FTC's plan too costly to car dealers, NADA says
Skip to main content
Sister Publication Links
  • Automotive News Canada
  • Automotive News Europe
  • Automotive News Mexico
  • Automotive News China
  • Automobilwoche
AN-LOGO-BLUE
Subscribe
  • Subscribe
  • Account
  • login
  • HOME
  • NEWS
    • Dealers
    • Automakers & Suppliers
    • News by Brand
    • Cars & Concepts
    • China
    • Shift
    • Mobility Report
    • Special Reports
    • Digital Edition Archive
    • This Week's Issue
    • GM appoints new director for Shanghai design studio
      China explores ambitious goal for EV sales by 2035
      Peugeot, Dongfeng to restructure joint venture
      Honda sales rise on Civic, CR-V, hybrids
    • Autonomous technology has grown deep roots in the farming sector
      The family tree of self-driving tech
      Military working to make its autonomous technology smarter
      Q&A with Red Whittaker
    • VW replaces head of ride-hailing unit amid strategy discord
      Spotting a fire truck ahead is easy for people, not so for cars
      GM taps Google for in-vehicle apps, voice assistant starting in 2021
      Japan will let driverless cars roam freely ahead of 2020 Olympics
    • Dealerships owned by ex-NFL stars face collapse, litigation
      Want a luxury car? Try a Kia
      Costly lesson of tortuous legal battle: Get it in writing
      Denny Hecker: A changed man?
    • A Corvette dealer's vow: I will not mark up
      Volvo plant may anchor Virginia R&D corridor
      India crashes, clouding global picture
      Westbrook racks up the dealership points
    • Access F&I
    • Fixed Ops Journal
    • Marketing
    • Used Cars
    • Sales
    • Best Practices
    • Dealership Buy/Sell
    • NADA
    • NADA Show
    • Automakers
    • Manufacturing
    • Suppliers
    • Regulations & Safety
    • Executives
    • Leading Women Network
    • Guide to Economic Development
    • PACE Awards
    • CES
    • Management Briefing Seminars
    • World Congress
    • Aston Martin
    • BMW
      • Mini
      • Rolls-Royce
    • Daimler
      • Mercedes Benz
      • Smart
    • Fiat Chrysler
      • Alfa Romeo
      • Chrysler
      • Dodge
      • Ferrari
      • Fiat
      • Jeep
      • Maserati
      • Ram
    • Ford
      • Lincoln
    • General Motors
      • Buick
      • Cadillac
      • Chevrolet
      • GMC
      • Holden
    • Honda
      • Acura
    • Hyundai
      • Genesis
      • Kia
    • Mazda
    • McLaren
    • Mitsubishi
    • Nissan
      • Infiniti
    • PSA
      • Citroen
      • Opel
      • Peugeot
    • Renault
    • Subaru
    • Suzuki
    • Tata
      • Jaguar
      • Land Rover
    • Tesla
    • Toyota
      • Lexus
    • Volkswagen
      • Audi
      • Bentley
      • Bugatti
      • Lamborghini
      • Porsche
      • Seat
      • Skoda
    • Volvo
    • (Discontinued Brands)
    • Auto Shows
      • Detroit Auto Show
      • New York Auto Show
      • Los Angeles Auto Show
      • Chicago Auto Show
      • Geneva Auto Show
      • Paris Auto Show
      • Frankfurt Auto Show
      • Toronto Auto Show
      • Tokyo Auto Show
      • Shanghai Auto Show
      • Beijing Auto Show
    • Future Product Pipeline
    • Photo Galleries
    • Car Cutaways
    • Design
  • OPINION
    • Blogs
    • Cartoons
    • Keith Crain
    • Automotive Views with Jason Stein
    • Columnists
    • China Commentary
    • Editorials
    • Letters to the Editor
    • Send us a Letter
    • Oil filters poised for a big change
      Have we reached peak supercar?
      Nissan's ProPilot 2.0 advances, frustrates
