Why Dealership Compliance Must Cover Paper, Not Just Cyber
Key takeaways
- The FTC Safeguards Rule originated with the Gramm-Leach-Bliley Act back in 2003 and has always included an IT component.
- Dealerships collect just as much customer data on paper as they do electronically, so paper records are an equal risk alongside electronic threats.
- A compliance program that only addresses cyber security misses physical paper stored in places like parts departments, showrooms, and employee desks.
- Some dealerships scan and shred paper records while others do not, largely due to the cost involved.
- Effective compliance requires an auditor who reviews actual processes and how data is collected before it becomes electronic, not just cyber protections.
Summary
The FTC Safeguards Rule, part of Gramm-Leach-Bliley since 2003, has always included an IT component, but the amendment taking effect in June sharpens those cyber requirements. The video argues that dealerships risk fixating on cyber security alone while overlooking that just as much sensitive customer data sits in paper form, stacked in parts departments, desks, and file boxes, as exists electronically in DMS and CRM systems. The point made is that compliance covers electronic, physical, and human risks together, not one category in isolation.
For a dealership, this means a cyber security solution alone won't satisfy Safeguards Rule obligations. Someone needs to audit actual processes, including how paper records are collected, stored, scanned, and shredded, since practices vary widely by store and carry real cost tradeoffs. The presenter's guidance is to evaluate the whole compliance picture, physical and digital, rather than treating cyber protection as the entire solution, and to bring in outside review of everyday paper handling as part of a complete program.
Transcript
Safeguards Rule history and cyber focus
My name is Terry Dortch, Automotive Risk Management Partners. I want to talk to you today a little bit about this whole compliance arena that we're in today. You know, the Safeguards Rule has been around a lot longer than most people may realize. This was all part of Gramm-Leach-Bliley back in 2003, and the Safeguards Rule has always had an IT component to it. It wasn't as clear and defined as it is today, which is coming out of that whole amendment that's due in June. And my whole purpose in this is, you know, let's not lose the forest through the trees, right? The cyber security part of all this is very, very important, but I can remember back in the 80s - some of you may not remember the 80s, but I do - and the talk of the town was that computers were going to eliminate paper. For those of you that were back then, we all thought that, right? Well, in my observations, we've increased the number, the volume of paper that we're producing today compared to what we did in the 80s. So I'm not so sure computers solved that issue.
Paper data as an equal threat to electronic data
And when I say that, the reason I'm bringing that up is because I don't think anyone is any greater of a threat than the other, but there's just as much data collected in a dealership today on paper as there is electronic. Now, we saw in our old company, you know, back in the early 2000s, the company that we sold, we saw this whole IT piece coming, and we actually partnered with a company that currently is handling the GM DIT for GM, where we could bring dealers a solution that, at that time, was a pretty strong solution that would help to mitigate or prevent various threats that were coming in electronically. But this whole compliance arena is just not about that electronic threat, but it's about the threat that's sitting on in your dealerships today. You know, you walk up into a parts department and you can see just stacks and stacks and boxes, and I mean there's legal boxes on top of legal boxes full of paper.
Compliance as an all-encompassing threat landscape
So this whole compliance arena is really an all-encompassing type of threat. It's electronic, it's physical, it's people, it's opportunities - and when I use the term opportunity, I use it loosely - but there's a lot of other things that need to be guarded against other than just a cyber threat alone. So when you're looking at your different solutions out there, make sure that you take into consideration the fact that we all collect paper like crazy, and I'm as guilty as anybody because I'm still of the old school where I like to read something, touch it, feel it, as much as I can.
Need for auditing processes beyond cyber solutions
So when you're looking at all of these different solutions, you could solve the cyber part of it, but you're not going to solve this over here unless you have someone coming in and actually doing your auditing, actually looking at your processes and talking to you about how you're collecting that data that eventually ends up in an electronic format. Right now a lot of stores are scanning and shredding and things of that nature, some stores aren't. I mean, there's a cost factor involved in all of that.
Looking at the entire compliance arena
So my whole point in all of this is that when you're looking at this compliance arena, make sure you look at the entire arena. Don't just pick out that one little aspect of it, that's the cyber piece. Not that that's not important, because it is, and obviously all of us now, your DMS systems are holding a ton of data, your CRM tools are holding a ton of data. But I guarantee you, walk through your showroom and go through a few desks, find out how much data you're going to see.
You know, the internet and this whole electronic age that we're in has created a lot of opportunities for us, and at the same time - I mean, think of Google, right? It created Google, which is probably one of the greatest things - our kids today couldn't go through school without Google. I guess in our day it was Cliff Notes, right?
Closing thoughts and contact information
So my whole point in all of this is that there's a lot more to be involved, or a lot more to look at, than just the cyber security. So don't ignore the forest, because there's a lot of other things out there that you need to pay attention to. And we're happy to sit down and discuss all of these options and variables with you. So give us a call, phone number, website, everything's right here on the screen. Just give us a buzz, we'll be more than happy to talk to you about it. There is a lot more to be considered than just the cyber aspect of it. Thanks, take care.
Questions this video answers
Does the FTC Safeguards Rule only apply to electronic data at dealerships?
No. While the Safeguards Rule has always had an IT component going back to Gramm-Leach-Bliley in 2003, dealerships collect just as much data on paper as electronically, so compliance must address both physical and electronic threats.
What should a dealership look for in a compliance solution?
A dealership should make sure the solution covers the entire compliance arena, not just the cyber piece, including physical paper records, and should involve someone auditing actual processes and how data is collected before it ends up in electronic systems.
Where is paper data typically overlooked in a dealership's compliance efforts?
Paper data piles up in places like the parts department, where stacks of legal boxes accumulate, as well as in showroom desks, yet many dealerships focus compliance efforts mainly on DMS and CRM electronic data instead.
Read more on this
-
Dealership Cybersecurity Requirements
A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...
-
FTC Safeguards Rule Compliance for Car Dealerships
Car dealerships that arrange financing or leases are "financial institutions" under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) app...
Covered in this video
- FTC Safeguards Rule
- Gramm-Leach-Bliley Act
- physical document security
- cyber security
- data collection auditing