The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.

Primary source: FTC auto dealer Safeguards Rule FAQs

What documents does the Safeguards Rule actually require for an auto dealer?

Details

Policywright splits the operating record into a WISP, incident response plan, acceptable use policy, and access control policy. For an auto dealer, those documents should map to Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.

Primary source: FTC auto dealer Safeguards Rule FAQs.

FAQ

What documents does the Safeguards Rule actually require for an auto dealer?

The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.

What is the data-flow issue for an auto dealer?

Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.

Is this legal advice?

No. It is source-cited educational content for a template product, not legal advice.

Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.