Showing posts with label Privacy Notices. Show all posts
Showing posts with label Privacy Notices. Show all posts

Tuesday, June 28, 2011

Dealer Practices to be Scrutinized by the FTC and CFPB

“Bottom-Feeders” to Be the First Scrutinized...

By: Thomas Hudson


When you are a lawyer, it seems that all your friends insist on telling you every lawyer joke they hear. One of my favorite recent ones: “What’s the difference between a lawyer and a carp?” The answer, after my obligatory “I give up” was, “One’s a scum-sucking bottom-feeder, and the other one’s just a fish.”

I immediately thought of that one when I read that Federal Trade Commission Chairman Jon Leibowitz, in a speech to the U.S. Chamber of Commerce, used the term “bottom-feeder” in describing the FTC’s agenda for the coming year in light of the creation of the Consumer Financial Protection Bureau (CFPB), with which the FTC will share enforcement authority over financial services companies.


Read the rest of this excellent article here: http://www.autodealermonthly.com/79/4078/ARTICLE/Dealer-Practices-to-be-Scrutinized-by-the-FTC-and-CFPB.aspx



Next Post: http://autofinanceinsider.blogspot.com/2011/05/compare-spending-habits-with-your-peers.html


Back to the Auto Finance Insider blog homepage:

Wednesday, November 10, 2010

Risk Based Pricing Rule - Further Clarification

Some of my dealer friends are thinking that compliance with this rule will be harder than it's going to be.

 

Let's look at it closer:


Starting Jan 1st 2011, you will just have to give consumers a new notice, called a Risk Based Pricing Notice.


The Government means to protect the consumers who, because of bad credit scores, won't get the same credit terms as those with good credit scores.


This notice is meant to make these consumers aware of this.


So dealers need to give EVERY applicant for credit - whether or not you get them financed - a notice that:


1. Shows them their credit score and which CRA it was pulled from,

2. Tells them what a credit score is and steps they can take to change it,

3. Displays a bar chart or other visual that shows where their credit score compares with the national average.


These notices will be available (at an additional charge) from the vendors that you use to pull your credit reports.


Simple.



Next Post: My original rant about the Risk Based Pricing Rule: CLICK HERE

The post also contains a link to the full 202 page text of the rule... exciting.


Back to the Auto Finance Insider blog homepage:

Tuesday, October 26, 2010

Risk Based Pricing Rule

As the Risk Based Pricing Rule goes into effect Jan 1st 2011, how many of you already have a negative view against it? More government regulation inflicted upon automobile dealers. More of our taxpayer dollars spent on a useless and confusing program

What is the Risk Based Pricing Rule and how is the automotive industry required to comply with it?

Here is a link to a good article written by Randy Hendrick (Dealer Track) for F&I Magazine: http://www.fi-magazine.com/Article/Story/2010/03/New-Credit-Rules-Decoded.aspx.

Randy points out that "the new notices are intended to complement adverse action notices, which dealers are already accustomed to issuing when they can’t attain financing for a customer. The difference with the risk-based pricing notices is that they must be handed to consumers before the transaction is consummated; that is, before the customer signs the retail installment sales contract (RISC)".

So it sounds like this is another item that will be required to be included with the customer's paperwork, and moved from one paperwork stack to the other, at the step directly before they sign the RISC.

Ok, so why exactly do we need to do this?

Below is a link to the full 202 page text of the rule: http://www.ftc.gov/os/2009/12/R411009riskbasedpricingfrn.pdf

Basically, the FTC and the Federal Reserve Board are trying to look after the public, specifically those who have less than perfect credit. They are requiring creditors (yes - dealerships are creditors) to give notice to consumers when their credit caused them to receive higher interest rates.

A dealership would need to calculate their average contract rate per financed customer, and provide this required disclosure to anyone who doesn't qualify for this average rate.

??? Talk about opening up a can of worms. How many times could doing this cost a deal? Or almost as bad - giving them a reason to walk out of the dealership under the premise of checking with their credit union.

Let's look further into this...