      Does Ford's '20 Mustang Shelby GT500 tip scale at 4,225 pounds?
    • view gallery
      1 photos
      Nissan's computer glitch
      view gallery
      1 photos
      Treasury Note Flip Flop
      view gallery
      1 photos
      Taking Charge
      view gallery
      1 photos
      Monthly Guessing Game
    • Piech left a large legacy
      Buy, sell or hold your store?
      When is enough, enough?
      Will VW's diesel scandal ever end?
    • September 6, 2019 | Wahl could bring cohesive message to GM’s brands
      August 30, 2019 | Piech’s impact is felt across the industry
      August 23, 2019 | VW doesn’t need partnership with Tesla
      August 16, 2019 | Car culture is alive and well
    • Setting the record straight on Cadillac
      Don't kill the Land Cruiser, just return it to its roots
      Piech left a large legacy
      Touch screens in cars don't make us safer — yet
    • Beijing must face reality in bid to spur auto sales
      It's time for Beijing to deregulate pickup use
      Aston Martin's 20M-pound payout vanishes behind China EV startup's woes
      China's soft market turns brutal for domestic brands
    • Get deal with Japan finished
      Fear of failure leads to more bad behavior
      Congress can't leave AV rules on autopilot
      Have we seen this all before? Only some of it
    • Many reasons not to rush into EVs
      Trump productive in long-term view
      Our last car won't be electric
      Extend tax credit on alternative fuels
  • DATA CENTER
  • VIDEO
    • AutoNews Now
    • First Shift
    • Special Video Reports
    • Weekend Drive
    • AutoNews Now: New, redesigned CUVs enter hot segment
      AutoNews Now: GM names Wahl global CMO
      AutoNews Now: Japan's Big 3 see U.S. sales soar in August
      AutoNews Now: UAW targets GM in contract talks
    • First Shift: Barra on Trump meeting: 'Productive and valuable'
      First Shift: August sales rise on light trucks, 'aggressive' incentives
      First Shift: FCA phasing out Fiat 500, 500e sales in U.S.
      First Shift: Dealerships close as Dorian approaches
    • What a Chevy dealer gets from his $7,000 car shows
      Small-town Toyota store rips up dealer playbook, becomes hotbed of innovation
      ‘It’s more humane’: Why one dealer pays service techs by the hour
      'You have to want it': Rising auto retailers tell their stories
    • Lear's focus on customer health, comfort, convenience
      Why JM Family is watching Amazon
      Mobility in the evolving urban ecosystem
      Celebrating car culture in the Motor City, Pebble Beach
  • EVENTS & AWARDS
    • Events
    • Awards
    • World Congress
    • Retail Forum: NADA
    • Canada Congress
    • Marketing 360: L.A.
    • Europe Congress
    • Retail Forum: Chicago
    • Leading Women Conference Detroit
    • Retail Forum: Toronto
    • Fixed Ops Journal Forum
    • 100 Leading Women
    • 40 Under 40 Retail
    • All-Stars
    • Best Dealership To Work For
    • PACE Awards
    • Rising Stars
    • Europe Rising Stars
  • JOBS
  • +MORE
    • Leading Women Network
    • Podcasts
    • Webinars
    • Publishing Partners
    • Classifieds
    • People on the Move
    • Newsletters
    • Contact Us
    • Media Kit
    • RSS Feeds
    • Shift: A Podcast About Mobility
    • Special Reports Podcasts
    • Weekend Drive Podcasts
    • Ally: Do It Right
    • DealerSocket
    • Facebook: The road to a zero-friction future
    • Guide To Economic Development
    • PayPal Credit: How consumer financing helps drive sales for online auto parts retailers
MENU
Breadcrumb
  1. Home
  2. Dealers
September 09, 2019 12:00 AM

