Compliance for Dealerships

FTC Safeguards Compliance for Dealerships, Built Into IT and Cybersecurity

Continuous compliance monitoring instead of a once-a-year audit scramble.

30 days to report a breach
FTC notification clock

FTC Safeguards compliance for dealerships means meeting the nine required elements of the FTC's Safeguards Rule, which treats dealerships as financial institutions under the Gramm-Leach-Bliley Act. Helion Technologies builds this into the same team that manages IT and cybersecurity, using proprietary tools and annual human-led penetration testing, so compliance runs continuously instead of getting handled once a year.

Dealerships that have a compliance vendor aren't always getting compliance. They're getting a product.

Nobody does.

A line item on an invoice, maybe a checklist, maybe a portal with a score in it, and the expectation that someone on their team is going to do something with it.

The dealership doesn't have a compliance team. That's the whole reason they bought the product in the first place. So the checklist sits there, the portal goes unlogged, and the monthly fee keeps clearing, while the actual work of identifying gaps, testing systems, rating vendors, and closing vulnerabilities never gets done.

That's not a knock on any specific vendor. It's how compliance products in this space are typically built, because doing the actual work is hard, requires real people, and costs more than a $650 monthly line item can cover.

Helion's approach is different. The compliance program is fully managed, which means Helion's team does the work, not yours.

Continuous Compliance

The Difference Between a Binder and a System

Compliance handled once a year is a snapshot. A risk assessment done in January says nothing about a vendor added in March or a new employee with access in July. Continuous compliance means the same team running Managed IT and Cybersecurity keeps the compliance posture current as things change, rather than reconstructing it from scratch every twelve months.

JanMarJulDec
Once a year
Continuous
Risk assessment New vendor / new employee access

Here's what that system actually does.

01 · Scan

A proprietary tool runs directly against a dealership's own PCs and servers, scanning for:

Customer data Credit card & banking info Outdated OS versions Email & website security gaps
02 · Review

That data feeds directly to Helion's compliance team, who run it against checklists built from the actual regulatory requirements.

03 · Report

A report with real action items, not a generic list of what's missing.

Annual

Human penetration testing

Performed by people, not an automated scan mislabeled as a pen test.

Semi-annual

Vulnerability monitoring

Semi-annual vulnerability monitoring in between annual pen tests.

Included

Vendor risk rating

Evaluating the security posture of every third-party vendor already connected to a dealership's systems, a step most compliance offerings in this space skip entirely.

It's completely managed, and built on Helion's own custom software, custom reporting, and API connections into the systems it monitors, not a resold third-party tool with Helion's logo on it.

Pen Test Finding

What That Actually Looks Like in Practice

That's the difference between a report that flags a risk and a team that actually closes it.

FOUND A Windows server running an old, forgotten web service with administrator access still wide open.
WHAT IT WAS A homegrown CRM nobody had used in years.
LOGIN
user: admin pass: admin
CLIENT Confirmed it hadn't been touched in years.
It was shut down that same week.

The Nine Required Elements

The FTC's amended Safeguards Rule (16 CFR Part 314) requires every covered dealership's information security program to include:

9
01

Qualified Individual

A designated person overseeing the entire program, accountable to leadership

02

Written risk assessment

Documented inventory of where customer data lives and what threatens it

03

Safeguards design

Controls built to address the risks identified

04

Access controls

Limits on who can reach customer data and systems

05

Encryption

Data protected at rest and in transit

06

Multi-factor authentication

Required on systems accessing customer information

07

Monitoring and testing

Ongoing verification that safeguards are actually working

08

Vendor oversight

Ensuring service providers meet the same security standard

09

Incident response plan

A documented plan for responding to and recovering from a security event

Source: Federal Trade Commission, Safeguards Rule FAQ for Automobile Dealers

New Compliance Surface

AI Governance & Compliance

Dealerships adopting AI tools — for service scheduling, F&I workflows, lead follow-up, or internal drafting — are creating a new compliance surface the original Safeguards Rule didn't anticipate. California's ADMT regulations, effective January 2026, add another layer for any dealership using automated decision-making in financing or credit decisions.

Helion extends its Continuous Compliance model to cover AI tool adoption as part of the same program. That means:

Usage visibility by department
Access controls on AI tools
An audit trail that feeds the same compliance reporting your IT and cybersecurity program already produces

Not a separate AI compliance vendor. The same team, the same program.

Learn more about Managed AI for Dealerships →

What 2,000+ Dealerships and 30 Years Looks Like

98% Client retention rate
2,000+ Dealerships under management nationwide
“

"We Already Did a Compliance Audit Last Year"

An audit is a moment in time. The Rule requires ongoing monitoring and testing, not a once-a-year checkbox. If nothing has been reviewed since that audit, whatever passed then may not reflect what's actually running today.

"We already have a compliance vendor."

Worth asking what that vendor actually does day to day. A lot of compliance products generate documentation without connecting to the IT and cybersecurity systems the documentation is supposed to describe, and a vague monthly line item on an invoice doesn't tell you which one you're paying for. If the vendor isn't the same team running monitoring and security, there's a gap between what's on paper and what's actually protected.

"Isn't this mostly a fine risk we can manage if it happens?"

The bigger cost usually isn't the fine. It's the downtime and recovery that come with an actual security event, which is a cybersecurity problem before it's ever a compliance one.

Common Questions

Does the FTC Safeguards Rule actually apply to my dealership?
If the dealership arranges financing or leasing for customers, yes. The FTC treats that as a financial institution activity under the Gramm-Leach-Bliley Act.
What happens if we have a breach?
Any event exposing 500 or more consumers' data has to be reported to the FTC within 30 days of discovery, a requirement that's been in effect since May 2024.
Who can serve as our Qualified Individual?
The Rule allows an employee, an affiliate, or a qualified third-party service provider to hold that role.
Is compliance a separate service from managed IT and cybersecurity?
No. It runs as part of the same team and system, not a separate contract with a separate vendor.
Does compliance work include real penetration testing?
Yes. Annual penetration testing is performed by human security assessors, in addition to ongoing vulnerability monitoring, not a scan alone mislabeled as a pen test.
Does this include rating the security of our third-party vendors?
Yes. Vendor risk assessment is part of the same program, evaluating the vendors already connected to a dealership's systems.
Does this cover AI tools we're starting to use?
Yes. Helion's Continuous Compliance model extends to AI governance — usage logs, access controls, and an audit trail that feeds directly into the same compliance program covering IT and cybersecurity. California's ADMT regulations, effective January 2026, also require documented AI governance for businesses using automated tools in financing or credit decisions. If your compliance program was written before your staff started using AI, there's a gap. This closes it.
We already have a WISP. What does Helion add?
Ongoing monitoring and updates as systems, vendors, and staff change, rather than a document that goes stale the day it's finalized.

The FTC's 30-day breach notification clock doesn't wait for the next scheduled audit.

Get Your Complimentary IT & Cybersecurity Assessment →