The finalized rules implement Section 311 of the Fair and Accurate Credit Transactions Act of 2003. The rule states that dealers can determine which customers should receive the notices by using the dealerships average credit score or their average credit tier.

The Dealer Exemption

There is also a dealer exception that doesn't require a notice to be given, but will require that the dealer spend extra money buying a product from the credit bureau they used in their decision. This product will show the credit score of the customer and where the score falls within the national average of scores.

NADA's response statement:

“Due to the difficulty in determining which subset of credit customers must receive risk-based pricing notices, NADA strongly urged the agencies to create an optional compliance mechanism that would allow dealers to provide all of their credit customers with a simple notice that satisfies the requirements of section 311,”

The statement reads:

“The agencies adopted this recommendation by permitting an exception notice to be issued in lieu of a risk-based pricing notice provided it contains the consumer's credit score, date the score was created, certain information to put the score in context, and additional boilerplate language concerning credit scores, credit reports, and how consumers may access their credit report".

Like the risk-based pricing notice, this notice must be handed to the customer before the transaction is consummated.

In conclusion:

The rebel in me wants to find some "generic fill in the blanks" form for the F&I Manager to hand-write the days date and the customers credit score copied from the top of the pulled credit report (that we already pay for). I will be looking into this after this post is published.

My amazement at the use of our tax dollars is never-ending - this program is confusing at best. There also seems to be no "teeth" anywhere in the text of the regulations, unless I missed it. What are the exact penalties for non-compliance?

Hmmm...

Most dealers will probably go for the dealer exception - handing EVERY customer a Credit Score Disclosure Form. This will require the dealership to buy the form from either Equifax, Experian or Transunion, and spend resources to print it off just to comply with the rule.

Requiring compliance is going to basically create another profit for the three credit bureaus at the expense of the automotive dealer.

Ok, I need a break.




Next post: AFI's take on the new "Safe Harbor" Privacy notices: CLICK HERE


Back to the Auto Finance Insider blog homepage:

Tuesday, September 28, 2010

Safe Harbor - New Privacy Notices

In November of last year, in order to produce uniformity in the privacy notices being issued to consumers, government agencies amended the Gramm-Leach-Bliley Act. The amendment called for the creation of an online form builder that would generate standardized compliant privacy notices.

The privacy notices that we have been commanded to provide to our customers since July of 2001 will not protect us from our government's wrath after Dec 31, 2010. It's been a good run though.

Anyway, there are new rules for the content that dealers need to have in their new privacy notices to give them the "safe harbor" that they enjoyed while providing the old privacy notice.

A "safe harbor" is a provision in the regulation that reduces a dealers potential liability if the dealer provides a privacy notice exactly the way the online tool dictates them to do. This makes the dealer compliant with federal law and protects them if any issues arise.

I am all for protection, so how do these privacy notices need to look?


Here is a link to the Privacy Notice Online Form Builder: This is where you will need to go to actually create your privacy notice.

http://www.federalreserve.gov/newsevents/press/bcreg/privacy_notice_instructions.pdf


and a FTC workshop on "Writing Effective Privacy Notices"

http://www.ftc.gov/bcp/workshops/glb/index.shtml


It looks like we will be giving a 2 page privacy notice doesn't it? Well, actually it could probably be tightened up into 1 page and still remain compliant. No - it states that there needs to be a Page 2 - and I quote:

"As in the proposed model form, the second page of the final model form provides additional explanatory information that, in combination with page one, ensures that the notice includes all elements described in the GLB Act as implemented by the privacy rule".

Maybe it can be front and back. Oh well - Still waiting to see what my main dealer group is going to roll out.


Wooooaaa...



Here's a link to the actual Rules and Regulations of this thing: http://www.ftc.gov/privacy/privacyinitiatives/PrivacyModelForm_FR.pdf

I continue to be amazed at the waste of our tax dollars.


Does anyone else have a headache?


Compare with the full text of Regulation P back from 2002: Regulation P - Compliance Guide for Small Entities

Seems like the Government continues to become more and more complicated in spite of itself - although I know that we still live in the greatest country in the world!