FTC's plan too costly to dealers, NADA says

Lindsay VanHulle Jackie Charniga
  • Tweet
  • Share
  • Share
  • Email
  • More
    Print

    Potential revisions to federal data security rules could add billions of dollars in costs to U.S. auto dealerships in total, as stores already are slumped under the weight of shrinking margins and slowing new-vehicle sales.

    Proposed changes to the Federal Trade Commission's Safeguards Rule, which dictates how financial institutions protect consumer data, would require dealerships nationwide to shell out hundreds of thousands of dollars each annually to comply, on top of what they spend to comply with other regulations, leaders of the National Automobile Dealers Association contend. NADA opposes the proposed changes and is asking the FTC to leave the rule as it is.

    Photo
    Welch: Smaller dealers will feel the squeeze.

    "The numbers are staggering, even if we're off by 10 or 20 percent," NADA President Peter Welch told Automotive News.
    The association estimates the total expense incurred by U.S. franchised dealerships could top $2.2 billion in initial startup costs, plus $2.1 billion per year in ongoing costs.

    "It puts a squeeze particularly on our smaller dealers," Welch said.

    In addition to higher costs for dealers, the proposed provisions may not even prevent some of the breaches, as intended, dealers and dealer advocates say. Lower compliance could be a consequence. But auto retailers' views aren't universally supported: Consumer advocates say any extra expenses should be the cost of doing business if that business includes financial transactions.

    Some dealership software companies, including prominent dealership management system providers, told Automotive News they generally support enhanced data security. But they declined to comment directly on the proposals or share details of upgrades they might need to make should the FTC enact the changes.

    DMS giant CDK Global Inc., for instance, told Automotive News in an email: "We consistently monitor and update security protocols based on changing regulations and requirements and we believe we are well-positioned to comply with the proposed changes to the (Gramm-Leach-Bliley) Safeguards Rule should they ultimately be adopted."

    The Safeguards Rule, which took effect in 2003, implements the privacy provisions in the federal Gramm-Leach-Bliley Act. As it stands, the rule requires dealerships to designate a program coordinator; conduct risk assessments on software handling sensitive customer data; identify risks and design and implement safeguards to protect against them; oversee service providers; and periodically evaluate the program.

    In its proposed changes, issued in March, the FTC seeks to strengthen the guidelines for how businesses considered financial institutions under the rule should protect consumers' private information as technology advances. The proposed changes are under consideration, FTC officials have said, with no timetable for a decision.

    Auto dealers are required to follow the Safeguards Rule because they offer lease and financing agreements. In public comments to the FTC, submitted in August, NADA and the National Independent Automobile Dealers Association, which represents nonfranchised used-car dealerships, claim the FTC has not provided enough data to justify that the proposed rule changes will lead to meaningful improvements in data security.

    "These new requirements reflect an unhelpful shift from a prudent reasonableness standard to a set of prescriptive requirements that may make sense for certain entities but are ill-suited to other financial institutions — in particular, for smaller entities," NADA wrote in its public comment.

    Prohibitively expensive

    NADA projected the cost the proposed requirements would place on auto dealers in a study of small and midsize dealerships.

    Small dealerships would pay $220,400 initially and $217,800 in annual costs, NADA estimates. Midsize operations would pay $367,550 initially and $336,050 in annual costs. Dealerships would pay both the upfront and annual costs in the first year, according to NADA.

    Photo
    Mierzwinski: Rule too vague

    NADA's Welch called the estimates conservative, noting that it's difficult to say how many dealerships already follow some of the proposed requirements. Larger dealership groups may be able to take advantage of economies of scale to lower costs per store.

    "While the numbers reflected in the cost analysis may be easily absorbable by a large, multi-billion-dollar financial institution, it will be prohibitive for many, if not most of our members, who simply do not have the revenue structure, or the margins to absorb costs of this nature and scale," NADA said in its comments to the FTC. Dealerships would have to pass along the costs to consumers, Welch told Automotive News.

    Michael Alf, general manager at St. Charles Toyota in Illinois, said he's worried about additional expenses related to increased regulations.

    "This is just another threat on the horizon of expenses going up," Alf said. "The hardest thing we deal with in the auto industry is the rise in expenses."

