Skip to main content
GuidesBy Rutvi VaderaAugust 28, 20269 min read

FTC Safeguards Rule in 2026: Warning Letters, Enforcement, and Who Is Covered

FTC Safeguards Rule in 2026: Warning Letters, Enforcement, and Who Is Covered

The direct answer: if your business extends credit, arranges financing, or handles consumer financial data without being a bank, the FTC Safeguards Rule almost certainly applies to you, and it has been fully mandatory since June 9, 2023. Nothing about the rule text changed in 2026. What changed is enforcement intensity: the FTC sent warning letters to 97 auto dealerships in March 2026, named them publicly on May 28, and penalty exposure runs up to $51,744 per violation per day. If you certified nothing, designated no Qualified Individual, and have no written program, you are not early. You are late, and the agency has started saying so in writing.

Status verified August 27, 2026. This page is updated when the regulatory status changes.

Who the Safeguards Rule actually covers

The rule implements the Gramm-Leach-Bliley Act for non-bank financial institutions, and the definition of "financial institution" is far broader than most operators assume. You do not need a charter, a license from a banking regulator, or the word "financial" in your name. You need to be significantly engaged in financial activities. That sweeps in:

Business type Why it is covered
Auto dealershipsArranging or facilitating financing or leasing is a financial activity, even when a lender funds the deal
Mortgage brokers and lendersDirect lending and brokering are core covered activities, including payday and title lenders
Tax preparersHandling consumer financial information in the course of preparing returns
Collection agenciesCollecting consumer debts is a financial activity
Investment advisers not registered with the SECState-registered advisers fall to the FTC rather than the SEC's parallel regime
Fintechs without bank chartersLending, payments, and money movement products without a banking regulator default to FTC jurisdiction
Higher education institutionsParticipating in federal student aid programs brings GLBA obligations

There is a partial carve-out for institutions holding information on fewer than 5,000 consumers, which relaxes a handful of the written-program requirements. Most mid-market firms blow past that threshold without noticing. A single-point dealership with a decade of deal jackets has tens of thousands of consumer records. If you are at or above 5,000, you get no exemptions at all.

The FTC maintains a dealer-specific FAQ that answers the applicability question in the agency's own words, which is worth reading before your compliance counsel does.

What has been mandatory, and since when

Every prescriptive requirement of the amended rule took effect on June 9, 2023. That means a covered institution should already have, today, a written information security program built around nine elements: a designated Qualified Individual who oversees the program, a written risk assessment, technical safeguards including encryption of customer information and multi-factor authentication for anyone accessing it, regular testing of controls, security awareness training, oversight of service providers, a process for keeping the program current, a written incident response plan, and at least annual reporting to the board or governing body.

A second clock started on May 13, 2024: covered institutions must notify the FTC within 30 days of discovering a breach involving the unencrypted information of 500 or more consumers. Those notifications are public. A dealership or lender that suffers a reportable event now creates its own enforcement record, which is one reason incident response planning has moved from paperwork to priority.

The FTC also published updated Safeguards guidance in June 2025. When an agency refreshes its plain-language guidance two years after the compliance deadline, it is closing off the "we did not understand what was required" defense before it ramps enforcement. That is exactly the sequence that played out.

We cover the nine elements and the evidence behind each one in more depth in our GLBA Safeguards Rule compliance guide, so this post will not re-walk them. The short version: the FTC did not ask for a policy binder. It asked for a running program with a named person responsible for it.

Not sure your program would survive an FTC inquiry?

A Z Cyber advisor can walk your current state against the nine Safeguards elements and brief you on the gaps, so you decide what to fix first.

Talk to an Advisor →

The 2026 enforcement picture, stated honestly

Three things happened in 2026, and they are worth keeping distinct, because a lot of vendor content blurs them together.

First, the warning letters. In March 2026 the FTC sent warning letters to 97 auto dealerships, and on May 28, 2026 it publicly named the recipients. A warning letter is not a fine and not a finding of violation. It is the step before one. It tells a named business that the agency believes it has a problem and is watching what happens next. Law firm commentary on the letters, including Crowell's client alert, reads them as the signal of renewed federal scrutiny of the dealer segment.

Second, the Lindsay Automotive settlement. On April 2, 2026, the FTC and the Maryland Attorney General announced a settlement with the Lindsay Automotive dealership group totaling $78 million, including individual liability for principals. To be precise: that case centered on deceptive pricing practices, not the Safeguards Rule. Anyone who tells you a dealership was fined $78 million for missing MFA is misstating the record. What the case does establish is that the FTC is willing to bring large, personal-liability actions against dealership groups, and that dealers are squarely in its enforcement field of view on every theory available to it.

Third, the penalty math. Civil penalty exposure for Safeguards violations is cited at up to $51,744 per violation per day. The per-day structure is the part that matters. A business with no Qualified Individual, no risk assessment, and no MFA is not carrying one violation. It is carrying several, each accruing daily, dating from whenever the obligation attached. That arithmetic is why "we will get to it next year" is a materially worse position in 2026 than it was in 2023.

