New FTC Safeguards Rule Obligation - Dealers Must Report 'Notification Events' to the FTC
Today, May 13, 2024, the Federal Trade Commission is implementing a rule which creates a new obligation for dealers to report certain breaches of consumer data.
Beginning May 13, if a dealer learns that a security event occurs such that the unencrypted private data of at least 500 consumers has been breached, the dealer has an obligation to report the incident to the FTC within 30 days.
The report must be made electronically on the FTC’s website using an FTC form, https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act/safeguards-rule-form.. The report will be made publicly available.
Failure to make a required report could result in the FTC’s seeking to impose a large fine on the dealer.
Notably, this requirement only applies to breaches of unencrypted consumer data.
Dealers are encouraged to take steps to protect consumer data and to encrypt the data such that a potential security breach leads to indecipherable data.
When making the report to the FTC, the dealer would need to include the following information:
· The name and contact information of the dealer;
· A description of the types of information that is involved;
· The date or date range of the breach;
· The number of consumers affected; and,
· A general description of the breach.
If the dealer learns that a security breach may have occurred, PAA strongly recommends that the dealer reach out to legal counsel immediately. Competent counsel should be able to determine if there is an obligation to report and what information must be reported. It is likely that the dealer will want counsel to prepare the FTC report to ensure that the FTC receives only the required information.
Dealers who wish to prepare for such a potential breach may want to consider reviewing and potentially implementing NADA’s “Incident Response Plan,” which is available in the “NADA Dealer Guide To New Safeguards Rule Requirements” at www.nada.org.
FTC Safeguards Rule
Effective June 9, 2023
The Safeguards Rule applies broadly to all “financial institutions,” including dealerships and other entities that provide or facilitate financial services.
The penalties for not complying with the Revised Safeguards Rule can be extensive and expensive. The FTC can initiate enforcement action against automobile dealers and penalties may include longterm consent decrees with your companies and sometimes your executives, extensive injunctive relief, and potential monetary fines for violations of the consent decree.
PAA Offers Compliance Reviews
Experienced PAA Staff review the dealership safeguarding manual, and policies and procedures to establish compliance with the FTC Safeguards Rule, including the new requirements implemented in 2022. For more information on Compliance Reviews provided by PAA’s Training and Compliance Department, contact Becky Ross at 717-255-8311, ext. 3319.
PAA Recommends ComplyAuto
ComplyAuto is a privacy rights management system built specifically for dealers. Processing consumer deletion, opt-out, right to know, and data portability requests in a fully automated solution. ComplyAuto also installs the required website tools, like compliant cookie banners, privacy policies, and consumer request portals. They offer a month to month subscription and no implementation fees. To schedule a demo, visit https://complyauto.com/schedule-demo/ or call (661) 214-8671.