Automotive Dealership IT & FTC Compliance

How Should Auto Dealerships Manage Third-Party Vendor Risk Under the FTC Safeguards Rule?

The FTC Safeguards Rule requires dealerships to vet DMS providers, payment processors, and other vendors. Here's how to build a vendor risk program.

By COMNEXIA
#vendor risk management#dealership vendors#third-party risk#FTC vendor requirements#FTC Safeguards Rule#dealership compliance

Every modern dealership runs on a stack of third-party technology: a dealer management system (DMS), a CRM, F&I platforms, payment processors, credit-pull services, digital retailing tools, and more. Each of those vendors touches customer data — and under federal law, the dealership remains responsible for what happens to that data even after it leaves the building.

That’s the part many dealers miss. The FTC Safeguards Rule doesn’t just regulate what happens inside your showroom. It requires you to actively oversee the security practices of the companies you share customer information with. This guide explains what the rule requires, which vendors to focus on, and how to build a vendor risk program a dealership can actually maintain.

What Does the FTC Safeguards Rule Require for Dealership Vendors?

The FTC Safeguards Rule (16 CFR Part 314) requires dealerships to select service providers capable of maintaining appropriate safeguards, to bind them to those safeguards by contract, and to periodically assess their security practices. Vendor oversight isn’t optional or implied — it’s a named element of the required information security program.

The rule stems from the Gramm-Leach-Bliley Act (GLBA), which treats dealerships that arrange or provide financing as “financial institutions.” The FTC amended the Safeguards Rule in 2021 to add specific, prescriptive requirements, and the compliance deadline for those updated provisions was June 9, 2023. Among them:

  • Designate a Qualified Individual to oversee the information security program
  • Prepare a written risk assessment — which must account for vendors that handle customer data
  • Oversee service providers through due diligence, contractual requirements, and periodic reassessment
  • Report to leadership at least annually, including material matters such as service provider arrangements

In other words, “our DMS vendor handles security” is not a compliance position. The FTC expects the dealership to verify that claim, put it in writing, and revisit it on a schedule.

Which Dealership Vendors Count as Service Providers?

Any vendor that receives, stores, processes, or can access nonpublic customer information is a service provider under the Safeguards Rule. For a typical dealership, that list is longer than most managers expect:

  • DMS providers — the single largest concentration of customer data in the dealership, including deal jackets, credit applications, and service histories
  • CRM and marketing platforms — names, contact information, purchase history, and behavioral data
  • F&I and credit platforms — Social Security numbers, credit reports, income data
  • Payment processors — card data and banking details
  • Digital retailing and website tools — lead forms, trade-in data, soft credit pulls
  • IT providers and managed service providers — anyone with administrative access to your network can reach customer data, even if they never “receive” it in the ordinary sense
  • Document storage, e-contracting, and shredding services — paper and digital disposal both count

A practical starting point is a data inventory: list every system that holds customer information, then list every company that can touch each system. That inventory becomes the foundation of both your written risk assessment and your vendor oversight program. COMNEXIA’s dealership IT team builds these inventories as the first step of every Safeguards engagement, because you cannot oversee vendors you haven’t identified.

How Do You Evaluate a DMS Provider’s Security?

Evaluate a DMS provider the way a regulator would evaluate you: ask for evidence, not assurances. The DMS holds more sensitive customer data than any other system in the store, so it deserves the deepest review. Key questions to put to your DMS vendor in writing:

  1. Is customer data encrypted at rest and in transit? Encryption of customer information is an explicit Safeguards Rule requirement for dealerships, and your vendor’s practices flow into your compliance posture.
  2. Is multi-factor authentication (MFA) available and enforced for all users accessing customer information — including vendor-side support staff?
  3. What third-party security attestations can they provide? Independent audit reports (such as SOC 2 examinations) and recognized certifications are far more meaningful than a marketing page that says “bank-level security.”
  4. How is access controlled and logged? Who at the vendor can view your customers’ data, and is that access recorded and reviewable?
  5. What is their incident response commitment? How quickly will they notify you of a security event affecting your data — in hours, not “as required by law”?
  6. What happens to your data at termination? Contractual data return and destruction terms matter, because dealership data has a long life and switching vendors is common.

The same framework applies to CRM, F&I, and payment vendors, scaled to the sensitivity of the data each one holds. Vendors that can’t answer these questions in writing are telling you something important.

What Should Vendor Contracts Say About Security?

Under the Safeguards Rule, dealerships must require service providers by contract to implement and maintain appropriate safeguards for customer information. A handshake or a generic terms-of-service page doesn’t satisfy this. At minimum, vendor agreements involving customer data should address:

  • A safeguards obligation — an explicit commitment to maintain administrative, technical, and physical safeguards appropriate to the data shared
  • Breach notification terms — a defined timeframe for the vendor to notify the dealership of a security event, with enough detail for the dealership to meet its own obligations
  • Data use limits — the vendor may use customer information only to provide the contracted service
  • Subcontractor terms — if the vendor passes data to fourth parties, those parties must be held to equivalent standards
  • Audit and assessment rights — the dealership’s right to request security documentation periodically
  • Data return and destruction — what happens to customer information when the relationship ends

Many dealership vendor contracts were signed years before the updated rule took effect and contain none of this. A contract review — prioritizing the DMS, F&I, and payment relationships first — is one of the highest-value compliance actions a dealer can take.

