Some of my dealer friends are thinking that compliance with this rule will be harder than it's going to be.
Let's look at it closer:
Starting Jan 1st 2011, you will just have to give consumers a new notice, called a Risk Based Pricing Notice.
The Government means to protect the consumers who, because of bad credit scores, won't get the same credit terms as those with good credit scores.
This notice is meant to make these consumers aware of this.
So dealers need to give EVERY applicant for credit - whether or not you get them financed - a notice that:
1. Shows them their credit score and which CRA it was pulled from,
2. Tells them what a credit score is and steps they can take to change it,
3. Displays a bar chart or other visual that shows where their credit score compares with the national average.
These notices will be available (at an additional charge) from the vendors that you use to pull your credit reports.
Simple.
Next Post: My original rant about the Risk Based Pricing Rule: CLICK HERE
The post also contains a link to the full 202 page text of the rule... exciting.
Back to the Auto Finance Insider blog homepage:
Wednesday, November 10, 2010
Risk Based Pricing Rule - Further Clarification
Posted by Auto Finance Insider (AFI) 0 comments
Labels: Adverse Action Notices, Compliance, GLBA, Privacy Notices, Red Flags Rule, Risk Based Pricing Rule, The Way it Should Be Done
Thursday, December 24, 2009
Don’t Get Bitten by Your Bird Dog
A good article by Patty Covington
Long-standing dealership practices aren’t necessarily legal dealership practices. Many of these questionable practices have been around for years - and often dealers keep using them, because “everyone does it.”
Dealers sometimes don’t think twice or consider whether the practices are legally permissible or even if they are good for business. Over time, these practices have simply become part of the dealership's operations.
Referral fees are a good example of these practices.
I’m not talking about leads purchased from a typical lead provider or the purchase of a marketing list. I’m talking about referral fees paid by one dealership to another dealership or payments between sales associates of different dealerships for the referral of a customer who buys a car.
This arrangement could be part of a formal referral fee program between dealerships. let’s say sales associate Frank at franchise dealership X agrees to refer his “turndown” customers to sales associate Tom at independent dealer Y.
The arrangement could even involve an individual not employed by a dealership.
No harm, right?
Well, maybe more than you might expect. If you, or your dealership, is involved with such a program, here are a couple of things you should consider:
State law may prohibit paying for a referral in connection with the sale of a car.
Some states specifically prohibit the practice, commonly called “bird-dogging.”
Louisiana is such a state. Some states, like Ohio, require that any commission or compensation paid for the sale of a car be to a person licensed as a salesperson in the dealer’s employ.
Other states have dealer and salesperson licensing laws that sweep in broker activities. Finally, some states have laws specifically targeted at the “brokering” of cars. Some of these laws require brokers to be licensed, while others simply prohibit the brokering of the sale of a car.
Information exchanged could violate privacy laws.
Even very basic information regarding a customer, like the customer’s name, could be “nonpublic personal information” under the federal Gramm-Leach Bliley Act (GLBA).
Credit applications and a customer’s FICO score also would constitute nonpublic personal information.
Under the GLBA, nonpublic personal information cannot be shared with unaffiliated third parties unless the dealership’s privacy notice specifically states that the dealership shares information in such a way.
If Social Security numbers are shared, other state privacy laws may be violated. A significant number of states have laws that prohibit certain disclosures relating to Social Security numbers.
In addition, if an employee shares customer information with another person against dealership policy, the disclosure could constitute a security breach. Some states have security breach laws that apply only to paper documents, but other states’ laws also cover electronic records.
Information exchanged could constitute a consumer report.
If credit applications or FICO scores are shared, the federal Fair Credit Reporting Act (FCRA) is implicated. These documents constitute consumer report information.
What does this mean?
First, the party giving out this consumer report information may be deemed to be a consumer reporting agency under the FCRA.
Secondly, the party receiving the consumer report information is required by the FCRA to have a “permissible purpose” for the information under the FCRA prior to receiving it.
