The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
Primary source: FTC auto dealer Safeguards Rule FAQs
What documents does the Safeguards Rule actually require for an auto dealer?
Details
Policywright splits the operating record into a WISP, incident response plan, acceptable use policy, and access control policy. For an auto dealer, those documents should map to Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.
Primary source: FTC auto dealer Safeguards Rule FAQs.
FAQ
What documents does the Safeguards Rule actually require for an auto dealer?
The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
What is the data-flow issue for an auto dealer?
Customer information starts in the credit application and F&I desk, then moves into the DMS, lender portals, identity-verification tools, deal jackets, and retained sales or lease records. OEM systems are not automatically dealer service providers, so the WISP should distinguish dealer-controlled systems from manufacturer systems.
Is this legal advice?
No. It is source-cited educational content for a template product, not legal advice.