How Often Should Dealerships Reassess Vendor Security?

The Safeguards Rule requires periodic reassessment of service providers, and annual review is the practical standard most compliance programs adopt. “Set it and forget it” vendor management is specifically what the rule was written to prevent.

A workable annual cycle for a dealership looks like this:

  • Annually: Refresh the vendor inventory, request updated security attestations from high-risk vendors, and confirm contract terms are still adequate
  • At every new vendor onboarding: Run the security questionnaire before signing, not after
  • After any vendor security incident: Reassess immediately, document what changed, and decide whether the relationship continues
  • At contract renewal: Treat renewal as a natural checkpoint to add missing security terms

Documentation is the point. The Qualified Individual’s required annual report to leadership must cover service provider arrangements, so each reassessment should produce a short written record: what was reviewed, what was found, what changed.

What Happens If a Dealership Vendor Has a Data Breach?

If a vendor breach exposes your customers’ unencrypted information, the dealership may have its own federal reporting obligation — the vendor’s breach does not stay the vendor’s problem. Since May 13, 2024, the Safeguards Rule has required financial institutions, including covered dealerships, to notify the FTC of a security breach involving the unencrypted information of at least 500 consumers, no later than 30 days after discovery. Those notices are submitted electronically and become part of the public record.

That 30-day clock is exactly why breach notification terms in vendor contracts matter so much. If your DMS provider takes six weeks to tell you about an incident, your own reporting window may already be blown. State breach notification laws — including Georgia’s — can add separate obligations to notify affected consumers.

A dealership’s incident response plan (another required Safeguards element) should explicitly cover the vendor-breach scenario: who receives vendor notifications, who determines whether the FTC threshold is met, who engages counsel, and who communicates with customers.

How Can a Dealership Run Vendor Risk Management Without a Security Team?

Most dealerships don’t need to hire a security department — they need a repeatable process and a partner who already knows the dealership technology stack. The core program is manageable:

  1. Inventory every vendor touching customer data
  2. Tier vendors by data sensitivity (DMS and F&I at the top)
  3. Question each high-tier vendor with a standard security questionnaire
  4. Contract for safeguards, breach notification, and data destruction
  5. Reassess annually and document everything
  6. Report findings through the Qualified Individual’s annual report

The hard part is usually not the framework — it’s knowing what good answers look like when a DMS or payment vendor responds, and pushing back when the answers are vague. That’s where experienced help pays for itself.

COMNEXIA has spent 35 years supporting businesses across Georgia from our Atlanta-area headquarters in Roswell, and automotive dealership technology is our specialty — DMS environments, F&I integrations, multi-location networks, and the compliance obligations that come with them. We serve as the outsourced IT arm for hundreds of businesses across Georgia, and for dealership clients that includes building and maintaining Safeguards-aligned vendor oversight as part of managed dealership IT. For dealers who want an independent review of their current vendor stack and contracts, our IT consulting team performs vendor risk assessments that produce the documentation the rule expects.

Frequently Asked Questions

Q: Does the FTC Safeguards Rule really apply to my dealership? A: If your dealership arranges or provides financing or leasing, you are a “financial institution” under the Gramm-Leach-Bliley Act and the Safeguards Rule applies. That covers the overwhelming majority of franchised and independent dealers. The updated rule’s compliance deadline was June 9, 2023, so these obligations are already in effect.

Q: My DMS provider says they’re compliant. Isn’t that enough? A: No. The rule places the oversight duty on the dealership: you must take reasonable steps to select capable providers, require safeguards by contract, and periodically assess their practices. A vendor’s own compliance claim — even a true one — doesn’t substitute for your documented due diligence.

Q: What’s the single most important vendor to review first? A: Your DMS provider. It concentrates the most sensitive data in the store — credit applications, Social Security numbers, deal records, and service histories — so a weakness there carries the most risk. F&I platforms and payment processors are the logical second tier.

Q: Do I have to report a breach that happens at my vendor? A: Potentially, yes. If unencrypted customer information of at least 500 consumers is acquired without authorization, the Safeguards Rule requires notification to the FTC within 30 days of discovery — and that obligation can land on the dealership even when the incident originated at a service provider. Contractual breach-notification terms with your vendors are what make meeting that deadline realistic.

Q: How much documentation is enough? A: Enough to show a regulator a working program: a current vendor inventory, completed security questionnaires or attestations for high-risk vendors, contracts containing safeguards language, dated reassessment notes, and coverage of service provider arrangements in the Qualified Individual’s annual report. If it isn’t written down, from a compliance standpoint it didn’t happen.


COMNEXIA provides managed IT, cybersecurity, and FTC Safeguards compliance support for automotive dealerships from its Roswell, Georgia headquarters. To talk through your dealership’s vendor risk posture, call (877) 600-6550 or visit our automotive dealership IT page.

Need Expert Technology Guidance?

Don't navigate complex technology decisions alone. Our consulting team provides the strategic guidance you need to make informed technology investments.