    Jim Ganther, a dealer consultant and president of Mosaic Compliance Services in Tampa, Fla., said an unintended consequence of higher costs is lower compliance. A chief information security officer position — one of the FTC's proposed changes — could cost $150,000, he said. Companies can take other steps that protect data, as the Safeguards Rule intends, but don't cost a lot of money, from training employees to spot a phishing attack to installing locked doors to the F&I office, Ganther added.

    Rather than tinkering with the existing rule, the FTC should focus on ensuring companies comply with current standards, he said.

    "When you make following the rule prohibitively expensive, you increase the odds of ignoring it," Ganther said.

    Widespread concern

    Dealers aren't alone in that claim. Trade groups representing industries as diverse as credit bureaus, wireless carriers and higher education similarly called for more flexibility and less one-size-fits-all in submitted comments.

    Their argument, however, doesn't carry a lot of weight with consumer advocates, who generally praised the proposed changes in a joint comment to the FTC. U.S. Public Interest Research Group joined more than a dozen consumer and other advocacy groups, including the National Consumer Law Center and the Consumer Federation of America, in describing the proposals as "reasonable and common-sense measures that any company dealing with large amounts of consumer personal information should take."

    Cost to comply
    The National Automobile Dealers Association says small and midsize dealers will each have to spend hundreds of thousands of dollars initially and annually to comply with proposed changes to the FTC's Safeguards Rule. Here is NADA's step-by-step estimate:
      Small Dealer*   Midsize Dealer**
      One-time cost Annual cost   One-time cost Annual cost
    Proposed change          
    Chief information
    security officer
    $24,000 $42,000   $31,000 $60,000
    Information security program
    based on written risk assessment
    $20,500 $20,500   $32,500 $32,500
    Data and systems
    inventory
    $13,500 $9,000   $20,000 $11,500
    Encrypt data at rest
    and in transit
    $8,000 $8,000   $10,000 $9,000
    Adopt secure development practices $9,000 $37,500   $9,000 $37,500
    Multifactor authentication for all
    accessing customer data
    $17,500 $6,500   $50,000 $30,500
    Include audit trails $20,000 $12,000   $40,000 $24,000
    Secure disposal procedure $20,000 $3,600   $40,000 $18,000
    Procedures for
    change management
    $20,000 $2,000   $40,000 $2,000
    Unauthorized activity monitoring $15,000 $26,000   $25,000 $32,000
    Penetration, vulnerability testing $15,500 $17,500   $24,750 $28,750
    Employee security
    awareness training
    $1,400 $10,950   $2,800 $18,800
    Periodic assessment
    of service providers
    $12,000 $9,000   $16,500 $13,500
    Required incident response plan $16,000 $5,250   $16,000 $8,000
    Required written
    chief information security
    officer report
    $8,000 $8,000   $10,000 $10,000
    Total cost incurred $220,400 $217,800   $367,550 $336,050
    *Operating on 1 site with roughly 50 employees
    **Operating on as many as 5 sites with more than 50 employees
    Source: NADA study

    "The [auto] industry is doing what it does well: It is putting a lot of associates and junior lawyers to work trying to scare the government," said Ed Mierzwinski, senior director of federal consumer programs for U.S. Public Interest Research Group.

    Mierzwinski said dealers' compliance cost estimates are the "worst-case scenario" devised by paid consultants and that the FTC's final rule likely will incorporate more flexibility than industry associations claim it will.

    "I would contend that it's being updated because it was way too vague before, but it's not going to become one-size-fits-all," he told Automotive News.

    "The little car dealer doesn't have as much information about as many people [as a credit bureau], but at the same time can easily protect it."

    The proposed changes follow high-profile data breaches in recent years, from Equifax to Target Corp. to Capital One. Dealers are not immune: DealerBuilt, a dealership software vendor in Mason City, Iowa, in June settled with the FTC after a 2016 breach that affected more than 12.5 million customers at 130 stores. The settlement was formally approved last week, according to the FTC.

    ‘Significant' amendments

    It's not that auto dealers oppose taking steps to protect consumers' personal information. On the contrary, groups representing new- and used-car dealers say, their customers expect them to protect private data, and they have done so for years.

