MRC 2026

Nov 15–17 · Palm Beach, FL

Retail strategy, AI and innovation for dealer leaders.

Get Tickets

Compliance

Is your dealership ready for the FTC Safeguards Rule?

Answer 16 questions drawn from the rule’s requirements (16 CFR Part 314). See how much of the program you have in place, and get a list of gaps to take to your Qualified Individual and IT provider.

FreeNo sign-upYour numbers stay in your browserAbout 5 minutes

Your dealership

Smaller institutions don’t need a written risk assessment, a fixed testing schedule, a written incident response plan or an annual written report (16 CFR 314.6). Everything else still applies.

People and planning
  1. Have you named a Qualified Individual to run your information security program?

    Staff, someone at an affiliate or a service provider. 314.4(a)

    Not required when you hold information on fewer than 5,000 consumers.

  2. Do you have a written risk assessment of where customer information could be exposed?

    It sets criteria for rating risks and checks your safeguards against them. 314.4(b)

    Not required when you hold information on fewer than 5,000 consumers.

  3. Do staff get security awareness training that’s kept up to date?

    Plus qualified people running security, your own or a provider’s. 314.4(e)

    Not required when you hold information on fewer than 5,000 consumers.

  4. Do you check that service providers can protect customer information, require it in their contracts and review them periodically?

    Not required when you hold information on fewer than 5,000 consumers.

Access and data
  1. Is access to customer information limited to the people who need it, and reviewed periodically?

    Not required when you hold information on fewer than 5,000 consumers.

  2. Do you keep an inventory of your data, systems, devices and the people who use them?

    Not required when you hold information on fewer than 5,000 consumers.

  3. Is customer information encrypted when it’s stored and when it travels over outside networks?

    Or protected by other controls your Qualified Individual has reviewed and approved. 314.4(c)(3)

    Not required when you hold information on fewer than 5,000 consumers.

  4. Do you use secure practices for software built for you, and check the security of outside apps you use?

    Not required when you hold information on fewer than 5,000 consumers.

  5. Does everyone who logs in to a system with customer information use multi-factor authentication?

    Unless your Qualified Individual approves equivalent controls in writing. 314.4(c)(5)

    Not required when you hold information on fewer than 5,000 consumers.

  6. Do you securely dispose of customer information within two years of when it was last used?

    Unless you need it for business or legal reasons, or it can’t practically be removed. 314.4(c)(6)

    Not required when you hold information on fewer than 5,000 consumers.

  7. Do you follow change management procedures for your systems and networks?

    Not required when you hold information on fewer than 5,000 consumers.

  8. Do you monitor and log what authorized users do, so unauthorized access gets noticed?

    Not required when you hold information on fewer than 5,000 consumers.

Testing and response
  1. Do you run continuous monitoring, or a penetration test every year and vulnerability assessments at least every six months?

    Not required when you hold information on fewer than 5,000 consumers.

  2. Do you have a written incident response plan?

    Goals, roles, communications, fixes, records and a review after each incident. 314.4(h)

    Not required when you hold information on fewer than 5,000 consumers.

  3. Does your Qualified Individual report to your board or a senior officer in writing at least once a year?

    Not required when you hold information on fewer than 5,000 consumers.

  4. Do you know how to notify the FTC within 30 days of discovering a security event that affects 500 or more consumers?

    Required for every covered dealer, whatever its size, since May 13, 2024. 314.4(j)

    Not required when you hold information on fewer than 5,000 consumers.

Your readiness

 

 

Want the rule in plain English? Read the Safeguards Rule explainer

 See the breakdown

How we score it

Each requirement you answer Yes counts in full and Partly counts half. No and Not sure count as gaps. If you hold customer information on fewer than 5,000 consumers, the four requirements the rule excuses drop out of the score.

Your answers stay in this browser, so you can come back to them. Copy a link to share them with your Qualified Individual or IT provider.

Where to start

  • Close the quick technical gapsMulti-factor authentication and encryption are often settings in systems you already have. Ask each vendor what’s switched on.
  • Put your vendors in scopeCustomer information also lives with your CRM, DMS, website and marketing vendors. Pasch Group’s website research found ad scripts still tracking shoppers after they opted out.Read the field guide
  • Write it downSeveral requirements are about having it in writing: the risk assessment, the incident response plan and the yearly report. If it isn’t written, it’s hard to show it exists.

Questions

Who has to follow the Safeguards Rule?

Financial institutions under the Gramm-Leach-Bliley Act, which includes car dealers that arrange financing or leases for customers.

What changed in 2023 and 2024?

Most of the detailed requirements in the amended rule took effect on June 9, 2023. The requirement to notify the FTC of events affecting 500 or more consumers took effect on May 13, 2024.

Do we have to tell customers about a breach?

The Safeguards Rule requires notifying the FTC, not customers. State data breach laws usually do require notifying affected customers, so check with your counsel.

Sources

  1. 16 CFR Part 314: Standards for Safeguarding Customer Information (eCFR)
  2. FTC Safeguards Rule: What Your Business Needs to Know (FTC)

This check is a planning aid, not legal advice. It follows 16 CFR Part 314 as of October 2026. Your Qualified Individual and your counsel decide what your program needs.

Updated October 11, 2026

Want a second pair of eyes on your numbers?

Tell us what you’re seeing and we’ll help you find what’s worth fixing first. No pitch.