Covered vertical

WISP for auto dealers

Auto dealers need a WISP when the business is covered by the FTC Safeguards Rule category automobile dealer financing or leasing basis. The practical coverage trigger is that the firm finance (or facilitate the financing of) automobiles for consumers, or lease automobiles for longer than 90 days. FTC coverage language: "finance (or facilitate the financing of) automobiles for consumers." Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.

Key facts

  • Auto dealers should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: finance (or facilitate the financing of) automobiles for consumers, or lease automobiles for longer than 90 days.
  • The data map should be vertical-specific: Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.
  • Some smaller dealerships may be under 5,000 consumers, but a busy finance office can cross the threshold through retained credit applications and lease records. Under 16 CFR 314.6, being under the threshold does not remove the basic written information security program or FTC breach-notification duty.

Key takeaways

  • Auto dealers should evaluate coverage under the FTC Safeguards Rule and document the factual trigger: finance (or facilitate the financing of) automobiles for consumers, or lease automobiles for longer than 90 days.
  • The data map should be vertical-specific: Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.
  • Some smaller dealerships may be under 5,000 consumers, but a busy finance office can cross the threshold through retained credit applications and lease records. Under 16 CFR 314.6, being under the threshold does not remove the basic written information security program or FTC breach-notification duty.
  • The lender is the real financial institution, not the dealership. The FTC says dealers who finance or facilitate consumer vehicle financing are covered; the dealership's own handling of credit applications, lender submissions, and deal records still has to be safeguarded.

Why auto dealers are covered

Auto dealers are covered when their business activity fits automobile dealer financing or leasing basis. The FTC issued dealer-specific Safeguards Rule FAQs in June 2025 to explain coverage, customer information, OEM relationships, service providers, and breach notification for dealerships.

The coverage test is factual. For this vertical, Policywright treats the trigger as: finance (or facilitate the financing of) automobiles for consumers, or lease automobiles for longer than 90 days. The sources block below is limited to primary-source or regulator materials so the page does not drift into unsourced compliance folklore.

For auto dealers, the FTC's own coverage language appears on the page as required: "finance (or facilitate the financing of) automobiles for consumers."

Where customer information lives

Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.

That data-flow map changes the WISP. A tax preparer worries about portals and e-file records; a collection agency worries about placement files, dialers, and dispute queues; an auto dealer worries about the credit application, F&I office, DMS, and lender portals.

A useful written program should name the systems, roles, vendors, access paths, retention points, and evidence records that fit the trade.

Common objection

The lender is the real financial institution, not the dealership. The FTC says dealers who finance or facilitate consumer vehicle financing are covered; the dealership's own handling of credit applications, lender submissions, and deal records still has to be safeguarded.

Policywright handles that objection by writing the factual basis into the packet rather than hiding it. If coverage is unclear, the firm should preserve the question for counsel instead of turning a WISP into an unsupported legal conclusion.

Under-5,000-consumer analysis

Some smaller dealerships may be under 5,000 consumers, but a busy finance office can cross the threshold through retained credit applications and lease records. Under 16 CFR 314.6, being under the threshold does not remove the basic written information security program or FTC breach-notification duty.

16 CFR 314.6 exempts smaller covered firms only from 314.4(b)(1), (d)(2), (h), and (i). It does not remove the written-program duty or the need to protect customer information with reasonable administrative, technical, and physical safeguards.

A serious small-firm packet should document the count assumption and keep the fuller controls where they are operationally useful.

Auto dealers WISP fit check
QuestionVertical-specific answerSource
Coverage triggerfinance (or facilitate the financing of) automobiles for consumers, or lease automobiles for longer than 90 daysFTC auto dealer Safeguards Rule FAQs
Customer data flowCustomer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.Document in WISP data inventory
Common objectionThe lender is the real financial institution, not the dealership. The FTC says dealers who finance or facilitate consumer vehicle financing are covered; the dealership's own handling of credit applications, lender submissions, and deal records still has to be safeguarded.FTC auto dealer Safeguards Rule FAQs
Small-firm exceptionSome smaller dealerships may be under 5,000 consumers, but a busy finance office can cross the threshold through retained credit applications and lease records. Under 16 CFR 314.6, being under the threshold does not remove the basic written information security program or FTC breach-notification duty.16 CFR 314.6

FAQ

Is this legal advice?

No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.

Does a small firm still need a written plan?

Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.

What if a control is not in place yet?

A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.

What makes auto dealers different from tax preparers?

The data flow and objection pattern are different. Auto dealers need a WISP that follows Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.

Does Policywright cover related non-Safeguards obligations?

No separate related obligation is claimed on this page. Policywright is focused on the Safeguards Rule policy packet and does not replace counsel.

Sources

Build a WISP for auto dealers.

Answer plain questions and receive a source-cited policy packet tailored to the firm's systems, vendors, and gaps.

Build my plan
Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.