DealerComply, an IT & cybersecurity practice from HERO, builds and maintains the written security program the FTC Safeguards Rule requires — so your F&I data, your OEM connections, and your dealer principal are covered before an examiner or a breach forces the issue.
Built for dealership operations — DMS integrations, OEM portals, and multi-rooftop groups, not generic office IT.
The Safeguards Rule has applied to dealers since June 2023, and the FTC's 2025 guidance made clear that OEM-mandated systems and third-party vendors don't get a pass. Enforcement is active — and the cost of getting caught unprepared dwarfs the cost of a real program.
The Safeguards Rule doesn't require perfection — it requires a documented, functioning program. Here's the core of what your dealership needs on file and in practice.
A named person accountable for the program — internal or outsourced to HERO as your virtual QI.
A documented inventory of where customer NPI lives and what threatens it, reviewed on a set schedule.
Role-based access so only staff who need customer financial data can reach it — DMS, CRM, and F&I systems included.
Customer information locked down whether it's sitting in a database or moving between your systems and a vendor's.
MFA on any system touching customer data — required, not optional, under the amended rule.
Continuous monitoring or annual penetration testing plus biannual vulnerability scans.
Contractual safeguards and risk review for every service provider — including OEM-mandated platforms.
A written plan your team can actually execute, plus the 30-day FTC breach reporting obligation.
Reference: FTC Safeguards Rule, 16 CFR §314.4 — "Automobile Dealers and the FTC's Safeguards Rule," FTC Business Guidance.
DealerComply isn't a template you file away. HERO's team designs, implements, and keeps your security program current as the rule, your systems, and your vendors change.
A full audit of your current environment against 16 CFR §314, mapped to your actual DMS, CRM, and F&I stack.
The formal, board-ready document the rule requires — built from your real operations, not a generic download.
HERO serves as your named QI, reporting on program status so no single staffer is left holding the liability.
Technical safeguards deployed across your systems without disrupting your sales or service floor.
Vendor risk reviews and contract language for every provider touching customer data — OEM portals included.
A tested response plan and hands-on support if you ever need to meet the FTC's 30-day notification clock.
We map your systems, vendors, and data flows against the Safeguards Rule's requirements.
We close the gaps — access controls, MFA, encryption — in the order that reduces the most risk first.
Your WISP, QI designation, and vendor records are written up and ready for an examiner or auditor.
Ongoing monitoring, annual testing, and program updates as your dealership and the rule evolve.
Fill this out and HERO's DealerComply team will walk your current setup against the Safeguards Rule's requirements — no obligation, no jargon, straight answers on what's already covered and what's exposed.
Response within one business day.
By submitting, you agree to be contacted by HERO / DealerComply about your compliance program. We don't sell your information.
If your dealership extends or arranges financing or leasing for personal-use vehicles — which covers the vast majority of franchised and many independent dealers — you're considered a financial institution under the Gramm-Leach-Bliley Act and must comply with the Safeguards Rule.
The FTC can pursue enforcement actions, and non-compliance also raises the odds a breach turns into class-action litigation and OEM or lender scrutiny. Beyond regulatory risk, most breach and remediation costs far exceed the cost of building a compliant program up front.
No. The rule requires a named Qualified Individual, but it doesn't have to be a full-time employee. HERO can serve as your outsourced QI, which is typically far more cost-effective for single-rooftop and small groups.
Not automatically. The FTC's 2025 guidance specifically addressed this — OEM-mandated platforms and vendor systems still fall under your vendor oversight obligations. You're responsible for assessing and documenting those relationships, not just assuming they're covered.
Most single-rooftop dealerships move from initial assessment to a documented, functioning program in 6–10 weeks, depending on how much remediation the gap assessment turns up. Multi-rooftop groups typically run longer due to system standardization.