Dealers Are Financial Institutions Under Federal Law

Most auto dealers don't think of themselves as financial institutions. But under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, any business that is "significantly engaged" in financial activities — including arranging vehicle financing — qualifies as a financial institution.

That classification comes with a federal requirement: a Written Information Security Plan documenting how your dealership protects the consumer financial data it collects.

⚠️ This isn't optional. The FTC Safeguards Rule applies to dealerships of every size — from a single-point independent lot to a large franchise group.

What Triggers the Requirement

Any one of the following activities at your dealership brings you under the Safeguards Rule:

Note the last point: a credit pull that didn't result in a sale still created a compliance obligation. The data existed in your system, and the FTC rule applies to its protection.

The F&I Department's Specific Exposure

Your Finance and Insurance office is the highest-risk area in any dealership from a data security perspective. F&I managers handle the most sensitive consumer data in the entire transaction:

In most dealerships, this data flows through multiple systems — the DMS, lender portals, desking software, and sometimes paper files. Each touchpoint is a potential exposure, and the FTC requires documented procedures for all of them.

💡 Many franchise dealers assume their manufacturer's compliance program covers this. It doesn't. Your franchisor's data security obligations run to the OEM, not to the FTC on your behalf. Your dealership's WISP is a separate, standalone requirement.

Buy-Here-Pay-Here Dealers Have the Highest Exposure

If you operate a buy-here-pay-here dealership, you face the greatest FTC Safeguards Rule exposure of any dealer type. BHPH dealers originate and hold consumer installment contracts directly — making them full-fledged creditors, not just financing arrangers.

That means you're holding loan portfolios of consumer financial data for the life of each contract, often across multiple locations and systems. A single breach of a BHPH dealer's portfolio could affect hundreds or thousands of customers — and trigger penalties for each missing safeguard across each affected file.

What a Dealer WISP Must Cover

The FTC requires your Written Information Security Plan to address the specific ways your dealership collects, stores, and transmits consumer financial data. For auto dealers, this typically includes:

How to Comply — Without a Compliance Department

Most dealerships don't have an in-house compliance officer. The FTC doesn't require one. What it requires is a documented security program that reflects how your dealership actually operates.

SafeguardsReady delivers a custom WISP for auto dealers in 48 hours, built from a short questionnaire about your specific setup — your DMS, your F&I workflow, your staff size, and your data handling practices. No lawyers, no calls, no retainer. Starting at $497, with multi-location pricing available for dealer groups.

The FTC fine is up to $50,120 per violation. A WISP costs $497.

Get Started

Need Help Organizing Your WISP Documentation?

  • Custom WISP built from your questionnaire responses
  • Word & PDF versions delivered in 48 hours
  • Loom video walkthrough of every section
  • Incident response plan included
  • No calls, no lawyers, no retainer
Get My WISP — $497 →

SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.

SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.