Mon - Sat: 9:00 AM - 6:00 PM
Pacific Time (Los Angeles)
Call: 844-376-2274
24/7 Nationwide Service
LIVEJoin Demo Call
Interactive Training Session

F&I & Compliance

Dealership Data Governance Framework

Not a policy binder nobody reads. A working set of decisions about who sees what, what you keep, and what you can prove after the fact.

Dealership data governance is the set of decisions about who owns customer data, who can see which parts of it, how consent and opt outs are recorded, how long records are kept, and how access is proven after the fact. It is mostly configuration and habit rather than paperwork. This page lays out a framework and names the controls that enforce it.

Why this stopped being optional

A dealership holds an unusually rich pile of personal information for a business its size. Full name, address, phone, email, driver's license, social security number on a credit application, income, employment, banking details, vehicle history and a recorded conversation archive. A store selling a hundred cars a month accumulates more sensitive data in a year than most small businesses handle in a decade.

Three pressures have converged on that pile. Regulators expect documented safeguards around customer information at financial institutions, and dealerships that arrange financing sit inside that definition. State privacy laws increasingly give consumers rights to know what you hold and to ask you to delete it, which is impossible to honor if you do not know where it lives. And attackers have noticed that dealer groups hold credit application data behind thinner defenses than a bank does.

The practical problem is that governance in most stores is not absent so much as undocumented. Someone knows the answers. That person is on vacation, or left in March. Nothing on this page is legal advice, and you should work the compliance specifics through with your own counsel, but the operational spine below is what makes any legal position defensible in the first place.

Start with an inventory of what you hold and where

Governance without an inventory is a theory. Before writing a single policy, spend an afternoon listing every place customer data actually sits in your operation. Most stores find twice as many locations as they expected.

The obvious ones: the dealer management system you run, the CRM, the credit application system, the phone system with its recordings, the website forms, the chat tool. Then the ones people forget. Spreadsheets on a sales manager's desktop. A shared inbox that has been collecting deal documents since 2019. Photos of driver's licenses in the camera roll on a store iPad. Text threads on personal cell phones, which is the largest uncontrolled repository in most dealerships and the one nobody wants to discuss.

For each location write down four things: what categories of data it holds, who can reach it, whether it is inside a system you administer, and how a record would be deleted if a consumer asked. That last column is where the exercise earns its keep, because the honest answer for personal phones and desktop spreadsheets is that you cannot delete it and cannot prove you did.

The conclusion most stores reach is that the fix is consolidation before it is policy. Every conversation that happens inside your platform is a conversation you can search, retain, redact and delete. Every conversation on a personal phone is one you cannot. The same argument runs through our page on CRM data cleanup, from the quality angle rather than the risk angle.

Decide ownership before you decide anything else

Ownership is the question that quietly resolves a dozen later arguments, and it has two halves.

Who owns it inside the store. Not who uses it, who is accountable for it. Name one person for customer data, one for consent and opt out status, one for user accounts and permissions. In a small store that may be the same person three times, which is fine as long as it is written down. Ownership with no name attached is what produces a data set nobody has looked at in four years.

Then who owns it between you and your vendors. Read the contract before you assume. The questions that matter: can you export your data in a usable format at any time, does that export include communication history and recordings, what happens to your records after you cancel, how long does the vendor retain copies, and who do they share it with. Our page on DMS data ownership deals with the hardest version of this, because DMS contracts are typically the least generous on this point.

Ask those questions of us too. You should be able to export your customer records and communication history, and the answer should not depend on how the cancellation conversation goes.

Access control, and the mistake almost every store makes

The default configuration at a lot of dealerships is that everyone can see everything, because that was easier during setup and nobody revisited it. It is the single most common finding when a store looks at its own systems seriously.

The principle is unglamorous: a person should see the data their job requires and no more. A service advisor does not need to see sales gross. A part time BDC agent does not need to open credit applications. A salesperson who left in June should not still have a working login, and in a surprising number of stores they do.

Role based permissions in the CRM are how this gets enforced rather than requested. Set roles by job function, not by seniority or by who complained. Review them on a schedule, quarterly is enough, and tie account deactivation to your existing offboarding checklist so it happens the same day someone leaves rather than the next time somebody notices.

Then make access reviewable. A login log tells you who signed in, from where and when, which turns a suspicion into a fact. Customer profiles hold personal information encrypted, and customer facing links use opaque tokens rather than sequential identifiers, which matters more than it sounds: a URL with a guessable record number in it is a data exposure waiting for somebody bored. Our CRM security checklist works through the configuration items in order.

Consent, opt outs and the record that proves them

Consent is where governance meets your marketing calendar, and it is the area with the most direct financial exposure.

