Dealership general manager's desk with a folder, desk calendar and red pen overlooking the car lot, representing the 30-day FTC Safeguards Rule breach notification deadline
Resources / Blog

FTC Safeguards Rule Breach Notification: What Dealers Must Report Within 30 Days

By Scot McConnorOctober 10, 2026 · 12 min read

The FTC Safeguards Rule notification requirement gives a dealership 30 days from discovery to report a breach to the FTC when unencrypted customer information on 500 or more consumers is acquired without authorization. It’s been in force since May 13, 2024.

Last updated: October 10, 2026

Day one of a breach, nobody at the store is thinking about a federal web form. The GM wants to know if the service drive can write repair orders. The controller wants to know if payroll runs Friday. Somebody’s on hold with the DMS vendor.

Meanwhile a clock started. Nobody set it.

I’ve been around dealers for nearly 30 years, and most of the ones I talk to know the FTC Safeguards Rule requirements exist. Fewer know it picked up a reporting deadline in 2024. And very few have decided who at the store would actually file the thing. So this post covers what the rule says, what counts, when the 30 days begin, what goes in the notice, and what I’d have sitting in a folder before anything goes wrong. It’s the reporting piece of a bigger subject, and the day-to-day protection side lives on our dealership cybersecurity services page. The rule’s nine standing duties are on our FTC Safeguards Rule checklist.

One caveat before we start. I’m a technology advisor, not a lawyer. Whether a specific incident has to be reported is a legal call, and your attorney makes it. My job is making sure the attorney has facts to work with.

Car dealership finance office desk with deal jackets and printed credit applications, the customer information covered by the FTC Safeguards Rule notification requirement

What the FTC Safeguards Rule Notification Requirement Says

The FTC Safeguards Rule notification requirement is the part of 16 CFR 314.4(j) that makes covered financial institutions, dealerships included, tell the Federal Trade Commission about a “notification event” involving at least 500 consumers. The notice goes through a form on the FTC’s website, as soon as possible and no later than 30 days after discovery.

The Commission approved the amendment 3-0 and announced it on October 27, 2023. It took effect the following spring. The FTC’s own business blog marked the day with a post titled, more or less, the notification requirement is now in effect, which is about as subtle as a federal agency gets.

Are you covered? Probably. The FTC’s June 2025 Safeguards FAQs for automobile dealers say a dealer is a financial institution if it finances or facilitates financing for consumers, or leases vehicles for longer than 90 days. That’s most franchised stores. A lot of independents too.

What Counts as a Notification Event at a Dealership

The rule defines a notification event as the acquisition of unencrypted customer information without the authorization of the person it belongs to. Three words in that sentence do most of the work.

Customer information. The FTC’s dealer FAQs give examples. Approved finance and lease applications with names, addresses, Social Security numbers, and account details. Spreadsheets listing who financed or leased with you. Service records on their own generally aren’t, unless they’re mixed in with the financing data, and in most stores they’re mixed in, because the DMS keeps everything about a customer in one place.

Unencrypted. Here’s the part people miss. Encrypted data counts as unencrypted if the encryption key was accessed by an unauthorized person too. Locking the file doesn’t help when the key was taped to it.

Acquisition. You don’t get to assume the intruder only looked around. Under the rule, unauthorized access to unencrypted customer information is presumed to be acquisition unless you have reliable evidence that it wasn’t, or couldn’t reasonably have been. Reliable evidence means logs. If your systems can’t show what was touched and what left the building, the presumption runs against you, and a question that should’ve taken an afternoon to answer turns into every customer record on the server counting toward the 500.

Five hundred isn’t many. A single rooftop can write that many finance deals in a few months.

When the 30-Day Clock Starts

Discovery. That’s the trigger. And the rule is specific about it: a notification event is treated as discovered on the first day it’s known to you, and “you” includes any employee, officer, or other agent of the dealership, other than the person who committed the breach.

Read that again from the store’s side. The clock doesn’t wait for the dealer principal to hear about it. It doesn’t wait for the forensic report. If a title clerk sees something wrong on a Tuesday and mentions it to a manager the following Monday, six days are already gone.

