P&A Providers & Administrators
MenuMENU
SearchSEARCH

Federal Safeguards Rule Amendments Ask Dealers to Shore Up their Information System Security

Industry analysts suggest it could cost dealers hundreds of thousands annually to comply with the new rules.

November 2, 2021
Federal Safeguards Rule Amendments Ask Dealers to Shore Up their Information System Security

Industry analysts suggest it could cost dealers hundreds of thousands annually to comply with the new rules.

2 min to read


 

Amendments to the federal Safeguards Rule will require U.S. auto dealerships to toughen up their information systems security to protect consumer data. 

In late October, the Federal Trade Commission passed amendments to the rule that made five key changes.

Ad Loading...
  1. Adds detailed requirements for the development and implementation of the information security program mandated under the existing rule. The ruling now includes specific requirements for risk assessment, system access controls, authentication and encryption, as well as mechanisms for ensuring effective employee training and oversight of service providers.

  2. Requires institutions to appoint a single "qualified individual" to be responsible for the information security program and requires that individual to submit periodic reports to boards of directors or governing bodies to provide senior management with better awareness of their financial institution's data security safeguards.

  3. Exempts financial institutions that collect information on fewer than 5,000 consumers from the following requirements: written risk assessments, incident response plan and annual reporting to the board of directors.

  4. Expands the definition of "financial institution" to include "finders,” that is companies that bring together buyers and sellers of a product or service — within the scope of the rule.

  5. Defines terms and provides related examples in the rule itself rather than incorporating them by reference from a related FTC rule.

The Safeguards Rule took effect in 2003 under the federal Gramm-Leach-Bliley Act, which classifies auto dealers as financial institutions because they offer financing agreements.

Revisions to the rule were approved on a 3-2 vote last month, with Commissioner Rohit Chopra voting in their favor before being sworn in as director of the Consumer Financial Protection Bureau.

The full impact of the rule changes on franchised dealerships remained unclear late last week pending reviews by NADA, compliance experts and dealership leaders.

NADA leaders raised multiple concerns about the proposed changes in public comments before the FTC and shared a cost analysis that indicated U.S. dealerships could face billions of dollars in additional compliance costs if the changes were adopted.

Ad Loading...

NADA’s 2019 analysis suggested dealerships would spend hundreds of thousands of dollars annually on compliance. In a cost study from 2019 on the FTC's initial proposal, NADA said the expense incurred by U.S. franchised dealerships could range from $220,000 for small dealerships to more than $300,000 for midsize dealerships in upfront costs, plus additional expenses each year after to maintain compliance. The association estimated that U.S. franchised dealerships would spend up to $2.2 billion in startup costs then $2.1 billion in annual costs.

Originally posted on Auto Dealer Today

More Compliance

Photo of desk in sunny office
Complianceby Terry O'LoughlinFebruary 1, 2026

What to Expect in 2026 - New Rules and Regulations on the Horizon

In Trump’s first year, just 60,917 pages were printed in the Federal Register, the official journal of the federal government, down 42%.

Read More →
ComplianceNovember 10, 2025

Singing a Gospel Song Backward

Crime and punishment in auto retail and how to avoid them

Read More →
ComplianceSeptember 15, 2025

Fines of the Times

Civil penalties for noncompliance with federal auto retail and finance rules and regulations can add up quickly. Use this checklist to cover your bases.

Read More →
Ad Loading...
Complianceby Hannah MitchellSeptember 5, 2025

Cyber Threats Continue Apace

Hackers, seeing auto retail vulnerabilities in 2024 CDK incident, are taking advantage, data show.

Read More →
ComplianceAugust 11, 2025

Your Synthetic ID Theft Policy

Frankenstein’s monster is coming for your dealership. Use this guide to recognize synthetic ID thieves and maintain Red Flags Rule compliance.

Read More →
ComplianceJune 30, 2025

The Regulatory Empire Is Striking Back

President Trump - entropist and corporate disruptor in consumer law

Read More →
Ad Loading...
ComplianceJune 26, 2025

How to Clear a Red Flag

Refine and enforce your dealership’s FTC-mandated ID theft-prevention program to ensure no transaction goes awry.

Read More →
Computer screen showing the Audit F&I Review Dashboard, displaying dealership selection and manager scorecard options for ABC Dealership.
Complianceby Press ReleaseJune 18, 2025

Mosaic Adds Continuous Monitoring With AuditF&I

New AuditF&I platform is designed to give dealerships a smarter way to stay compliant.

Read More →
ComplianceJune 9, 2025

The Real ID Deadline

Challenges auto dealers may still face verifying identities

Read More →
Ad Loading...
IndustryMay 28, 2025

Mount Rushmore and Tariffs

A return to autarky? Are tariffs good policy?

Read More →