Dealer Data Security: What the Law Actually Requires
Dealer data security under the FTC Safeguards Rule: encryption, MFA, breach reporting, record retention periods, and what skipping it really costs.
A car dealership is a strange kind of business. You sell metal, but what you actually hold is data: Social Security numbers, driver's licenses, credit applications, bank details, income statements. That is exactly the data identity thieves want, and federal law treats you accordingly. Dealer data security is not optional and it is not new. Most dealers are legally "financial institutions" under the FTC Safeguards Rule, which means encryption, multi-factor authentication, and a written security program are requirements, not suggestions. This guide covers what the law demands, how long you have to keep records, why MFA is the control most stores still skip, and what the last two years of dealership cyberattacks actually cost.
Note: This article is general information, not legal advice. Penalty figures get adjusted over time and state rules vary, so confirm current numbers and talk to your attorney or state dealer association before you rely on anything here. Last reviewed July 2026.
The wake-up call: what cyberattacks have cost dealers
If you worked a deal desk in the summer of 2024, you don't need convincing. The CDK Global attack started with back-to-back incidents on the evenings of June 18 and 19, 2024, and knocked out the dealer management system that roughly 15,000 dealerships depended on, per CBS News. Stores reverted to paper. Dealership employees posted on Reddit that they were relying on spreadsheets and sticky notes to sell parts and make repairs while holding off on larger transactions.
The outage ran about two weeks before CDK said substantially all dealer connections were live again on July 2. The bill was enormous:
- Anderson Economic Group put direct dealer losses at about $1.02 billion over the three weeks from June 19 to July 5, 2024, including roughly 56,200 lost new-vehicle sales.
- AutoNation, one of the largest dealer groups in the country, told the SEC in a Form 8-K filing that the incident cut its Q2 2024 earnings by approximately $1.50 per share.
- Blockchain analysis firm TRM Labs traced a transfer of roughly 387 bitcoin, worth about $25 million at the time, to a wallet likely controlled by the BlackSuit ransomware group days after the attack, as reported by CyberScoop.
And CDK was not a one-off. The same month, Findlay Automotive Group, with dealerships across five states, had its own cybersecurity incident that restricted sales and service operations. In 2025, dealer software provider Motility Software Solutions, which serves about 7,000 dealerships (mostly RV and powersports), disclosed a ransomware attack detected in August that exposed data on 766,000 people.
The trend line is the scary part. CDK's own 2023 dealership cybersecurity study, published months before the big attack, found 17% of dealerships had experienced a cyberattack or incident in the past year. Its follow-up report, published in December 2024, found that number had jumped to 35% of dealers in 2024, with 92% of those reporting a negative financial or operational impact.
For context on what a breach costs anywhere: IBM's Cost of a Data Breach Report 2025 put the global average at $4.44 million, with the U.S. average hitting a record $10.22 million. No dealership absorbs that quietly.
Yes, your dealership is a "financial institution"
The law that matters most is the FTC Safeguards Rule (16 CFR Part 314), issued under the Gramm-Leach-Bliley Act. The FTC's own Safeguards Rule FAQs for automobile dealers say it plainly: dealers who finance or facilitate the financing of vehicles are financial institutions because lending money is a financial activity under federal law, and dealers who lease vehicles for longer than 90 days qualify too. If you arrange financing through lenders, carry your own paper, or lease, you are covered.
The amended rule's core requirements have been fully enforceable since June 9, 2023, after the FTC extended the original December 2022 deadline by six months. That grace period is long gone. If your store still has no written program, you are not early, you are late.
The Safeguards Rule sits alongside the Red Flags Rule (identity theft detection) and OFAC screening (sanctions checks). They are separate obligations that usually all apply to the same store.
What the Safeguards Rule actually requires
The rule, at 16 CFR 314.4, spells out the elements of a compliant information security program. Two of them deserve their own headlines.
Encryption is required, at rest and in transit
Under 16 CFR 314.4(c)(3), you must protect by encryption all customer information you hold or transmit, both in transit over external networks and at rest. That means the deal jackets on a shared drive, the credit apps in your CRM, the scanned driver's licenses in an email inbox. If encrypting something is truly infeasible, your Qualified Individual can approve, in writing, an effective compensating control. The default, though, is encrypt everything.
