Are Credit Card Numbers Sensitive Personal Information Under the FTC Safeguards Rule?

Credit card numbers are sensitive personal information under the FTC Safeguards Rule and also fall under PCI-DSS. Here is what dealers must actually do about it.

Quick answer: Yes. Credit card numbers are sensitive personal information under the FTC Safeguards Rule. They are also regulated under PCI-DSS. Dealers who accept card payments for down payments, service work, or parts are on the hook for both.

Two rulebooks, same underlying obligation

Credit card numbers sit at the intersection of two frameworks that dealers must comply with:

  • FTC Safeguards Rule. Treats card numbers as sensitive personal information that must be inventoried, protected, and audited.
  • PCI-DSS. The payment card industry standard that governs how card data is stored, processed, and transmitted.

Both frameworks require the same core work: minimize where card numbers are stored, encrypt what you must store, control who can access it, and prove the controls work.

Where dealers store card data without realizing it

Every operator we ask says "we do not store cards." Every audit finds card numbers in:

  • Deal notes and free-text CRM fields where an F&I manager typed the number for convenience
  • Service write-up notes
  • Email attachments from customers sending a card image for a deposit
  • Old batch reports from your payment processor
  • Recorded calls that captured a customer reading a card number aloud

You cannot protect what you cannot see. And you cannot see it without a data foundation that scans every field for card-number patterns.

What the rule actually requires

  • Never store card numbers you do not need. Tokens beat raw numbers every time.
  • Encrypt what you store. At rest and in transit.
  • Access controls. Role-based, with logs.
  • Written risk assessment. Every location, every export path.
  • Vendor management. Your processor, DMS, and CRM all need to attest to their controls.

The data-ownership answer

The reason most dealers cannot pass a credit-card portion of a Safeguards audit is not that they intentionally hoard card data. It is that they have no way to see where card-shaped strings ended up across ten systems.

QoreCloud gives you that visibility. Every customer record, every note field, every attachment is consolidated into one dealer-owned data foundation. You can scan for card numbers with a plain-English query, redact them at the source, and prove it happened.

Read the pillar: FTC Safeguards Rule for Auto Dealers: Why the Answer Is Owning Your Data.

Frequently asked questions

Are credit card numbers sensitive personal information under the FTC Safeguards Rule?

Yes. Credit card numbers are financial account identifiers and qualify as sensitive personal information. They are also regulated separately under PCI-DSS.

Do I have to comply with both Safeguards and PCI-DSS?

Yes, if you accept card payments. The two frameworks overlap heavily on encryption, access control, and audit requirements.

Where do dealers accidentally store card numbers?

CRM note fields, deal jacket PDFs, service write-ups, email attachments, recorded calls, and old processor batch reports. Auditors find them constantly.

How do I remove card numbers from unstructured fields?

You need a data foundation that can scan every text field and attachment for card patterns and redact them at the source. Manual review does not scale.

How does QoreCloud help with card-data Safeguards compliance?

QoreCloud consolidates every dealership system into one dealer-owned foundation and lets you scan, audit, and redact card numbers with plain-English queries.