agent Entrepreneur logo
MenuMENU
SearchSEARCH

It’s the Same, but Different

While we do not know what the political shift brought about by the last election cycle will do with any degree of certainty, the popular perception is that we can expect increased regulatory scrutiny.

by Robert J. Wilson, Esq.
March 25, 2021
It’s the Same, but Different

While we do not know what the political shift brought about by the last election cycle will do with any degree of certainty, the popular perception is that we can expect increased regulatory scrutiny.

IMAGE: Kanawatvector via GettyImages.com

4 min to read


Many of us are suffering from “new normal” fatigue. As we struggle to understand all the new challenges, some describe the new normal as the same but different. We are tired of the changes forced on us by the pandemic and other events, but in the compliance world, the standards have remained constant. While we do not know what the political shift brought about by the last election cycle will do with any degree of certainty, the popular perception is that we can look forward to increased regulatory scrutiny. With that in mind, this is a good time to revisit the Safeguards Rule.

As the COVID pandemic pushes retailing into the digital realm, and more and more NPI is pushed into the cloud, what steps has your business taken to safeguard this valuable information?

Ad Loading...

By way of summary, the Safeguards Rule requires you to protect the security, confidentiality, and integrity of customer information through implementing an information security program (ISP), which contains administrative, technical, and safeguard components. In addition, an employee is to be designated to coordinate the ISP; reasonably foreseeable internal and external risks are to be identified and the sufficiency of safeguards are to be assessed; safeguards are to be designed and implemented to address identified risks; regular testing and monitoring of the safeguard’s key controls, systems and procedures is to be done; reasonable steps are to be taken in selecting vendors who maintain appropriate safeguards; vendors are to be contractually required to implement appropriate safeguards; and the ISP is to be evaluated and adjusted in light of monitoring and testing.

Holding a party responsible for the actions of its vendor was the cornerstone of a recent FTC action. In 2020, the FTC brought an enforcement action against Ascension Data & Analytics, LLC (Ascension). Ascension was a data analytics company that obtained mortgage loan information including names, dates of birth, social security numbers, drivers’ license numbers, credit files, and tax returns (collectively non-public personally identifiable financial information or NPI) for 60,593 customers. Ascension outsourced scanning of the NPI to a third-party vendor named PairPrep, Inc. PairPrep stored the NPI on a cloud-based server; however, it misconfigured both the server and storage location so that the NPI was not protected at all. No password was required to access the information, all that was needed to access the NPI was the internet address and storage location. The NPI of the 60,593 customers was stored on this unsecured cloud-based server for more than a year before the lack of security was discovered.

Surprisingly, Ascension did have a policy regarding its vendors and was required to vet the security measures of its vendors; however, it did nothing to assess PairPrep’s security measures. In the proposed Consent Order with the FTC, Ascension neither admits nor denies any of the FTC claims; however, there are some lessons worth noting. The Consent Order required, among other things, that Ascension obtain written documentation of vendors information security policies and practices; provide a written description of safeguards in place to protect NPI; provide written yearly updates; and have a third party perform yearly vulnerability scanning and penetration testing of the vendor, which may not rely solely on assertions or attestations by management. The Consent Order required 10 years of assessments and certification directly to the FTC itself and required Ascension to provide a copy of the Consent Order for 20 years to all listed parties. Each violation of the Consent Order (e.g. failure to safeguard customer information) is subject to a penalty of up to $43,280.

The takeaway here is that it is certainly easier to avoid a mess than to clean up a mess. Had Ascension followed its own policy and vetted its vendor, it would not have had to address the FTC enforcement action, suffered damage to its reputation, and caused harm to more than 60,000 of its customers. As the COVID pandemic pushes retailing into the digital realm, and more and more NPI is pushed into the cloud, what steps has your business taken to safeguard this valuable information? More specifically, what steps have you taken to make sure your vendors are safeguarding this information? This case makes it clear that your vendor’s failures are your failures. Warren Buffet says that risk comes from not knowing what you are doing. We now know that risk also comes from not knowing what your vendors are doing. Managing that risk will continue to be a constant in the years ahead. Stay safe.

