Showing posts with label Safeguards Rule. Show all posts
Showing posts with label Safeguards Rule. Show all posts

Thursday, December 24, 2009

Don’t Get Bitten by Your Bird Dog

A good article by Patty Covington

Long-standing dealership practices aren’t necessarily legal dealership practices. Many of these questionable practices have been around for years - and often dealers keep using them, because “everyone does it.”

Dealers sometimes don’t think twice or consider whether the practices are legally permissible or even if they are good for business. Over time, these practices have simply become part of the dealership's operations.

Referral fees are a good example of these practices.

I’m not talking about leads purchased from a typical lead provider or the purchase of a marketing list. I’m talking about referral fees paid by one dealership to another dealership or payments between sales associates of different dealerships for the referral of a customer who buys a car.

This arrangement could be part of a formal referral fee program between dealerships. let’s say sales associate Frank at franchise dealership X agrees to refer his “turndown” customers to sales associate Tom at independent dealer Y.

The arrangement could even involve an individual not employed by a dealership.

No harm, right?

Well, maybe more than you might expect. If you, or your dealership, is involved with such a program, here are a couple of things you should consider:


State law may prohibit paying for a referral in connection with the sale of a car.

Some states specifically prohibit the practice, commonly called “bird-dogging.”

Louisiana is such a state. Some states, like Ohio, require that any commission or compensation paid for the sale of a car be to a person licensed as a salesperson in the dealer’s employ.

Other states have dealer and salesperson licensing laws that sweep in broker activities. Finally, some states have laws specifically targeted at the “brokering” of cars. Some of these laws require brokers to be licensed, while others simply prohibit the brokering of the sale of a car.


Information exchanged could violate privacy laws.

Even very basic information regarding a customer, like the customer’s name, could be “nonpublic personal information” under the federal Gramm-Leach Bliley Act (GLBA).

Credit applications and a customer’s FICO score also would constitute nonpublic personal information.

Under the GLBA, nonpublic personal information cannot be shared with unaffiliated third parties unless the dealership’s privacy notice specifically states that the dealership shares information in such a way.

If Social Security numbers are shared, other state privacy laws may be violated. A significant number of states have laws that prohibit certain disclosures relating to Social Security numbers.

In addition, if an employee shares customer information with another person against dealership policy, the disclosure could constitute a security breach. Some states have security breach laws that apply only to paper documents, but other states’ laws also cover electronic records.


Information exchanged could constitute a consumer report.

If credit applications or FICO scores are shared, the federal Fair Credit Reporting Act (FCRA) is implicated. These documents constitute consumer report information.

What does this mean?

First, the party giving out this consumer report information may be deemed to be a consumer reporting agency under the FCRA.

Secondly, the party receiving the consumer report information is required by the FCRA to have a “permissible purpose” for the information under the FCRA prior to receiving it.

The FCRA sets forth an elaborate set of rules, requirements, and conditions for consumer reporting agencies and users of consumer reports.

The implications of being a consumer reporting agency are enormous. In addition, some states regulate these practices.


Calling a potential customer could violate “Do Not Call” rules.

You will violate the federal Telemarketing Sales Rule (TSR) if you call a potential customer registered with the Federal Trade Commission’s Do Not Call registry.

State mini-DNC registries and rules may also apply.

Exceptions available under the TSR will likely not apply because the customer initially contacted and dealt with the referring dealership, not the dealership following up on the referral.


Finance and lender broker licensing may apply.

Some states have finance and lending broker laws that are triggered for finance transactions.

Since most cars are financed, these laws may be implicated. Rhode Island has such a law. These laws typically impose licensing requirements.


If your dealership sells its financing contracts to sales finance companies and banks, it has entered into a dealer agreement regarding those contracts.

Typically, dealer agreements contain representations and warranties from the selling dealer to the effect that the dealer is in compliance with all state and federal laws applicable to the sales and financing transactions reflected by the contracts.

