Vendor breach response

What should a dealership do after a software vendor data breach?

Treat it as an incident involving your customers, because it is. Establish what data was involved, whose data it was, when the vendor knew, and what the vendor is doing. Your obligations to customers and regulators follow from the data, not from who was breached. This is issue-spotting information and not legal advice; involve qualified counsel early.

Direct answerSeptember 1, 2026 reviewedNeutral evaluation
01

Establish scope in writing

Which systems, which records, which fields, which date range, which rooftops. Verbal reassurance from an account manager is not a scope statement. Request written confirmation and keep it.

02

Check what your contract already required

Notification timeframes, cooperation obligations, indemnity, audit rights and remediation commitments are either in the agreement or they are not. This is the moment those clauses either work or reveal that they were never negotiated.

03

Preserve the record

Keep the communications, the timeline and your own actions. Whatever follows — customer notification, insurance, regulatory contact — depends on an accurate account of who knew what and when.

04

Then fix the class, not the instance

After the immediate response, revisit vendor oversight: which other providers hold similar data, whether their security review is current, and whether the same contractual gap exists across the estate.

Decision checklist

What to verify

Open procurement templates →

Get the scope in writing: systems, records, fields, dates

Check the notification and cooperation clauses in the contract

Preserve communications and your own timeline

Re-check every other vendor holding similar data

Related market maps

Continue the research

People also research

Related dealership technology questions