    Rather, they argue, the FTC's proposed changes remove flexibility that has, for more than 15 years, allowed financial institutions to comply with the law in a way that fits their business.

    Photo
    Petersen: No specific results

    Scott Dube, president of Bill Dube Hyundai in Wilmington, Mass., says dealerships carry consumer data that isn't necessarily implicated in the Safeguards Rule.

    "You bring your car in for an oil change — that has nothing to do with being a financial institution, nor does the FTC see it that way," Dube said. "But how do I treat some data one way and other data another way, especially when they're all in the same system?"

    Dube, a former president of the Massachusetts State Automobile Dealers Association and an NADA director, said he sees elements of the FTC proposal as a complete overhaul.

    While he is uncertain exactly how much in compliance costs his dealership takes on each year, Dube estimated it was around $10,000.

    NIADA, which represents more than 16,000 used-car dealers, pegged the ongoing, annual cost of compliance at $240,000 to $330,000, based on a survey of its dealership members and their information technology vendors.

    "This particular rule puts a lot of cost implementation on small businesses without pointing to very specific results that will come," Shaun Petersen, NIADA's senior vice president of legal and government affairs, told Automotive News.

    FTC spokeswoman Juliana Gruenwald told Automotive News the agency initially sought general feedback in August 2016, before proposed rule changes were drafted. The amendments released this year were "significant," Gruenwald said via email, prompting the agency to seek more comments before adopting a final rule.

    Cost-intensive personnel

    Franchised dealers are likely in the same boat as independent retailers when it comes to filling the chief information security officer position, Dube said.

    Dube's store has fewer than 30 employees and sells fewer than 100 vehicles, new and used, per month. Stores of this size will have particular trouble appointing a qualified person to that post, Dube said. NADA said its members estimated the salary required for that position could exceed $150,000 — though NADA used a much more conservative number related to outsourcing the position in the cost study it submitted to the FTC. NADA members also reported to the association that chief information security officer consulting services could cost as much as $10,000 per day.

    Dube has no qualms about the position itself — only that it's unnecessary for every dealership. Multinational banks maintaining millions, if not billions, of customer records require a dedicated person to manage information security, he said.

    But "in a small business, under 30 employees, you're going to hire a new, highly compensated employee that is purely an expense?" Dube said.

    "That, to me, is a solution in search of a problem."

    Letter
    to the
    Editor

    Send us a letter

    Have an opinion about this story? Click here to submit a Letter to the Editor, and we may publish it in print.

    Recommended for You
    Digital Edition
    THIS WEEK'S EDITION
    See our archive
    Fixed Ops Journal
    Fixed Ops Journal -- 8-19-19
    Read the issue
    See our archive
    Sign up for free newsletters
    EMAIL ADDRESS

    Please enter a valid email address.

    Please enter your email address.

    Please select at least one newsletter to subscribe.

    You can unsubscribe at any time through links in these emails. For more information, see our Privacy Policy.

    Get Free Newsletters

    Sign up and get the best of Automotive News delivered straight to your email inbox, free of charge. Choose your news – we will deliver.

    Subscribe Today

    Get 24/7 access to in-depth, authoritative coverage of the auto industry from a global team of reporters and editors covering the news that’s vital to your business.

    Subscribe Now
    Connect With Us
    • Facebook
    • Instagram
    • LinkedIn
    • Twitter

    Our Mission

    The Automotive News mission is to be the primary source of industry news, data and understanding for the industry's decision-makers interested in North America.

    AN-LOGO-BLUE
    Contact Us

    1155 Gratiot Avenue
    Detroit, Michigan
    48207-2997

    (877) 812-1584

    Email us

    Automotive News
    ISSN 0005-1551 (print)
    ISSN 1557-7686 (online)

    Fixed Ops Journal
    ISSN 2576-1064 (print)
    ISSN 2576-1072 (online)

    Resources
    • About us
    • Contact Us
    • Media Kit
    • Subscribe
    • Manage your account
    • Reprints
    • Ad Choices Ad Choices
    • Sitemap
    Legal
    • Terms and Conditions
    • Privacy Policy

    Connect With Us

    Connect With Us
    • Twitter
    • Facebook
    • Instagram
    • LinkedIn

    Our mission

    The Automotive News mission is to be the primary source of industry news, data and understanding for the industry's decision-makers interested in North America.

