The Industry's Leading Source For F&I, Sales And Technology

Article

Dumpster Diving

December 2012, F&I and Showroom - Feature

by Tom Hudson

One of the first things my firm does when conducting an on-site dealer or finance company compliance audit is to go Dumpster diving. We want to see whether confidential customer information protected by federal law is being tossed in the trash can for anyone to find. No, we don’t actually put on our garbage man overalls and crawl in the Dumpster, but we do ask a lot of pointed questions about what goes into the trash. We also ask for a copy of the dealership’s federally required disposal policy.

The whole process usually elicits a blank stare, which is a little odd given that federal requirements regarding the safeguarding and disposal of protected consumer information have been around now for several years.

Maybe the recent news that the Federal Trade Commission (FTC) tagged a company with a $100,000 civil penalty will make dealers pay attention.

Here’s what happened: A company that provides management services to more than 300 payday loan and check cashing stores, as well as an affiliated company that owns and operates several stores, agreed to pay $101,500 to settle FTC charges that they violated federal law by allowing sensitive consumer information to be tossed out with the trash.

The FTC charged that PLS Financial Services Inc. and The Payday Loan Store of Illinois Inc. violated its Disposal Rule by failing to take reasonable measures to protect consumer information, resulting in the disposal of credit reports containing sensitive personal identifying information in unsecured Dumpsters near several PLS Loan Stores and PLS Check Cashers locations. PLS Group Inc., which owns PLS Financial Services and The Payday Loan Store of Illinois, was also named in the complaint.

The FTC also charged the companies with violating the Gramm-Leach-Bliley Safeguards Rule and Privacy Rule, which require financial institutions to develop and use safeguards to protect consumer information, as well as deliver privacy notices to consumers.

The FTC also charged that all three defendants violated the FTC Act by misrepresenting that they had implemented reasonable measures to protect sensitive consumer information. The apparent translation of this charge is that the companies had privacy policies but, apparently, ignored them.

The FTC alleged that PLS Group owns approximately two dozen operating companies, that in turn own and operate more than 300 retail stores in nine states under the names PLS Loan Stores and PLS Check Cashers. These stores offer a variety of products and services, including payday loans, check cashing, automobile title loans, debit cards, phone cards, and notary services. PLS Financial Services provides management services to these locations, including establishing their policies and procedures for the handling and disposal of consumer financial information.

In addition to the $101,500 civil penalty imposed on PLS Financial Services and the Payday Loan Store of Illinois, the settlement bars all of the companies from violating the Disposal, Safeguards Rule and Privacy Rule. It also prohibits them from misrepresenting the extent to which they maintain and protect the privacy and integrity of personal information.

The order also requires that the companies implement and maintain a data security program with independent third-party audits every other year for the next 20 years. It also imposes bookkeeping and record-keeping provisions to allow the FTC to monitor compliance with the order.

The consent judgment, by its terms, is for settlement purposes only, and does not constitute an admission that the law was violated. But they do have the force of law when approved and signed by the District Court judge.
This is the third time the FTC has charged a violation of the Disposal Rule.

So, it’s evident that the FTC is serious about enforcing the Privacy Rules. And you can’t comply with the mandate by crafting a policy and then putting it on a bookshelf and ignoring it. The policy needs to be one that the organization’s privacy officer is charged with implementing and maintaining, and the privacy officer needs to be fired if something like this happens.

At least that’s what would happen if he or she worked for me.
Thomas B. Hudson is a partner in the law firm of Hudson Cook LLP and the author of several widely read compliance manuals available at CounselorLibrary.com. ©Counselor Library.com 2012, all rights reserved. Based on an article from Spot Delivery. Single print publication rights only, to F&I and Showroom magazine. HC# 4826-7282-4337 (12/12).

Your Comment

Please note that comments may be moderated. 
Leave this field empty:
Your Name:  
Your Email:  

Blog

So Here's the Deal

Ronald J. Reahard
The Dealer Moved My Goal Posts

By Ronald J. Reahard
Top trainer has hard-earned advice — and a word of warning — for F&I pros whose dealers seem to change their pay plans every time they have a good month.

Addressing F&I’s Internet Problem

By Ronald J. Reahard
A frustrated F&I manager poses an increasingly common question: How do you sell protection products to customers who demand the final price by phone and then show up with a bank check?

(Video) Selling Eight Products Without Losing the Customer

By Ronald J. Reahard

He Had a Goal: Remembering David Ressler

By Ronald J. Reahard

Done Deal

Gregory Arroyo
The Repair Is Covered

By Gregory Arroyo
The editor opens up about his first service-contract claim, which resulted in a covered and repaired vehicle as well as a few lessons.

Change Is Happening

By Gregory Arroyo
Saddened by the potential loss of another piece of his childhood, the editor tries to put the pieces together when he realizes there’s a good lesson to be learned in a toy retailer’s likely demise.

Who Will Take Up the CFPB's Torch?

By Gregory Arroyo

Military Lending Act Guidance: The Gift That Keeps On Giving

By Gregory Arroyo

Mad Marv

Marv Eleazer
Is That Legal?

By Marv Eleazer
Is manipulating a sales agreement to accommodate a customer’s request to cash out of a dealer-arranged retail sales contract allowed? His Madness gets answers from the industry’s top legal mind.

Overcome Your F&I Weaknesses

By Marv Eleazer
His Madness issues a challenge to every F&I professional: Eradicate your bad work habits, diversify your lender spread, and check your God complex at the door.

Proper Deal Structure Moves Mountains

By Marv Eleazer

Show Us Some Love

By Marv Eleazer

On the Point

Jim Ziegler
Bound to Fail

By Jim Ziegler
Da Man returns with a message to vehicle manufacturers jumping into the subscription waters: It ain’t gonna happen.

Sharpen Your Survival Skills

By Jim Ziegler
‘Da Man’ has a plan you can use to survive the collapse of the car business and remain profitable through the dealer apocalypse.

Sales Rock Stars Still Exist

By Jim Ziegler

The New Stooges

By Jim Ziegler