data-security
Resources / Blog

California Consumer Privacy Act (CCPA) Enforcement & What It Means For Dealers Nationwide

By Erik NachbahrSeptember 1, 2020 · 3 min read

CCPA is a California state law intended to enhance the privacy rights and consumer protection for its residence.  A key aspect of the CCPA is that businesses take “reasonable measures” to secure consumers’ personal and identifiable information (PII) – such as names, addresses, social security numbers, credit card numbers, credit scores, and bank account numbers.

The California Attorney General defines “reasonable measures” as compliance with the 20 controls established by the Center for Internet Security (CIS).  The implementation and ongoing management of these IT best practices are essential to keeping a dealer’s data, systems, and finances secure.  The implementation of these best practices not only mitigates the risk of a cybersecurity breach but also enhances the dealership’s ability to sell and service more cars and trucks.  However, most dealers do not comply.  In California, not complying with these best practices now has consequences.

Beginning July 2020 CCPA is now enforceable.  This means the lawsuits are starting.  The law now has teeth.  Further, there will likely be a ballot measure in November calling for the creation of the California Privacy Protection Agency.  If passed – which appears to be highly likely – then the agency would staff privacy professionals to enforce CCPA.  California isn’t messing around when it comes to the privacy and protection of consumer information.

The implementation of the IT best practices that are required to claim that “reasonable measures” have been taken to secure consumer data can’t be done overnight.  It’s much more than just adding a privacy clause to your website.  To learn about what it takes to implement these IT best practices, Erik Nachbahr (Founder & President, Helion Technologies) recently did a webinar to explain.  The webinar called Dealer IT Best Practices; Protecting Against Cybercrime and Boosting Productivity describes a practical step-by-step process that dealers can take to attain CCPA compliance, mitigate their risk of a cybersecurity breach, and boost dealership productivity.

CCPA has implications for dealers nationwide.  There is a consumer data privacy revolution underway and laws like CCPA are spreading across the country.  In fact, there is talk of the creation of a federal consumer privacy law that will be tougher than CCPA.  The implementation of IT best practices is beneficial for every dealer – not just those in California.

We live in a dangerous world and cybercrime is exploding.  Forcing businesses to up their game regarding their cybersecurity defenses isn’t a bad thing.  This is needed and the time to act is now.

About the author

Erik Nachbahr

Founder & President, Helion Technologies

Erik Nachbahr founded Helion Technologies in 1997 and has spent nearly 30 years working exclusively with automotive and heavy truck dealerships. Helion now supports more than 2,000 dealerships and 35,000 end users with managed IT, cybersecurity, FTC Safeguards compliance, Tekion enablement, and managed AI, all under one team. A CISSP, Erik writes and speaks about the parts of dealership technology most operators inherit rather than choose: vendor sprawl, AI governance, and cyber risk. His goal is simple: make the technology work so dealerships can focus on what they do best, selling and servicing cars and heavy trucks.

Confidence in your current setup and actual protection aren't always the same thing. The only way to know which one you have is to look.

Get Your Complimentary IT & Cybersecurity Assessment →