Current through 2024 Legislative Session Act Chapter 531
Section 4919 - Consumer data protection(a) As used in this section: (1) "Consumer data" means "nonpublic personal information," as defined in 15 U.S.C. § 6809 (4), that is collected by a motor vehicle dealer and is provided by the motor vehicle dealer directly to a manufacturer or third party acting on behalf of a manufacturer. "Consumer data" does not include the same or similar data which is obtained by a manufacturer from any other source.(2)a. "Data management system" means a computer hardware or software system that meets both of the following: 1. Is owned, leased, or licensed by a motor vehicle dealer, including a system of web-based applications, computer software, or computer hardware, whether located at the motor vehicle dealership or hosted remotely.2. Stores and provides access to consumer data collected or stored by a motor vehicle dealer.b. "Data management system" includes dealership management systems and customer relations management systems.(b) Notwithstanding the provisions of any franchise agreement, with respect to consumer data a manufacturer or a third party acting on behalf of a manufacturer must do all of the following: (1) Comply with all, and not knowingly cause a motor vehicle dealer to violate any, applicable restrictions on reuse or disclosure of the consumer data established by federal or state law and provide a written statement to the motor vehicle dealer upon request describing the established procedures adopted by the manufacturer or third-party acting on behalf of the manufacturer which meet or exceed any federal or state requirements to safeguard the consumer data, including those established in the Gramm-Leach-Bliley Act, 15 U.S.C. §§ 6801 et seq.(2) Upon the written request of the motor vehicle dealer, provide a written list of the consumer data obtained from the motor vehicle dealer and all persons to whom any consumer data has been provided by the manufacturer or a third party acting on behalf of a manufacturer during the preceding 6 months. The dealer may make such a request no more than once every 6 months. The list must indicate the specific fields of consumer data that were provided to each person. Notwithstanding the foregoing sentences of this paragraph (b)(2) of this section, such a list need not include: a. A person to whom consumer data was provided, or the specific consumer data provided to such person, if the person was, at the time the consumer data was provided, 1 of the manufacturer's service providers, subcontractors, or consultants acting in the course of such person's performance of services on behalf of or for the benefit of the manufacturer or motor vehicle dealer, provided that the manufacturer has entered into an agreement with such person requiring that the person comply with the safeguard requirements of applicable state and federal law, including, but not limited to, those established in the Gramm-Leach-Bliley Act, 15 U.S.C. §§ 6801 et seq.b. A person to whom consumer data was provided, or the specific consumer data provided to such person, if the motor vehicle dealer has previously consented in writing to such person receiving the consumer data provided and the motor vehicle dealer has not withdrawn such consent in writing.(3) Not require a motor vehicle dealer to grant the manufacturer or a third party direct or indirect access to the dealer's data management system to obtain consumer data as a part of any program or otherwise. A manufacturer must permit a motor vehicle dealer to furnish consumer data in a widely accepted file format, such as comma delimited, and through a third-party vendor selected by the motor vehicle dealer. However, a manufacturer may access or obtain consumer data directly from a motor vehicle dealer's data management system with the prior express written consent of the dealer. The consent must be in the form of a stand-alone written document that is separate from the parties' franchise agreement, is executed by the dealer principal, and may be withdrawn by the dealer upon 30 days' written notice to the manufacturer.(4) Indemnify the motor vehicle dealer for any third-party claims asserted against or damages incurred by the motor vehicle dealer to the extent caused by access to, use of, or disclosure of consumer data in violation of this section by the manufacturer, a third-party acting on behalf of the manufacturer, or a third-party to whom the manufacturer has provided consumer data.Added by Laws 2017 , ch. 289, s 8, eff. 6/30/2018.