Dealership office employee reporting a possible data security problem to the general manager, the moment the 30-day FTC breach notification clock starts

Thirty days sounds roomy. It isn’t. In that window somebody has to work out what was accessed, whether it was encrypted, whether it left, and how many consumers are in it, usually while the store is also trying to sell cars and get its systems back. I’d plan on the first week disappearing.

What Goes in the FTC Notice

The form itself is short. The FTC describes it as basic, high-level information, and its Safeguards Rule business guide says that if you don’t know everything yet, you report what you know and file an update later. Six items come straight from 314.4(j)(1).

What the notice must includeWhere a dealership gets it
Name and contact information of the reporting institutionThe legal entity that holds the customer information, which in a group may not be the name on the sign
Types of information involvedYour data inventory: what’s stored where, by system
Date or date range of the event, if it can be determinedAccess and activity logs
Number of consumers affected or potentially affectedA count from the DMS, CRM, and F&I systems that were in reach
A general description of the eventThe incident record your response team keeps as it goes
Whether a law enforcement official has determined in writing that public notice would impede a criminal investigation or damage national security, and how the FTC can reach that officialYour attorney and the investigating agency

Look at the right-hand column. The form is easy. The inputs aren’t. A store that has never written down where its customer information lives can’t fill in the second line, and a store without usable logs can’t fill in the third or fourth.

Also worth knowing: the FTC says your report may be made public. A law enforcement official can ask for public disclosure to be held back for up to 30 days, and for up to 60 more with a written request. After that it’s up to Commission staff.

The FTC Is One Clock, and There Are Others

The Safeguards Rule only covers telling the FTC. It doesn’t require you to notify your customers. State law does that, and according to the National Conference of State Legislatures, all 50 states plus the District of Columbia, Guam, Puerto Rico, and the Virgin Islands have breach notification laws on the books. Each has its own definitions and its own deadline. A multi-rooftop dealer group with stores in four states is reading four statutes.

Dealer principal and attorney at a conference table reviewing printed breach notification deadlines for the FTC and state laws after a dealership data incident

So the 30 days is rarely the only number in play.

  • The FTC, as soon as possible and within 30 days of discovery, when 500 or more consumers are involved.
  • State attorneys general and affected customers, on whatever schedule each state’s law sets. Your attorney tracks these.
  • Publicly traded dealer groups have a separate one. Under SEC rules adopted in July 2023, a material cybersecurity incident goes on a Form 8-K within four business days of deciding it’s material.
  • Then the paperwork you signed yourself. Cyber insurance policies, lender agreements, and manufacturer agreements can carry notice terms of their own, and I’d read them before you need them.

Which one’s shortest? Depends on the store. That’s the point of sorting it out on a quiet week.

What to Have Ready Before Day One

None of this is exotic. It’s a folder. The dealers who handle an incident well aren’t smarter than the ones who don’t. They just answered the dull questions in advance.

A Name Next to the Filing

Who decides whether an event is reportable, and who submits the form? Write both names down, with a backup for each. Section 314.4(h) already asks for a written incident response plan with clear roles and decision-making authority, so the notice decision belongs in that plan, next to the phone numbers for your attorney and your cyber insurance carrier.

A Way for the Front Line to Raise a Hand

Remember who starts the clock. Any employee. If the people at the cashier window and the F&I desk don’t know where to report something odd, the store finds out late and the 30 days gets shorter. One phone number. One email address. Tell them twice a year.

Logs You Can Actually Read

The presumption of acquisition is the expensive part of this rule, and logs are the only thing that rebuts it. Section 314.4(c)(8) of the Safeguards Rule already expects you to monitor and log what authorized users do and to detect unauthorized access. In practice that means the logs exist, they go back far enough, and a person looks at them. Our security operations center is staffed around the clock by live US-based analysts for that reason, because an alert nobody reads at 2 a.m. on a Sunday is just a record of what went wrong.

