agent Entrepreneur logo
MenuMENU
SearchSEARCH

Equifax + Facebook = GDPR?

The European Union’s General Data Protection Regulation raises the bar for a number of compliance issues, particularly the way your dealer clients protect and defend their customers’ nonpublic personal information.

November 14, 2018
Equifax + Facebook = GDPR?

Photo via iStock

4 min to read


A colleague of mine asked me, “Who in the auto dealer industry really cares about the General Data Protection Regulation?” I thought about titling this article “GDPR: Who Cares?” But upon further reflection, I thought that the GDPR might bring focus to data management and data protection and give a sneak peek toward future trends.

The Question

Ad Loading...

Let’s start with some background. The Equifax data breach of 2017 affected almost half of all Americans, approximately 142 million people. Nonpublic personal information (NPI) such as names, Social Security numbers, birth dates, driver’s license numbers, and other information was disclosed. In 2018, approximately 50 million Facebook users’ profiles, including personal information, was obtained by Cambridge Analytica in one of the largest known social media network breaches. 

GDPR is a European Union data protection and privacy regulation which went into effect on May 25, 2018. GDPR establishes strict standards for consent and data breach notification (among other standards) and provides for penalties of up to 4% of global revenue.

In terms of data breach notification-based facts reported in the media, Equifax took 143 days to discover the data breach and 40 days after the discovery to notify affected individuals. Facebook is said to have discovered that users’ personal information was harvested some time in late 2015, but an announcement was not made until March 2018. (Note that Facebook claims that the harvesting of millions of user profiles by Cambridge Analytica was not a data breach.)

“The GDPR ‘sets the bar’ for data compliance. That bar is currently higher than contemplated U.S. standards.”

In the U.S., several bills on data breach have been introduced, most notably the Consumer Privacy Protection Act of 2017 and the Data Security and Breach Notification Act. The Consumer Privacy Protection Act of 2017 would establish a national standard for “comprehensive consumer privacy and data security programs” for larger companies. 

Ad Loading...

While the FTC, the U.S. attorney general and state attorneys general would have enforcement authority, there is no private right of action. (A private right of action is a case brought by the individual consumer rather than a regulatory entity such as the FTC.) The legislation only provides for notification of a data breach “as expediently as possible” and “without unreasonable delay” rather than a specific time period. 

The Data Security and Breach Notification Act also seeks to create a single standard rather than the current varying state requirements of data breach notification. The Data Security and Breach Notification Act includes a 30-day data breach reporting rule for larger companies (regarding non-healthcare data).

As opposed to the two proposed U.S. Acts above, the GDPR requires a 72-hour data breach notification. When this short timeline is combined with immense penalties, data security and management becomes much more important. 

The Answer

So, the answer to my friend asking who cares about GDPR is as follows: While most U.S. dealers will have few customers who are residents of the European Union or other factors subjecting them directly to the GDPR, the GDPR “sets the bar” for data compliance. That bar is currently higher than contemplated U.S. standards, but gives us all a look into the future. 

Ad Loading...

The GDPR represents a change, on a global scale, in the acceptable methods for handling data across the world. The GDPR elevates compliance to center stage and has quantifiable standards and enormous penalties to ensure it will be taken seriously.

We in America have been, perhaps, too lax with our data standards — think unsecured credit applications, unaccounted-for deal jackets, or DMS and other vendor systems with unfettered NPI access — and, to paraphrase the immortal Sam Cooke, “A change is going to come.” The only question is whether your shop is prepared for it. 

DISCLAIMER: Content provided in this article is intended for informational purposes only and should not be construed as legal advice and should not be relied upon or acted upon without you retaining counsel to provide specific legal advise based upon your particular situation, jurisdiction and circumstances. No duties are assumed, intended or created by this communication. No attorney- client relationship is being created by your review or use of this material.

