16 CFR Part 314 · GLBA Safeguards Rule

Your dealership is a
financial institution.
The FTC treats it that way.

DealerComply, an IT & cybersecurity practice from HERO, builds and maintains the written security program the FTC Safeguards Rule requires — so your F&I data, your OEM connections, and your dealer principal are covered before an examiner or a breach forces the issue.

Built for dealership operations — DMS integrations, OEM portals, and multi-rooftop groups, not generic office IT.

Safeguards Status
16 CFR §314 · GLBA
DEALERCOMPLY
by HERO
UNDER REVIEW
WISP on file
Pending
Qualified Individual
Unassigned
MFA enforced
Partial
Vendor oversight
Unverified
Risk assessment
Not on file
Breach reporting plan
Not on file
ISSUED: THIS DEALERSHIPREF# DC-000000
Why this isn't optional

Non-compliance costs more than the fix does

The Safeguards Rule has applied to dealers since June 2023, and the FTC's 2025 guidance made clear that OEM-mandated systems and third-party vendors don't get a pass. Enforcement is active — and the cost of getting caught unprepared dwarfs the cost of a real program.

$4.9M
Average cost of a data breach for a mid-size organization in 2024.
SRC: IBM COST OF A DATA BREACH REPORT
9
Distinct safeguards the FTC requires in a written security program — not a checkbox policy.
SRC: FTC SAFEGUARDS RULE, 16 CFR §314.4
30 DAYS
Window to notify the FTC after discovering a qualifying breach affecting 500+ consumers.
SRC: FTC BREACH NOTIFICATION AMENDMENT
What the rule actually requires

Eight things an examiner will ask to see

The Safeguards Rule doesn't require perfection — it requires a documented, functioning program. Here's the core of what your dealership needs on file and in practice.

Qualified Individual

A named person accountable for the program — internal or outsourced to HERO as your virtual QI.

Written Risk Assessment

A documented inventory of where customer NPI lives and what threatens it, reviewed on a set schedule.

Access Controls

Role-based access so only staff who need customer financial data can reach it — DMS, CRM, and F&I systems included.

Encryption at Rest & Transit

Customer information locked down whether it's sitting in a database or moving between your systems and a vendor's.

Multi-Factor Authentication

MFA on any system touching customer data — required, not optional, under the amended rule.

Monitoring & Testing

Continuous monitoring or annual penetration testing plus biannual vulnerability scans.

Vendor & OEM Oversight

Contractual safeguards and risk review for every service provider — including OEM-mandated platforms.

Incident Response Plan

A written plan your team can actually execute, plus the 30-day FTC breach reporting obligation.

Reference: FTC Safeguards Rule, 16 CFR §314.4 — "Automobile Dealers and the FTC's Safeguards Rule," FTC Business Guidance.

How HERO builds it

One program, built and maintained for you

DealerComply isn't a template you file away. HERO's team designs, implements, and keeps your security program current as the rule, your systems, and your vendors change.

Assessment

Gap & Risk Assessment

A full audit of your current environment against 16 CFR §314, mapped to your actual DMS, CRM, and F&I stack.

Documentation

Written Security Program (WISP)

The formal, board-ready document the rule requires — built from your real operations, not a generic download.

Oversight

Virtual Qualified Individual

HERO serves as your named QI, reporting on program status so no single staffer is left holding the liability.

Implementation

MFA, Encryption & Access Controls

Technical safeguards deployed across your systems without disrupting your sales or service floor.

Vendor Management

OEM & Third-Party Oversight

Vendor risk reviews and contract language for every provider touching customer data — OEM portals included.

Response

Incident Response & Breach Reporting

A tested response plan and hands-on support if you ever need to meet the FTC's 30-day notification clock.

Getting started

From first call to fully documented

01

Assess

We map your systems, vendors, and data flows against the Safeguards Rule's requirements.

02

Remediate

We close the gaps — access controls, MFA, encryption — in the order that reduces the most risk first.

03

Document

Your WISP, QI designation, and vendor records are written up and ready for an examiner or auditor.

04

Maintain

Ongoing monitoring, annual testing, and program updates as your dealership and the rule evolve.

Free gap assessment

Find out where your dealership stands

Fill this out and HERO's DealerComply team will walk your current setup against the Safeguards Rule's requirements — no obligation, no jargon, straight answers on what's already covered and what's exposed.

  • 20-minute call with a compliance-focused IT specialist
  • Plain-language summary of your gaps, ranked by risk
  • No cost, no pressure — built for dealer principals and GMs
GAP ASSESSMENT · SAMPLE SAFEGUARDS REPORT REF# DC-000000 62 RISK SCORE / 100 Pass Flagged Missing PG 01 FINDINGS SUMMARY 6 OF 9 SAFEGUARDS REVIEWED Access Controls PARTIAL Multi-Factor Auth PASS Risk Assessment MISSING Vendor & OEM Oversight FLAGGED Encryption at Rest PASS Incident Response Plan MISSING HERO · DEALERCOMPLY PG 02

Request Your Assessment

Response within one business day.

By submitting, you agree to be contacted by HERO / DealerComply about your compliance program. We don't sell your information.

Common questions

FTC Safeguards Rule, answered

Does the FTC Safeguards Rule actually apply to my dealership?

If your dealership extends or arranges financing or leasing for personal-use vehicles — which covers the vast majority of franchised and many independent dealers — you're considered a financial institution under the Gramm-Leach-Bliley Act and must comply with the Safeguards Rule.

What happens if we're not compliant?

The FTC can pursue enforcement actions, and non-compliance also raises the odds a breach turns into class-action litigation and OEM or lender scrutiny. Beyond regulatory risk, most breach and remediation costs far exceed the cost of building a compliant program up front.

Do we need a full-time IT security hire for this?

No. The rule requires a named Qualified Individual, but it doesn't have to be a full-time employee. HERO can serve as your outsourced QI, which is typically far more cost-effective for single-rooftop and small groups.

Are we covered if our DMS or OEM portal handles security?

Not automatically. The FTC's 2025 guidance specifically addressed this — OEM-mandated platforms and vendor systems still fall under your vendor oversight obligations. You're responsible for assessing and documenting those relationships, not just assuming they're covered.

How long does it take to get compliant?

Most single-rooftop dealerships move from initial assessment to a documented, functioning program in 6–10 weeks, depending on how much remediation the gap assessment turns up. Multi-rooftop groups typically run longer due to system standardization.