IT technician with a clipboard checking a dealership network rack, part of keeping the access logs that show what a breach did and did not reach

Encryption, and the Keys Somewhere Else

Encrypted customer information that’s taken without its key isn’t a notification event under the definition. That’s a real reason to encrypt at rest and in transit, which 314.4(c)(3) asks for anyway. Keep the keys away from the data. Otherwise you’ve bought nothing.

A Count You Can Run in an Hour

How many consumers are in the DMS? The CRM? The old server from the store you bought in 2019? If the answer takes a week, that’s a week of the 30. Run the count once now, per system and per rooftop, and write down how you did it.

Vendor Terms in Writing

Your DMS, CRM, and F&I vendors hold your customer information on their hardware. Ask each one how fast they’ll tell you about an incident involving your data, and get it in the contract. We went through that list in our post on what the Motility DMS breach taught truck dealers, and every question in it applies to car stores as well.

Who Should Own the Clock

Dealers tend to hear about this rule from whoever is selling them something that week. A compliance binder. A scanning tool. A training subscription. Each of those can be useful, and none of them files a notice or counts consumers at 9 p.m. on day 12.

There’s a question I ask whenever a plan looks finished. What am I not doing? For breach notification the honest answer at most stores is the unglamorous stuff: the inventory, the logs, the names on the plan. It takes one partner who sees the network, the security monitoring, and the compliance file together, because a notification event touches all three in the same hour.

That’s the work we do. Helion Technologies has supported dealerships since 1997, and today that’s 2,000-plus dealerships and 35,000 end users, with a 98% client retention rate and an average of 82 seconds to reach a support agent. Our FTC Safeguards compliance program for dealerships keeps the incident response plan, the data inventory, and the vendor file current between audits, so the folder is already there when somebody needs it.

What Dealers Ask Us About the 30-Day Clock

Does the FTC rule make us notify our customers too?
Not this rule. Section 314.4(j) covers notice to the FTC and nothing else. Customer letters come from state breach notification laws, which exist in all 50 states, and each one sets its own trigger and deadline. Your attorney works out which apply.
We keep fewer than 5,000 customer records. Are we off the hook?
From some of the rule, but not from this part. Section 314.6 excuses institutions holding information on fewer than 5,000 consumers from four things: the written risk assessment, the penetration testing and monitoring requirement, the written incident response plan, and the annual board report. Notifying the FTC isn’t on that list. I’d write the response plan anyway. You’ll want it.
The breach was at our DMS vendor. Is the 30 days still ours?
That one goes to your attorney, the same day you hear about it. The rule talks about customer information being acquired without authorization, and the FTC’s dealer FAQs don’t spell out how that works when the data sat on a vendor’s system. Ask the vendor, in writing, how many of your consumers were involved and what was taken. Don’t wait for their letter.
Will the FTC publish what we report?
It can. The FTC’s guidance says a report may be made public, for example in a listing of breach notifications or in response to a Freedom of Information Act request. If law enforcement is investigating and has asked you to hold off, there’s a place on the form to say so.
What if we still don’t have a firm count on day 30?
File with what you have. The form asks for consumers affected or potentially affected, and FTC guidance says to report what you know and submit an updated report when you learn more. A late notice is a worse problem than an incomplete one.

Find Out Before the Clock Does

Here’s a fair test. Could your store say, today, where its customer information lives, how many consumers are in each system, and who files the notice? If the answer is no, that’s worth knowing now.

Our complimentary IT and cybersecurity assessment walks through exactly those questions. We’ll tell you what’s in place and what’s missing. No binder required.

About the author

Scot McConnor

VP of Technology Advisory, Helion Technologies

Scot McConnor is VP of Technology Advisory at Helion Technologies. He started on the dealership sales floor in the late '90s, spent five years selling CRM solutions to dealers, and has spent the past 20 years helping dealerships treat IT as a competitive advantage instead of a cost center.

Scot McConnor on LinkedIn

Confidence in your current setup and actual protection aren't always the same thing. The only way to know which one you have is to look.

Get Your Complimentary IT & Cybersecurity Assessment →