• Stop being a LURKER - join our dealer community and get involved. Sign up and start a conversation.

Reply to thread

In my conversations at NADA it became clear that vendors are very confused about how to become compliant.

Based on the letter of the law, almost no vendors can actually be compliant without severely compromising their functionality.


I am very curious to see how this is going to proceed. We can encrypt every piece of data about every customer, but if we can't transfer it between vendor APIs or send it to the client's screen in bulk, then it's going to make every day tasks much more difficult.


In the VIN Solutions example, I don't believe their API has encrypt and decrypt built in, it just encrypts the entire communication channel.

What I am hearing, is that this is not sufficient under the new law and the information must actually be sent as encrypted data only, not just over an encrypted channel.