What should a dealership do after a software vendor data breach?
Treat it as an incident involving your customers, because it is. Establish what data was involved, whose data it was, when the vendor knew, and what the vendor is doing. Your obligations to customers and regulators follow from the data, not from who was breached. This is issue-spotting information and not legal advice; involve qualified counsel early.
Establish scope in writing
Which systems, which records, which fields, which date range, which rooftops. Verbal reassurance from an account manager is not a scope statement. Request written confirmation and keep it.
Check what your contract already required
Notification timeframes, cooperation obligations, indemnity, audit rights and remediation commitments are either in the agreement or they are not. This is the moment those clauses either work or reveal that they were never negotiated.
Preserve the record
Keep the communications, the timeline and your own actions. Whatever follows — customer notification, insurance, regulatory contact — depends on an accurate account of who knew what and when.
Then fix the class, not the instance
After the immediate response, revisit vendor oversight: which other providers hold similar data, whether their security review is current, and whether the same contractual gap exists across the estate.
What to verify
Get the scope in writing: systems, records, fields, dates
Check the notification and cooperation clauses in the contract
Preserve communications and your own timeline
Re-check every other vendor holding similar data
Continue the research
Related dealership technology questions
What should a dealer ask before signing a software contract?
Confirm the exact products, implementation, service levels, data rights, security obligations, fees, renewal mechanics, price changes, termination, transition support and order-of-precedence across every incorporated document. Obtain qualified legal review for the dealer’s situation.
Vendor security reviewWhat security questions should dealerships ask software vendors?
Ask about governance, independent assessments, access control, encryption, logging, vulnerability management, incident response, resilience, data retention, subprocessors and contract obligations. Scope the review to the actual service and data involved.
Digital retailing definitionWhat is automotive digital retailing?
Automotive digital retailing supports some or all of the shopping and deal process online, such as payments, trade, credit, protection products, documents and handoff to the showroom. The term does not guarantee an end-to-end transaction or identical online and in-store terms.
Vendor acquisition diligenceWhat should dealers do when a software vendor is acquired or rebranded?
Confirm the legal contracting entity, product roadmap, support organization, data practices, integrations, pricing, renewal terms, account ownership and any required consent. A rebrand may be cosmetic; an acquisition may change dependencies or commercial terms, but neither should be assumed.