FI showroom red and grey logo
MenuMENU
SearchSEARCH

5 Steps to Data Security

Big data is no longer just an asset; it can also be a liability. Retail expert shares five simple steps to keeping your data safe and preventing your dealership from becoming a statistic.

by David Nathanson
April 7, 2015
5 Steps to Data Security
4 min to read


There is no shortage of headlines depicting the danger of unsecured data: Data breaches at big-name companies like Target, Sony Pictures, and Anthem Inc. have resulted in nearly 230 billion leaked records and a slew of legal actions. And these breeches weren’t anomalies.   

Clearly, big data is no longer simply an asset. The liability associated with data has become clear as we have witnessed breeches across industries with ever-increasing frequency. With the immense fallout trailing each attack, worldwide attention is now being focused on data security, and regulators are starting to take notice.

Ad Loading...

In May 2014, the Federal Trade Commission (FTC) published a study examining the practices of several major data brokers — companies that collect consumers’ personal data and sell it, largely without the knowledge of those consumers. The regulator said in its report that it found a fundamental lack of transparency in the practices of these companies. So, why does this matter to you? Because the FTC listed dealerships as one of the sources from which data brokers acquire customer information.

So, with data security on the forefront of the public’s mind and attention being focused on our industry, will your data risk plan hold? Will your DMS and web application security thwart all outside attempts at invasion? When the rubber hits the pavement, will your business and clients be kept safe?

If you need to bolster your dealership’s data security plan, here’s an easy five-step process that will take you from where you are to where you want to be:

Step 1: Understand Applicable Laws
While the Gramm-Leach-Bliley Act is rather lengthy in its entirety, the most crucial component for dealers to understand is who it holds responsible for data breaches. Edith Ramirez, FTC chair, emphasized this point at a 2013 security forum, where she asserted that it was the regulator’s responsibility to hold companies accountable for safeguarding consumer data. Accordingly, you should ensure that at least one staff member is up-to-date on all applicable laws.  

Step 2: Control Access
Currently, most dealerships allow vendors unlimited access to their data. This issue is exacerbated by a lack of monitoring of that vendor access.

Ad Loading...

To combat this growing problem, your dealership should generate a list of all usernames and passwords that grant access to your DMS and web-based applications, and then verify that all are tied to valid data recipients. This should include both external vendor and dealership employee login credentials assigned for each application deployed by your dealership. Additionally, make sure you have a process in place to promptly remove access from employees who have left your dealership.

Step 3: Dictate How Your Data Is Used
The National Automobile Dealers Association has recommended that all dealerships push DMS data to their vendors, rather than grant access to their DMS for data pulls. This seemingly small shift in how data is moved will empower dealerships with the knowledge of what data is being sent and where. The NADA’s recommendation also applies to any web-based applications, such as the dealership’s CRM, scheduling applications and other third-party sites used in a dealership, especially those that contain customer or transaction information.

Step 4: Have Binding Agreements in Place
It is best practice for dealerships to have pertinent agreements in place prior to any and all data movement. In addition to having a binding contract with each data-receiving vendor, be sure to understand each contract and what it enables a vendor to do with your data. You should also have agreements with all of your employees covering dealership policies of data access and use — including security policies and practices. The agreements should be reviewed annually.

Step 5: Reinforce Your Plan   
No plan can sufficiently address all potential risks. Although your DMS providers, OEMs and web-based application vendors may offer forms of protection, they can lack dealer focus. Discuss your plan with a professional, independent, third-party consultant and ensure your dealership is covered by a cyber-liability insurance policy.  

We can no longer remain complacent when it comes to our data security; the risk and cost are too great. Start planning today to reduce your dealership’s risk and exposure — your dealership and your clients are worth it.

Ad Loading...

David Nathanson is the head of the retail advisory practice division at motormindz, an automotive consultancy specializing in automotive manufacturing, retail, fleet, marketing communications and technology. Email him at david.nathanson@bobit.com.

Subscribe to Our Newsletter

More Digital

Ron Reahard, president of Reahard & Associates, announcing an integration with ImpactMenu to enhance F&I transaction recording, compliance and dealership performance insights.
Digitalby StaffMarch 19, 2026

Reahard & Associates Forges New Integration

The firm's F&I Insight tie-up with The Impact Group’s ImpactMenu platform is designed to enhance finance-and-insurance transaction recording for auto dealerships.

Read More →
Chris Walsh, president and acting CEO of Reynolds and Reynolds, promoting the company’s Amplify 2026 event for dealership professionals focused on technology and operations.
Industryby StaffMarch 13, 2026

Registration Open for Reynolds Amplify Retail Summit

Advancements with Reynolds' AI Agent, Rey, will take center stage this August at the Park Hyatt Aviara in Carlsbad, Calif., near San Diego.

Read More →
A customer signs documents on a digital e-contracting tablet using a stylus while a dealership employee points to the screen, alongside the Reynolds and Reynolds and Assurant logos.
Digitalby StaffMarch 6, 2026

Automotive Training Academy by Assurant Grows Offering

A new Atlanta location on Reynolds and Reynolds' docuPAD e-contracting system is designed to broaden access for auto professionals.

Read More →
Ad Loading...
A dealership customer works with an F&I representative at a desk during the vehicle purchase process.
Digitalby StaffJanuary 30, 2026

Assurant Debuts Virtual Solution for Dealers' Staffing Challenges

Company says on-demand access to F&I specialists is shown to boost dealership efficiency and profitability.

Read More →
DigitalDecember 16, 2025

What to Do When Your Vendor Is Hacked

The quickest way to turn a breach into a crisis is to wing it. Follow this seven-step playbook to ensure you meet your obligations.

Read More →
Digitalby Hannah MitchellDecember 3, 2025

Dealer Credit Service Provider Breached

Hack exposed thousands of dealerships’ customer data

Read More →
Ad Loading...
DigitalNovember 18, 2025

Unearthing the Gold in Your Dealership Data

How to take a smarter path to revenue

Read More →
Digitalby Hannah MitchellOctober 29, 2025

Auto Dealers’ Take on AI

Study finds recognition of its usefulness, but franchisers are treading sometimes confusing waters carefully

Read More →
Digitalby Hannah MitchellSeptember 22, 2025

Synthetic ID Fraud Comes With Clues

TransUnion research reveals telltale signs that the information a customer provides could be faked.

Read More →
Ad Loading...
DigitalSeptember 17, 2025

The Looming Threat of Deepfakes

They represent a new era of auto and financial fraud.

Read More →