This is the requirement that turns "we keep deal files in a filing cabinet and a spreadsheet" into a legal problem. Unencrypted customer data on a laptop that walks out the door is not just an incident, it is a rule violation.
Multi-factor authentication is required, full stop
Under 16 CFR 314.4(c)(5), you must implement multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved, in writing, reasonably equivalent or more secure controls. Not just the DMS. Any system holding customer information: email, the CRM, the shared drive, remote access.
MFA gets its own section below, because it is the single control with the biggest gap between how cheap it is and how many stores skip it.
The rest of the checklist
The remaining elements of a compliant program:
- A Qualified Individual who oversees, implements, and enforces the program (16 CFR 314.4(a)). This can be an employee or someone at a service provider, but somebody must own it by name.
- A written risk assessment identifying where customer information lives and what threatens it (314.4(b)).
- Access controls: people see only the customer data their job needs (314.4(c)(1)).
- Monitoring and testing: either continuous monitoring of your systems or, failing that, annual penetration testing plus vulnerability assessments at least every six months (314.4(d)).
- Staff security training (314.4(e)).
- Vendor oversight (314.4(f)): select and retain service providers that can maintain safeguards, require those safeguards by contract, and periodically reassess them. After CDK, nobody should need convincing that your vendors are your risk. The FTC's biggest case in the dealer ecosystem was against a DMS vendor: in 2019 it settled with DealerBuilt after a hacker accessed unencrypted personal information of about 12.5 million consumers stored for 130 dealership clients. The FTC said the data was stored and transmitted in clear text, without any access controls or authentication protections.
- A written incident response plan for security events that materially affect customer information (314.4(h)).
- An annual written report from the Qualified Individual to your board or, if you have none, a senior officer (314.4(i)).
- Secure disposal of customer information no later than two years after the last date it is used, unless you have a legitimate business or legal reason to keep it (314.4(c)(6)). More on that in the records section.
Small-dealer relief exists, but it is narrow
If your store maintains customer information on fewer than 5,000 consumers, 16 CFR 314.6 exempts you from the written risk assessment, the continuous monitoring or pen-testing requirement, the written incident response plan, and the annual board report. It does not exempt you from encryption, MFA, access controls, disposal, training, vendor oversight, or naming a Qualified Individual. The safeguards that actually stop a breach apply to every covered dealer, whatever your size.
Since May 2024, you must report breaches to the FTC
The Safeguards Rule now has teeth on disclosure. Since May 13, 2024, a "notification event," meaning unauthorized acquisition of unencrypted customer information involving at least 500 consumers, must be reported to the FTC as soon as possible and no later than 30 days after discovery. The reports are public. Notice the word unencrypted in that definition: encryption is effectively your safe harbor, because properly encrypted data that is stolen without the key generally does not trigger the reporting duty.
After the CDK attack, the FTC did not waive anything. What happened instead, per NADA, was an accommodation on paperwork: CDK could file a single consolidated notification on behalf of affected dealers. The obligation itself stayed.
What non-compliance costs
FTC civil penalties are adjusted for inflation: the maximum for FTC Act rule and order violations rose to $53,088 per violation in January 2025, and that figure still applies today. Per violation adds up quickly when every consumer record is in play. And the FTC has been willing to act against dealers directly for more than a decade: its first data-security case against a dealership was Franklin's Budget Car Sales in 2012, where file-sharing software on the dealership network exposed the personal information of 95,000 consumers. The settlement included independent security audits every other year for 20 years.
