Auto Dealers · FTC Safeguards
Under the FTC Safeguards Rule, your dealership is a financial institution. Is your security built to prove it?
If you arrange financing, the Safeguards Rule already applies to you — a written security program, encryption, MFA, monitoring, and trained staff. We put all of it in place, and a real team stands behind it.
The rule
What the Safeguards Rule actually requires.
Required safeguards · every dealer
16 CFR Part 314
- 01A written information security program with a designated Qualified Individual
- 02Encryption of customer data, in transit and at rest
- 03Multi-factor authentication on systems touching nonpublic personal information
- 04Continuous monitoring or regular penetration testing
- 05Annual employee security awareness training
- 06Vendor oversight — including OEM-mandated platforms (not exempt)
- 07A written incident response plan
Every item above is something we build, run, or document for you — not a checklist you get handed back.
Why dealers choose Nexplay
Built for how a dealership actually runs.
Real people, not an alert queue
Your account is run by a team that learns your dealership — and picks up the phone when something happens.
We speak auto
DMS environments, F&I data, and the OEM-mandated platforms the FTC won't let you treat as someone else's problem.
Remediation included
When something is found, we fix it and confirm it's closed. The work doesn't land back on your office manager.
Proof when you're asked
When the FTC, your lender, or your insurer comes calling, the program is already in writing.
Straight answers
What dealers ask us first.
- Does the FTC Safeguards Rule actually apply to my dealership?
- If you arrange or broker financing, yes. The rule treats dealerships as financial institutions, and it has applied since June 2023. There is no revenue floor that exempts you — dealers under 5,000 consumers are exempt only from a few specific requirements, not from the rule.
- We already use the security tools our OEM requires. Isn't that covered?
- No. Vendor oversight is your obligation under the rule, and an OEM-mandated platform is a vendor like any other. You are still responsible for confirming it does what it claims and documenting that you checked.
- What does a written information security program have to include?
- A designated Qualified Individual, encryption of customer data in transit and at rest, multi-factor authentication on systems touching nonpublic personal information, continuous monitoring or regular penetration testing, annual staff training, vendor oversight, and a written incident response plan.
- Do you fix what you find, or just report it?
- We fix it. Remediation is part of the service — when something is found, we close it and confirm it is closed. Nothing lands back on your office manager as a to-do list.
Find out where you stand.
A free readiness check against the Safeguards Rule: what you have, what's missing, and what it takes to close the gap.
