Yes, if the firm is covered by the FTC Safeguards Rule as automobile dealer financing or leasing basis, it needs a written security program for customer information. Citation: 16 CFR Part 314 and FTC auto dealer Safeguards Rule FAQs.
Primary source: FTC auto dealer Safeguards Rule FAQs
Does an auto dealer need a WISP?
Details
finance (or facilitate the financing of) automobiles for consumers, or lease automobiles for longer than 90 days. Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems. Some smaller dealerships may be under 5,000 consumers, but a busy finance office can cross the threshold through retained credit applications and lease records. Under 16 CFR 314.6, being under the threshold does not remove the basic written information security program or FTC breach-notification duty.
Primary source: FTC auto dealer Safeguards Rule FAQs.
FAQ
Does an auto dealer need a WISP?
Yes, if the firm is covered by the FTC Safeguards Rule as automobile dealer financing or leasing basis, it needs a written security program for customer information. Citation: 16 CFR Part 314 and FTC auto dealer Safeguards Rule FAQs.
What is the data-flow issue for an auto dealer?
Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.
Is this legal advice?
No. It is source-cited educational content for a template product, not legal advice.