Commentators tracking the FTC's posture consistently report that when the agency does look at a covered institution's security program, MFA and incident response are the focal points. Those are also the two controls your cyber insurer already asks about at renewal, a convergence we cover in our guide to cyber insurance requirements in 2026. Fixing them once satisfies both audiences.

The Qualified Individual problem

Of the nine elements, the one that stalls most mid-market institutions is the first: someone has to own the program. The rule allows the Qualified Individual to be an employee or an outsourced provider, and there is no certification requirement. But the designation is not decorative. The QI oversees the risk assessment, the safeguards, the testing, and the annual board report, and the institution retains full compliance responsibility no matter who holds the title.

In practice, most dealerships, lenders, and tax practices cannot hire a full-time security executive, so the role lands on a controller or general manager with no security background and no support. That is a designation, not a program. The workable alternative for most covered institutions is an outsourced arrangement where an external advisor leads and runs the program day to day while the institution keeps the designation and the decisions. We wrote a full breakdown of how that works, and what the FTC expects the institution to retain, in our guide to outsourcing the GLBA Qualified Individual role.

If you are behind, the order of operations

For an institution starting from little or nothing, sequence matters more than ambition. Designate the Qualified Individual first, because every other element needs an owner. Complete the written risk assessment second, because it determines which safeguards your program actually needs; a structured risk assessment against the rule's requirements gives you the document the FTC asks for first. Then close the two controls enforcement focuses on: MFA everywhere customer information is accessible, and a written, tested incident response plan that can meet the 30-day FTC notification clock. Training, vendor oversight, and the board reporting cadence follow. None of this is exotic. All of it needs to exist in writing, with dates, before the inquiry arrives rather than after.

What to watch next

The near-term signal is what becomes of the 97 warning letters. Letters that produce no response typically convert into investigations, so watch for Safeguards-specific enforcement actions against named dealerships through late 2026 and into 2027. Watch also for whether the FTC extends the warning-letter pattern beyond dealers to the rest of the covered population: mortgage brokers, tax preparers, and collection agencies have the same obligations and, on average, thinner programs. Two standing clocks continue to run regardless: the 30-day FTC breach notification duty for incidents affecting 500 or more consumers, and the Qualified Individual's written report to the board, due at least annually. If your last board report does not exist, that is the gap to close before year end.

Frequently Asked Questions

Does the FTC Safeguards Rule apply to my dealership?

Almost certainly yes, if your dealership arranges or facilitates financing or leasing. That activity makes you a financial institution under the Gramm-Leach-Bliley Act, which puts you under the FTC Safeguards Rule. The requirements have been fully mandatory since June 9, 2023, and the FTC signaled its focus on dealers by sending warning letters to 97 dealerships in March 2026. A partial exemption softens some requirements for institutions holding information on fewer than 5,000 consumers, but most dealerships exceed that threshold.

What does the FTC Safeguards Rule require?

A written information security program built around nine elements: a designated Qualified Individual who oversees the program, a written risk assessment, technical safeguards including encryption and multi-factor authentication, regular testing, security awareness training, oversight of service providers, a process to keep the program current, a written incident response plan, and at least annual reporting to the board or governing body. Since May 13, 2024, covered institutions must also notify the FTC within 30 days of a breach affecting 500 or more consumers' unencrypted information.

What happened with the FTC warning letters to auto dealers in 2026?

In March 2026 the FTC sent warning letters to 97 auto dealerships, and it publicly named the recipients on May 28, 2026. Warning letters are not fines, but they put a dealership on notice that the agency is watching, and they typically precede enforcement for businesses that do not respond. Separately, the April 2, 2026 settlement with Lindsay Automotive totaled $78 million; that case centered on deceptive pricing practices rather than the Safeguards Rule, but it confirms that federal scrutiny of dealerships has escalated on multiple fronts at once.

What are the penalties for violating the FTC Safeguards Rule?

Civil penalty exposure is cited at up to $51,744 per violation per day. Because each unaddressed requirement can count as a separate ongoing violation, a business that has never designated a Qualified Individual, never completed a written risk assessment, and never deployed multi-factor authentication is accruing exposure on multiple clocks simultaneously. Recent FTC actions against dealership groups have also included individual liability for owners and executives, which changes the risk calculation for principals who have treated compliance as deferrable.

Who can serve as the Qualified Individual under the Safeguards Rule?

The Qualified Individual can be an employee or an outsourced provider such as a virtual CISO or service firm. There is no certification requirement; qualification is judged by whether the person can actually run the information security program. The catch is that the institution retains full compliance responsibility either way and must supervise any outsourced provider. Naming a controller or general manager with no security background, and giving them no support, satisfies the letter of the designation but leaves the program the FTC examines empty.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.