FI showroom red and grey logo
MenuMENU
SearchSEARCH

FTC Charges First Dealer With GLB Privacy Violations

The Federal Trade Commission reached settlements with a dealer and a software company after the federal regulator charged them with exposing consumer information through peer-to-peer, file-sharing software.

by Staff
June 12, 2012
4 min to read


WASHINGTON, D.C. — The FTC has charged two businesses, including Statesboro, Ga.-based Toyota Scion dealer, with illegally exposing the sensitive personal information of thousands of consumers by allowing peer-to-peer, file-sharing software to be installed on their corporate computer systems.

Settlements with the dealer and debt collection business, will bar misrepresentations about their privacy, security, confidentiality, and integrity of any personal information. Both companies must also establish and maintain comprehensive information security programs.

Ad Loading...

The FTC charged that Statesboro, Ga.-based Franklin's Budget Car Sales Inc., also known as Franklin Toyota/Scion, compromised consumers' personal information by allowing P2P software to be installed on its network, which resulted in sensitive financial information being uploaded to a P2P network.

Despite a privacy policy stating that customer information will only be viewed by employees who require the information to provide products and services, the dealership, according to the FTC’s complaint, allegedly failed to implement reasonable security measures to protect consumers' personal information. As a result, the complaint states, information for 95,000 consumers was made available on the P2P network. The information included names, addresses, Social Security numbers, dates of birth and driver's license numbers.

The agency charged that Franklin failed to assess risks to the consumer information it collected and stored online, and failed to adopt policies to prevent or limit unauthorized disclosure of information. It also allegedly failed to prevent, detect and investigate unauthorized access to personal information on its networks, failed to adequately train employees and failed to employ reasonable measures to respond to unauthorized access to personal information.

Because Franklin is a financial institution, the alleged security failures violated the Gramm-Leach-Bliley (GLB) Safeguards Rule, as well as Section 5 of the FTC Act. Franklin also allegedly failed to provide annual privacy notices and provide a mechanism by which consumers could opt out of information sharing with third parties, a violation of the GLB Privacy Rule. This is the FTC’s first action against an auto dealer charging GLB violations.

The settlement agreement with Franklin will bar misrepresentations about the privacy, security, confidentiality, and integrity of personal information collected from consumers. It bars Franklin from violating the GLB Safeguards Rule and Privacy Rule. Under the settlement, Franklin Auto must also establish and maintain a comprehensive information security program and undergo data security audits by independent auditors every other year for 20 years.

Ad Loading...

In a separate case, P2P technology’s usage came into question. The FTC found that P2P software can pose significant data security risks.A 2010 FTC examination of P2P-related breaches uncovered a wide range of sensitive consumer data available on P2P networks. Files shared to a P2P network are available for viewing or downloading by any computer user with access to the network. Generally, a file that has been shared cannot be permanently removed from the P2P network. In addition, files can be shared among computers long after they have been deleted from the original source computer.

The FTC alleged that EPN Inc., a debt collector based in Provo, Utah, failed to implement reasonable security measures for personal information on its computers and networks. The company’s clients include healthcare providers, commercial credit organizations and retailers.

As a result of these failures, EPN's chief operating officer was able to install P2P file-sharing software on the EPN computer system, causing sensitive information, including Social Security numbers, health insurance numbers and medical diagnosis codes of 3,800 hospital patients, to be made available to any computer connected to the P2P network. The agency charged that the company did not have an appropriate information security plan, failed to assess risks to the consumer information it stored, did not adequately train employees, did not use reasonable measures to enforce compliance with its security policies, such as scanning its networks to identify any P2P file-sharing applications operating on them, and did not use reasonable methods to prevent, detect and investigate unauthorized access to personal information on its networks. According to the agency, the failure to implement reasonable and appropriate data security measures was an unfair act or practice and violated federal law.

The settlement order with debt collector EPN bars misrepresentations about the privacy, security, confidentiality, and integrity of any personal information. It requires EPN to establish and maintain a comprehensive information security program. It also requires EPN to undergo data security audits by independent auditors every other year for 20 years.

The Commission voted 5-0 to accept the consent agreement packages containing the proposed consent orders for public comment. The FTC will publish a description of the consent agreement packages in the Federal Register. The agreement will be subject to public comment for 30 days, beginning today and continuing through July 9, after which the Commission will decide whether to make the proposed consent order final.

More F&I

Photo of a three-seat vehicle back seat
F&Iby Hannah MitchellMay 22, 2026

F&I Reaches for the Sky

The increasingly important profit center continued making gains in the first quarter, according to StoneEagle data, ancillary products proving more popular as consumers hold onto their buys longer.

Read More →
Cover image for a BOK Financial report titled “Timing the market: How avoiding volatility entirely can hurt long-term reinsurance program performance.” The image shows several road construction barricades with flashing amber warning lights lined up in a nighttime work zone. Beneath the image, red text explains that avoiding volatility can mean falling behind inflation and missing market rebounds that drive long-term surplus growth. The BOK Financial logo appears at the bottom right.
SponsoredMay 8, 2026

Timing the Market Can Hurt Long-Term Program Performance

For dealer-owned reinsurance entities, avoiding volatility entirely can mean falling behind inflation and missing market rebounds that drive long term surplus growth. Missing just a handful of strong market days can materially impact cumulative returns—an important reminder for long horizon trust and investment strategies.

Read More →
Ryan Ruff, The 90/10 Rule, Automotive Training Academy, Sales Series
F&IMay 6, 2026

The 90/10 Rule

In this video, Ryan Ruff explains the rule that elite sales professionals use to turn ordinary conversations into unforgettable customer experiences.

Read More →
Ad Loading...
Photo of essential oil diffuser on desk next to laptop
F&IMay 4, 2026

Your Office Is Talking

What’s the atmosphere saying about you to your customers? You can make minor adjustments and additions that transform your space into one that creates trust with the people on the other side of the desk.

Read More →
"Effective training ensures the customer’s needs remain at the heart of everything we do. When that is the focus, both sales and profits naturally improve." by Rick McCormick with F&I and Showroom logo and picture of Rick McCormick
F&IMay 1, 2026

F&I Training Fundamentals

How can auto dealerships help F&I managers fulfill their vital role in the most effective ways? Industry expert Rick McCormick shares his insights on the best ways to train these professionals and help them maintain good habits.

Read More →
Photo of car tire and the tread mark it left in snow
F&Iby Hannah MitchellApril 29, 2026

Not Just Any Tire Will Do

More consumers and businesses are opting for all-season options for various reasons as safety, sustainability and convenience push practical change.

Read More →
Ad Loading...
Photo of robot holding a laptop
F&Iby Hannah MitchellApril 27, 2026

How AI Will Drive the Next Wave of Innovation in Finance & Insurance

It’s time to take the next digital step to free F&I managers to handle the most challenging aspects of customer meetings.

Read More →
Photo of notepad and pen next to computer keyboard on desktop
F&IApril 13, 2026

Control in Sales Is an Illusion

Some of it should be given to the customer, but that doesn’t mean the F&I office relinquishes the process. In fact, a different approach both builds trust and boosts sales.

Read More →
Photo of external keyboard on office deak next to window
F&IApril 7, 2026

The Limited Warranty Game

Bringing it in-house benefits the dealership and its customers.

Read More →
Ad Loading...
Woman in casual clothing sitting at a desk
F&Iby Rick McCormickMarch 31, 2026

Curb The Confusion

Talk to F&I customers like you’d talk to a friend, without industry lingo or sales-like questions, and use hard proof to show, not tell, them about a need.

Read More →