Personal Data Gets an Early Start in 2021

Posted by

on

Written by: Hao Nguyen, General Counsel of ComplyAuto

The early bird gets the worm, and personal data lined up yesterday. The Office of Administrative Law (OAL) remained busy through the year by releasing a fourth set of proposed modifications to the regulations relating to the California Consumer Privacy Act (CCPA) in early December. These modifications are a result of a public comment period in which the general public submitted questions and comments to further clarify the text. Here is a summary of the modifications. For the full text, please see a link on the Office of Attorney General website here.

Offline “Do Not Sell My Info” Disclosure Requirement

In addition to posting the required opt out disclosures online, businesses that “sell” consumers’ personal information (“PI”) must now also provide offline instructions on how consumers can opt-out of the sale of their PI. In other words, dealers will need to post conspicuous signage that informs consumers of how they can exercise their right to stop the “sale” of their PI to third parties. If you do not currently have a sign, please review our sample made available on our website (“Sample CCPA Sign” in the upper-right).

Am I Actually “Selling” Personal Information?

Probably. While this warrants a longer discussion that is outside the scope of this article, the CCPA broadly defines the term “sale” beyond just an exchange of PI for monetary value. Several vehicle manufacturers have already taken the position that data sharing arrangements such as through the dealer’s DMS, CRM, and other integrations constitute a “sale” of information under the CCPA. Further, other types of sharing, such as data pushes to direct mail or email marketing companies, may constitute a sale since the consumers’ PI is being provided in exchange for the vendor’s advertising services. Finally, third-party cookies that track consumers across websites (e.g., retargeting ads) may also be considered a sale.

Reminder to Obtain CCPA Service Provider Agreements 

It’s important to remember that the CCPA provides an exception to the broad definition of “sale” so long as the dealer is sharing PI with a “service provider” that has signed a written agreement containing certain contractual restrictions. Therefore, dealers are going to want to have qualifying vendors sign a CCPA service provider agreement so that they can limit their liability and exposure to CCPA “do not sell” and “opt out” requirements. See the CNCDA’s CCPA Handbook for a sample agreement, or chat with us at ComplyAuto about how we can help you automatically identify and track the vendors that need to sign the agreement.

What do I do?

To satisfy the new requirement for the offline disclosure, we recommend posting CCPA signage (or updating your existing signs) to inform consumers of their right to opt-out of the sale of their information in areas where personal information is collected, including, but not limited to, your sales, finance, service, and parts departments. Make sure the sign directs the consumer to where they can submit their request, such as the required interactive webform. ComplyAuto clients already have access to these signs that direct consumers to client’s unique interactive online request portal that we implemented directly into their website.

Standardized Opt-Out Button

Businesses that sell PI must also add a newly designed (and government-prescribed) “opt-out” button to their website. Specifically, the button must be added to the left side of the “Do Not Sell My Personal Information” link and, when clicked, must direct the consumer to the same webpage or online location where they can submit their request. The regulations also require that the button be approximately the same size as any other buttons used on your webpage.

What do I do?

All existing ComplyAuto clients – nothing. You have a working “Do Not Sell My Information” link in your cookie banner and this button will be automatically added when it becomes necessary. For everyone else, you will need to contact your website provider to get this button added if, and when, these new regulations are adopted. In the meantime, you might want to evaluate the current size of your website’s standard buttons since this new opt-out button will need to match them in size.

ComplyAuto: A Purpose-built Solution for your Auto Group or Single-Point Dealership

Looking for a full suite of CCPA compliance tools for your dealership and want to be covered from state enforcement penalties? Please visit our website to learn more about us and our ComplyAuto Compliance Guarantee.

The Battle Over Personal Data, and the Dealers Caught in the Crossfire

Mock OSHA Assessment

FEATURES:

  • On-demand eight-hour assessment that imitates a real OSHA audit.
  • Conducted by an EHS Pro with OSHA-10 or OSHA-30 certification and 5+ years of experience. 
  • Simulated employee interviews
  • Issue tracking and task management
  • Detailed assessment reports after the assessment with images, videos, and recommended steps for remediation.

    Privacy & Cyber Compliance Suite

    FEATURES:

    • Custom legal policies with real-time updates, including the Information Security Program (ISP)
    • Customized Incident Response Plan (IRP)
    • Internal risk assessment tools and hands-on guidance
    • Biannual penetration testing (2) 
    • Biannual vulnerability scans (2)
    • Employee security awareness training and completion tracking
    • Extensive vendor management library – hundreds of vendor-completed GLBA contracts & risk assessments
    • Device & systems inventory automation and mapping tools
    • Unlimited industry-specific internal phishing simulations to train staff
    • Complete 50-state privacy compliance required by your state (CA, CO, CT, DE, IA, IN, MT, OR, TN, TX, UT, VA)
    • Website cookie consent banners and unique consumer privacy request portals
    • Annual report to the Board of Directors generated every year
    • Compliance Guarantee

      CPR/AED Certification

      FEATURES:

      • Instruction provided by Certified American Red Cross Instructors.
      • Practical, hands-on training sessions to practice CPR and AED techniques
      • Proper automated external defibrillator (AEDs) instruction and operation
      • American Red Cross exam and certification
      • Access to study materials, manuals, and resources for continued education and reference.
      • Available for organizations and groups, allowing for tailored training sessions.

