the Front Row - February 2022

Page 12

compliance feature

FTC Expands Data Security Requirements, Impacting Dealers BY ROBERT EBIN, ESQ. AND EMILY HARTMAN

At the end of October, the Federal Trade Commission (FTC) announced its expansion of the Safeguards Rule to better protect consumer financial information from cyberattacks and security breaches. The amended Rule’s most significant requirements will take effect one year from the date it’s published in the Federal Register, which means dealers will need to comply likely by the fourth quarter of 2022. Here are five things you need to know.

Rule Expands Data Security Requirements for Written Programs For background, the FTC created the Safeguard Rule as part of a directive from the Gramm-Leach-Bliley Act. The Safeguard Rule has been around since 2003, directing financial institutions, which includes dealerships that extend credit and lease terms, to develop and implement a written information security program. The updated Rule includes much more detail about the required elements that must be included in an information security program, like addressing access controls, data inventory and classification, encryption, secure development practices, authentication, information disposal procedures, change management, testing, and incident response.

Identify One Qualified Individual to Oversee Data Security The previous Rule allowed “an employee 10 | THE FRONT ROW | WSIADA.COM FEBRUARY 2022

or employees” to take responsibility for the information security program, but the new rule requires only one “Qualified Individual.” This person must write an annual status report and provide it to the board of directors or the business’s governing body. The report must cover overall status updates of the program, compliance, and all security breaches or events that occurred in the past year.

If You Have Less Than 5,000 Customers, You Could Be Exempt From Some Requirements There is an included exemption for financial institutions that collect data on less than 5,000 customers. These organizations are exempt from certain requirements, including the written risk assessment, incident response plan, and submitting the report to the Board of Directors.

The Definition of Financial Institution Is More Expansive The Safeguard Rule applies to any financial institution, which includes dealerships that extend credit and lease terms. The updated Rule now includes any organizations participating in activities that the Federal Reserve Board identifies as incidental to financial activities. This change brings “finders,” or companies that bring together buyers and sellers, under

the Rule. Additionally, several other definitions were directly added to the Rule from the Privacy of Consumer Financial Information Rule.

Open Comment Period: Should Organizations Report Large Data Breaches to the FTC? On top of the updates, the FTC announced a 60-day open comment period regarding whether or not the Safeguard Rule should be further amended to require financial institutions to report to the FTC any data breaches or other security incidents that impact 1,000 or more customers’ information.

What Should You Do? Continue to monitor for more information from the FTC. Seek out your legal counsel to review your current policies and procedures, help determine what changes you’ll need to make, and figure out how you’ll make them in the coming year.

KPA is Here to Help If you use KPA’s Vera F&I software and services, our customer information security training and consultants are here to help ensure you and your employees understand these changes and how they impact your business. Our Cybersecurity Training Package can help educate your employees on what to look for and prevent a data breach before one occurs. n


Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.