If your referral program violates such laws, you might find yourself forced to repurchase those contracts. Not a good day.

Finally, in addition to the above legal issues, there may be some practical matters that should be considered. For instance, are dealership associates referring the “right” deals to another dealership?

Is it possible that a sales associate will earn more on a referral than he would have earned if he’d sold the car himself? That may be possible with subprime discount deals.

It’s better to carefully consider whether what “everybody else is doing,” is first legal and second, makes sense for your business. It’s not that unusual for commonly accepted practices to come under fire.


Patricia E. Covington is a partner with Hudson Cook, LLP, a Hanover, Maryland-based law firm that represents national and state banks, savings associations, credit unions, mortgage bankers, and licensed lenders in the development and maintenance of consumer mortgage, automobile finance, and other credit programs.


BACK TO THE AUTO FINANCE INSIDER HOMEPAGE: http://www.AutoFinanceInsider.blogspot.com

Wednesday, June 3, 2009

The Day After - GM Dealers Get Letters

A strong and emotional article by Greg Goebel



Today, June 2nd, was the day that 5969 dealers received FedEx packages of either good news, a Participation Agreement (OK, it's not-so-bad-news, your franchise agreement may be renewed), or bad news, a Wind-Down agreement and payment of some monies to help you liquidate your inventories.

My phone started ringing early this morning. Five friends/clients all with at least one Wind-Down, and some with Participation Agreements. Shortly after the calls I had copies of the agreements forwarded to me. Out of confidentiality I can't post copies here of the documents, but they weren't short.

Bottom line is that dealer have until June 12th to sign and return the documents to GM. They were absolutely as heavy handed as I predicted they would be in yesterday's blog. Incorrigible.

Wind-down dealers may purchase no more vehicles from GM, but must stay in business through at minimum January 2010, and up to October 31, 2010. They must continue to service and honor warranties. However, they may not return any parts - whether currently owned, or those bought from GM during the 18 month transition. Yeah, that's right. Order a part, have GM ship you the wrong one and you own it, regardless. The RIM program is gone. I have one client that has about $140 in GM parts in inventory. That is going to leave a mark. His Wind-Down incentive? $36K.

The smallest package I heard today was for a nearly new store in a smaller market that is losing Pontiac and Cadillac. (Cadillac was an addition from May 15th). $12,000 is all they get.

There are a number of friends and clients that I have not talked with today. I truly hope no news is good news, but based on the heavy handedness put forth by GM for those that get to keep their franchises (if they comply) there may not be any good news. Dealers are being asked to blindly agree that they "must substantially increase its sales of new [GM vehicles]" and that the dealer will be assigned goals each year that they must meet. (Sidebar: Has a manufacturer ever been overly optimistic on what their market share should be?) They must willing to use their best efforts to "stock sufficient additional motor vehicles" in order to hit these assigned sales goals. MORE INVENTORY?! Have you seen the seven, eight or nine month supplies that some dealers have? They want them to take more?!

No duals will be allowed with non-GM franchises. Expect to have facility upgrades mandated. (That has worked so well for Toyota dealers over the past 12 months...) Oh yeah...one last thing. You agree to indemnify GM and agree not to file suit.

Yes, you may call me cynical, but I am not sure which side got the worse end of the deal. OK, I have repeatedly stated, it is just incorrigible to have your independent profitable business terminated for you, so sure, they are getting the worse end, but I am not sure I would run out and celebrate for the other group. This is the ultimate "shotgun wedding."

Finally, what was my advice? It was simple - sign the agreements. If you don't, you get to pay an attorney to go to battle. Then, should you win the battle (and I assure you it won't be cheap), you still lose the war. You will be grouped with the Old GM assets (what few there are) and all the old liabilities. As wrong as it is, GM's offer is still better than what is being offered terminated Chrysler dealers. It at least gives them some time to plan to do something and a modicum of compensation.

