FI showroom red and grey logo
MenuMENU
SearchSEARCH

Federal Safeguards Rule Amendments Ask Dealers to Shore Up their Information System Security

Industry analysts suggest it could cost dealers hundreds of thousands annually to comply with the new rules.

November 2, 2021
Federal Safeguards Rule Amendments Ask Dealers to Shore Up their Information System Security

Industry analysts suggest it could cost dealers hundreds of thousands annually to comply with the new rules.

2 min to read


 

Amendments to the federal Safeguards Rule will require U.S. auto dealerships to toughen up their information systems security to protect consumer data. 

In late October, the Federal Trade Commission passed amendments to the rule that made five key changes.

Ad Loading...
  1. Adds detailed requirements for the development and implementation of the information security program mandated under the existing rule. The ruling now includes specific requirements for risk assessment, system access controls, authentication and encryption, as well as mechanisms for ensuring effective employee training and oversight of service providers.

  2. Requires institutions to appoint a single "qualified individual" to be responsible for the information security program and requires that individual to submit periodic reports to boards of directors or governing bodies to provide senior management with better awareness of their financial institution's data security safeguards.

  3. Exempts financial institutions that collect information on fewer than 5,000 consumers from the following requirements: written risk assessments, incident response plan and annual reporting to the board of directors.

  4. Expands the definition of "financial institution" to include "finders,” that is companies that bring together buyers and sellers of a product or service — within the scope of the rule.

  5. Defines terms and provides related examples in the rule itself rather than incorporating them by reference from a related FTC rule.

The Safeguards Rule took effect in 2003 under the federal Gramm-Leach-Bliley Act, which classifies auto dealers as financial institutions because they offer financing agreements.

Revisions to the rule were approved on a 3-2 vote last month, with Commissioner Rohit Chopra voting in their favor before being sworn in as director of the Consumer Financial Protection Bureau.

The full impact of the rule changes on franchised dealerships remained unclear late last week pending reviews by NADA, compliance experts and dealership leaders.

NADA leaders raised multiple concerns about the proposed changes in public comments before the FTC and shared a cost analysis that indicated U.S. dealerships could face billions of dollars in additional compliance costs if the changes were adopted.

Ad Loading...

NADA’s 2019 analysis suggested dealerships would spend hundreds of thousands of dollars annually on compliance. In a cost study from 2019 on the FTC's initial proposal, NADA said the expense incurred by U.S. franchised dealerships could range from $220,000 for small dealerships to more than $300,000 for midsize dealerships in upfront costs, plus additional expenses each year after to maintain compliance. The association estimated that U.S. franchised dealerships would spend up to $2.2 billion in startup costs then $2.1 billion in annual costs.

Originally posted on Auto Dealer Today

More Compliance

Photo of two skeletons playing banjos

Dueling Banjos in the Car Biz

Reports and accounts at variance show auto dealers’ trust profiles have risen in many consumers’ minds but that there remains a need for greater transparency by some.

Read More →
Photo of a man signing a paper at a desk while a man in a suit looks on

NADA and the Miracle on 34th Street

Automotive dealers should follow the National Automobile Dealers Association's consumer-friendly guidelines in order to minimize their legal risks.

Read More →
ComplianceFebruary 6, 2026

Another Look at a Recent Data Breach

Get caught up on the most pressing legal and regulatory matters facing dealers and F&I professionals, including data security, shotgun purchases, and inconsistent payment quotes.

Read More →
Ad Loading...
ComplianceNovember 26, 2025

Turnover and Compliance

Why ongoing training is a necessity

Read More →
ComplianceNovember 10, 2025

Singing a Gospel Song Backward

Crime and punishment in auto retail and how to avoid them

Read More →
ComplianceSeptember 26, 2025

The Best Thing a Dealer Can Do to Avoid Legal Problems

Citing the issue is a strategy borrowed from the legal field itself.

Read More →
Ad Loading...
ComplianceSeptember 15, 2025

Fines of the Times

Civil penalties for noncompliance with federal auto retail and finance rules and regulations can add up quickly. Use this checklist to cover your bases.

Read More →
ComplianceAugust 26, 2025

Goodwill and Car Dealers

A dealer goodwill tale is a cautionary tale worth paying attention to.

Read More →
ComplianceJune 30, 2025

The Regulatory Empire Is Striking Back

President Trump - entropist and corporate disruptor in consumer law

Read More →
Ad Loading...
ComplianceJune 26, 2025

How to Clear a Red Flag

Refine and enforce your dealership’s FTC-mandated ID theft-prevention program to ensure no transaction goes awry.

Read More →