Actually - come to think of it...


I have been scanning this monstrosity of the rules and regs of the final rule, and I don't see the words "Safe Harbor" anywhere in the rule. It is just titled "The Final Model Privacy Form Under The Gramm-Leach-Bliley Act"


If anyone can find it and prove me wrong - please leave a comment.



In fact - do a Google search for "Safe Harbor Privacy Notice" and you'll see examples of the Safe-Harbor privacy rules of large companies such as Merck and even Ford Motor Credit on the first page of results.


BUT.......


Their notices keep these companies in compliance with information sharing policies between American companies and the European Union and Switzerland.

From MeadeWestvaco:

"MeadWestvaco Corporation is committed to protecting the privacy and security of its Employee Personal Information and has certified that it abides by the Safe Harbor privacy principles as set forth by the United States Department of Commerce. The principles regulate the use, collection, storage and transfer of data between the European Union and the United States. This Policy outlines the practices and procedures for implementing these principles."




So why are Automotive Compliance gurus all referring to our version as a Safe-Harbor Privacy notice?


It really doesn't matter does it.

I'll bet that I am the first to expose the truth though - ha.

Anyway - sorry to all of my readers for the lack of recent posts. Building a company is exhaustive work.

Please feel free to leave comments!!

Cheers

AFI


Next post: my comments on the U.S. Fidelis fiasco.


Back to the Auto Finance Insider blog homepage:

Thursday, December 24, 2009

Don’t Get Bitten by Your Bird Dog

A good article by Patty Covington

Long-standing dealership practices aren’t necessarily legal dealership practices. Many of these questionable practices have been around for years - and often dealers keep using them, because “everyone does it.”

Dealers sometimes don’t think twice or consider whether the practices are legally permissible or even if they are good for business. Over time, these practices have simply become part of the dealership's operations.

Referral fees are a good example of these practices.

I’m not talking about leads purchased from a typical lead provider or the purchase of a marketing list. I’m talking about referral fees paid by one dealership to another dealership or payments between sales associates of different dealerships for the referral of a customer who buys a car.

This arrangement could be part of a formal referral fee program between dealerships. let’s say sales associate Frank at franchise dealership X agrees to refer his “turndown” customers to sales associate Tom at independent dealer Y.

The arrangement could even involve an individual not employed by a dealership.

No harm, right?

Well, maybe more than you might expect. If you, or your dealership, is involved with such a program, here are a couple of things you should consider:


State law may prohibit paying for a referral in connection with the sale of a car.

Some states specifically prohibit the practice, commonly called “bird-dogging.”

Louisiana is such a state. Some states, like Ohio, require that any commission or compensation paid for the sale of a car be to a person licensed as a salesperson in the dealer’s employ.

Other states have dealer and salesperson licensing laws that sweep in broker activities. Finally, some states have laws specifically targeted at the “brokering” of cars. Some of these laws require brokers to be licensed, while others simply prohibit the brokering of the sale of a car.


Information exchanged could violate privacy laws.

Even very basic information regarding a customer, like the customer’s name, could be “nonpublic personal information” under the federal Gramm-Leach Bliley Act (GLBA).

Credit applications and a customer’s FICO score also would constitute nonpublic personal information.

Under the GLBA, nonpublic personal information cannot be shared with unaffiliated third parties unless the dealership’s privacy notice specifically states that the dealership shares information in such a way.

If Social Security numbers are shared, other state privacy laws may be violated. A significant number of states have laws that prohibit certain disclosures relating to Social Security numbers.

In addition, if an employee shares customer information with another person against dealership policy, the disclosure could constitute a security breach. Some states have security breach laws that apply only to paper documents, but other states’ laws also cover electronic records.


Information exchanged could constitute a consumer report.

If credit applications or FICO scores are shared, the federal Fair Credit Reporting Act (FCRA) is implicated. These documents constitute consumer report information.

What does this mean?

First, the party giving out this consumer report information may be deemed to be a consumer reporting agency under the FCRA.

Secondly, the party receiving the consumer report information is required by the FCRA to have a “permissible purpose” for the information under the FCRA prior to receiving it.

