Does the FTC Safeguards Rule Cover Phone Number and Home Address as Sensitive Personal Information?

On their own, a phone number and a home address are not automatically sensitive under the FTC Safeguards Rule. Combined with other data, they usually are. Here is the dealer test.

Quick answer: By themselves, a phone number and a home address are not automatically sensitive personal information under the FTC Safeguards Rule. Combined with a name, date of birth, financial account, or other identifiers, they are. That combination is exactly what a dealership customer record contains.

The rules real test

The Safeguards Rule protects customer information that could enable identity theft or unauthorized account access. A standalone phone number is a low risk. A phone number tied to a full name, address, date of birth, VIN, deal number, and financing details is a high-value identity-theft package.

For auto dealers, this is the entire point. Every CRM record, every deal jacket, and every service history record contains the combined data set. That is why dealers must treat phone numbers and home addresses in customer records as sensitive under the rule.

What "combined" looks like at a dealership

A single customer record in a dealership typically contains:

  • Name
  • Address
  • Phone number and email
  • Date of birth
  • Drivers license number
  • Deal number and financing details
  • Vehicle VIN and service history

That is a full identity profile. Losing any part of it is a Safeguards event.

What the rule requires

The same three things every other sensitive category triggers:

  • Written risk assessment covering every system that stores the record
  • Encryption at rest and in transit
  • Access controls and audit logging

The data-ownership answer

The problem is not knowing whether phone numbers are sensitive. The problem is that dealers cannot see all the places their customer records live. Marketing tools, CRMs, service write-ups, quote systems, and text-messaging platforms all hold copies.

QoreCloud consolidates those copies into one dealer-owned data foundation. Every customer record, in one place, with encryption and audit logging. When the auditor asks "show me everywhere this customers contact information is stored," the answer is one query, not a scavenger hunt.

Read the pillar: FTC Safeguards Rule for Auto Dealers: Why the Answer Is Owning Your Data.

Frequently asked questions

Is a phone number sensitive personal information under the FTC Safeguards Rule?

On its own, no. Combined with a name, address, or other identifiers, yes. Every dealership customer record meets that combined test.

Is a home address sensitive personal information under the FTC Safeguards Rule?

On its own, no. Inside a customer record with name, DOB, financial data, or VIN, yes. Dealers must treat address data as sensitive.

Do I need to encrypt marketing lists that contain phone and address?

If those lists are tied to identified customers, yes. That is a customer record under the rule, and encryption plus access control apply.

What if my texting or marketing vendor stores customer contact info?

You are still responsible. Vendor management is an explicit Safeguards requirement. Every vendor holding customer data belongs in your risk assessment.

How does QoreCloud help protect combined customer records?

QoreCloud consolidates customer records from every dealership system into one dealer-owned foundation with encryption, access control, and audit logging.