The FCRA sets forth an elaborate set of rules, requirements, and conditions for consumer reporting agencies and users of consumer reports.
The implications of being a consumer reporting agency are enormous. In addition, some states regulate these practices.
Calling a potential customer could violate “Do Not Call” rules.
You will violate the federal Telemarketing Sales Rule (TSR) if you call a potential customer registered with the Federal Trade Commission’s Do Not Call registry.
State mini-DNC registries and rules may also apply.
Exceptions available under the TSR will likely not apply because the customer initially contacted and dealt with the referring dealership, not the dealership following up on the referral.
Finance and lender broker licensing may apply.
Some states have finance and lending broker laws that are triggered for finance transactions.
Since most cars are financed, these laws may be implicated. Rhode Island has such a law. These laws typically impose licensing requirements.
If your dealership sells its financing contracts to sales finance companies and banks, it has entered into a dealer agreement regarding those contracts.
Typically, dealer agreements contain representations and warranties from the selling dealer to the effect that the dealer is in compliance with all state and federal laws applicable to the sales and financing transactions reflected by the contracts.
If your referral program violates such laws, you might find yourself forced to repurchase those contracts. Not a good day.
Finally, in addition to the above legal issues, there may be some practical matters that should be considered. For instance, are dealership associates referring the “right” deals to another dealership?
Is it possible that a sales associate will earn more on a referral than he would have earned if he’d sold the car himself? That may be possible with subprime discount deals.
It’s better to carefully consider whether what “everybody else is doing,” is first legal and second, makes sense for your business. It’s not that unusual for commonly accepted practices to come under fire.
Patricia E. Covington is a partner with Hudson Cook, LLP, a Hanover, Maryland-based law firm that represents national and state banks, savings associations, credit unions, mortgage bankers, and licensed lenders in the development and maintenance of consumer mortgage, automobile finance, and other credit programs.
BACK TO THE AUTO FINANCE INSIDER HOMEPAGE: http://www.AutoFinanceInsider.blogspot.com
Posted by Auto Finance Insider (AFI) 7 comments
Labels: Compliance, Do Not Call rule, False Claims Act (FCA), GLBA, Privacy Notices, Red Flags Rule, Safeguards Rule, Telemarketing Sales Rule, The Way it Should Be Done, Thomas Hudson
Saturday, April 19, 2008
Are You Compliant? Part 3
A Review of Recent Developments Part 3
Document Preparation Fees
Many dealerships charge various fees when a vehicle is delivered, including a document preparation fee. However, the so-called “doc fee” frequently comes under fire. Recently, consumer attorneys have developed a new attack on the doc fee. They are now arguing that a dealership is essentially practicing law without a licence by charging a fee to prepare documents. And as you know, that’s illegal. Just like you need to be a doctor to practice medicine, you need to be a licensed attorney to practice law. I don’t buy the argument that charging a doc fee equates to the unauthorized practice of law, but several courts have. This is why many states regulate the fees dealers charge. While dealers need to be familiar with these laws, they may not always help defend against this new attack on doc fees. If you’re charging a document preparation fee, it may be a good idea to contact your legal counsel to discuss the matter.
Credit Card Truncation
Under the FACT Act, credit card numbers on receipts have to be truncated so only the last five digits are shown. However, did you know the rule also requires that receipts not show expiration dates? Unfortunately, many people miss that part of the rule.
There was a lot of litigation about the expiration date after the rule went into effect at the end of 2006, especially in California. The good news is that this is an easy matter to handle. You just need to check every credit card machine in the dealership and make sure they’re all printing out receipts with the card numbers properly truncated — and without the expiration date.
Privacy Rules
Most dealerships know about their general responsibilities for safeguarding their customers’ personal, non-public information under the Gramm-Leach-Bliley Act. But do they know all the details? For instance, the Safeguards Rule requires a dealership name a specific employee to oversee safeguard activities.
