Skip to Main Content

HERSHEY AMERICA'S LARGEST RV SHOW® - September 14-20, 2026 TICKETS ON SALE NOW

FTC Issues Key Safeguards Rule FAQ for Auto Dealers

Jun 01, 2025
7 mins
Share

On June 16, 2025 the Federal Trade Commission (FTC) released its first set of Frequently Asked Questions (FAQs) on the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule since the revised rule took effect in 2023. These new FAQs specifically cover auto dealerships and generally address their relationships with OEMs and other third-party vendors.

In 2021, the FTC amended the Safeguards Rule to provide more specific guidelines for financial institutions (including dealerships) and to ensure that the Rule keeps pace with current technology.

The amended Safeguards Rule requires financial institutions to have written information security programs to protect the customer information they have and certain safeguards, which are listed below. A further amendment in 2023 requires financial institutions to report to the FTC certain data breaches and security incidents involving their customer information. That requirement took effect in May 2024.

Following this, NADA published “A Dealer Guide to the FTC Safeguards Rule” to provide information and resources to aid dealerships in compliance.

The Guide is available at https://www.nada.org/nada/education-consulting/driven-managementguide/dealer-guide-ftc-safeguards-rule-l43 and dealerships should have a physical, written information security program in place.

Dealers are encouraged to use NADA’s Dealer Guide to Safeguards Rule to assist with compliance. The Guide provides step-by-step instructions, compliance tips, and IT guidance. There is also a sample “Written Information Security Program” in Appendix A of the guide, as well as a sample data breach notification letter.

Frequently Asked Questions

As an automobile dealer, I already comply with the Privacy Rule. Do the requirements of the Safeguards Rule differ from the Privacy Rule requirements?

Yes, the Privacy Rule addresses consumer and customer information collection and sharing practices, while the Safeguards Rule addresses how the dealership must protect the customer information collected and maintained.

Can a company be considered a service provider for purposes of the Safeguards Rule and not the Privacy Rule, or vice versa?

A company that is a “service provider” for purposes of the Safeguards Rule might also qualify as a service provider under the Privacy Rule, but they do not entirely overlap. “Service provider” is not a defined term under the Privacy Rule, but the Safeguards

Rule defines the term “service provider” to mean “any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution that is subject to this part.” The Safeguards Rule says that when you give a service provider access to customer information, you must monitor the safeguards that service provider uses to protect that information.

The bottom line is that to be a service provider under the Safeguards Rule, the other company must be providing you with a service that involves access to customer information.

Will an OEM always be a service provider under the Safeguards Rule? For example, if I provide an OEM with information to enable a customer to receive recall notices, is the OEM automatically a service provider?

No – an OEM will not be a service provider under the Safeguards Rule unless they are providing you with services. An OEM does not become your service provider just because you share information with them. If they are not providing you with services, they are not a service provider, and the Safeguards Rule would not require you to oversee the OEM’s safeguards. For example, a company that collects customer names and addresses from you so the company can use them in recall notices in the future would not be providing you with a service, and so would not be considered a service provider in connection with that activity. However, you would need to conduct a separate analysis to determine if you need to comply with the Privacy Rule’s notification and consent requirements before you share information with the OEM.

Can I send OEMs records like (i) customer lists with names and addresses and (ii) Retail Delivery Reports that include names, addresses, and VIN numbers without violating the Privacy Rule or the Safeguards Rule?

It depends. If you collect a name and address from everyone who is buying a car from you – whether they seek financing or seek a lease from you or not – and you provide that list to an OEM, the name and address information by itself would not be covered by the Privacy Rule or the Safeguards Rule. The same is true for Retail Delivery Reports that include a name and address and a VIN number. It’s neither consumer information nor customer information.

If you disclose name and address information together with information obtained in the financing process – even information simply indicating that the consumer has applied for or received financing – then that information is covered by the Privacy Rule, and you need to comply with the privacy notice and opt-out requirements of the Privacy Rule.

With respect to the Safeguards Rule, the name and address information by themselves are neither consumer information nor customer information, as noted above. You are not obligated to protect, say, a record such as a paper document that includes individuals’ names and addresses alone. If that document indicates whether those individuals obtained financing from you, however, then that information is customer information and you would have an obligation to protect that information under the Safeguards Rule.

Even if a particular record is not customer information, if you keep customer information on your network you need to implement safeguards to protect your network generally. You would also have to oversee the OEM’s safeguards if you disclose that information to an OEM that is acting as a service provider.

What if I store all of the information that I collect from individuals, including financing information, sales reports, and other information, in one place, and I give a service provider direct access to it? Do I have to monitor the service provider’s safeguards with regard to the information that is not “customer information”?

Yes. Under the Safeguards Rule, you have an obligation to protect customer information. You also have obligations with respect to securing information systems that contain customer information or that are connected to a system containing customer information.

If you provide a service provider direct access to your system, appropriate oversight of the service provider would include addressing the risk that the service provider’s direct access to your information system would pose.

What do I need to do to comply with the Safeguards Rule when it comes to service providers? Do I have to require my service providers to implement all ten of the specific measures that the Safeguards Rule requires me to implement?

It depends. Companies that help you process transactions, send out marketing materials, or shred paper documents could be service providers under the Safeguards Rule. The third party must be providing you a service to qualify as a service provider, though, and the service has to relate to customer information.

Your obligation to oversee the service provider does not mean that you have to get the service provider to agree to meet all of the Safeguards Rule requirements that apply to you as a financial institution, though. The Safeguards Rule gives you the flexibility to select service providers whose safeguards are appropriate for the customer information they will be using.

If I do not “hold the paper” or take possession of customers’ car loans, do I have a “continuing relationship” with the customer? If I no longer have a continuing relationship, does the Safeguards Rule still require me to protect the information received from the customer?

Yes. If your dealership arranges or brokers a loan for a consumer, then you are in a “continuing relationship” with that consumer for purposes of safeguarding the customer information they provided to you. The personally identifiable financial information the customer, or another financial institution, provided to you in order for you to arrange or broker the loan or financing is “customer information” subject to the Safeguards Rule. It remains customer information even after the end of the customer relationship (e.g., if you no longer hold the note) – in other words, you must continue to protect customer information that you obtained from a customer, even if they are no longer a customer, for as long as you have that customer information in your possession.

You can securely dispose of the customer information at any point, however, and should do so once you no longer have a business need to keep it.

PAA Offers Compliance Reviews Experienced PAA Staff review the dealership safeguarding manual, and policies and procedures to establish compliance with the FTC Safeguards Rule. For more information, contact Becky Ross at 717-255-8311, ext. 3319

Categories: Industry News