agent Entrepreneur logo
MenuMENU
SearchSEARCH

The Equifax Data Breach: A Compliance Lesson in Disguise

February 8, 2018
The Equifax Data Breach: A Compliance Lesson in Disguise

The Equifax Data Breach: A Compliance Lesson in Disguise

3 min to read


By now, the immensity of the Equifax data breach has started to sink into our collective consciousness ... 142 million consumers, half of all Americans, have been adversely affected by the complete failure of Equifax to safeguard their nonpublic personal information (NPI). Keep in mind that those 143 million consumers are going to be adversely affected by the Equifax data breach for the rest of their lives!


So what does this mean for automotive dealerships? This is a compliance lesson, writ large, for all of the world to see. More specifically, this is an example of a compliance failure, the size and scope of which we have never seen before. Whether or not Equifax will survive this catastrophic event remains to be seen. Multiple class actions have been filed alleging the failure of Equifax to comply with the Fair Credit Reporting Act (FCRA), the failure of Equifax to comply with state data breach laws and negligence by reason of its failure, after previous security incidents, to take reasonable action under the circumstances. The dollar exposure of Equifax in these class actions will certainly be in the millions of dollars.

Ad Loading...


Facts reported in the news indicate that it took Equifax 143 days to discover the data breach and 40 days after the discovery of the breach to notify the affected individuals. State laws vary, but data breach notification acts typically require notice “without unreasonable delay” or “whenever it becomes aware” of the data breach or similar language. Undoubtedly, the length of the delay here was unreasonable and did not occur as soon as Equifax was aware of the data breach and Equifax will suffer the consequences.


In particular, the computer application that the hackers took advantage of was patched approximately two months before the Equifax attack occurred, and notice of this was available on the National Vulnerability database. This episode points to the inescapable conclusion that Equifax did not have a robust data security program in place (e.g. no regular checking for software/application updates, no regular monitoring of published vulnerabilities) and, certainly, had no plan of action for the possibility that a security event could occur (e.g. 40-day delay to figure out what to do).


A complete compliance management system (CMS) would require policies and procedures, training, audit and complaint management and would bring, at a minimum, a double failsafe approach to compliance —first via policies, then via training and, if both of those failed, through audit.


On the dealership floor, the impact of one in two customers suffering the consequences of this monumental data breach will be significant. In response to the Equifax data breach, many consumers have implemented credit freezes and/or have placed a fraud alert on their file. (Does your CMS address credit freezes and fraud alerts?)


If the hackers have gained access to the consumer’s credit information, then there is the possibility of unauthorized charges on the consumers account which will need to be investigated and there will be an increased urgency to ensure that the consumer is actually the person they represent themselves to be. This means compliance with the Red Flags Rule will become even more critical.

Ad Loading...


What is the takeaway here? Implementation of a complete CMS will be even more critical to protect your customers and reputation. Going forward, fraud prevention and consumer protection will need even added attention from dealerships to avoid being dragged down with Equifax into the failed compliance whirlpool — or is it a cesspool?


DISCLAIMER: Content provided in this article is intended for informational purposes only and should not be construed as legal advice and should not be relied upon or acted upon without specific legal advice based upon your particular situation, jurisdiction and circumstances. No attorney-client relationship is being created by your review or use of this material. © 2017 Robert J. Wilson

Topics:Industry
Subscribe to Our Newsletter

More Industry

Closeup photo of the front of a white car
Industryby Hannah MitchellMay 21, 2026

New-Vehicle Sales Picture Relative

A May forecast is complicated by last spring’s trade tariff effects on auto retail. Despite continued hard realities, many consumers took advantage of ways to bite the bullet.

Read More →
Nissan logo on front of building
Industryby Lauren LawrenceMay 21, 2026

Auto Group Acquires Third Nissan Rooftop

Iowa-based Coleman Automotive Group recently acquired its seventh dealership, McGrath Nissan, which it renamed Nissan of Elgin.

Read More →
Wooden people figures of different colors in a row, similar to board game pieces
IndustryMay 20, 2026

Building an Extraordinary F&I Agency

Work to determine your specialized talent, because that fact will determine everything about your agency’s future.

Read More →
Ad Loading...
Photo of new Chevrolet Bolt parked on a beach
Industryby Hannah MitchellMay 14, 2026

EVs Getting More Attractive

A growing percentage of U.S. consumers are open to switching and fewer are adverse to the idea, according to a recently completed survey. That’s despite the end of a tax break.

Read More →
Benchmark bar graph showing April 2026 EV Sales
Industryby Lauren LawrenceMay 14, 2026

EV Sales Drop in April Following Surge

North American electric-vehicle sales were down 28% year-over-year, a sharp contrast from global EV sales growth of 6%.

Read More →
Photo of a loan contract on a desk
Industryby Hannah MitchellMay 13, 2026

Auto Lenders, Consumers on a Tightrope

April borrowing data shows that more consumers are bending over backward to buy vehicles, though subprime lending cooled off for the month.

Read More →
Ad Loading...
Shifting Loan Demands A Sign of the Times, Loan Application paperwork with a pen and a car outline, Auto Dealer Today
Industryby Lauren LawrenceMay 8, 2026

Auto Loan Outlook Shows Cracks

Recent survey data shows that the overall demand for auto loans is down, but the demand for subprime loans is up as consumers face economic uncertainty and affordability pressures.

Read More →
Photo of buyer and seller representatives in Waco Mitsubishi sale outside the dealership
Industryby Hannah MitchellMay 7, 2026

Lone Star State Store Sells

The Mitsubishi location moves from one Texas automotive group to another, continuing this year’s spate of brisk buy-sell activity.

Read More →
2026 Mitsubishi Outlander in front of the company’s first national Gallery dealer facility
Industryby Lauren LawrenceMay 7, 2026

Mitsubishi Gallery Makes Progress

As part of its 2030 business plan, Mitsubishi's North America arm will soon open its first 'gallery' store in Tennessee, where customers can learn about the brand, vehicles and technology.

Read More →
Ad Loading...
hand signing paperwork on a clipboard on top of a desk with a gavel to the side

Senators Propose Chinese Connected Car Ban

Just weeks before President Trump is set to meet with the Chinese president, two U.S. senators proposed a bill with the aim of protecting Americans’ data.

Read More →