Securing Dealership Vendor Contracts to Limit Data Breach Liability
Key takeaways
- Vendors that dial into dealership systems or visit in person often have access to sensitive dealership data.
- Hackers frequently target the vendors that service multiple dealerships rather than attacking a single dealership directly.
- A dealership can be held liable if a vendor with access to its data is hacked or sued.
- ARMP provides a third-party service provider contract built around compliance that verifies vendors are protecting dealership data.
- Having a solid compliance program in place helps a dealership set up an affirmative defense if a lawsuit occurs after a breach.
Summary
Vendors with regular access to dealership systems, whether dialing in remotely or visiting in person, represent a major point of exposure for data breaches. Hackers increasingly target the vendors that service multiple dealerships rather than attacking a single store directly, since one compromised vendor can expose data across many rooftops. That makes it essential for every dealership to have solid, verified vendor contracts confirming that each provider is taking the necessary precautions to protect any data it can access.
If a vendor is hacked or sued, that liability can come back on the dealership, and attorneys in these cases tend to name every party they can in a lawsuit. Dortch explains that a proper third-party service provider contract, focused specifically on compliance obligations, helps set up an affirmative defense if that happens. ARMP offers to review a dealership's vendor list and put these agreements in place directly, and he urges dealers to check their current vendor contracts now rather than waiting until after an incident occurs.
Transcript
Vendor access as a data security risk
Hi, I'm Terry Dortch with Automotive Risk Management Partners. I want to talk to you today about vendor contracts. Um, not compliance vendors, vendors in general. One of the things that we need to get out of this whole CDK event is this: you have vendors dialing into your system on a regular basis, you have people coming into your store on a regular basis that have access to a multitude of information. Make sure your vendor contracts are solid. Make sure that you've verified that they are taking all the necessary precautions to protect whatever data they have access to. If you're not doing that, you're going to get in trouble. You got to, because here, these hackers aren't necessarily coming to Fred Jones Ford. They're coming to the vendors that handle Fred Jones Ford, Tom Smith Chevy, you know, Bob's Honda. That's what they're doing.
ARMP's third-party service provider contract
So my bond, what you got to do is you got to make sure those vendor contracts are solid. Part of our program is that we do that for you. You give us a list of your vendors, contact name, we take care of it from there. We're going to make sure that you have a solid vendor contract with them, actually a third-party service provider contract that we provide. We've created it, it's strictly around compliance. It basically says they're going to take all the necessary precautions to protect the data and everything, because if they get sued, or they get hacked and they get sued, it's going to come back to you.
Lawsuit exposure and affirmative defense
You know, typically what a law firm or an attorney does is they're just going to throw a bunch of crap against the wall. They're going to go out and name everybody they can in a lawsuit. You've got to make sure that you're protected, and the only way that you can do that is with a good compliance company that's going to lay everything out so that we can set it up to wage that affirmative defense. We do that for you.
Call to action to review vendor program
Please take five or 10 minutes, take a look at your program now. If you don't think it's sufficient, call us. The information is here on the screen. We'll be more than happy to take care of it for you, and I guarantee you we'll do a good job. It will be, you will be protected. Thank you, take care.
Questions this video answers
Why do vendor contracts matter for dealership data security?
Vendors dial into dealership systems and have access to sensitive data regularly. Hackers often target the vendors that service multiple dealerships rather than attacking a single dealership directly, so weak vendor contracts create an entry point for breaches affecting many stores at once.
What should a dealership vendor contract include?
It should be a third-party service provider contract that verifies the vendor is taking all necessary precautions to protect any data they access. This is important because if a vendor is hacked or sued, the liability can come back to the dealership.
How does ARMP help with vendor contracts?
Dealerships provide ARMP a list of vendors and contact names, and ARMP takes care of creating a solid third-party service provider contract built strictly around compliance, ensuring vendors commit to protecting data.
What happens if a dealership gets sued after a data breach?
According to the speaker, attorneys typically name everybody they can in a lawsuit, so a dealership needs a good compliance company to lay everything out and set up an affirmative defense to be protected.
Read more on this
-
Dealership Cybersecurity Requirements
A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...
-
FTC Safeguards Rule Compliance for Car Dealerships
Car dealerships that arrange financing or leases are "financial institutions" under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) app...
Covered in this video
- Vendor contracts
- Third-party service provider agreements
- Data breach liability
- Affirmative defense in compliance lawsuits