FI showroom red and grey logo
MenuMENU
SearchSEARCH

Data Breach 101

By all reports, billions of records have been exposed by reported data breaches. If the unthinkable occurs, having a well thought out data breach response plan will help you manage the challenges you will face.

by Robert J. Wilson, Esquire
November 11, 2020
Data Breach 101

By all reports, billions of records have been exposed by reported data breaches. If the unthinkable occurs, having a well thought out data breach response plan will help you manage the challenges you  will face.​

4 min to read


Data breach seems like it should be a four-letter word and hopefully one never uttered when talking about your business. In addition to common claims of negligence, data breaches can give rise to statutory claims for damages, such as under the California Consumer Privacy Act of 2018 (CCPA). Similar legislation is pending in other states.

The old adage about an ounce of prevention being worth a pound of cure applies with special urgency here.

Ad Loading...

If however, the unthinkable happens, then what? The following is a brief checklist of data breach response considerations.

  1. Process: There should be a written data breach response plan designating a coordinator/point person to lead the data breach investigation team. Team members and responsibilities should be specified. The investigation should cover: closing the breach, determining the scope of accessed information, and determining the cause/method of the breach.

  2. Insurance: Is there insurance to cover the data breach? If so, the insurance company should be notified right away, and you should review next steps with counsel to ensure that you do not get a denial of coverage due to taking an action which has not be approved by the insurance company.

  3. Forensics: Do you have a forensic IT team in case of a data security incident? You should review with counsel exactly what information should be in any IT report before it is written since it could possibly be subject to discovery in regulatory, class action, or other data breach lawsuits.

  4. Notification: Data breach notices required by law and any required regulatory and/or law enforcement reporting should be prepared and promptly delivered.

  5. Public Relations: Do you have a public relations firm selected to help manage communication/messaging?

  6. Mitigation: Do you have a mitigation partner who can provide reasonable and necessary mitigation costs such as credit monitoring and identity theft assistance? 

  7. Compliance Management System: Data breach response plans should be covered in policies and procedures for the business, as part of an overall Compliance Management System (CMS). The new realities brought on by COVID such a remote work should also be addressed. Have your policies and procedures specified password and virtual private network protocols? How is communication and storage of private customer data to be handled? How is the use of personal devices such as cell phones and tablets managed? Who reviews vendor access and the scope of access granted to vendors (e.g. into the DMS or CRM)? What training is given to employees? What testing of the information security network is being done and how frequently is it done?

Data breach and the lack of policies and procedures can be used by resourceful attorneys

to mount a two-pronged attack: 1. allege a violation of Gramm-Leach-Bliley Act (GLB) such as a failure to safeguard customer non-public personal information, and then 2. claim that the violation of GLB in turn constitutes an unfair deceptive and abusive act or practice (UDAAP).

These cases and claims are disastrous to both a business’ bottom line and reputation.

Ad Loading...

By all reports, billions of records have been exposed by reported data breaches. How would a data breach affect your company and what should you do? Policies and procedures as well as education and training from a complete Compliance Management System should be part of the “front end.” and a data breach response plan should be part of the “back end.” The old adage about an ounce of prevention being worth a pound of cure applies with special urgency here. If, however, the unthinkable occurs, having a complete written, well thought out data breach response plan will help you manage the challenges you will face.

Content provided in this article is intended for informational purposes only and should not be construed as legal advice and should not be relied upon or acted upon without retaining counsel to provide specific legal advice based upon your particular situation, jurisdiction and circumstances. No duties are assumed, intended or created by this communication. No attorney-client relationship is being created by your review or use of this material.

© 2020 Robert J. Wilson, All Rights Reserved

Robert J. Wilson, Esquire (Bob) is a Philadelphia lawyer and is general counsel for ARMD Resource Group. Bob is the principal of Wilson Law Firm and has over 30 years of experience both as a counselor and as a litigator in State and Federal Courts. Risk management, problem solving and dispute resolution are his core competencies. Bob’s practice is largely in the consumer finance space, and he regularly consults with Lenders and contributes articles on various compliance related issues.

Originally posted on Agent Entrepreneur

Subscribe to Our Newsletter

More Digital

Light 'trail' to illustrate the idea of a digital trail
Digitalby Gil Van OverMay 18, 2026

Four Keys to Your Digital Trail Defense

Federal regulators are cracking down on hidden fees. This protective measure could mean the difference between winning and losing a lawsuit or surviving a duel with the Dark Side.

Read More →
Hyundai Motor Group Tech Talent Forum 2026 September 17-18 San Jose, California. background of starry night
Digitalby Lauren LawrenceApril 20, 2026

Hyundai Hosts Tech Talent Forum

Technology leaders from Hyundai Motor Group will have open discussions at the inaugural HMG Tech Talent Forum on topics ranging from autonomous driving to 'smart' manufacturing.

Read More →
car outline on top of a data background
Digitalby Lauren LawrenceApril 7, 2026

Dealers Seek Actionable AI

Dealers are facing growing frustrations with current generic artificial intelligence tools, according to a survey by Lotlinx, which found they want a solution that understands their inventories.

Read More →
Ad Loading...
Ron Reahard, president of Reahard & Associates, announcing an integration with ImpactMenu to enhance F&I transaction recording, compliance and dealership performance insights.
Digitalby StaffMarch 19, 2026

Reahard & Associates Forges New Integration

The firm's F&I Insight tie-up with The Impact Group’s ImpactMenu platform is designed to enhance finance-and-insurance transaction recording for auto dealerships.

Read More →
Chris Walsh, president and acting CEO of Reynolds and Reynolds, promoting the company’s Amplify 2026 event for dealership professionals focused on technology and operations.
Digitalby StaffMarch 13, 2026

Registration Open for Reynolds Amplify Retail Summit

Advancements with Reynolds' AI Agent, Rey, will take center stage this August at the Park Hyatt Aviara in Carlsbad, Calif., near San Diego.

Read More →
A customer signs documents on a digital e-contracting tablet using a stylus while a dealership employee points to the screen, alongside the Reynolds and Reynolds and Assurant logos.
Digitalby StaffMarch 6, 2026

Automotive Training Academy by Assurant Grows Offering

A new Atlanta location on Reynolds and Reynolds' docuPAD e-contracting system is designed to broaden access for auto professionals.

Read More →
Ad Loading...
A dealership customer works with an F&I representative at a desk during the vehicle purchase process.
Digitalby StaffJanuary 30, 2026

Assurant Debuts Virtual Solution for Dealers' Staffing Challenges

Company says on-demand access to F&I specialists is shown to boost dealership efficiency and profitability.

Read More →
DigitalDecember 16, 2025

What to Do When Your Vendor Is Hacked

The quickest way to turn a breach into a crisis is to wing it. Follow this seven-step playbook to ensure you meet your obligations.

Read More →
Digitalby Hannah MitchellDecember 3, 2025

Dealer Credit Service Provider Breached

Hack exposed thousands of dealerships’ customer data

Read More →
Ad Loading...
DigitalNovember 18, 2025

Unearthing the Gold in Your Dealership Data

How to take a smarter path to revenue

Read More →