For the rest, take it or leave it. (Wink-wink - we guess it is kind of hard to leave that big expensive facility we had you build.) I doubt the winners will ever forget the gun that GM has put to their heads. Of course GM says they want transparency and to be a good partner. That looks like lipstick on a pig to me...and this is one big pig contract. Sounds like to me they have been associating with some career politicians too long already.

Wow.

AFI's take on this: I hope all these dealers take care in securing all those deal jackets full of customer information. There is a GM dealership where I bought a car from several years ago on this list whose General Manager will be getting a personal visit from me to explain how their red flags and safeguards procedures will be protecting my private information. Keep this in mind if you purchased a vehicle from a closing dealership. What a nightmare - thinking about trash pickers looking through piles of deal jackets and all the info contained therin. Aarrgghh - Please wake me up.


View Greg Goebel's blog HERE


BACK TO THE AUTO FINANCE INSIDER HOMEPAGE: http://www.AutoFinanceInsider.blogspot.com


Dealership Death Watch - Car Dealer Photos

Monday, May 11, 2009

Congress Mulls Significant Expansion of the False Claims Act

AFI: Important to keep in mind as you design your Red Flags Rule program.

From: Metropolitan Corporate Counsel


Originally a Civil War-era statute, the False Claims Act (FCA) was significantly revised in 1986 to protect whistle-blowers who disclose activities at their companies that may defraud the government.

Now this unfamiliar act is at the forefront again as federal bailout money is injected into the economy with a need for greater visibility.

Every entity that does business with the federal government (or does business with another company that does business with the federal government) is potentially the target of an FCA lawsuit.

It is critical that companies take proactive steps to minimize their exposure to FCA lawsuits, such as setting up rigorous compliance programs, employee outreach programs, and putting structures in place to address potential areas of exposure.

Read the rest of the article: HERE


BACK TO THE AUTO FINANCE INSIDER HOMEPAGE: http://www.AutoFinanceInsider.blogspot.com

Saturday, February 21, 2009

Tempting Times Can Tempt the Best

by : Gil Van Over


AFI - I wish my picture looked this good.


Temptations abound.


Should I continue with my heart healthy diet and order the salad for dinner or go ahead and splurge just once (again) for a Reuben sandwich with fries?

Should I get another half hour of sleep before heading out to a dealership or get up and spend 30 minutes on the treadmill?

Should I write my article on the plane or expand my mind with the diabolical Sudoku puzzle?

Temptations play with our minds and our decision-making process. Temptations will sometimes lead us to do something we know isn’t right, but succumb anyway.


Examples:


Here are some examples of temptations leading employees or consumers astray:


An office employee at a west coast dealership was arrested and charged with felony embezzlement. According to published reports, she was in some personal distress due to health issues and her husband’s failed trucking business.

The United States Treasury Department is warning dealers that people are using fraudulent financial documents intended to resemble Treasury related instruments to purchase vehicles. These are identified as “personal promissory notes” or “private offset bonds.”

There have also been numerous stories over the last few months about sales or F&I employees stepping over the bank fraud line. The Feds are proclaiming that they are stepping up efforts to ferret out bank fraud.

As tempting times can tempt the best, dealerships should realize that even the most trusted employee, or the most unassuming consumer, could find themselves in desperate financial troubles. Here are some tips to help prevent this from happening at your dealership.


Employee theft:


The office employee who allegedly embezzled the money had the responsibility to open the mail, receive the bank statement, reconcile the bank statement and make the daily bank deposit. She was able to write personal checks to the dealership, take the cash and cover up the bounced checks when the bank statements showed up.

This dealership might have avoided the embezzlement if it had separated these various duties. The person who opens the mail cannot also be responsible for reconciling the bank statement. The person who makes the daily deposit cannot also reconcile the bank statement.

Many internal thefts are uncovered by other employees who see something that just doesn’t make sense and brings the suspicious transaction to a manager’s attention. Use employees to audit and review others’ work.