Record retention: what to keep and for how long
Data security and record keeping pull in opposite directions, and the law expects you to manage both: keep required records for their full retention period, then get rid of what you no longer need. Here are the federal anchors, plus one state example:
| Record | Keep for | Authority |
|---|---|---|
| Odometer disclosure statements (and powers of attorney used for them) | 5 years, retrievable, at your primary place of business | 49 CFR 580.8 |
| OFAC screening and sanctions-relevant transaction records | 10 years (raised from 5, effective March 12, 2025) | 31 CFR 501.601 |
| IRS Form 8300 (cash payments over $10,000) plus supporting docs | 5 years from filing | IRS Form 8300 reference guide |
| Truth in Lending / Regulation Z evidence of compliance (BHPH and dealers financing in their own name) | 2 years | 12 CFR 1026.25 |
| Florida example: dealer purchase/sale/exchange records, titles, temp tag dates, buyer and seller details | 5 years | Fla. Stat. 320.27(6) |
A few practical notes:
- The OFAC change is recent and easy to miss. The recordkeeping period doubled to 10 years in March 2025, following the 2024 statute that extended the sanctions limitations period. If your document retention policy still says five years for OFAC records, it is out of date.
- State deal-jacket rules vary. Florida's five years is typical, but check your own state's dealer licensing statute; your DMV or dealer board publishes it.
- The FTC Used Car Rule adds display obligations while the car is on the lot: a Buyers Guide displayed prominently and conspicuously on every used vehicle offered for sale (16 CFR 455.2), and the final version given to the buyer at sale, incorporated into the contract (16 CFR 455.3).
Disposal is a legal duty too
Two rules govern the other end of the record's life:
- The Safeguards Rule disposal clock (16 CFR 314.4(c)(6)): securely dispose of customer information no later than two years after the last date it is used for the customer, unless a legitimate business purpose or a law (like the retention periods above) requires keeping it. You must also periodically review your retention policy to minimize unnecessary holdings. A filing room full of 15-year-old credit applications is not an archive, it is liability.
- The FACTA Disposal Rule (16 CFR Part 682): when you dispose of anything derived from a consumer report, take reasonable measures so it cannot practicably be read or reconstructed. Burn, pulverize, or shred paper. Destroy or erase electronic media. Deal jackets tossed whole into the dumpster behind the lot are exactly the scenario this rule was written for.
The clean mental model: every record has a legally required lifespan; keep it safely for exactly that long, then destroy it properly. Both halves are the law.
MFA: the cheapest control, and the one most stores skip
Here is the strange part. The single most effective account security measure is nearly free, takes an afternoon to roll out, and is legally required for covered dealers. And most small businesses still have not done it.
The effectiveness numbers are not subtle:
- Microsoft's foundational study concluded that enabling MFA blocks over 99.9% of account compromise attacks. Its Digital Defense Report 2023, using real-world attack data from Microsoft Entra, updated the figure: MFA reduces the risk of compromise by 99.2%. Microsoft also reports that more than 99.9% of compromised accounts did not have MFA enabled.
- CISA and the FBI, citing industry research, advise that users who enable MFA are up to 99 percent less likely to have an account compromised, and CISA's small business guidance urges starting with administrator accounts and aiming for phishing-resistant MFA.
Now the adoption numbers:
- A Cyber Readiness Institute survey of 1,403 small business owners found 54% of SMBs do not use MFA for their business, and only 13% require it for most account or application access.
- Its 2024 follow-up found the gap widening: 65% of SMBs do not use MFA and do not plan to implement it.
Meanwhile, stolen credentials remain a dominant way attackers get in. Verizon's 2025 Data Breach Investigations Report found credential abuse was the top initial attack vector at 22% of breaches. The 2026 edition saw vulnerability exploitation (31%) overtake credentials for the first time in the report's 19 years, and analyses of the full report still put credential abuse somewhere in roughly four in ten breaches, with a majority involving the human element.
IBM's 2024 report adds the kicker: breaches that start with stolen credentials take longer to identify and contain than any other vector, nearly ten months on average.
Put those together and the picture for a dealership is blunt. A password alone protecting your CRM, your email, or your DMS login is the exact weakness that both the attackers and the FTC have already named. If you do nothing else after reading this, turn on MFA everywhere customer data lives, starting with email and any remote access. It satisfies a legal requirement and closes your most likely breach path in the same afternoon.
A practical data security program for a real dealership
The rule scales to your size. For a typical independent store, compliance looks like this:
- Name your Qualified Individual. Office manager, controller, or an outside IT provider. Write the name down in the program.
- Map your customer data. Where do credit apps, licenses, and deal jackets live? DMS, CRM, email, shared drives, phones, filing cabinets. You cannot protect what you have not listed.
