Dealers Do Not Need to Provide Notice to the FTC Regarding CDK - May Have State Requirements
The Pennsylvania Automotive Association (PAA) provided this update on the CDK breach.
On July 1, NADA published information stating that dealers have no obligation to file a breach notification with the FTC related to the CDK matter.
NADA, in coordination with CDK counsel, proposed to the FTC that the FTC permit CDK to file a single electronic notice on behalf of all of its affected dealer clients should CDK conclude, based on its internal investigation of the incident, that the notification requirement has been triggered. The FTC accepted NADA’s proposal, and CDK will communicate directly with its dealer clients related to this matter.
As reported in previous communications, the FTC Safeguards Rule was recently amended to require financial institutions (including dealers) to provide an electronic notice to the FTC as soon as possible and no later than 30 days after discovering a notification event involving the information of at least 500 consumers. A notification event is the unauthorized acquisition of unencrypted customer information.
Pennsylvania Reporting Requirements
While CDK will contact the FTC on dealer’s behalf, Pennsylvania also has reporting requirements to customers. In Pennsylvania, dealers must provide a notice of the data breach to customers whose information is subject to unauthorized access. At this time, dealers have not been advised if their data was accessed. CDK will need to provide dealerships with lists of customers and what categories of personal information were subject to unauthorized access. Similar to the FTC filing, CDK may provide notice to dealer’s customers; if not, this obligation will fall to the dealer. Until dealers know whose information was compromised, there is no way of notifying the affected persons.
As additional information becomes available, it will be provided to the dealer community.