Software can help retailers comply with privacy laws

Posted by

on


ComplyAuto was formed by a dealer who hired software developers to create tools for retailers to comply with complicated privacy laws.


In 2019, months before the California Consumer Privacy Act was set to take effect, Chris Cleveland started to figure out how much data his dealership group, Galpin Motors, collected about its customers.


Cleveland, Galpin’s compliance director, spent months mapping out consumer data to prepare for the new law, which gives consumers rights to know the data businesses collect about them and to limit how businesses can use it.


During his research, Cleveland realized that notifying vendors of a consumer’s request under the law, figuring out which vendors had access to an individual customer’s data and understanding what data vendors even kept was practically a full-time job.

“There’s got to be software out there that can do this for us, automatically, right? There’s no way that this is a sustainable process to have to manually respond to every one of these requests,” Cleveland said. “To our surprise, there really wasn’t any software out there that did anything like that.”

So Cleveland and friend Shane McCallan, who also had worked in automotive compliance, decided to hire software developers to build their own. ComplyAuto was built for their own dealerships, but by October 2020, the pair began to offer the services to other stores. It’s now a standalone business with more than 330 dealerships as customers.


Cleveland, 32, who is ComplyAuto’s CEO and continues to work at Galpin, spoke with Staff Reporter Lindsay VanHulle. Here are edited excerpts.

On the challenges of privacy compliance: The average dealership — what I’m learning is — they don’t have compliance professionals. They don’t have a compliance director. They don’t have an in-house attorney.

A lot of the dealerships we’re working with, it’s the [general manager] who’s been tasked with CCPA compliance, or it’s the marketing director, and they’re just like, “This is way outside of my wheelhouse.”
You think it was hard for us, Shane and I, to do it in our own groups — [it] took us months and months to figure out. Imagine a dealership [that] doesn’t have a legal department. And so the pain points are even harder for them to get their arms around. They don’t even know where to start.
On why dealerships should care: Privacy is just becoming a brand promise. Consumers are rightfully concerned about their privacy, which is why you see this movement throughout the U.S. of states enacting privacy legislation.


It goes a long way for dealerships to say, “Hey, we care about your privacy. We’re going to allow you to make decisions on how we share your information. We’re going to allow you to opt out to tracking third-party cookies that track you across Facebook and things like that.”


I think people want that. It’s almost like social responsibility.


On how the tool works: Do you ever use TurboTax? [It] takes a very complex process like filing your state and federal taxes and turns it into simple yes-or-no questions. We have a dealer-centric approach to that.
So, for example, for each category of personal information, we’ll ask targeted questions like, “Do you track your service loaners?” Because if you do, you’re obviously collecting geolocation data on those customers, and you got to disclose that.

So we kind of go through this wizard with simple yes-or-no questions that takes that eight-month process into literally 20 minutes or less.


On ComplyAuto’s future plans: I can’t share too much about it right now, but it will just be the ultimate compliance solution for everything else that isn’t data security.

So think of traditional sales and F&I compliance. We’re going to modernize that — make deal jacket audits and the old-school methods of compliance a thing of the past and turn it into something where you don’t need to train your salespeople to be lawyers.


On staying ahead when it comes to data privacy: Under the CCPA, dealerships are one of the few industries that collect literally every category [of] information covered under the law, just because of the nature of the dealership. You’re doing finance transactions. You’re doing test drives, so it’s driver’s license info. You’re doing service; they’ve got vehicle information. Some dealerships even collect geolocation data when they’re tracking loaners. We’re doing digital marketing and all the website stuff
We’re collecting a lot of personal information. And it’s just naive of dealers to think that this isn’t going to be an issue moving forward. And to just kind of wait until it affects them is a mistake because, as I learned at Galpin, it is not a quick, overnight process.

Source URL: https://www.autonews.com/technology/software-can-help-retailers-comply-privacy-laws

New CCPA Regulations Already Went into Effect. Are You Covered?
Personal Data: Update on California’s Personal Data Laws (CCPA) and Lessons from the VW-Audi Data Breach

Mock OSHA Assessment

FEATURES:

  • On-demand eight-hour assessment that imitates a real OSHA audit.
  • Conducted by an EHS Pro with OSHA-10 or OSHA-30 certification and 5+ years of experience. 
  • Simulated employee interviews
  • Issue tracking and task management
  • Detailed assessment reports after the assessment with images, videos, and recommended steps for remediation.

    Privacy & Cyber Compliance Suite

    FEATURES:

    • Custom legal policies with real-time updates, including the Information Security Program (ISP)
    • Customized Incident Response Plan (IRP)
    • Internal risk assessment tools and hands-on guidance
    • Biannual penetration testing (2) 
    • Biannual vulnerability scans (2)
    • Employee security awareness training and completion tracking
    • Extensive vendor management library – hundreds of vendor-completed GLBA contracts & risk assessments
    • Device & systems inventory automation and mapping tools
    • Unlimited industry-specific internal phishing simulations to train staff
    • Complete 50-state privacy compliance required by your state (CA, CO, CT, DE, IA, IN, MT, OR, TN, TX, UT, VA)
    • Website cookie consent banners and unique consumer privacy request portals
    • Annual report to the Board of Directors generated every year
    • Compliance Guarantee

      CPR/AED Certification

      FEATURES:

      • Instruction provided by Certified American Red Cross Instructors.
      • Practical, hands-on training sessions to practice CPR and AED techniques
      • Proper automated external defibrillator (AEDs) instruction and operation
      • American Red Cross exam and certification
      • Access to study materials, manuals, and resources for continued education and reference.
      • Available for organizations and groups, allowing for tailored training sessions.