- Turn on MFA everywhere that touches customer information. Email first, then DMS, CRM, and remote access.
- Encrypt at rest and in transit. Modern cloud dealer software should do this by default; ask your vendors to confirm in writing where your data is encrypted and how. Get full-disk encryption on laptops.
- Limit access by role. Salespeople do not need the whole customer database. Deactivate accounts the day someone leaves.
- Put retention periods in writing using the table above, add your state's rule, and set a yearly calendar reminder to shred and purge what has aged out.
- Write the incident response plan (who calls whom, how you isolate systems, when the 30-day FTC reporting clock starts) even if you are under the 5,000-consumer threshold and not strictly required to. The CDK outage proved you also need a plan for your vendor going down: how do you desk deals and take payments on paper for two weeks?
- Train the floor. Phishing is the top threat dealers themselves report. Ten minutes at a sales meeting each quarter beats an annual seminar nobody remembers.
- Hold your vendors to it. Ask every software provider about encryption, MFA support, and breach history. You are legally required to.
Frequently asked questions
Does the FTC Safeguards Rule apply to car dealers?
Yes, for most dealers. The FTC's own dealer FAQs state that dealers who finance or facilitate financing are financial institutions under the Gramm-Leach-Bliley Act, and dealers who lease vehicles for longer than 90 days qualify as well. Cash-only dealers with no financing or leasing activity may fall outside the rule, but arranging even third-party financing brings a store in. Full compliance with the amended rule has been required since June 9, 2023.
Is multi-factor authentication legally required at a dealership?
For covered dealers, yes. 16 CFR 314.4(c)(5) requires multi-factor authentication for any individual accessing any information system that holds customer information, unless the dealership's Qualified Individual approves reasonably equivalent or more secure controls in writing. The small-dealer exemption for stores with data on fewer than 5,000 consumers does not remove the MFA requirement.
What encryption does the Safeguards Rule require?
All customer information must be encrypted both at rest and in transit over external networks (16 CFR 314.4(c)(3)). If encryption of certain data is infeasible, the Qualified Individual may approve an effective alternative compensating control in writing. Encryption also matters for breach reporting: the FTC reporting duty is triggered by unauthorized acquisition of unencrypted customer information, so properly encrypted data stolen without the key generally does not trigger a report.
How long do car dealers need to keep records?
It depends on the record. Federal anchors include odometer disclosure statements for 5 years (49 CFR 580.8), OFAC sanctions screening records for 10 years since March 2025 (31 CFR 501.601), IRS Form 8300 copies for 5 years, and Truth in Lending compliance evidence for 2 years (12 CFR 1026.25). States add their own deal-record periods, for example Florida requires 5 years under Fla. Stat. 320.27(6). Once no retention period or business need applies, the Safeguards Rule expects secure disposal within two years of last use, and the FACTA Disposal Rule requires destruction so records cannot practicably be read or reconstructed.
Do dealers have to report data breaches?
Yes. Since May 13, 2024, the Safeguards Rule requires covered dealers to notify the FTC of any unauthorized acquisition of unencrypted customer information involving 500 or more consumers, as soon as possible and no later than 30 days after discovery. The notifications are published on the FTC's site. State breach notification laws can add separate duties to notify affected consumers.
What did the CDK Global attack cost dealers?
Anderson Economic Group estimated about $1.02 billion in direct losses across dealers for the roughly three-week disruption starting June 19, 2024, including approximately 56,200 lost new-vehicle sales. Individual groups disclosed real numbers too: AutoNation reported an earnings hit of about $1.50 per share for the quarter in an SEC filing. Blockchain analysts also traced a transfer of roughly $25 million in bitcoin to a wallet linked to the attackers.
Where to start
Treat this like safety recalls: not a project you finish, a standard you run the store by. Name the person, turn on MFA, encrypt the data, write down the retention calendar, and make your vendors show their work. None of that requires an enterprise budget. If you would rather have encryption, access controls, MFA, and audit trails built into the software that already runs your deals instead of bolted on around it, that is exactly how we built AutoDealer.io's security, and it is worth a look whenever you are ready.