
WASHINGTON, D.C. — The Federal Trade Commission has released its first official guidance directed specifically at auto dealerships regarding the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, which governs how financial institutions must protect consumer data. This marks the first time the FTC has issued Frequently Asked Questions (FAQs) on the topic since the revised rule took effect in 2023.
The newly published guidance clarifies how dealerships should handle their relationships with automakers and third-party vendors when it comes to sharing sensitive customer information. Under the GLBA Safeguards Rule, any business that collects, processes, or shares nonpublic personal information (NPI) related to finance or leasing arrangements must maintain strict oversight of that data – and that includes most auto dealerships.
According to the FTC’s latest interpretation, dealers are responsible for ensuring full compliance with the rule when they give outside parties access to databases containing sensitive information, such as Social Security numbers, customer credit application details, or finance-related identifiers. That includes sharing customer lists or even working with an OEM that provides digital tools or analytics.
Crucially, the rule does not distinguish between a third-party vendor and an OEM – both are considered “service providers” under the regulation. As a result, dealerships must take steps to vet these providers, enter into formal data protection agreements with them, and actively monitor their data security practices over time.
The FTC emphasized that the Safeguards Rule is separate from the GLBA’s Privacy Rule, which focuses on consumer disclosures and opt-out rights. While the Privacy Rule governs how information can be shared, the Safeguards Rule focuses on how that information must be protected.
The revised GLBA Safeguards Rule, which underwent significant updates in 2021 and 2023, introduced more stringent requirements for data encryption, access controls, multi-factor authentication, and incident response planning. As of May 2024, financial institutions – including dealerships – are now required to notify the FTC within 30 days if a data breach affects 500 or more consumers.
The new FAQs reinforce that compliance is not optional or one-size-fits-all. Dealers must tailor their information security programs to the scale and nature of the data they handle, but the FTC made it clear that nearly all scenarios involving finance-related customer data will demand strong protections.
As digital integration with OEMs and vendors continues to grow across the auto industry, the FTC’s latest guidance is a reminder that consumer data security is a shared responsibility. Dealerships that fail to properly manage third-party relationships or neglect their cybersecurity obligations could face regulatory scrutiny – or worse, become the target of a breach.

Joe Mcdermott is a staff reporter who keeps his eyes peeled for interesting automotive news. He works mainly for our Long Island Guide as well as our IT firm, SEARCHEN NETWORKS®. Mcdermott, one of our first and thus veteran reporters, is also a data analyst for select independent news and media organizations in the United States.