Content provided in this article is intended for informational purposes only and should not be construed as legal advice and should not be relied upon or acted upon without retaining counsel to provide specific legal advice based upon your particular situation, jurisdiction and circumstances. No duties are assumed, intended or created by this communication. No attorney-client relationship is being created by your review or use of this material.

Ad Loading...

© 2021 Robert J. Wilson, All Rights Reserved

Robert J. Wilson, Esquire (Bob) is a Philadelphia lawyer and is General Counsel for ARMD Resource Group, creator of the Virtual Compliance Manager® (“VCM”).

Subscribe to Our Newsletter

More Industry

chart showing the quarterly electric vehicle market share from 2020-2025
Industryby Lauren LawrenceMarch 27, 2026

EV Sales Slide While Hybrids Climb

California, as usual, led the country in EV registrations in the fourth quarter, but the U.S. as a whole saw a 43% year-over-year volume decrease.

Read More →
Photo of new car's tail light
Industryby Hannah MitchellMarch 26, 2026

New-Vehicle Sales Ride Tax Returns Wave

Forecasts show that the spring sales season is rising above overriding economic concerns, among them continuously rising car prices, trade tariffs, elevated interest rates, and now a war.

Read More →
Photo of Toyota car parked in front of a Toyota dealership
Industryby Hannah MitchellMarch 23, 2026

2025 Dealership Buy-Sells a Record

The Kerrigan Index shows that despite a chaotic year of musical trade tariffs, high vehicle prices and more roadblocks, acquirers still flush with pandemic-era cash accelerated the consolidation pace.

Read More →
Ad Loading...
Infographic from ABB titled “The Intelligent Factory is Accelerating as Automation Investment Increases.” It shows a robotic manufacturing assembly line on the left and key statistics on the right. Highlights include: 33% of manufacturers prioritize cost control, 31% are increasing investment in automation and robotics, 30% cite labor shortages and rising wages as challenges, and 34% identify energy and material costs as a leading concern. Additional sections explain competitive pressures and how automation technologies like robots improve efficiency, consistency, and productivity in modern manufacturing.
Industryby Lauren LawrenceMarch 19, 2026

Automation Acceleration Seen in Manufacturing

Labor shortages, material costs and tariffs are just a few of the reasons automakers are looking to expand their investments in automation and robotics this year.

Read More →
Overhead view of container cargo ship loaded with vehicles
Industryby Hannah MitchellMarch 19, 2026

War Threatens Major U.S. Auto Exports Stream

The Middle East imports a sizable share of vehicles made in the states. It’s unclear how the Iran War could affect the keystone market for U.S. automakers.

Read More →
row of cars, used vehicle demand spikes, chart showing data spike, F&I and Showroom logo
Showroomby Lauren LawrenceMarch 11, 2026

Used Market Gains Speed

New-vehicle sales fell year-over-year for the fifth month in a row in February, making retail deliveries the slowest they’ve been since 2023, according to a CarGurus report.

Read More →
Ad Loading...
Graphic showing used-vehicle days to turn rate
Showroomby StaffMarch 10, 2026

Black Book: Weekly Market Update

Both vehicle values and conversion rates sped up last week as two segments outperformed in the pre-spring burst of buying.

Read More →
Photo of Chevrolet Bolt on a beach
Showroomby Hannah MitchellMarch 9, 2026

Economical Electric

GM says it sells the cheapest electric vehicle in the U.S. market. It explains how it made improvements to the entry-level EV while keeping its price down.

Read More →
Hyundai logo and 40 Years in America in front of a starry background
Industryby Lauren LawrenceMarch 5, 2026

Hyundai Celebrates U.S. Milestone

The South Korean automaker said it supports 570,000 jobs in the U.S. with a planned investment of $26 billion between 2025 and 2028, according to President and CEO José Muñoz.

Read More →
Ad Loading...
Showroomby Lauren LawrenceMarch 4, 2026

Used-Vehicle Program Aims to Draw More Buyers

GM says more than 750 dealers across the U.S. are enrolled in CarBravo and that in January CarBravo dealers sold over two times the certified volume of Chevrolet, Buick and GMC dealers using traditional CPO.

Read More →