      HR Fundamentals

      FEATURES:

      • Customized policy builder with real-time updates
      • E-sign functionality for required employee policies 
      • Online HR training with employee completion tracking
      • State-specific policies and training
      • Employee management tool
      • Training and policies include Workplace Violence, Active Shooter, IT and Electronic Device Use, Biometric Data Privacy, Sexual Harassment, and more 
      • HR Fundamentals access is included with any other ComplyAuto product

        Encrypted Messaging

        FEATURES:

        • Encrypt SMS text and email messaging among staff, clients, and customers when sending and receiving files
        • Track usage and detect violations in real-time
        • Advanced security features include auto-deletion of files, Multi-Factor Authentication protection, IP safelisting, and domain blocklisting
        • Supports compliance with various state and federal regulations and recognized industry standards: GLBA, HIPAA, SOC 2, ISO 27001, NIST, CIS Controls, SEC

          Safety Compliance Suite

          FEATURES:

          • Concierge on-site onboarding 
          • On-demand safety walkthroughs conducted by experienced EHS Pros at various intervals – once, twice, or four times per year
          • Comprehensive Online Training Library and employee progress tracking
          • Automated 50-State Legal Injury & Illness Reporting
          • Policy Builders with Automatic Updates
          • Simplified SDS Creation and Management
          • Guided risk mitigation
          • Signage builder & tracking
          • Efficient equipment inspections with QR Codes
          • Tier 1 Spill Prevention Control and Countermeasure Plan 
          • Automated Tier 2 environmental reporting for all 50 states 
          • Unlimited one-on-one support from our dedicated team
          • Workplace Violence and Active Shooter Policy and Training
          • Unlimited one-on-one support from our dedicated team
          • Automated Tier II environmental reporting for all 50 states.

            EduTech Course 3

            Program to Fulfill AG Disciplinary Order - $299/student

            The California AG routinely penalizes facilities that violate these laws and requires them to perform specific remedies while on probation. One of these remedies requires the ARD to take a course that outlines the laws and regulations of the Automotive Repair Act. This program fulfills the requirement.

            FEATURES:  

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            EduTech Course 2

            Program to Fulfill BAR Remedial Training - $299/student

            As part of their authority to levy fines and corrective actions against repair facilities, the Bureau of Automotive Repair may direct them to take a remedial training program. This program is intended for facilities who have already been identified by the BAR as needing corrective action and have committed to taking a remedial training course in lieu of specific penalties.The California Attorney General (AG) has required violating automotive repair dealers to take a course that instructs students on the laws and regulations of the Automotive Repair Act as part of the disciplinary order.

            FEATURES:

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            • Automated notification to the Bureau of Automotive Repair

             

            EduTech Course 1

            Automotive Repair Act Certification Training - $49/month per rooftop

            Provide advisors and technicians with the knowledge and tools necessary to comply with California laws and regulations and be viewed favorably by the Bureau of Automotive Repair.

            FEATURES:

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            F&I Compliance Suite

              • Precise Deal Jacket Audits to identify and address real-world F&I compliance issues accurately.
              • Focused Compliance on specific F&I compliance concerns such as Fair Lending Compliance Solutions, California Litigation, Vehicle Safety Recalls, Used Vehicle History, FTC Buyers Guide & Federal Warranty Disclosures, 
              • Automated EZ Cash Reporting & Anti-Money Laundering with IRS Reporting 
              • Spot Delivery & Unwind Management
              • Real-Time Issue Identification Quickly detect compliance gaps and issues, enabling swift corrective action and risk mitigation.
              • Online F&I Compliance Training 
              • Compliance Guarantee

                Device & Email Security

                FEATURES:

                The combined features create a dynamic defense system that adapts to evolving cybersecurity threats and secures the organization's digital ecosystem.

                • Continuous threat detection and response powered by Coro:
                  • EDR (Endpoint Detection and Response) 
                  • MDR (Managed Detection and Response) 
                  • 24/7 Security Operations Center team
                  • Swift response and alert to potential security breaches
                • Enhanced authentication and access control via Multi-factor Authentication (MFA) powered by Duo Security™
                • Advanced email security to shield e-threats such as phishing, malware, spam, and scams – integrates with Google Workspace & Microsoft Office 365.
                • Data governance and Data Loss Prevention (DLP)  detect and manage employee data-sharing practices. 
                • Device-level encryption for Windows and macOS
                • Public & unencrypted wifi blocking
                • Next-gen antivirus
                • Automated password policy and session locking enforcement