Data Privacy and Cybersecurity An Overview for New Hampshire Dealers BY COMPLYAUTO NHADA Diamond Partner As a car dealer, privacy and cybersecurity probably aren’t at the top of your daily to-do list, but they should be on your radar. The way dealers collect and manage customer data has changed dramatically in recent years, and the rules governing it have become much more complex. This article covers five key areas that every New Hampshire dealer should know about. I. FTC SAFEGUARDS RULE Automobile dealerships are regulated as “financial institutions” under the Gramm-Leach-Bliley Act (GLBA) and must comply with the Federal Trade Commission’s (FTC) Standards for Safeguarding Customer Information, commonly known as the Safeguards Rule. The Safeguards Rule got a major overhaul in 2021 and compliance with the new requirements for dealers isn’t simple. Dealers are on the hook for a long list of technical and procedural requirements — and for most, trying to handle it all in-house is a heavy lift. What does compliance look like in practice? Dealers need a designated qualified individual overseeing the program who reports to ownership or senior management at least annually. Customer data must be encrypted, both when it’s stored and when it’s being transmitted. Every employee with access to customer information systems needs multi-factor authentication. On top of that, dealers need access controls, regular vulnerability assessments, penetration testing and a tested incident response plan. One requirement that often catches dealers off guard: The rule also requires monitoring and logging of authorized user activity, which means you need to be watching for insider misuse, not just outside attacks. II. STATE PRIVACY LAWS: A GROWING PATCHWORK THAT INCLUDES NEW HAMPSHIRE Twenty states have now passed comprehensive consumer privacy laws, and more are on the way. While these laws vary, they share a common core: Consumers have rights to access, correct, delete and opt out of the sale of their data, and businesses face new obligations around data minimization, handling sensitive data categories, and vendor contracts. For a dealership with customers across state lines, several of these laws may already apply at once. New Hampshire joined the list when Gov. Sununu signed the New Hampshire Data Privacy Act (NHDPA). The NHDPA gives New Hampshire residents the right to access, correct and delete their personal data, get a portable copy of it, and opt out of targeted advertising, certain profiling and most data sales. But does the NHDPA apply to dealers? It’s a question of the amount and kind of data that dealers process. First, thresholds. The NHDPA applies only to businesses that, during a one-year period, either process personal data of at least 35,000 unique New Hampshire consumers, or process data of at least 10,000 consumers and derive more than 25% of gross revenue from selling personal data. Second, the NHDPA exempts financial institutions and data subject to Title V of the GLBA. Because franchised dealers are financial institutions under GLBA and subject to the FTC Safeguards Rule, there is a strong argument that dealers fall within this exemption. That said, the exemption’s scope and how aggressively the New Hampshire Attorney General may interpret it is worth confirming with counsel before concluding the NHDPA doesn’t apply to your store. 14
RkJQdWJsaXNoZXIy ODQxMjUw