For example, have someone other than the department manager periodically conduct a physical inventory audit. Someone other than the accounts payable clerk should occasionally review all the checks written over a two-week period of time. Someone other than the rebate clerk should from time to time reconcile the rebates applied for and rebates credited.

Having independent audits conducted by other employees in the dealership can uncover theft and act as a deterrent. Just alternate the areas that employees review to minimize the likelihood of collusion.


Consumer fraud:


Many of the stories I read about con artists scamming dealers involves a certain level of either greed or stupidity or both.

One story involved a young couple presenting out of state personal checks to purchase two luxury vehicles. The couple agreed to prices in excess of MSRP. The apparently greedy sales manager approved the Saturday delivery. By Monday, the checks were no good and the couple (and luxury cars) were long gone.

This story includes both greed (prices in excess of MSRP) and stupidity (young couple, out of state personal checks, weekend delivery). The sales manager overlooked the obvious red flags.

There are usually some red flags or warning signs in a consumer fraud transaction. Identify them and train your staff on how to identify them and make the appropriate delivery decision.


Bank fraud:


Unfortunately, when times get a little rough, employees may be tempted to resort to old-school fraudulent practices to sell or finance a vehicle.

The temptation is to give someone a raise on a credit application, or arrange for a straw purchase, or to increase the vehicle’s value to the lender through non-existent options or falsify the amount of the down payment.

The rationale is apparently a combination of “everyone is doing it” and “I won’t get caught.”

Since bank fraud with a federally insured institution is a federal crime, this flawed rationale could end up in jail time for the offender.

First, not everyone is doing it. Most dealers have reputable employees who don’t commit bank fraud. Second, the likelihood of getting caught is increasing every day as the Feds continue to focus on the credit crisis and understand that bank fraud constitutes a part of the problem.


To protect yourself and to minimize the likelihood of bank fraud within your four corners, institute this four-part program:


• Unequivocally declare to all employees that bank fraud is not condoned and offenders will be terminated.

• Establish a credit application submission policy that requires the consumer to complete a handwritten credit application and that information is accurately submitted to the lenders.

• Periodically audit the handwritten credit applications to the application submitted via DealerTrack, Route One and others.

• Terminate any offenders.


The same process applies to minimizing potentially deceptive practices such as payment packing, stuffing products, trading rate for product or discriminatory pricing.

Anything less may be viewed by your employees as permission to commit bank fraud in your name.

Gil Van Over is the president of gvo3 & Associates, a nationally recognized dealer compliance consulting firm. He assists dealers with F&I and sales compliance.


BACK TO THE AUTO FINANCE INSIDER HOMEPAGE: http://www.AutoFinanceInsider.blogspot.com

Monday, February 18, 2008

Excerpt from new article: "The Essentials of a Compliance Process"

hot off the presses from Gil Van Over:

Dealers have seen two federal rules promulgated on them in the last five years along with an update to another federal guideline.

The Safeguards Rule (2003) and the Red Flags Rule (2008) both require that dealers adapt processes that most did not have in place prior to the requirements.

The Safeguards Rule, of course, requires that dealers protect consumers’ personal, non-public information from being fleeced by identity thieves.

The Red Flags Rule mandates that dealers escalate their responsibilities to help detect and prevent identity theft.

The Federal Sentencing Guidelines (2004) are a set of rules that judges must follow when imposing sentences on guilty parties. With a good compliance and ethics program in place, a judge can reduce potential fines and penalties by up to 95 percent.

All three (Safeguards Rule, Red Flags Rule, and Federal Sentencing Guidelines) provide a dealer with insight of what the federal government considers to be an effective compliance process.

