Dealers Are Financial Institutions Under Federal Law
Most auto dealers don't think of themselves as financial institutions. But under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, any business that is "significantly engaged" in financial activities — including arranging vehicle financing — qualifies as a financial institution.
That classification comes with a federal requirement: a Written Information Security Plan documenting how your dealership protects the consumer financial data it collects.
⚠️ This isn't optional. The FTC Safeguards Rule applies to dealerships of every size — from a single-point independent lot to a large franchise group.
What Triggers the Requirement
Any one of the following activities at your dealership brings you under the Safeguards Rule:
- Collecting and submitting credit applications to lenders
- Arranging dealer-assisted financing through a captive or third-party lender
- Originating and holding your own retail installment contracts (BHPH)
- Offering extended warranties or F&I products that involve consumer financial data
- Holding customer data from credit pulls even on deals that don't close
Note the last point: a credit pull that didn't result in a sale still created a compliance obligation. The data existed in your system, and the FTC rule applies to its protection.
The F&I Department's Specific Exposure
Your Finance and Insurance office is the highest-risk area in any dealership from a data security perspective. F&I managers handle the most sensitive consumer data in the entire transaction:
- Full credit applications with Social Security numbers
- Income verification documents
- Employment records
- Bank account information for down payment verification
- Insurance documentation
In most dealerships, this data flows through multiple systems — the DMS, lender portals, desking software, and sometimes paper files. Each touchpoint is a potential exposure, and the FTC requires documented procedures for all of them.
💡 Many franchise dealers assume their manufacturer's compliance program covers this. It doesn't. Your franchisor's data security obligations run to the OEM, not to the FTC on your behalf. Your dealership's WISP is a separate, standalone requirement.
Buy-Here-Pay-Here Dealers Have the Highest Exposure
If you operate a buy-here-pay-here dealership, you face the greatest FTC Safeguards Rule exposure of any dealer type. BHPH dealers originate and hold consumer installment contracts directly — making them full-fledged creditors, not just financing arrangers.
That means you're holding loan portfolios of consumer financial data for the life of each contract, often across multiple locations and systems. A single breach of a BHPH dealer's portfolio could affect hundreds or thousands of customers — and trigger penalties for each missing safeguard across each affected file.
What a Dealer WISP Must Cover
The FTC requires your Written Information Security Plan to address the specific ways your dealership collects, stores, and transmits consumer financial data. For auto dealers, this typically includes:
- DMS security — how customer data in your dealer management system is protected and access-controlled
- Lender portal access — procedures for managing login credentials and access for F&I staff
- Paper document handling — how physical credit applications and contracts are stored and destroyed
- Employee access controls — who can see customer financial data, and what happens when staff leave
- Vendor oversight — your DMS provider, CRM, and F&I software vendors all handle consumer data on your behalf
- Incident response — what your dealership does if there's a data breach
How to Comply — Without a Compliance Department
Most dealerships don't have an in-house compliance officer. The FTC doesn't require one. What it requires is a documented security program that reflects how your dealership actually operates.
SafeguardsReady delivers a custom WISP for auto dealers in 48 hours, built from a short questionnaire about your specific setup — your DMS, your F&I workflow, your staff size, and your data handling practices. No lawyers, no calls, no retainer. Starting at $497, with multi-location pricing available for dealer groups.
The FTC fine is up to $50,120 per violation. A WISP costs $497.
Need Help Organizing Your WISP Documentation?
- Custom WISP built from your questionnaire responses
- Word & PDF versions delivered in 48 hours
- Loom video walkthrough of every section
- Incident response plan included
- No calls, no lawyers, no retainer
SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.
SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.