The FCRA sets forth an elaborate set of rules, requirements, and conditions for consumer reporting agencies and users of consumer reports.

The implications of being a consumer reporting agency are enormous. In addition, some states regulate these practices.


Calling a potential customer could violate “Do Not Call” rules.

You will violate the federal Telemarketing Sales Rule (TSR) if you call a potential customer registered with the Federal Trade Commission’s Do Not Call registry.

State mini-DNC registries and rules may also apply.

Exceptions available under the TSR will likely not apply because the customer initially contacted and dealt with the referring dealership, not the dealership following up on the referral.


Finance and lender broker licensing may apply.

Some states have finance and lending broker laws that are triggered for finance transactions.

Since most cars are financed, these laws may be implicated. Rhode Island has such a law. These laws typically impose licensing requirements.


If your dealership sells its financing contracts to sales finance companies and banks, it has entered into a dealer agreement regarding those contracts.

Typically, dealer agreements contain representations and warranties from the selling dealer to the effect that the dealer is in compliance with all state and federal laws applicable to the sales and financing transactions reflected by the contracts.

If your referral program violates such laws, you might find yourself forced to repurchase those contracts. Not a good day.

Finally, in addition to the above legal issues, there may be some practical matters that should be considered. For instance, are dealership associates referring the “right” deals to another dealership?

Is it possible that a sales associate will earn more on a referral than he would have earned if he’d sold the car himself? That may be possible with subprime discount deals.

It’s better to carefully consider whether what “everybody else is doing,” is first legal and second, makes sense for your business. It’s not that unusual for commonly accepted practices to come under fire.


Patricia E. Covington is a partner with Hudson Cook, LLP, a Hanover, Maryland-based law firm that represents national and state banks, savings associations, credit unions, mortgage bankers, and licensed lenders in the development and maintenance of consumer mortgage, automobile finance, and other credit programs.


BACK TO THE AUTO FINANCE INSIDER HOMEPAGE: http://www.AutoFinanceInsider.blogspot.com

Monday, August 31, 2009

Everybody does it

Another "reality check" by Gil Van Over

I’ve read more than a few depositions over the last couple of years. Some of the questions asked by plaintiff’s attorneys shed light on the risks faced in a dealership’s operations. Today I will discuss the best rate discussion.

Background

This consumer sued the dealership under the state’s unfair and deceptive practices act alleging that the finance manager arranged for a straw purchase and inflated the vehicle’s book value to the lender in order to obtain a credit approval. The consumer was also countersuing the lender to get the deficiency balance waived.

Interrogation

Attorney: Ms. Finance Manager, do you remember my client?

FIM: No.

Attorney: You don’t remember completing this transaction?

FIM: No, it was over three years ago.

Attorney: Let’s look at Exhibit A. This is from the deal jacket your dealership provided. Would you agree it is a credit application?

FIM: Yes.

Attorney: Can you read the name in the ‘Applicant” box?

FIM: Joan Straw.

Attorney: Now let’s look at Exhibit B. This is also from the deal jacket your dealership provided. What is this form?

FIM: It is a retail contract.

Attorney: Can you read the name of the buyer in the top left box?

FIM: Tom Purchaser.

Attorney: Is Joan Straw listed?

FIM: No.

Attorney: Did Joan Straw sign the contract?

FIM: No.

Attorney: Can you explain why Joan did not sign the contract, yet applied for credit?

FIM: It looks like we put the car in Tom’s name. Maybe Joan did not qualify.

Attorney: Moving on. Exhibit C is a condition report from the repossession company. Exhibit D is the NADA book-out sheet from the deal jacket your dealership provided. Exhibit E is a sheet listing the differences in the options on the vehicle. Can you explain why the book-out sheet lists more options than the condition report?

FIM: Maybe the bank needed a higher book value to approve the loan.

Attorney: Why would you put the car in someone else’s name and inflate the value of the vehicle to the lender in order to get a credit approval?

FIM: Everybody does it to sell cars.