Safeguards Rule
The Safeguards Rule contains five elements a dealer must follow to be in compliance:
• Name a compliance officer
• Conduct a risk assessment
• Develop a policy and procedure
• Provide employee training
• Conduct periodic audits

Red Flags Rule
Compliance with the Red Flags Rule requires six elements.
• Name a compliance officer
• Conduct a risk assessment
• Develop a policy and procedure
• Provide employee training
• Conduct periodic audits
• Write an annual report on program’s effectiveness

Federal Sentencing Guidelines
The sentencing commission has outlined the elements it considers necessary for an effective compliance and ethics program:
• Standards and procedures to prevent and detect criminal conduct
• Peonnrsel screening related to program goals
• Training
• Auditing, monitoring and evaluating program effectiveness
• Non-retaliatory internal reporting systems
• Incentives and discipline to promote compliance
• Reasonable steps to prevent further offenses upon detection of a violation

The elements of a compliance program
Not surprisingly, a dealer looking to establish a compliance process in sales and F&I should follow the model the government provides.

Name a compliance officer – Put someone in charge. Depending on your size, it can become the additional responsibility of the person responsible for your risk management functions, or it can be a newly created position. Either way, make it someone’s responsibility to develop the processes, the procedures, and the policies and report to you.

Conduct a risk assessment – Figure out where your compliance shortcomings are. It could be an inconsistent payment quoting methodology, or the inconsistent use of a menu, or the inconsistent completion of forms. It could be a lack of safeguarding consumer information, or the lack of a crosschecking process to detect employee fraud or the lack of buyer’s guides on used cars. The compliance officer is to conduct a thorough risk assessment to determine where your risk is.

Develop a policy and procedure manual – Once the compliance officer has determined where the risks are and how the processes are supposed to work, he or she should develop policy and procedure manuals for both sales and F&I. These manuals must define and describe the organization’s expectations on how an employee is to complete certain tasks.

Provide employee training – Now that you have a manual on how the employees are expected to perform their jobs, let them know. Give them a copy of the manual a week before starting the training so that they have ample time to review the material. Then provide the training and have the employees sign an acknowledgement form certifying that they have read the material and agree to abide.

Conduct periodic audits – Ah…the trust but verify stage. This is why I call this a compliance process, not a program. A process must be continually monitored and refined as new information becomes available. A program is like a manufacturer’s incentive, it comes and goes and no one remembers it a year later. You must conduct periodic audits and document any shortcomings and corrective actions you took, including disciplinary. You must also refine your policy and procedure manuals to reflect your actual process if the employees find a better way to do something.

Back to blog homepage

Wednesday, January 16, 2008

Implementing an Effective Red Flags Program - Webinar Pt1

By: Michael Benoit – Hudson Cook
Robert Miller – Co-founder/Attorney Principal - Compli

Webinar, Jan 16, 2008

This is what I took from the webinar. These notes will document my dealership’s compliance with both the Safeguards Rule and the Red Flag Rule.

A Red Flag is a pattern, ……, or specific activity that indicates possible existence of identity theft.

The Federal “Red Flag Rules” requires automobile dealerships to implement an “Identity Theft Program” on January 1, 2008. Compliance is required on November 1, 2008. Hudson Cook recommends the program to be implemented on October 1st to give a margin to evaluate effectiveness.

“Dealers are Lending Institutions” states Michael Benoit of Hudson Cook. If a dealership enters into retail installment sale agreements with a customer, they are lenders under the FCRA and the FTC and subject to laws and regulations affecting lending institutions.

If you have successfully implemented a Safeguards program, you can implement a successful Red Flag program, Benoit states. The two programs are very similar. As the first step to comply with the Safeguards rule is to develop a written Information Security Program, the first step in implementing the Red Flag Rules would be to develop a Written Identity Theft Program.

Each dealership needs its own written “Identity Theft Program.” The implemented Program must:

• Identify the Red Flags
• Detect the Red Flags
• What the responses will be if a Red Flag is found
• Periodically audit the dealerships operations to insure compliance with the policies and procedures.

Benoit states that a more detailed webinar explaining the 26 Red Flags that the FTC has included in its guidelines will be available on Feb 27th 2008 from Compli’s website.