The rule also requires a written information security plan that is periodically reviewed. Do you have a written plan? Has your dealership designated someone to oversee the program? Have you yet to fill the position after the person you designated left the dealership? Have you done the required periodic evaluations?
Now, you may be doing your best to comply with the rule, but you aren’t compliant if you aren’t meeting the detailed requirements of the Safeguards Rule.
Just remember that many of these rules governing how we operate our business act like moving targets. This is why periodic reviews of your compliance efforts is required. Just remember, even the best compliance programs can get better. Thankfully, there are plenty of resources available to help. So take advantage and don’t get caught with an outdated policy.
Todd Clarke is an associate counsel for JM&A. For more information, visit www.jmagroup.com.
Link to source article here
F&I Manager profile:
http://www.AutoFinanceInsider.com
Back to blog homepage
Posted by Auto Finance Insider (AFI) 3 comments
Labels: Compliance, FACT Act, Finance and Insurance, GLBA, Privacy Notices, Processing Fees, The Way it Should Be Done
Saturday, December 8, 2007
Finishing with the GLBA
by: AFI
Study this fantastic presentation on "The Implementation of the Safeguards Rule" published the University of Georgia. Someone put a lot of work into this. If you want your F&I Director to really feel comfortable that you know the GLBA - know this info!
http://www.infosec.uga.edu/sate/presentations/Gramm-Leach-Bliley_Act_at_UGA.ppt
Read this client alert from Goodwin Proctor LLP. "What Can You Do To Reduce Your Exposure?" - Requirements for Safeguarding Customer Data.
http://www.goodwinprocter.com/~/media/9120AE2E76094F6EBAED1D158158AD61.ashx
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
*** This post is going to be HEAVY in discussions of the Red Flag Rule that is scheduled to go into effect November 1, 2008.
Read the above link - sound familiar?
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Possible Changes into the GLBA:
Numerous change proposals include:
1) Using “opt-in” instead of “opt-out.” Opt-in policies can explicitly allow a financial institution the ability to share data; however the customer must expressly check a box or sign a statement giving this authority to the institution. Without an opt-in, financial institutions can be under express obligation not to share the information provided. Essentially, the burden of information protection passes to the financial institution with”opt-in.” This approach has been proposed, partially because of the practice of many financial institutions and web sites in general to automatically check the box of the “please share my information with whomever you feel like it and spam me mercilessly.” This technique is how many firms get around “opt-in” by essentially opting individuals in automatically.
2) If opt-outs are still used, then financial institutions should be required to provide easy access to privacy policies at branch offices and on the Web.
3) Provide consumers with the right to review any disclosed information or to correct inaccurate or incomplete data.
4) Give states additional jurisdiction to enforce GLBA provisions to enhance enforcement efforts.
5) Providing clear and human-understandable privacy policies, which clearly spell everything out, and allow people to understand explicitly how their information may be used
What are some penalties for violating GLBA?
Violation of the GLBA may result in a civil action brought by the United States Attorney General, and can carry the following penalties:
1) “the financial institution shall be subject to a civil penalty of not more than $100,000 for each such violation”
2) “the officers and directors of the financial institution shall be subject to, and shall be personally liable for, a civil penalty of not more than $10,000 for each such violation.”
Short Summary:
The GLBA is certainly a step forward on the way to protect the user’s financial and personal information. Identity Access Management solutions are crucial when it comes to implementing compliance automation.
Possible Changes into the GLBA first printed 10/2/2007. Olga. Links Business Group LLC. Retrieved on 12/8/2007 from: http://www.linksbusinessgroup.com/blog/2007/10/02/identity-access-management-regulations/#comment-769
Back to blog homepage
Posted by Auto Finance Insider (AFI) 0 comments
Labels: Compliance, Finance and Insurance, GLBA, Safeguards Rule
Saturday, November 3, 2007
(GLBA) Gramm - Leach - Bliley Act Part 2 - "Privacy Rule"
by: AFI
I remember back in 2001 when the controller of our dealer group told all of the F&I managers that we needed to have customers sign Privacy Notices. A big case full of the things showed up with instructions that every one who signs a credit ap must sign one of these also. That was it. We originally made the salespeople get it signed at the same time as they got the credit application signed.
