal, or former employee login outside MFA.

Force MFA on DealerSocket, VinSolutions, DealerLeads.com, your DMS, dealership email, remote access tools, cloud storage, and every system holding customer information.

Do not accept a vendor’s statement saying MFA is “available.” Ask whether MFA is mandatory for every dealership user, administrator, support technician, and third-party integration.

A Florida Honda dealership fine of $125,000 tied to this check does not appear in FTC public enforcement records. Do not publish the claim without a case number or order. The documented dealer-sector example is DealerBuilt. The FTC alleged weak authentication, missing access controls, and unencrypted data contributed to exposure of information belonging to about 12.5 million consumers.

ACTION: Pull an MFA status report for every user and disable unprotected access by Friday.

#3 Role-Based Access Controls

Fine risk: A salesperson, former employee, temporary worker, or vendor account sees records unrelated to the job.

Auditors look beyond whether a login exists. They look at what each login opens.

Map access by role. Sales staff rarely need full access to funded credit files. BDC staff rarely need Social Security numbers. Vendors should receive only the records required for contracted work.

Review:

• Customer Social Security numbers

• Driver’s license images

• Credit applications and bureau reports

• Bank and payment details

• Employee payroll and tax files

Remove shared accounts. Disable former employee access on the employee’s last day. Review administrator privileges each quarter and preserve the review record.

The FTC also expects monitoring of authorized-user activity. Turn on access logs for systems holding customer information. Decide who reviews alerts and how fast the owner must respond.

ACTION: Export all active users from your DMS, CRM, email, and file systems. Remove stale and excessive access by Friday.

#4 Employee Training and Phishing Tests

Fine risk: Your training vendor marks every employee “complete,” but nobody knows how to report a fake DocuSign request.

FTC guidance requires security awareness training and regular refreshers. The rule does not prescribe quarterly training, though quarterly sessions create a stronger record and address turnover common inside dealerships.

Run one short lesson and one phishing test every quarter. Cover fake password resets, fraudulent wire instructions, MFA approval bombing, malicious QR codes, customer-data downloads, and lost devices.

Document each session. Keep the date, topic, attendee list, completion report, test result, retraining record, and manager sign-off.

Training without records gives an auditor no proof. A completion spreadsheet without follow-up also looks weak when the same employee fails several tests.

Set a clear reporting route. Every employee should know one email address or phone number for suspected incidents. Speed matters more than certainty.

ACTION: Schedule the next phishing test and export the last four training reports by Friday.

#5 Data Encryption at Rest and in Transit, Plus Vendor Audits

Fine risk: A stolen laptop, exposed backup, or open vendor portal reveals readable customer information.

The rule calls for encryption on your systems and during transmission. Where encryption is infeasible, the Qualified Individual must approve effective alternative controls in writing.

Check databases, laptops, backups, file transfers, email attachments, shared drives, website forms, and vendor portals. Confirm encryption status with evidence, not a checkbox on a questionnaire.

The FTC’s DealerBuilt complaint provides a concrete warning. The agency alleged personal data sat and traveled in clear text. An insecure backup connection remained exposed for 18 months, and the breach affected dealer customer records.

Audit high-risk vendors yearly. Run quarterly exposure scans where contracts and systems permit. Request encryption standards, penetration-test summaries, breach history, access controls, subcontractor lists, cyber insurance, and incident-notification terms.

ACTION: Get written encryption confirmation from your five highest-risk vendors by Friday.

#6 Vendor Risk Assessment

Fine risk: Your CRM, DMS, website provider, call-recording platform, lead vendor, or document processor loses customer data. Your dealership still owns the compliance problem.

FTC guidance says dealerships must select capable service providers, place security duties in contracts, monitor vendor work, and reassess vendor suitability.

Build one vendor register. Record the data each company receives, the system connection, the business owner, contract date, renewal date, last security review, and termination process.

Every vendor touching customer information should sign an agreement covering safeguards, access limits, breach notice, subcontractors, record return or deletion, audit rights, and cooperation after an incident.

A generic confidentiality clause is too thin. Your agreement needs measurable security duties.

Start with vendors holding Social Security numbers, credit applications, driver’s licenses, payment details, or large customer lists. Review those vendors first.

ACTION: List every vendor with customer-data access and flag missing security agreements by Friday.

#7 Incident Response Plan

Fine risk: A breach starts Friday night. The GM calls the MSP, the MSP calls the software vendor, and nobody preserves logs or contacts counsel.

The Safeguards Rule requires a written incident response plan. The plan should name decision-makers, internal steps, communication routes, documentation procedures, system-recovery work, and post-incident review.

Build a contact sheet for the Dealer Principal, GM, Qualified Individual, IT provider, cyber insurer, breach counsel, forensic firm, OEM contact, and affected vendors.

The often-used “72-hour FTC deadline” is inaccurate. Under the Safeguards Rule, a financial institution must notify the FTC as soon as possible and no later than 30 days after discovering unauthorized acquisition involving at least 500 consumers’ unencrypted information. State laws, contracts, and insurance policies often impose different or shorter deadlines.

Your first 72 hours still matter. Isolate affected systems, preserve logs, stop unauthorized access, notify counsel and insurance, record every decision, and avoid wiping evidence.

Run a tabletop exercise twice each year. Use a realistic event, such as a compromised CRM administrator account.

ACTION: Print the response plan, verify every phone number, and run a 30-minute tabletop by Friday.

The Compliance Table

CheckRisk LevelTime to FixWho Owns It
Written WISPCritical1 to 3 daysQualified Individual
MFACritical2 to 8 hoursIT lead and system owners
Role-based accessHigh4 to 8 hoursDepartment managers
Training and phishing testsHigh1 dayHR and Qualified Individual
Encryption and vendor auditsCritical1 to 5 daysIT lead and vendor owners
Vendor risk assessmentHigh2 to 5 daysCompliance and legal
Incident response planCritical1 dayGM and Qualified Individual

ACTION: Print this table, write one name beside every owner, and review open items Friday morning.

