MenuMENU
SearchSEARCH

Providers, Administrators, and the Safeguards Rule

The P&A segment must follow the same path traveled by dealers who, 15 years ago, found themselves suddenly operating under the same privacy standards as other ‘financial institutions.’

April 16, 2019
Providers, Administrators, and the Safeguards Rule

The P&A segment must follow the same path traveled by dealers who, 15 years ago, found themselves suddenly operating under the same privacy standards as other ‘financial institutions.’

Credit:

Photo courtesy of ACE

3 min to read


The Safeguards Rule went into effect on May 23, 2003, and brought with it a raft of new obligations for dealerships. Having lived through that event, I can attest to the consternation it caused. The Safeguards Rule applies to “financial institutions,” and dealerships, because they originate financing, fall within the definition of financial institution. Having to learn how to act like banks did not come easy to most of the industry.

Fortunately for providers and administrators, they do not originate financing and therefore are not considered financial institutions. Thus, the burdens of the Safeguards Rule do not fall upon your shoulders, right?

Wrong. 

The Safeguards Rule obligates dealerships to both follow its requirements and only use service providers that also follow the terms of the Safeguards Rule. What is a “service provider,” you ask? 

“Service provider” means any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution that is subject to this part. In other words, providers and administrators of service contacts, among others, by virtue or receiving customer data. Why is this important? Because dealerships are required to “Oversee service providers, by:

  1. Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; and

  2. Requiring your service providers by contract to implement and maintain such safeguards.”16 CFR 314.4(d)

In other words, dealerships may only do business with providers and administrators that follow the Safeguards Rule as well, at least to the extent appropriate for the data at issue.

While providers and administrators routinely receive, maintain, process and otherwise have access to customer information, it rarely involves such sensitive data as Social Security number, financial account numbers, or mother’s maiden name.

Yet even more mundane customer information can be misused to a customer’s detriment. Consider the following phone conversation:

Caller: Hello, Mr. John Smith?

Customer: This is he. 

Caller: Mr. Smith, this is Tom Jones from Oconomowoc Motors. You purchased a 2019 Queen Pea Family Truckster from us on Oct. 12 for $37,500, correct?

Customer: That’s right.

Caller: A routine audit of our records indicated that you were overcharged for the service contract you purchased in connection with that transaction. We intend to reimburse you $750, plus interest. If you just give us your bank account information, we will transfer that amount immediately.

All the information needed for an identity thief to “spoof” a customer and obtain the customer’s bank account information is typically part of the customer’s file held by the provider or administrator. 

At a practical level, what does this mean? What must providers and administrators do to comply with the Safeguards Rule? Essentially, what dealerships must do, providers must mirror. In a nutshell, those obligations are seven:

  1. Conduct a risk assessment, specifically considering employee training and management, IT systems, and detecting, preventing, and responding to attacks or system failures.

  2. Design and implement safeguards that address the risks identified.

  3. Oversee your own service providers.

  4. Evaluate and adjust your information security program in response to regular audits of its effectiveness and performance. 

Sound like a lot? It is, but it’s important. If a dealership’s service contract provider is not in compliance with the Safeguards Rule, the dealership is not in compliance, either. Putting your dealership clients in a position of legal peril is not a good business plan. Conversely, assuring your clients (and prospective clients) that you’ve thought this through for their protection can only help solidify your relationship.

Topics:Compliance
Subscribe to Our Newsletter
No form configuration provided. Please set either Form ID or Form Script.

More Compliance

F&INovember 10, 2025

Singing a Gospel Song Backward

Crime and punishment in auto retail and how to avoid them

Read More →
ComplianceOctober 6, 2025

The Jurisprudence of Pricing

Legal concept helps makes sense of California’s recently passed version of the failed federal CARS legislation.

Read More →
ComplianceSeptember 15, 2025

Fines of the Times

Civil penalties for noncompliance with federal auto retail and finance rules and regulations can add up quickly. Use this checklist to cover your bases.

Read More →
Ad Loading...
Digitalby Hannah MitchellSeptember 5, 2025

Cyber Threats Continue Apace

Hackers, seeing auto retail vulnerabilities in 2024 CDK incident, are taking advantage, data show.

Read More →
ComplianceAugust 11, 2025

Your Synthetic ID Theft Policy

Frankenstein’s monster is coming for your dealership. Use this guide to recognize synthetic ID thieves and maintain Red Flags Rule compliance.

Read More →
IndustryJuly 17, 2025

Trump 2.0 and Enforcement Priorities

The upshot is don’t relax, because regulation indeed continues.

Read More →
Ad Loading...
ComplianceJune 30, 2025

The Regulatory Empire Is Striking Back

President Trump - entropist and corporate disruptor in consumer law

Read More →
IndustryJune 26, 2025

How to Clear a Red Flag

Refine and enforce your dealership’s FTC-mandated ID theft-prevention program to ensure no transaction goes awry.

Read More →
Computer screen showing the Audit F&I Review Dashboard, displaying dealership selection and manager scorecard options for ABC Dealership.
F&Iby Press ReleaseJune 18, 2025

Mosaic Adds Continuous Monitoring With AuditF&I

New AuditF&I platform is designed to give dealerships a smarter way to stay compliant.

Read More →
Ad Loading...
DigitalJune 9, 2025

The Real ID Deadline

Challenges auto dealers may still face verifying identities

Read More →