Again Benoit stresses: “Take a deep breath. If you have successfully implemented a Safeguards Program, you can implement a successful Red Flag Program. They are very similar.”

PENALTIES for violating the Red Flag Rule could be a combination of multiple avenues of enforcement:

• $2500.00 per violation for violating the FCRA Act.
• $11,000.00 per violation of the FTC Act.
• Possible violations of state unfair and deceptive practices laws.

WHAT IS COVERED BY THE RULE?

• Retail Installment Sale Contract transactions only.
a. All consumer and business retail installment sale transactions whether or not you intend to hold the paper.

ADVICE FROM HUDSON COOK:

• For Red Flag, just treat all info for starters as if it is subject to the Safeguards Rule.

• Appoint a Joint ISP/ITD Program Coordinator. Include Patriot Act customer ID requirements.

MUST CONTAIN REASONABLE POLICIES AND PROCEDURES TO:

• Identify relevant Red Flags for your business and incorporate into a written program.

• Detect relevant Red Flags that have been incorporated into your written program.

• Respond.

• Periodically update ITP program.

KEY POINTS:

The Initial Identity Theft Program must be approved by the dealership’s Board of Directors or appropriate committee of the Board of Directors. If no Board, an authorized Principal must approve.

TRAINING – must train as necessary to effectively implement the ITP program.

SERVICE PROVIDERS – must exercise appropriate & effective oversight of service provider arrangements.

WHICH FLAGS TO INCLUDE? –

1. The ones that the corporation has experienced.

2. The ones that the FTC has included in its guidelines. All 26 of them.

*** Include in your ITP program those things that you already do to control reasonably feasible risks.

(You should already be doing this by complying with the Safeguards Rule).

RISK FACTORS:

• Types of accounts you offer or maintain.

• Methods used to open accounts.

• Methods through which you allow access to accounts.

• Previous experiences with Identity Theft.

SOURCES OF RED FLAGS:

• Dealership experience.

• New experiences of identity theft.

• Applicable Supervisory Guidance. See: www.FTC.gov.

DEVELOPING YOUR CORPORATE POLICY AND PROCEDURE MANUAL:

Bookmark: http://www.AutoFinanceInsider.blogspot.com. This site will become the authority on Automotive F&I policy procedure and compliance.

Back to blog homepage

Saturday, January 5, 2008

$50,000 Fine for Tossing Borrowers' Credit Reports in Dumpster

A mortgage company that left loan documents with consumers’ sensitive personal and financial information in and around an unsecured dumpster has agreed to settle Federal Trade Commission charges that it violated federal regulations.

The FTC’s complaint alleges that Northbrook, Illinois-based American United Mortgage Company violated the Disposal, Safeguards, and Privacy rules by failing to properly dispose of credit reports or information taken from credit reports, failing to develop or implement reasonable safeguards to protect customer information, and not providing customers with privacy notices.

“Every business, whether large or small, must take reasonable and appropriate measures to protect sensitive consumer information, from acquisition to disposal,” FTC Chairman Deborah Platt Majoras said. “This agency will continue to prosecute companies that fail to fulfill their legal responsibility to protect consumers’ personal information.”

According to the FTC’s complaint, American United collects personal information about consumers, including Social Security numbers, bank and credit card account numbers, income and credit histories, and consumer reports. Since at least December 2005, the company engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for consumers’ personal information.

Among other things, the company allegedly failed to implement reasonable policies and procedures requiring the proper disposal of consumers’ personal information, including consumer reports; to take reasonable actions in disposing of such information; and to identify reasonably foreseeable internal and external risks to consumer information. The company also allegedly failed to develop, implement, or maintain a comprehensive written information security program.

As a result of the company’s failures, the complaint alleges, on multiple occasions American United documents containing consumers’ personal information were found in and around a dumpster, near its office, that was unsecured and easily accessible to the public. In February 2006, for example, hundreds of such documents were found, many in open trash bags, including consumer reports for 36 consumers.