The 3 Biggest Mistakes Dealers Make

  1. Thinking IT handles compliance

Your MSP manages systems. Management owns the Safeguards Rule. The FTC expects a Qualified Individual, written risk decisions, vendor oversight, and senior-level reporting.

  1. Keeping no evidence

Screenshots, signed reports, access reviews, training logs, contracts, test results, and meeting notes prove work happened. Verbal assurances disappear during an audit.

  1. Running one annual compliance push

Dealership staff, vendors, systems, and threats change throughout the year. Review access and vendors quarterly. Update the risk assessment after major system or business changes.

ACTION: Put quarterly WISP, access, training, vendor, and incident-response reviews on the management calendar by Friday.

The Bottom Line

Start with the WISP and MFA this week. Those checks establish ownership and block a common route into customer systems.

Do not claim they cover 70% of fines. No public FTC dataset supports that percentage. The stronger statement is simpler. Missing documentation leaves no defense, and missing MFA leaves an open door.

For the FTC Safeguards Rule dealership 2026 review, keep one evidence folder with the WISP, risk assessment, user-access reports, training records, encryption proof, vendor agreements, test results, incident plan, and annual management report.

ACTION: Assign one executive owner and hold a 20-minute compliance review by Friday.

Related: 8 CRM Automations That Recover Cold Leads

Sponsored by Gas.net — powering dealership growth through intelligent data.

Your browser does not support the video tag.

Alt text: “Gas.net connects franchise dealers with integrated analytics and marketing tools.”

complianceCybersecurityFTCRiskSafeguards Rule
Share 0 FacebookTwitterPinterestEmail
previous post
10 AI Workflows for Car Dealerships 2026: How Managers Save 15 Hours a Week Right Now

Leave a Comment Cancel Reply

Save my name, email, and website in this browser for the next time I comment.

Recent Posts

  • FTC Safeguards Rule Dealership 2026: 7 Checks That Reduce Fine and Lawsuit Risk
  • 10 AI Workflows for Car Dealerships 2026: How Managers Save 15 Hours a Week Right Now
  • 8 CRM Automations That Recover Cold Dealer Leads and Increase Sales in 2026
  • Rick Case Automotive Group CEO and Community Leader Rita Case Appointed to the Federal Reserve Bank of Atlanta’s Miami Branch Board of Directors
  • Amberly Allen of Dealer Merchant Services is Delivering on a Great Idea that Saves Dealer Groups Millions

Recent Comments

  1. Ty Jacobb on Car Dealerships and Automotive YouTube Marketing Strategy
  2. Laurette Hilyard on How to Rank Higher on Google
  3. Kelly Kleinman on Benny Mazzier, Managing Partner with Marketing Solutions STL
  4. Benny Mazzier on Benny Mazzier, Managing Partner with Marketing Solutions STL
  5. Hal Hoadley on Improving Your Sales-to-Service Hand-Off

Follow Us

Recent Posts

  • FTC Safeguards Rule Dealership 2026: 7 Checks That Reduce Fine and Lawsuit Risk

    August 19, 2026
  • 10 AI Workflows for Car Dealerships 2026: How Managers Save 15 Hours a Week Right Now

    August 18, 2026
  • 8 CRM Automations That Recover Cold Dealer Leads and Increase Sales in 2026

    August 18, 2026
  • Rick Case Automotive Group CEO and Community Leader Rita Case Appointed to the Federal Reserve Bank of Atlanta’s Miami Branch Board of Directors

    January 19, 2023
  • Amberly Allen of Dealer Merchant Services is Delivering on a Great Idea that Saves Dealer Groups Millions

    January 19, 2023

Newsletter

Categories

  • 2019 Vendors of the Year (16)
  • Advertising and Marketing (18)
  • AI & Automation (1)
  • Ask an Expert (4)
  • Authors (12)
  • Auto Dealer HR (1)
  • Blog (10)
  • Business Trends (72)
  • Car Humor (16)
  • CRM (5)
  • Dealership of the Week (1)
  • digital retailing (2)
  • Editor's Picks (3)
  • Exclusives (5)
  • Featured Blogger (13)
  • Finance & Interest (10)
  • FixedOps (17)
  • FTC & Legal (1)
  • Future Trends (38)
  • Guest Bloggers (12)
  • Human Resources (22)
  • Interviews (144)
  • Job Board (1)
  • Lead Management (2)
  • Mid-Day Report (16)
  • NADA (27)
  • National Dealership Standings (34)
  • no show (1)
  • Podcast (10)
  • Press Release (21)
  • Reputation Management (6)
  • Sales (33)
  • Sean Kelley (4)
  • Sellers & Sitters (1)
  • Service (9)
  • Social Media (20)
  • Steve Roessler (1)
  • Technology (53)
  • Trending (81)
  • Uncategorized (21)
  • Vendor Reviews (1)
  • Vendor Selection (41)
  • Websites (16)
  • Who's Happening in Automotive (37)
Dealership News
  • Interviews
  • Business Trends
  • Sales
  • Trending
  • Job Board
  • Podcast
  • Tech
  • Technology
  • Dealership of the Week
  • Auto Dealer HR
  • Car Humor
Dealership News
  • Interviews
  • Business Trends
  • Sales
  • Trending
  • Job Board
  • Podcast
  • Tech
  • Technology
  • Dealership of the Week
  • Auto Dealer HR
  • Car Humor
© 2017–2026 DealershipNews.com. All Rights Reserved.