Solution

First, realize that “Everybody does it” it both a lame excuse and a blatant misstatement of the truth. Most dealerships do not encourage or allow straw purchases or power booking or other forms of potential bank fraud.

That does not mean that a rogue F&I or Sales Manager won’t periodically cross the line and put your dealership at risk.

Protect yourself by implementing a few common sense policies.

Expressly Forbid Bank Fraud – I just finished watching the NCAA men’s basketball championship game. Memphis coach John Calipari will forever be questioned about why he did not call a time-out with ten seconds left in regulation to review and set up his defense. As the leader, he potentially left a question in his player’s minds about what was expected to close the deal.

Do not put yourself in the same situation in litigation. Let there be no doubt about your policy with your employees. Make it known, through your actions and through your employee manual and through your F&I and Sales Procedure Manual that bank fraud is not acceptable or tolerated. Fire the next person who you find committing bank fraud.

Belt and Suspenders Auditing – The guy in front of me yesterday at the airport security check-in line had to take extra time to get undressed for the Magnometer. First, the belt. Next, the suspenders. The TSA agent asked the obvious question, “Why both?” the man’s answer; “If one breaks, the other one will hold up my pants.”

Set up your own belt and suspenders approach to auditing deals. Start with the billing clerk. Make it part of the checklist to briefly review credit applications for alterations or numbers being printed after the rest of the application is completed. Require that every used deal have a book-out sheet signed and dated by a manager that is affirming that the options listed are indeed on the vehicle.

The second level audits should be completed by the Office Manager or Controller or Compliance Officer. Randomly pull five deals per F&I Manager on a monthly basis and scrutinize the file for potential bank fraud issues.

Finally, get independent help. Periodically, but at least annually, have a sampling of files reviewed by your attorney, accountant or compliance consultant.


Gil Van Over is the President and founder of gvo3 & Associates, a nationally recognized F&I, Sales and Red Flag Rule compliance consulting and training firm (www.gvo3.com).


BACK TO THE AUTO FINANCE INSIDER HOMEPAGE: http://www.AutoFinanceInsider.blogspot.com


Dealership Death Watch: Car Dealer Photos, Car Dealership Pictures, Auto Dealer Pictures

Saturday, April 19, 2008

Are You Compliant? Part 3

A Review of Recent Developments Part 3


Document Preparation Fees

Many dealerships charge various fees when a vehicle is delivered, including a document preparation fee. However, the so-called “doc fee” frequently comes under fire. Recently, consumer attorneys have developed a new attack on the doc fee. They are now arguing that a dealership is essentially practicing law without a licence by charging a fee to prepare documents. And as you know, that’s illegal. Just like you need to be a doctor to practice medicine, you need to be a licensed attorney to practice law. I don’t buy the argument that charging a doc fee equates to the unauthorized practice of law, but several courts have. This is why many states regulate the fees dealers charge. While dealers need to be familiar with these laws, they may not always help defend against this new attack on doc fees. If you’re charging a document preparation fee, it may be a good idea to contact your legal counsel to discuss the matter.

Credit Card Truncation

Under the FACT Act, credit card numbers on receipts have to be truncated so only the last five digits are shown. However, did you know the rule also requires that receipts not show expiration dates? Unfortunately, many people miss that part of the rule.

There was a lot of litigation about the expiration date after the rule went into effect at the end of 2006, especially in California. The good news is that this is an easy matter to handle. You just need to check every credit card machine in the dealership and make sure they’re all printing out receipts with the card numbers properly truncated — and without the expiration date.

Privacy Rules

Most dealerships know about their general responsibilities for safeguarding their customers’ personal, non-public information under the Gramm-Leach-Bliley Act. But do they know all the details? For instance, the Safeguards Rule requires a dealership name a specific employee to oversee safeguard activities.

The rule also requires a written information security plan that is periodically reviewed. Do you have a written plan? Has your dealership designated someone to oversee the program? Have you yet to fill the position after the person you designated left the dealership? Have you done the required periodic evaluations?

Now, you may be doing your best to comply with the rule, but you aren’t compliant if you aren’t meeting the detailed requirements of the Safeguards Rule.

