agent Entrepreneur logo
MenuMENU
SearchSEARCH

FTC Charges First Dealer With GLB Privacy Violations

June 12, 2012
4 min to read


WASHINGTON — The FTC has charged two businesses, including Statesboro, Ga.-based Toyota Scion dealer, with illegally exposing the sensitive personal information of thousands of consumers by allowing peer-to-peer, file-sharing software to be installed on their corporate computer systems.


Settlements with the dealer and debt collection business, will bar misrepresentations about their privacy, security, confidentiality, and integrity of any personal information. Both companies must also establish and maintain comprehensive information security programs, reported F&I and Showroom magazine.

Ad Loading...


The FTC charged that Statesboro, Ga.-based Franklin's Budget Car Sales Inc., also known as Franklin Toyota/Scion, compromised consumers' personal information by allowing P2P software to be installed on its network, which resulted in sensitive financial information being uploaded to a P2P network.


Despite a privacy policy stating that customer information will only be viewed by employees who require the information to provide products and services, the dealership, according to the FTC’s complaint, allegedly failed to implement reasonable security measures to protect consumers' personal information. As a result, the complaint states, information for 95,000 consumers was made available on the P2P network. The information included names, addresses, Social Security numbers, dates of birth and driver's license numbers.


The agency charged that Franklin failed to assess risks to the consumer information it collected and stored online, and failed to adopt policies to prevent or limit unauthorized disclosure of information. It also allegedly failed to prevent, detect and investigate unauthorized access to personal information on its networks, failed to adequately train employees and failed to employ reasonable measures to respond to unauthorized access to personal information.


Because Franklin is a financial institution, the alleged security failures violated the Gramm-Leach-Bliley (GLB) Safeguards Rule, as well as Section 5 of the FTC Act.


Franklin also allegedly failed to provide annual privacy notices and provide a mechanism by which consumers could opt out of information sharing with third parties, a violation of the GLB Privacy Rule. This is the FTC’s first action against an auto dealer charging GLB violations.

Ad Loading...


The settlement agreement with Franklin will bar misrepresentations about the privacy, security, confidentiality, and integrity of personal information collected from consumers. It bars Franklin from violating the GLB Safeguards Rule and Privacy Rule.


Under the settlement, Franklin Auto must also establish and maintain a comprehensive information security program and undergo data security audits by independent auditors every other year for 20 years.


In a separate case, P2P technology’s usage came into question. The FTC found that P2P software can pose significant data security risks. A 2010 FTC examination of P2P-related breaches uncovered a wide range of sensitive consumer data available on P2P networks. Files shared to a P2P network are available for viewing or downloading by any computer user with access to the network. Generally, a file that has been shared cannot be permanently removed from the P2P network. In addition, files can be shared among computers long after they have been deleted from the original source computer.


The FTC alleged that EPN Inc., a debt collector based in Provo, Utah, failed to implement reasonable security measures for personal information on its computers and networks. The company’s clients include healthcare providers, commercial credit organizations and retailers.


As a result of these failures, EPN's chief operating officer was able to install P2P file-sharing software on the EPN computer system, causing sensitive information, including Social Security numbers, health insurance numbers and medical diagnosis codes of 3,800 hospital patients, to be made available to any computer connected to the P2P network. The agency charged that the company did not have an appropriate information security plan, failed to assess risks to the consumer information it stored, did not adequately train employees, did not use reasonable measures to enforce compliance with its security policies, such as scanning its networks to identify any P2P file-sharing applications operating on them, and did not use reasonable methods to prevent, detect and investigate unauthorized access to personal information on its networks. According to the agency, the failure to implement reasonable and appropriate data security measures was an unfair act or practice and violated federal law.

Ad Loading...


The settlement order with debt collector EPN bars misrepresentations about the privacy, security, confidentiality, and integrity of any personal information. It requires EPN to establish and maintain a comprehensive information security program.


It also requires EPN to undergo data security audits by independent auditors every other year for 20 years.


The Commission voted 5-0 to accept the consent agreement packages containing the proposed consent orders for public comment. The FTC will publish a description of the consent agreement packages in the Federal Register. The agreement will be subject to public comment for 30 days, beginning today and continuing through July 9, after which the Commission will decide whether to make the proposed consent order final.

More Industry

Photo of Cadillac Lyriq SUV on road with partly cloudy sky in background
Industryby Hannah MitchellApril 16, 2026

Used Autos Selling for More

A recent price spike due to several larger market forces, though it hasn’t dulled demand, is pushing more consumers to efficient models to squeeze in buys.

Read More →
Photo of facade of Waldorf Toyota car dealership
Industryby Hannah MitchellApril 16, 2026

Maryland Auto Group Sells

A group out West picked up the major D.C.-area collection, putting it in the upper tiers of private automotive groups in the U.S.

Read More →
Line graphic showing Cox Automotive's March Credit Availability Index status
Industryby Hannah MitchellApril 13, 2026

Auto Lending Opens Up in March

Lenders loosened access for subprime borrowers, and consumers with negative equity reached a record high, Cox Automotive reported.

Read More →
Ad Loading...
electric vehicle next to an urban charging station. EV Demand Diverges. F&I and Showroom logo
Industryby Lauren LawrenceApril 10, 2026

EV Interest Varies Regionally

U.S. consumer interest in electric vehicles lags behind other countries despite the rising gas prices caused by the ongoing war in the Middle East.

Read More →
Photo of the rear of a Mercedes GLC 400 electric SUV with a skyline in the background
Industryby Hannah MitchellApril 10, 2026

Brands Weighed on Projected Recalls

Research reveals the brands and models most likely to have higher recall rates over their lifetimes. While some brands rank high, addressing safety issues can be a selling point.

Read More →
Photo of white 2026 Ford Bronco on a sandy beach
Industryby Hannah MitchellApril 10, 2026

March New-Vehicle Sales Don’t Reflect War

Cox Automotive data shows Americans doubled down on big-is-better despite price increases. Slightly higher incentives helped fuel the demand.

Read More →
Ad Loading...
Photo of several cars on lifts in a service center
Industryby Hannah MitchellApril 9, 2026

Franchised Dealers Stand to Gain Service Business

Cox Automotive research shows both the opportunities and the challenges in turning consumers’ growing affordability needs into increased fixed-operations revenue.

Read More →
Photo of office desk with open laptop on it and an empty chair next to it
IndustryApril 9, 2026

What Matters Most in Building Your Agency

The partner you choose for growth and expansion is key, because better is the ultimate goal instead of growth for growth’s sake.

Read More →
car with hood open, an arm holding a wrench, The most loyal generation text, Agent Entrepreneur logo
Industryby Lauren LawrenceApril 9, 2026

Service Drives Gen Z Loyalty

The dealership profit center plays an important role in customer retention, and generation Z customers are showing the highest loyalty rates, based on recent CDK Global data.

Read More →
Ad Loading...
Photo of man with most of his face hidden as he types on a computer keyboard
Industryby Hannah MitchellApril 2, 2026

Fake Auto Dealer Websites Frauding Consumers

The Point Predictive study traced a pattern across more than 100 websites it believes are being developed by an international theft ring.

Read More →