Regulations Requiring Annual Training:
Auto Dealerships & Insurance Agencies
FTC Safeguards Rule
- 16 CFR §314.4 – FEDERAL TRADE COMMISSION (FTC), SAFEGUARDS RULE (All insurance agencies and auto dealerships in the US).
- Annual training requirement for all staff with access to customer data.
Insurance Agencies that Sell Financial Products (Series 6 & 63)
SEC/FINRA Regulation S-P
- 17 CFR §248.30 – SECURITIES AND EXCHANGE COMMISSION (SEC), REGULATION S-P (Series 6 & 63).
- Considered part of best practices.
Insurance Products in New York
NY Department of Financial Services
- 23 NYCRR §500 – CYBERSECURITY REQUIREMENTS FOR FINANCIAL SERVICES COMPANIES (All NY licensed agencies)
- Annual training requirement for all New York licensed staff, even if they passes a non-resident license in New York.
Insurance Products in States Other Than NY.
National Association of Insurance Commissioners
- NAIC MODEL LAW 668 – INSURANCE DATA SECURITY LAW
- Annual training requirement for all state licensed staff
Who Should Attend Training?
- According to the FTC: All staff that have access to customer data.
- NYDFS: “Covered Entities” a.k.a. all individuals licensed to sell insurance products in the state of New York.
- NAIC Model Law 668: “Covered Entities” a.k.a. all individuals licensed to sell insurance products in each state they are licensed and that have enacted these regulations. Note: this is constantly being updated as more state enact these regulations.
- Data Droplets can help you determine if you are licensed in states with these requirements and what the requirements consist of.

Key Benefits

Reduce Liability Anxiety
Our training program helps alleviate the stress and uncertainty associated with compliance, ensuring that your business understands how to meet all regulatory requirements.

Stay Informed
Gain complete knowledge of the various regulatory requirements for protecting customer data and its implications for your operations, empowering you to make informed decisions.
Why Choose Data Droplets?
Accredited, Certificate Awarding Training Programs:
- Internationally Accredited Cybersecurity Certification.
- Attendees receive a Certificate of Compliance for proof in annual attendance
- In the event of an audit or regulatory inquiry, we maintain all class rosters for proof of attendance/compliance.
- One class that covers up to four (4) regulatory annual training requirements.
