• Home
  • News
  • E-Cars
  • Technology
  • Dealer
  • Guides
  • Editorials
ProCar Digest
SUBSCRIBE
No Result
View All Result
  • Home
  • News
  • E-Cars
  • Technology
  • Dealer
  • Guides
  • Editorials
ProCar Digest
SUBSCRIBE
No Result
View All Result
ProCar Digest
No Result
View All Result
Home Dealer

Safeguards and the Service Drive

by Car Digest
September 11, 2023

Does the Safeguards Rule apply to the dealership’s service drive? The short answer is ‘yes’. - IMAGE: Getty Images

Does the Safeguards Rule apply to the dealership’s service drive? The short answer is ‘yes’.

IMAGE: Getty Images

There is a Safeguards Rule-related question I get asked so often that I think it worthwhile to answer it here – with any luck, I will never get asked it again. The question is this: Does the Safeguards Rule apply to the dealership’s service drive? The short an-swer is ‘Yes.’ The longer answer follows.

As a first principle, the Safeguards Rule applies to a certain type of entity, not specific departments within an entity 22 auto dealer today to which it applies. The entities to which the Safeguards Rule applies are “financial institutions.” When you hear the term “financial institution,” you think banks, credit unions, credit card companies and so on, and you would be correct.

But the definition of “financial institution” is more broad than the obvious. To quote the Rule:

Financial institution means any institution the business of which is engaging in an activity that is financial in nature or incidental to such financial activities as described in section 4(k) of the Bank Holding Company Act of 1956, 12 U,S,C, 1843(k). An institution that is significantly engaged in financial activities, or significantly engaged in activities incidental to such financial activities, is a financial institution.

So now we turn to the Bank Holding Company Act of 1956 to see what, exactly, constitutes a “financial activity”:

(i) Lending, exchanging, transferring, investing for others, or safeguarding financial assets other than money or securities.

(ii) Providing any device or other instrumentality for transferring money or other financial assets.

(iii) Arranging, effecting, or facilitating financial transactions for the account of third parties.

Does originating retail installment sale contracts (RISCs) to finance the sale of motor vehicles sound like it fits within that definition? To quote Rowan & Martin’s Laugh-In, “You bet your sweet bippy.”

Safeguarding customer information – and the integrity of the dealership’s entire data environment – is an ongoing, overarching process that starts with an attitude of protect everything. To be effective, there must be no exceptions.

But wait, there’s more. The Rule itself calls out automobile dealerships as an example of a financial institution:

An automobile dealership that, as a usual part of its business, leases automobiles on a nonoperating basis for longer than 90 days is a financial institution with respect to its leasing business because leasing personal property on a nonoperating basis where the initial term of the lease is at least 90 days is a financial activity listed in 12 CFR 225.28(b)(3) and referenced in section 4(k)(4)(F) of the Bank Holding Company Act, 12 U.S.C. 1843(k)(4)(F).

Note two things from the above. First, dealerships are almost certainly financial institutions subject to the Safeguards Rule (there is a narrow exception for dealerships that have fewer than 5,000 customer records). And second, the Rule applies to dealerships as institutions, not as departments. Which brings us back to the service drive.

The rationale I hear for the belief the Rule might not apply to a dealership’s activities in the service drive is that leases and RISCs are not generated in that department. That is both true and beside the point. The Safeguards Rule is not designed to (only) protect RISCs and leases, but to protect “customer information” generally. And that definition is quite broad:

Customer information means any record containing nonpublic personal information about a customer of a financial institution, whether in paper, electronic, or other form, that is handled or maintained by or on behalf of you or your affiliates.

Of course, this definition requires us to find another one. What is “nonpublic personal information”? Per the Rule, it includes “Personally identifiable financial information.” Does your service drive accept credit cards or personal checks? Of course it does – and that means it handles or maintains customer information.

Let’s take this a step further and imagine a dealership whose service drive only accepts cash. Would the Safeguards Rule apply in that situation? Almost certainly. First, because the Rule applies to financial institutions, not departments of financial institutions. And second, because customer information can be accessed from the service drive. Does the service department have access to the dealership’s DMS? Of course it does, and that point of access must be protected.

Do service department employees have dealership email addresses? If so, the service drive represents a safeguards risk, as email-based malware attacks are a significant risk to the security of the dealership’s entire IT network – the mother lode of customer information.

To return to our short answer, yes, the Safeguards Rule applies to the service drive. At a minimum, employee training (including phishing awareness), multi-factor authentication, data encryption, continuous network endpoint monitoring, and access controls should be implemented in this area.

Why? Because safeguarding customer information – and the integrity of the dealership’s entire data environment – is an ongoing, overarching process that starts with an attitude of protect everything. To be effective, there must be no exceptions.

ABOUT THE AUTHOR: James Ganther is the president of Mosaic Compliance Services.

Related Posts

Ford Recalls Affect Several Models

Ford Recalls Affect Several Models

by Car Digest
May 9, 2025

Recalls affect F-150s, Explorers, Expeditions and Lincoln NavigatorsPexels/Harrison Tincher Ford issued two separate recalls affecting nearly 150,000 pickup and SUV...

Dicey Driving Declines

Dicey Driving Declines

by Car Digest
May 7, 2025

General phone use by drivers fell last year, along with speeding, but other risky behaviors increased.Pexels/Attila Darvas Some risky driving...

Used Prices Climb

Used Prices Climb

by Car Digest
May 5, 2025

Used pickup trucks saw the biggest average price increases in April, according to Carfax: $660. Used-vehicle prices are on the...

ID.Buzzes Recalled

ID.Buzzes Recalled

by Car Digest
May 4, 2025

The rear seat bench could fit three passengers, though it's intended for just two and accordingly has two seat belts.Volkswagen...

A Preowned Vehicle Strategy in a Challenging Market

A Preowned Vehicle Strategy in a Challenging Market

by Car Digest
May 1, 2025

The new-vehicle sales department, while prominent, often poses the most uncertainty.Pexels/Obi Onyeador The automotive market has experienced significant disruptions in...

Law Firms Tops in Auto Work

Law Firms Tops in Auto Work

by Car Digest
April 30, 2025

A&O Shearman, Kirkland & Ellis topped competitors in the quarter.Pexels/Mikhail Nilov Two law firms snagged the most automotive-sector mergers and...

New-Vehicle Sales Losing Steam

New-Vehicle Sales Losing Steam

by Car Digest
April 28, 2025

Though April new-vehicle sales started strongly, Cox Automotive said they started to dwindle in the second half of the month.Pexels/Vraj...

Load More

Related Post

2024 Chevrolet Suburban vs. Ford Expedition

2024 Chevrolet Suburban vs. Ford Expedition

April 24, 2024
The Most Ridiculous Cars and Trucks You’ve Ever Seen

The Most Ridiculous Cars and Trucks You’ve Ever Seen

June 10, 2024
EV Charger Solution Said to Work for All Models

EV Charger Solution Said to Work for All Models

August 10, 2024
4 Steps for Trading in Your Car

4 Steps for Trading in Your Car

July 8, 2024
2024 Hyundai Kona: A Trim Comparison

2024 Hyundai Kona: A Trim Comparison

April 17, 2024
Freeway Speeding Can Endanger Communities

Freeway Speeding Can Endanger Communities

April 25, 2024
2021 Chevrolet Traverse: A Trim Comparison

2021 Chevrolet Traverse: A Trim Comparison

June 5, 2023
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Do not sell my personal information.
Cookie SettingsAccept
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • News
  • Guides
  • E-Cars
  • Dealer
  • Technology
  • Editorials

© 2022 procardigest.com