      HR Fundamentals

      FEATURES:

      • Customized policy builder with real-time updates
      • E-sign functionality for required employee policies 
      • Online HR training with employee completion tracking
      • State-specific policies and training
      • Employee management tool
      • Training and policies include Workplace Violence, Active Shooter, IT and Electronic Device Use, Biometric Data Privacy, Sexual Harassment, and more 
      • HR Fundamentals access is included with any other ComplyAuto product

        Encrypted Messaging

        FEATURES:

        • Encrypt SMS text and email messaging among staff, clients, and customers when sending and receiving files
        • Track usage and detect violations in real-time
        • Advanced security features include auto-deletion of files, Multi-Factor Authentication protection, IP safelisting, and domain blocklisting
        • Supports compliance with various state and federal regulations and recognized industry standards: GLBA, HIPAA, SOC 2, ISO 27001, NIST, CIS Controls, SEC

          Safety Compliance Suite

          FEATURES:

          • Concierge on-site onboarding 
          • On-demand safety walkthroughs conducted by experienced EHS Pros at various intervals – once, twice, or four times per year
          • Comprehensive Online Training Library and employee progress tracking
          • Automated 50-State Legal Injury & Illness Reporting
          • Policy Builders with Automatic Updates
          • Simplified SDS Creation and Management
          • Guided risk mitigation
          • Signage builder & tracking
          • Efficient equipment inspections with QR Codes
          • Tier 1 Spill Prevention Control and Countermeasure Plan 
          • Automated Tier 2 environmental reporting for all 50 states 
          • Unlimited one-on-one support from our dedicated team
          • Workplace Violence and Active Shooter Policy and Training
          • Unlimited one-on-one support from our dedicated team
          • Automated Tier II environmental reporting for all 50 states.

            EduTech Course 3

            Program to Fulfill AG Disciplinary Order - $299/student

            The California AG routinely penalizes facilities that violate these laws and requires them to perform specific remedies while on probation. One of these remedies requires the ARD to take a course that outlines the laws and regulations of the Automotive Repair Act. This program fulfills the requirement.

            FEATURES:  

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            EduTech Course 2

            Program to Fulfill BAR Remedial Training - $299/student

            As part of their authority to levy fines and corrective actions against repair facilities, the Bureau of Automotive Repair may direct them to take a remedial training program. This program is intended for facilities who have already been identified by the BAR as needing corrective action and have committed to taking a remedial training course in lieu of specific penalties.The California Attorney General (AG) has required violating automotive repair dealers to take a course that instructs students on the laws and regulations of the Automotive Repair Act as part of the disciplinary order.

            FEATURES:

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            • Automated notification to the Bureau of Automotive Repair

             

            EduTech Course 1

            Automotive Repair Act Certification Training - $49/month per rooftop

            Provide advisors and technicians with the knowledge and tools necessary to comply with California laws and regulations and be viewed favorably by the Bureau of Automotive Repair.

            FEATURES:

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            F&I Compliance Suite

              • Precise Deal Jacket Audits to identify and address real-world F&I compliance issues accurately.
              • Focused Compliance on specific F&I compliance concerns such as Fair Lending Compliance Solutions, California Litigation, Vehicle Safety Recalls, Used Vehicle History, FTC Buyers Guide & Federal Warranty Disclosures, 
              • Automated EZ Cash Reporting & Anti-Money Laundering with IRS Reporting 
              • Spot Delivery & Unwind Management
              • Real-Time Issue Identification Quickly detect compliance gaps and issues, enabling swift corrective action and risk mitigation.
              • Online F&I Compliance Training 
              • Compliance Guarantee

                Device & Email Security

                FEATURES:

                The combined features create a dynamic defense system that adapts to evolving cybersecurity threats and secures the organization's digital ecosystem.

                • Continuous threat detection and response powered by Coro:
                  • EDR (Endpoint Detection and Response) 
                  • MDR (Managed Detection and Response) 
                  • 24/7 Security Operations Center team
                  • Swift response and alert to potential security breaches
                • Enhanced authentication and access control via Multi-factor Authentication (MFA) powered by Duo Security™
                • Advanced email security to shield e-threats such as phishing, malware, spam, and scams – integrates with Google Workspace & Microsoft Office 365.
                • Data governance and Data Loss Prevention (DLP)  detect and manage employee data-sharing practices. 
                • Device-level encryption for Windows and macOS
                • Public & unencrypted wifi blocking
                • Next-gen antivirus
                • Automated password policy and session locking enforcement