Just remember that many of these rules governing how we operate our business act like moving targets. This is why periodic reviews of your compliance efforts is required. Just remember, even the best compliance programs can get better. Thankfully, there are plenty of resources available to help. So take advantage and don’t get caught with an outdated policy.

Todd Clarke is an associate counsel for JM&A. For more information, visit www.jmagroup.com.

Link to source article here

F&I Manager profile:
http://www.AutoFinanceInsider.com

Back to blog homepage

Saturday, January 5, 2008

$50,000 Fine for Tossing Borrowers' Credit Reports in Dumpster

A mortgage company that left loan documents with consumers’ sensitive personal and financial information in and around an unsecured dumpster has agreed to settle Federal Trade Commission charges that it violated federal regulations.

The FTC’s complaint alleges that Northbrook, Illinois-based American United Mortgage Company violated the Disposal, Safeguards, and Privacy rules by failing to properly dispose of credit reports or information taken from credit reports, failing to develop or implement reasonable safeguards to protect customer information, and not providing customers with privacy notices.

“Every business, whether large or small, must take reasonable and appropriate measures to protect sensitive consumer information, from acquisition to disposal,” FTC Chairman Deborah Platt Majoras said. “This agency will continue to prosecute companies that fail to fulfill their legal responsibility to protect consumers’ personal information.”

According to the FTC’s complaint, American United collects personal information about consumers, including Social Security numbers, bank and credit card account numbers, income and credit histories, and consumer reports. Since at least December 2005, the company engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for consumers’ personal information.

Among other things, the company allegedly failed to implement reasonable policies and procedures requiring the proper disposal of consumers’ personal information, including consumer reports; to take reasonable actions in disposing of such information; and to identify reasonably foreseeable internal and external risks to consumer information. The company also allegedly failed to develop, implement, or maintain a comprehensive written information security program.

As a result of the company’s failures, the complaint alleges, on multiple occasions American United documents containing consumers’ personal information were found in and around a dumpster, near its office, that was unsecured and easily accessible to the public. In February 2006, for example, hundreds of such documents were found, many in open trash bags, including consumer reports for 36 consumers.

In March 2006, FTC staff notified the company in writing about this situation, and on at least two occasions afterward, more such documents were found in and around the same dumpster.

The complaint charges American United Mortgage Company with violating the FTC’s
Disposal Rule, which requires companies to dispose of credit reports and information from credit reports in a safe and appropriate manner, and the FTC’s Safeguards Rule, which requires financial institutions to take appropriate measures to protect customer information.

The complaint also alleges that from July 1, 2001 until March 2006, the company failed to provide its customers with a privacy notice describing its information collection and sharing practices with respect to affiliated and non-affiliated third parties, as required by the FTC’s Privacy Rule.

The stipulated judgment and final order requires American United to pay a $50,000 civil penalty for violations of the Disposal Rule and prohibits the company from further violations of the Disposal, Safeguards, and Privacy rules. The settlement also requires American United to obtain, every two years for the next 10 years, an audit from a qualified, independent, third-party professional to ensure that its security program meets the standards of the order.

This is the FTC’s first Disposal Rule case and its 15th case challenging faulty data security practices by companies that handle sensitive consumer information.

link to source article

WOW, I really wonder how much more of this is really going on !!!

Back to blog homepage

Saturday, November 3, 2007

(GLBA) Gramm - Leach - Bliley Act Part 2 - "Privacy Rule"

by: AFI

I remember back in 2001 when the controller of our dealer group told all of the F&I managers that we needed to have customers sign Privacy Notices. A big case full of the things showed up with instructions that every one who signs a credit ap must sign one of these also. That was it. We originally made the salespeople get it signed at the same time as they got the credit application signed.

It wasn't until a short while later did I receive the full explanation of exactly why a Privacy Notice needed to be issued.

Dealers are required to issue Privacy Notices to customers who avail themselves of vehicle funding and indemnification services offered by the dealer, even when an outside lender provides the credit.

