top of page
IronShield-Advisors-logo

Does the FTC Safeguards Rule Apply to Equipment Dealers That Offer Financing?

Writer: Kenny Mollitor
Kenny Mollitor
Jul 15
2 min read
If your equipment dealership offers customer financing or leasing, the short answer is yes—the FTC Safeguards Rule almost certainly applies to you.
If your equipment dealership offers customer financing or leasing, the short answer is yes—the FTC Safeguards Rule almost certainly applies to you.

When Your Dealership Is Considered a Financial Institution


Under the Gramm–Leach–Bliley Act (GLBA), businesses that extend or arrange credit for consumers are treated as financial institutions, even if they don’t look like banks or traditional auto dealers. If your store helps customers finance tractors, implements, or other equipment, you are expected to maintain a written information security program and appropriate safeguards for customer data.


Activities that put you in scope:

• Help customers complete finance or lease applications.

• Collect and transmit credit applications to lenders or captive finance programs.

• Offer in-house financing, leasing, or payment plans tied to personal financial information.

• Maintain customer finance records in your systems, email, or shared folders.


What Compliance Actually Requires (Plain English)


If your dealership is in scope, the FTC expects you to:

• Maintain a Written Information Security Program (WISP) that fits your size, complexity, and data exposure.

• Conduct a written risk assessment of where customer information lives and what could go wrong.

• Designate a Qualified Individual responsible for overseeing and enforcing your security program.

• Implement safeguards such as access controls, encryption, secure disposal, and change management.

• Train employees regularly on identifying and avoiding common threats like phishing and business email compromise.

• Oversee service providers that handle your customer data and hold them to appropriate security standards.

• Monitor and test your safeguards, and report program status to ownership or a governing body at least annually.


This isn’t about buying the biggest firewall you can find. It’s about documenting how you manage risk and being able to show your work when an auditor, lender, or regulator asks.


Common Misconceptions from Equipment Dealers


Many equipment dealers stay exposed because of a few recurring misunderstandings:

“We’re not an auto dealer, so this doesn’t apply.” The rule is about the function you perform, not the OEM on your sign. If you help consumers finance purchases, you are likely in scope.


“Our OEM or DMS handles that.” OEMs and software providers can be critical partners, but they don’t remove your responsibility. You still control what happens inside your store: who accesses data, how it’s stored, and how it’s protected.


“Our IT provider has us covered.” IT partners can implement tools and controls, but the FTC expects dealership-level ownership, a WISP, and governance. “IT handles it” is not a compliant answer during an audit.


How IronShield Helps Dealers Get Audit-Ready


For most dealers, the hardest part is not the technology—it’s translating regulations into a simple, practical plan. IronShield Advisors focuses on:

• Clarifying whether your operations trigger Safeguards expectations.

• Mapping where your customer information actually lives (systems, email, paper files, personal devices).

• Building a dealership-sized WISP that covers the required elements without becoming a 200-page monster.

• Identifying and prioritizing the highest-impact gaps before an OEM, lender, or insurer raises the issue.


Instead of guessing, you can know exactly where you stand—and have documented evidence to back it up.


Want a short, dealership-specific readiness check against the Safeguards Rule? Contact IronShield Advisors for a quick assessment and a clear list of what’s missing before your next floor-plan review.

 
 
 

Comments


bottom of page