    Copyright © 1996-2019. Crain Communications, Inc. All Rights Reserved.
    • HOME
    • NEWS
      • Dealers
        • Access F&I
        • Fixed Ops Journal
        • Marketing
        • Used Cars
        • Sales
        • Best Practices
        • Dealership Buy/Sell
        • NADA
        • NADA Show
      • Automakers & Suppliers
        • Automakers
        • Manufacturing
        • Suppliers
        • Regulations & Safety
        • Executives
        • Leading Women Network
        • Guide to Economic Development
        • PACE Awards
        • CES
        • Management Briefing Seminars
        • World Congress
      • News by Brand
        • Aston Martin
        • BMW
          • Mini
          • Rolls-Royce
        • Daimler
          • Mercedes Benz
          • Smart
        • Fiat Chrysler
          • Alfa Romeo
          • Chrysler
          • Dodge
          • Ferrari
          • Fiat
          • Jeep
          • Maserati
          • Ram
        • Ford
          • Lincoln
        • General Motors
          • Buick
          • Cadillac
          • Chevrolet
          • GMC
          • Holden
        • Honda
          • Acura
        • Hyundai
          • Genesis
          • Kia
        • Mazda
        • McLaren
        • Mitsubishi
        • Nissan
          • Infiniti
        • PSA
          • Citroen
          • Opel
          • Peugeot
        • Renault
        • Subaru
        • Suzuki
        • Tata
          • Jaguar
          • Land Rover
        • Tesla
        • Toyota
          • Lexus
        • Volkswagen
          • Audi
          • Bentley
          • Bugatti
          • Lamborghini
          • Porsche
          • Seat
          • Skoda
        • Volvo
        • (Discontinued Brands)
      • Cars & Concepts
        • Auto Shows
          • Detroit Auto Show
          • New York Auto Show
          • Los Angeles Auto Show
          • Chicago Auto Show
          • Geneva Auto Show
          • Paris Auto Show
          • Frankfurt Auto Show
          • Toronto Auto Show
          • Tokyo Auto Show
          • Shanghai Auto Show
          • Beijing Auto Show
        • Future Product Pipeline
        • Photo Galleries
        • Car Cutaways
        • Design
      • China
      • Shift
      • Mobility Report
      • Special Reports
      • Digital Edition Archive
      • This Week's Issue
    • OPINION
      • Blogs
      • Cartoons
      • Keith Crain
      • Automotive Views with Jason Stein
      • Columnists
      • China Commentary
      • Editorials
      • Letters to the Editor
      • Send us a Letter
    • DATA CENTER
    • VIDEO
      • AutoNews Now
      • First Shift
      • Special Video Reports
      • Weekend Drive
    • EVENTS & AWARDS
      • Events
        • World Congress
        • Retail Forum: NADA
        • Canada Congress
        • Marketing 360: L.A.
        • Europe Congress
        • Retail Forum: Chicago
        • Leading Women Conference Detroit
        • Retail Forum: Toronto
        • Fixed Ops Journal Forum
      • Awards
        • 100 Leading Women
        • 40 Under 40 Retail
        • All-Stars
        • Best Dealership To Work For
        • PACE Awards
        • Rising Stars
        • Europe Rising Stars
    • JOBS
    • +MORE
      • Leading Women Network
      • Podcasts
        • Shift: A Podcast About Mobility
        • Special Reports Podcasts
        • Weekend Drive Podcasts
      • Webinars
      • Publishing Partners
        • Ally: Do It Right
        • DealerSocket
        • Facebook: The road to a zero-friction future
        • Guide To Economic Development
        • PayPal Credit: How consumer financing helps drive sales for online auto parts retailers
      • Classifieds
      • People on the Move
      • Newsletters
      • Contact Us
      • Media Kit
      • RSS Feeds