Skip to content

Your Dealership’s Biggest Data Risk May Be a Vendor You Forgot About

KPA

Your dealership probably knows its major technology vendors.

The DMS. The CRM. The website provider. The digital retailing platform.

The less obvious vendor relationships are often the easiest to overlook. For example, a marketing agency may still have system access, your service department may have adopted a new texting platform, an old API integration may remain connected, or an employee may be using an AI tool that was never formally reviewed or approved. Start with one question:

Do you know which outside companies can access your customer information today?

For dealerships subject to the Federal Trade Commission’s Safeguards Rule, that is not just an IT question. It is a compliance obligation.

The Safeguards Rule requires covered financial institutions to select service providers capable of protecting customer information, require appropriate safeguards by contract, and periodically reassess those providers based on risk.

That means vendor oversight cannot end when the contract is signed.

Approval Is the Beginning, Not the End

A vendor may have passed your security review three years ago, but that approval was based on the relationship at that point in time.

Since then, the vendor’s services, security practices and integrations may have changed. Your dealership’s use of the vendor’s services may have changed as well, including the information it shares and the access the vendor has to dealership systems.

That is why vendor oversight should continue after the initial review and contract. Not every vendor requires the same level of scrutiny, but those with access to more sensitive information or critical systems generally warrant closer attention.

Risk-based oversight starts with an accurate picture of who your vendors are—and that list may be longer than you think.

Your Vendor List May Be Longer Than You Think

Dealerships rely on a growing network of technology providers with varying levels of access to customer information and dealership systems. Not all those relationships go through a formal approval process. A department adopts a new application, a marketing company installs another tool, or an old vendor remains connected after being replaced.

Individually, these decisions may seem routine. Collectively, they create a basic problem:

You cannot protect customer information if you do not know who has access to it.

Under the Safeguards Rule, a service provider includes any person or company that receives, maintains, processes or has access to customer information while providing services to a covered financial institution.

Effective vendor oversight starts with knowing who your vendors are, then understanding what information they can access and how they have agreed to protect it.

The Contract Matters

A vendor telling you that it takes cybersecurity seriously is not the same as the vendor agreeing to protect your customer information.

The Safeguards Rule requires covered financial institutions to require service providers, by contract, to implement and maintain appropriate safeguards.

That makes the agreement itself part of the dealership’s security program.

Dealerships should understand what information a provider can access, how that information will be protected, whether other parties may receive it, what happens after a security incident and what happens to the information when the relationship ends.

A polished security webpage can support due diligence, but it cannot replace the contract.

Watch for the Vendor No One Approved

Another challenge is the vendor that never made it onto the approved list at all.

It has never been easier for an employee to introduce new technology into a dealership workflow.

An employee can create an account, upload a document, connect an application or enter a customer interaction into an AI tool in a matter of minutes. Just as quickly, dealership information may be sitting in another company’s environment.

The tool may be legitimate and useful, but before dealership or customer information is introduced, someone should understand where that information goes and how it will be used.

  • Is it retained, and if so, for how long?
  • Can the provider use it for other purposes?
  • Is the information shared with other service providers or third parties?
  • What security controls protect it?

This is where vendor management and employee behavior intersect.

Employees do not need to become cybersecurity experts. They do need to understand when a new tool should go through the dealership’s review process.

The goal is not to discourage employees from using useful technology. It is to make sure the privacy and security implications are evaluated before customer information is introduced into a new tool.

Offboarding Deserves the Same Attention as Onboarding

Dealerships can spend considerable effort bringing new technology online.

Removing it may receive far less attention.

When a vendor relationship ends, credentials, API connections, integrations, user accounts and stored information do not necessarily disappear with the contract.

Someone should be responsible for verifying that vendor access has been fully terminated.

The dealership should also understand what happens to information already in the vendor’s possession. Is it returned? Deleted? Retained? If retained, for how long and why?

Five Questions Worth Asking Now

Your dealership should be able to answer five questions:

  1. Who can access our customer information?
    Maintain an accurate inventory of vendors that receive, process, store or can access it.
  2. What can each vendor access?
    Understand what information is involved and whether that access is necessary.
  3. Did we evaluate the risk before granting access?
    Assess whether the provider can appropriately safeguard the information it handles.
  4. Are we periodically reassessing the relationship?
    Periodically reassess vendors based on their risk and continued ability to safeguard customer information.
  5. What happens when we stop doing business with them?
    Remove access and address customer information that remains in the vendor’s possession.

If your dealership cannot confidently answer those questions, the issue is not simply whether a vendor-management policy exists. It is whether the dealership has visibility into where its customer information is going and who can still access it.

Vendor oversight should reflect the environment you have today, not the one you documented years ago.

The vendor worth another look may not be the one you just approved. It may be the one no one remembers is still connected.


—-

 

Additional Resources:
Automobile Dealers and the FTC’s Safeguards Rule: Frequently Asked Questions and FTC Safeguards Rule: What Your Business Needs to Know.

 

Back To Top