@Alex Snyder
These are some questions that I have for Refresh Friday.
1. Each State likely has their own Data Retention minimum requirements. In Nebraska it is clearly stated to be 5 years. I have heard that there are maximum retention timelines as well, but don't positively know what they are.
Can I retain customer information in my CRM as long as we have periodic contact with this person on an ongoing basis for purposes of customer care and communication? We typically contact every customer in some form at least 2 times per year. What are the rules specifically?
2. ADF/XML emails are not secure. All of our incoming ADF/XML emails move from websites to a stand alone Email Parsing application. The parsed data then comes into my CRM via API which is secure. No data is transmitted into my CRM through unsecured methods. At what point is this incoming data considered "my data"? When it hits my Email Parse, or when the consumer clicks SUBMIT on my website or any 3rd party listing site?
3. If the answer to #2 is that the data security responsibility falls on me when the customer clicks SUBMIT, then what are we supposed to do if a vendor does not have the ability to send data via API? I understand the ease of responding with "don't do business with them", but is that considered reasonable?
4. The ADF/XML data referenced above is very basic Customer Information. Name, Phone, Email, and what vehicle they are looking at. There is not Credit Information contained in these Emails. I realize that the safeguards rule doesn't differentiate. I just wanted to be clear what the information is.