Auto Finance News
  • Home
  • News
  • AI Tool
  • Big Wheels Data
  • Events
    • Auto Finance Summit
    • Auto Finance Summit East
    • Auto Finance Capital Summit (NEW)
    • PowerSports Finance Summit
    • Current Webinars
    • Webinar Library
    • Equipment Finance Connect
  • Podcast
  • Features
  • Powersports
  • Subscribe
No Result
View All Result
  • Login
Auto Finance News
  • Home
  • News
  • AI Tool
  • Big Wheels Data
  • Events
    • Auto Finance Summit
    • Auto Finance Summit East
    • Auto Finance Capital Summit (NEW)
    • PowerSports Finance Summit
    • Current Webinars
    • Webinar Library
    • Equipment Finance Connect
  • Podcast
  • Features
  • Powersports
  • Subscribe
  • Login
No Result
View All Result
Auto Finance News
No Result
View All Result

Home » 3 strategies for lenders to mitigate internal threats to consumer data security

3 strategies for lenders to mitigate internal threats to consumer data security

Susan ChylikbySusan Chylik
September 4, 2019
in Compliance
Reading Time: 4 mins read
0
Sharpening Decisions With Alternative Data [Podcast]

© Can Stock Photo / SergeyNivens

With the enactment of the California Consumer Privacy Act of 2018 and the barrage of copycat legislation in other states, there has been significant focus on consumer data and privacy issues from the vantagepoint of the consumer: what information is collected and how consumers can direct companies what to do — or not do — with that information. While the discussion has largely centered on data security within the context of protections from external threats, auto lenders’ loss–mitigation efforts need to consider internal threats to consumer data, as well.  

Lenders big and small that amass consumer data are made up of employees — employees with access to data. So, how should a company protect itself against this internal threat to data security? This article outlines three steps lenders can implement to manage how employees access data and plan for corrective action. 

  1. Control Access. Evaluate the different types of data your business collects and who has access to that information. Not all employees should have access to all kinds of data. There should be controls around which levels of authority within the company should have access to data (depending on the type of data) and, then within each level, which individual employees. Each employee should have a level of access that corresponds to the role and responsibility of the position. Clear organization charts and detailed job descriptions will go a long way in helping lenders determine which levels of authority and which individual employees should have access to which types of data. Additionally, robust policies and procedures will support lenders’ efforts to document and implement data-management processes. 
  1. Check and Double-Check. Once data access controls are in place, auto lenders should conduct audits and ongoing monitoring to ensure that the right employees are accessing the correct data for the right purpose. This testing should be done according to a predetermined schedule but should also be conducted randomly. Testing should cover the types of data that are being accessed, the people that are accessing the data, and the use of the data after it is accessed. It should also identify access attempts by unauthorized employees and access by authorized employees whose use of the data is improper or beyond the scope of the employee’s authority. 
  1. Be Prepared to Take Action. If testing reveals unauthorized access to or improper use of consumer data, companiesneed to be prepared to take action. The action could be against the offender — including additional training and disciplinary action, even termination. The severity of the action will depend on the sensitivity of the data at issue and seriousness of the data usage. Or, the action could be taken at the company level. After discovering internal access breaches, lenders should strengthen access controls and improve company policies and procedures. Gaps revealed during an audit test of data access should be addressed to eliminate or minimize future access issues. 

Susan Chylik is a Member in McGlinchey Stafford’s consumer financial services compliance team and can be contacted at SChylik@mcglinchey.com or (216) 378-9913. McGlinchey Stafford is the Compliance Partner of Auto Finance Excellence (AutoFinanceExcellence.org), a sister service of Auto Finance News.  

Tags: Best Practicescalifornia consumer privacy actcompliancemcglincheyMcGlinchey Stafford
Previous Post

Volkswagen Bank taps OneSpan for encryption to fight hackers

Next Post

Fraudsters plead guilty in $1m auto loan scheme

Related Posts

CFPB sues TransUnion
Compliance

Trump nominates a new CFPB head, but Vought isn’t going anywhere

November 20, 2025
CFPB to cut financial firm supervision, curb fintech focus
Compliance

CFPB funding in jeopardy following DOJ decision 

November 12, 2025
A seal at the Consumer Financial Protection Bureau (CFPB) headquarters in Washington, D.C.
Compliance

CFPB change to nonbank oversight could affect securitizations  

October 29, 2025
Row of used cars in the rain
Capital & Funding

California CARS Act could indirectly impact auto securitizations

October 23, 2025
Next Post
Fraudsters plead guilty in $1m auto loan scheme

Fraudsters plead guilty in $1m auto loan scheme

Please login to join discussion

Stay Informed with Our Newsletters

PowerSports Finance - Monthly coverage of the powersports lending market

The Roadmap Podcast

ABOUT US

HELP CENTER

ADVERTISE

PRIVACY TERMS

ADA COMPLIANCE

CODE OF JOURNALISM ETHICS

[wt_cli_manage_consent]

EXECUTIVES OF THE YEAR

AUTO FINANCE EXCELLENCE AWARDS

MAGAZINE ARCHIVE

INDUSTRY GLOSSARY

facebook linkedin twitter podcast podcast

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
    • All News
    • Capital & Funding
    • EVs
    • Technology
    • Management
    • Powersports Finance News
    • Risk Management
    • Sales & Marketing
  • Events
    • Auto Finance Summit East
    • Equipment Finance Connect
    • Auto Finance Summit
    • PowerSports Finance Summit
  • Features
    • Latest Issue
    • Features
    • New Tracks
    • Car Culture
    • Staffing Shuffles
    • Under The Hood
    • Spotlight
    • Issue Archive
  • Podcast
  • Big Wheels Data
  • SUBSCRIBE
  • Log In / Account

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.