© 2018 Robert J. Wilson, All Rights Reserved

Robert J. Wilson, Esquire (Bob) is a Philadelphia lawyer and is General Counsel for ARMD Resource Group. Bob is the principal of Wilson Law Firm and has over 30 years of experience both as a counselor and as a litigator in State and Federal Courts. Risk management, problem solving and dispute resolution are his core competencies. Bob’s practice is largely in the consumer finance space and he regularly consults with Lenders and contributes articles on various compliance related issues.

Topics:Industry
Subscribe to Our Newsletter

More Industry

chart showing the quarterly electric vehicle market share from 2020-2025
Industryby Lauren LawrenceMarch 27, 2026

EV Sales Slide While Hybrids Climb

California, as usual, led the country in EV registrations in the fourth quarter, but the U.S. as a whole saw a 43% year-over-year volume decrease.

Read More →
Photo of new car's tail light
Industryby Hannah MitchellMarch 26, 2026

New-Vehicle Sales Ride Tax Returns Wave

Forecasts show that the spring sales season is rising above overriding economic concerns, among them continuously rising car prices, trade tariffs, elevated interest rates, and now a war.

Read More →
Photo of Toyota car parked in front of a Toyota dealership
Industryby Hannah MitchellMarch 23, 2026

2025 Dealership Buy-Sells a Record

The Kerrigan Index shows that despite a chaotic year of musical trade tariffs, high vehicle prices and more roadblocks, acquirers still flush with pandemic-era cash accelerated the consolidation pace.

Read More →
Ad Loading...
Infographic from ABB titled “The Intelligent Factory is Accelerating as Automation Investment Increases.” It shows a robotic manufacturing assembly line on the left and key statistics on the right. Highlights include: 33% of manufacturers prioritize cost control, 31% are increasing investment in automation and robotics, 30% cite labor shortages and rising wages as challenges, and 34% identify energy and material costs as a leading concern. Additional sections explain competitive pressures and how automation technologies like robots improve efficiency, consistency, and productivity in modern manufacturing.
Industryby Lauren LawrenceMarch 19, 2026

Automation Acceleration Seen in Manufacturing

Labor shortages, material costs and tariffs are just a few of the reasons automakers are looking to expand their investments in automation and robotics this year.

Read More →
Overhead view of container cargo ship loaded with vehicles
Industryby Hannah MitchellMarch 19, 2026

War Threatens Major U.S. Auto Exports Stream

The Middle East imports a sizable share of vehicles made in the states. It’s unclear how the Iran War could affect the keystone market for U.S. automakers.

Read More →
row of cars, used vehicle demand spikes, chart showing data spike, F&I and Showroom logo
Showroomby Lauren LawrenceMarch 11, 2026

Used Market Gains Speed

New-vehicle sales fell year-over-year for the fifth month in a row in February, making retail deliveries the slowest they’ve been since 2023, according to a CarGurus report.

Read More →
Ad Loading...
Graphic showing used-vehicle days to turn rate
Showroomby StaffMarch 10, 2026

Black Book: Weekly Market Update

Both vehicle values and conversion rates sped up last week as two segments outperformed in the pre-spring burst of buying.

Read More →
Photo of Chevrolet Bolt on a beach
Showroomby Hannah MitchellMarch 9, 2026

Economical Electric

GM says it sells the cheapest electric vehicle in the U.S. market. It explains how it made improvements to the entry-level EV while keeping its price down.

Read More →
Hyundai logo and 40 Years in America in front of a starry background
Industryby Lauren LawrenceMarch 5, 2026

Hyundai Celebrates U.S. Milestone

The South Korean automaker said it supports 570,000 jobs in the U.S. with a planned investment of $26 billion between 2025 and 2028, according to President and CEO José Muñoz.

Read More →
Ad Loading...
Showroomby Lauren LawrenceMarch 4, 2026

Used-Vehicle Program Aims to Draw More Buyers

GM says more than 750 dealers across the U.S. are enrolled in CarBravo and that in January CarBravo dealers sold over two times the certified volume of Chevrolet, Buick and GMC dealers using traditional CPO.

Read More →