{"id":1027,"date":"2022-04-28T09:34:26","date_gmt":"2022-04-28T14:34:26","guid":{"rendered":"http:\/\/efgintelligence.com\/lendingcurve\/?p=1027"},"modified":"2022-04-28T09:34:26","modified_gmt":"2022-04-28T14:34:26","slug":"data-security-compliance-in-2022","status":"publish","type":"post","link":"https:\/\/efgintelligence.com\/lendingcurve\/data-security-compliance-in-2022\/","title":{"rendered":"Data Security Compliance in 2022"},"content":{"rendered":"<p>According to the nonprofit <a href=\"https:\/\/www.idtheftcenter.org\/post\/the-identity-theft-resource-centers-inaugural-2021-business-aftermath-report-shows-the-impacts-identity-crimes-have-on-small-businesses\/\">Identity Theft Resource Center<\/a>, more than half of all small businesses in the US experienced at least one security or data breach in 2021, a 17 percent increase from 2020, at an average expense of $250,000 to $500,000 per incident. As automotive lenders and dealers increase their use of digital sales and technology to house personal and confidential information, data breach incidents have a direct impact on both revenue and regulatory compliance.<\/p>\n<h3>The Safeguards Rule<\/h3>\n<p>The Federal Trade Commission issued a final rule that amends the Safeguards Rule (the \u201cRule\u201d) that went into effect January 10, 2022. The Rule places requirements on \u201cfinancial institutions\u201d regarding information security programs and the use of customer information. The amended rule notably expands the \u201cfinancial institution\u201d definition, which is now applicable to debt collectors and certain debt buyers, among others. Many businesses are now finding themselves subject to the Rule for the first time.<\/p>\n<p><strong>Update:<\/strong> Prior to the revisions, the Rule required covered entities to perform a risk assessment and then develop and implement safeguards to address identified risks. Now, risk assessments must include <u>specific criteria and be in writing.<\/u><!--more--><\/p>\n<p><strong>Update:<\/strong> Financial institutions must \u201caddress access controls, data inventory and classification, encryption, secure development practices, authentication, information disposal procedures, change management, testing, and incident response.\u201d<\/p>\n<p><strong>Update:<\/strong> While employee training and vendor oversight was part of the existing rule, the amended rule takes these to the next level.\u00a0 Covered entities are now required to have <u>\u201cmechanisms designed to ensure that such training and oversight are effective.\u201d<\/u><\/p>\n<p><strong>Update: <\/strong>Auto lenders must contact their service providers to ensure the <u>providers also implement and maintain appropriate safeguards<\/u> to protect consumer information.<\/p>\n<p><strong>How are you working with your dealership partners and consumer protection product administrators to ensure compliance on all levels?<\/strong> Automotive lenders and dealers work with a significant amount of consumer confidential information, including social security numbers, pay stubs, utility bills, and more. In addition, most dealers in the U.S. have migrated to web-based platforms for conducting business, especially with regards to credit applications.<\/p>\n<h3>Data Security and EFG<\/h3>\n<p>At EFG, we recognize that data security is mission critical to successfully conducting business in today\u2019s market.<\/p>\n<p>It is for this reason that EFG Companies became the first F&amp;I product administrator to achieve <strong>SOC 1 SSAE-16<\/strong> certification in 2016. Since then, EFG has aggressively pursued heightened controls and protocols each year and has also achieved <strong>SOC 2 SSAE-18<\/strong> certification.<\/p>\n<p>Administered by the American Institute of Certified Public Accountants under the Statement of Standards for Attestation Engagements (SSAE), <strong>the SOC 1 and SOC 2 certifications are the most widely recognized standard<\/strong> providing companies with a method for reporting information about the design and operation of internal systems and controls relating to privacy and security regulations.<\/p>\n<p>Additionally, the company recently achieved certification by the Payment Card Industry Security Standards Council (PCI SSC) as <strong>PCI Data Security Standard compliant.<\/strong> PCI Data Security Standards (PCI DSS) protect payment account data for merchants, service providers, and financial institutions throughout the payment lifecycle, removing the incentive for criminals to steal it. Specifically, PCI DSS contains a set of requirements based on collaboration between major card brands including American Express, Discover, Mastercard and Visa, to prevent payment data breaches and payment card fraud. Companies achieving certification deliver a higher standard of security for personal confidential information and compliance with federal, state, and local regulatory requirements.<\/p>\n<p>With more than 40 years of experience in advising clients on how to achieve compliant profitability, EFG Companies has the processes, training and tools to deliver the utmost <a href=\"https:\/\/www.efgcompanies.com\/compliance-security\/\">data security<\/a> for our clients, partners and contract holders. We help dealers and lenders stay on the right side of compliance with ongoing training, <a href=\"https:\/\/www.efgcompanies.com\/services\/common-sense-compliance\/\">compliance reviews<\/a>, and <a href=\"https:\/\/afip.com\/\">AFIP certification<\/a>. <a href=\"https:\/\/www.efgcompanies.com\/about-efg\/contact-us\/\">Contact us<\/a> today to learn more.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to the nonprofit Identity Theft Resource Center, more than half of all small businesses in the US experienced at least one security or data breach in 2021, a 17 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1028,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"jetpack_post_was_ever_published":false,"footnotes":""},"categories":[79],"tags":[259,185,101,254,258],"class_list":["post-1027","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","tag-data-security","tag-federal-trade-commission","tag-ftc","tag-identity-theft-resource-center","tag-safeguards-rule"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/efgintelligence.com\/lendingcurve\/wp-content\/uploads\/sites\/4\/2022\/04\/Featured-Article-Template-1.png?fit=1200%2C526&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p7ht2K-gz","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/posts\/1027","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/comments?post=1027"}],"version-history":[{"count":1,"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/posts\/1027\/revisions"}],"predecessor-version":[{"id":1029,"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/posts\/1027\/revisions\/1029"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/media\/1028"}],"wp:attachment":[{"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/media?parent=1027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/categories?post=1027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/efgintelligence.com\/lendingcurve\/wp-json\/wp\/v2\/tags?post=1027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}