It wasn't until a short while later did I receive the full explanation of exactly why a Privacy Notice needed to be issued.
Dealers are required to issue Privacy Notices to customers who avail themselves of vehicle funding and indemnification services offered by the dealer, even when an outside lender provides the credit.
The notices are required to be delivered regardless of whether the nonpublic information is shared with unrelated entities or not.
*** More boring legal stuff:
The Federal Reserve board dictates in Section 313.4 - Initial privacy notice to consumers required.
Initial notice requirement. You must provide a clear and conspicuous notice that accurately reflects your policies and practices to:
* Customers and Consumers. Before you disclose any nonpublic personal information about the consumer to any nonaffiliated third party.
313.5 - specifies the need to send annual privacy notices if you are a lienholder.
313.9 - How to provide privacy and opt-out notices.
313.10 - Conditions for disclosure.
* You may not, directly or through any affiliate, disclose any nonpublic personal information about a consumer to a nonaffiliated third party unless:
1. You have provided to the consumer the initial notice as required by 313.4;
2. You have provided to the consumer an opt out notice as required in 313.7;
3. You have given the consumer a reasonable opportunity, before you disclose the information to the nonaffiliated third party, to opt out of the disclosure; and
4. The consumer does no opt out.
Pretty cut and dry I think.
The Privacy notice used by my dealership since July 2001 uses the following exact words.
Consult your legal council before copying and using this notice.
Back to blog homepage
Posted by Auto Finance Insider (AFI) 0 comments
Labels: Compliance, Finance and Insurance, GLBA, Privacy Notices
Friday, October 19, 2007
The Gramm - Leach - Bliley Act Part 1
by: AFI
The never ending excitement of attempting to comprehend the Gramm - Leach - Bliley Act is next on our list. Compliance with this act is a HUGE part of how to measure a well run Automotive F&I Department. Enjoy:
The Gramm - Leach - Bliley Act was enacted in 1999 with the intent of protecting the confidential personal and financial information disclosed by consumers. This Act has two phases.
1 The first phase of the Gramm - Leach - Bliley act, the "Financial Privacy Rule," became effective in November 2000 and caused us to have to issue privacy notices.
2 The second phase, the Safeguards Rule, went into effect May 23, 2003. It sets out specific steps dealerships and other financial institutions must take to protect nonpublic customer information from unauthorized access.
The Privacy Rule mandates the issuance of Privacy Notices to inform customers as to the disposition of the nonpublic personal information they provide dealers in the course of purchasing a vehicle, arranging for funding and in some cases, acquiring insurance.
Essentially, the customer has to be told what is being done with his or her information beyond sending it to banks and/or lenders for the purpose of securing funding for the vehicle.
The customer is given the right to "opt-out" with regard to the sharing of his or her confidential information.
Dealers are required to issue privacy notices. These notices must be delivered regardless of whether the nonpublic information is shared with unrelated entities or not.
In addition, the financial institution to whom the dealership assigns the loan to is required to provide annual notices regarding it's privacy policy. (These are the legal-ese small print notices you get in the mail from every lender you have an open account with).
The rule went into effect in November 2000 and compliance was required as of July 1, 2001. I will never forget all the "jumping through hoops" my Finance Department did during this time. We did what we had to to do it right. We were a well run F&I department.
Check out the new site: http://www.autofinanceinsider.com/
Back to blog homepage
Posted by Auto Finance Insider (AFI) 0 comments
Labels: Compliance, Finance and Insurance, GLBA, Privacy Notices, The Way it Should Be Done