In March 2006, FTC staff notified the company in writing about this situation, and on at least two occasions afterward, more such documents were found in and around the same dumpster.

The complaint charges American United Mortgage Company with violating the FTC’s
Disposal Rule, which requires companies to dispose of credit reports and information from credit reports in a safe and appropriate manner, and the FTC’s Safeguards Rule, which requires financial institutions to take appropriate measures to protect customer information.

The complaint also alleges that from July 1, 2001 until March 2006, the company failed to provide its customers with a privacy notice describing its information collection and sharing practices with respect to affiliated and non-affiliated third parties, as required by the FTC’s Privacy Rule.

The stipulated judgment and final order requires American United to pay a $50,000 civil penalty for violations of the Disposal Rule and prohibits the company from further violations of the Disposal, Safeguards, and Privacy rules. The settlement also requires American United to obtain, every two years for the next 10 years, an audit from a qualified, independent, third-party professional to ensure that its security program meets the standards of the order.

This is the FTC’s first Disposal Rule case and its 15th case challenging faulty data security practices by companies that handle sensitive consumer information.

link to source article

WOW, I really wonder how much more of this is really going on !!!

Back to blog homepage

Saturday, December 8, 2007

Finishing with the GLBA

by: AFI


Study this fantastic presentation on "The Implementation of the Safeguards Rule" published the University of Georgia. Someone put a lot of work into this. If you want your F&I Director to really feel comfortable that you know the GLBA - know this info!

http://www.infosec.uga.edu/sate/presentations/Gramm-Leach-Bliley_Act_at_UGA.ppt


Read this client alert from Goodwin Proctor LLP. "What Can You Do To Reduce Your Exposure?" - Requirements for Safeguarding Customer Data.

http://www.goodwinprocter.com/~/media/9120AE2E76094F6EBAED1D158158AD61.ashx

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

*** This post is going to be HEAVY in discussions of the Red Flag Rule that is scheduled to go into effect November 1, 2008.

Read the above link - sound familiar?

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

Possible Changes into the GLBA:

Numerous change proposals include:

1) Using “opt-in” instead of “opt-out.” Opt-in policies can explicitly allow a financial institution the ability to share data; however the customer must expressly check a box or sign a statement giving this authority to the institution. Without an opt-in, financial institutions can be under express obligation not to share the information provided. Essentially, the burden of information protection passes to the financial institution with”opt-in.” This approach has been proposed, partially because of the practice of many financial institutions and web sites in general to automatically check the box of the “please share my information with whomever you feel like it and spam me mercilessly.” This technique is how many firms get around “opt-in” by essentially opting individuals in automatically.

2) If opt-outs are still used, then financial institutions should be required to provide easy access to privacy policies at branch offices and on the Web.

3) Provide consumers with the right to review any disclosed information or to correct inaccurate or incomplete data.

4) Give states additional jurisdiction to enforce GLBA provisions to enhance enforcement efforts.

5) Providing clear and human-understandable privacy policies, which clearly spell everything out, and allow people to understand explicitly how their information may be used

What are some penalties for violating GLBA?

Violation of the GLBA may result in a civil action brought by the United States Attorney General, and can carry the following penalties:

1) “the financial institution shall be subject to a civil penalty of not more than $100,000 for each such violation”

2) “the officers and directors of the financial institution shall be subject to, and shall be personally liable for, a civil penalty of not more than $10,000 for each such violation.”

Short Summary:

The GLBA is certainly a step forward on the way to protect the user’s financial and personal information. Identity Access Management solutions are crucial when it comes to implementing compliance automation.


Possible Changes into the GLBA first printed 10/2/2007. Olga. Links Business Group LLC. Retrieved on 12/8/2007 from: http://www.linksbusinessgroup.com/blog/2007/10/02/identity-access-management-regulations/#comment-769

Back to blog homepage