The notices are required to be delivered regardless of whether the nonpublic information is shared with unrelated entities or not.


*** More boring legal stuff:


The Federal Reserve board dictates in Section 313.4 - Initial privacy notice to consumers required.

Initial notice requirement. You must provide a clear and conspicuous notice that accurately reflects your policies and practices to:
* Customers and Consumers. Before you disclose any nonpublic personal information about the consumer to any nonaffiliated third party.


313.5 - specifies the need to send annual privacy notices if you are a lienholder.

313.9 - How to provide privacy and opt-out notices.

313.10 - Conditions for disclosure.


* You may not, directly or through any affiliate, disclose any nonpublic personal information about a consumer to a nonaffiliated third party unless:

1. You have provided to the consumer the initial notice as required by 313.4;

2. You have provided to the consumer an opt out notice as required in 313.7;

3. You have given the consumer a reasonable opportunity, before you disclose the information to the nonaffiliated third party, to opt out of the disclosure; and

4. The consumer does no opt out.


Pretty cut and dry I think.


The Privacy notice used by my dealership since July 2001 uses the following exact words.
Consult your legal council before copying and using this notice.



Privacy Notice
In connection with your transaction, this dealership may obtain information about you as described in this notice, which we handle as stated in this notice.
1. We collect nonpublic personal information about you from the following sources:
* Information we receive from you on applications or other forms;
* Information about your transactions with us, our affiliates or others; and
* Information we receive from a consumer reporting agency.
2. We may disclose all of the information we collect, as described above, to the companies that perform marketing services on our behalf or to other financial institutions with whom we have joint marketing agreements. We may make such disclosures about you as a consumer, customer, or former customer. At no time will your information be sold to any third party nor disclosed to any company or individual without a need to know that information.
3. We may also disclose nonpublic personal information about you as a consumer, customer, or former customer, to nonaffiliated third parties as required by law.
4. We restrict access to nonpublic personal information about you to those employees who need to know that information to provide products or services to you. We maintain physical, electronic, and procedural safeguards that comply with federal regulations to guard your nonpublic personal information.
CUSTOMER ACKNOWLEDGEMENT: I (we) acknowledge that I (we) received a copy of this notice on the date indicated below.
---------------------------- ----------
customer signature date


Back to blog homepage

Friday, October 19, 2007

The Gramm - Leach - Bliley Act Part 1

by: AFI

The never ending excitement of attempting to comprehend the Gramm - Leach - Bliley Act is next on our list. Compliance with this act is a HUGE part of how to measure a well run Automotive F&I Department. Enjoy:

The Gramm - Leach - Bliley Act was enacted in 1999 with the intent of protecting the confidential personal and financial information disclosed by consumers. This Act has two phases.

1 The first phase of the Gramm - Leach - Bliley act, the "Financial Privacy Rule," became effective in November 2000 and caused us to have to issue privacy notices.

2 The second phase, the Safeguards Rule, went into effect May 23, 2003. It sets out specific steps dealerships and other financial institutions must take to protect nonpublic customer information from unauthorized access.


The Privacy Rule mandates the issuance of Privacy Notices to inform customers as to the disposition of the nonpublic personal information they provide dealers in the course of purchasing a vehicle, arranging for funding and in some cases, acquiring insurance.

Essentially, the customer has to be told what is being done with his or her information beyond sending it to banks and/or lenders for the purpose of securing funding for the vehicle.

The customer is given the right to "opt-out" with regard to the sharing of his or her confidential information.

Dealers are required to issue privacy notices. These notices must be delivered regardless of whether the nonpublic information is shared with unrelated entities or not.

In addition, the financial institution to whom the dealership assigns the loan to is required to provide annual notices regarding it's privacy policy. (These are the legal-ese small print notices you get in the mail from every lender you have an open account with).

The rule went into effect in November 2000 and compliance was required as of July 1, 2001. I will never forget all the "jumping through hoops" my Finance Department did during this time. We did what we had to to do it right. We were a well run F&I department.

Check out the new site: http://www.autofinanceinsider.com/

Back to blog homepage