Here is a brief summary of the points Brad discusses
- Potential reporting under federal regulations
- FTC recently amended the Safeguards Rule to include a requirement to report to the FTC any "notification event" (commonly referred to as a "breach") involving 500 or more customers' unencrypted data as soon as possible, and no later than 30 days after discovery of the event.
- Dealer must report the breach even if it happened at a vendor.
- FTC reports are public information.
- Potential reporting under state law
- Definitions, timeframes, and reporting thresholds differ among the states.
- State laws often require a dealer to provide customer notification, and a dealer may also have to notify a state agency.
(Check out the ComplyAuto breach reporting wizard tool for more information.)
- Business Interruption Insurance Coverage
Dealers whose operations are impacted by the CDK systems being down might consider exploring whether they have business interruption coverage under any of their insurance policies that could provide relief for expenses and losses arising from the interruption in business resulting from the outage. Each insurance policy is different and historically business interruption coverage was associated with physical casualties (e.g., fire damage), but in recent years some cyber insurance policies have included business interruption coverage.