Three rules cover most of it. First, record consent at the moment it is given, with what the customer actually agreed to and when. A consent you cannot evidence is a consent you do not have. Second, honor an opt out immediately and across every channel and department. A customer who unsubscribes from service marketing should not receive a sales text next Tuesday, and treating those as separate lists is both a compliance problem and an obvious trust problem. Third, keep the version of the terms the customer accepted, because the terms will change and you will eventually need to show which text was on the screen that day.

The mechanics exist for this. Opt out status is held on the customer record and applies across the platform rather than per campaign. SecureWebX runs a compliance module with a versioned consent gate, so a store can show which version of the terms an applicant accepted and when they accepted it. Applications collect identity verification at intake, and documents are collected inside the system rather than by text message photo.

Financing campaigns carry an extra constraint worth stating explicitly, because stores get this wrong with good intentions. Fair lending rules forbid narrowing a credit related audience by age, gender, income, marital status, household size, education, language or ZIP code. That is not a platform limitation, it is the law, and a targeting idea that sounds clever in a marketing meeting can be illegal. See consent management for the messaging side.

Retention: decide what you delete, then actually delete it

Most dealerships have no retention policy, which in practice is a policy of keeping everything forever. That is the worst option available, because every record you hold past its usefulness is pure liability with no offsetting value.

Write a schedule with three columns: category of record, how long you keep it, and why. The why matters, because retention periods are usually driven by something concrete, a statutory requirement, a lender requirement, an insurance position or a genuine business need. If no one can articulate the reason, the answer is that you keep it shorter.

Treat the categories separately. Deal documents and credit applications usually carry the longest defensible periods and the highest sensitivity. Marketing contact records are the opposite: useful while a relationship is live, a liability once it is dead. Call recordings and transcripts need a stated period, and stores almost never set one. Website form submissions from people who never responded should not sit in your database for six years.

Then build the deletion into a process rather than an intention. A quarterly review that actually removes records, and a defined path for handling a consumer deletion request, including how you confirm the requester is who they say they are. Our page on privacy request management covers the request workflow specifically.

Data quality is a governance problem too

Governance conversations focus on risk and skip accuracy, which is a mistake, because a database full of wrong data creates its own exposure and burns real money every week.

Bad phone numbers and dead email addresses damage more than a campaign's response rate. They damage your sending reputation, so the messages that would have reached good customers start landing in spam folders. Duplicate records mean two salespeople call the same customer and a manager cannot tell which conversation is the real one. Stale ownership fields mean an opt out gets recorded against the wrong record, which is the compliance version of the same problem.

Hygiene tools handle the mechanical part. A built in email validator and phone validator check contact data before it goes into a campaign rather than after. Duplicate lead management, a blacklist with import, a trash bin and email domain authentication cover the rest of the surface. Phones are stored in a single normalized format, which sounds trivial until you try to match a customer record against an inbound call and discover four formats of the same number in your own database.

Set a standard, enforce it at entry, and audit it quarterly. Cleaning data once is a project. Keeping it clean is governance.

What we do and do not do here, plainly

So the boundaries are clear before you plan around us.

We provide: role based permissions and user management, a login log, customer profiles with encrypted personal information and opaque tokens for customer facing links, platform wide opt out handling, a blacklist with import, duplicate lead management, an email validator and a phone validator, email domain authentication, call recording with transcription, a trash bin, and three reporting layers. Through SecureWebX: secure credit applications, apply links, document collection inside the system, identity verification at intake, a compliance module with versioned consent, worksheets and eFax.

We do not provide: a dealer management system or any accounting function, general ledger, deal posting, title and registration work, or parts and service systems. We are not a legal or compliance advisory service, and nothing here is legal advice. We do not certify your store against any regulation, and any vendor who says they do is selling you something you should read carefully.

What we can do is make the operational half enforceable rather than aspirational. If you want the compliance and application side specifically, the digital F and I platform page covers SecureWebX in detail, or call 844-376-2274 and ask what your configuration would look like.

Frequently Asked Questions

Where do we start if we have no governance program at all?

Inventory first. List every place customer data actually lives, including spreadsheets, shared inboxes and personal phones. Then name an owner for customer data, consent status and user accounts. Policies written before an inventory describe a store you do not have.

Does LeadLocate hold our customer data, and can we get it back?

Yes we store consumer data, and the Privacy Policy describes what we hold. You should be able to export customer records and communication history in a usable format. Ask that question of every vendor you use, and get the answer before you sign rather than during a cancellation.

How long should a dealership keep customer records?

There is no single answer, and anyone giving you one without seeing your operation is guessing. Write a schedule by category with a stated reason for each period, keep deal and credit records under the longest defensible period, and shorten everything you cannot justify. Confirm the specifics with your counsel.

Can we restrict what a salesperson sees?

Yes. Role based permissions are set by job function, so a service advisor does not see sales gross and a part time BDC agent does not open credit applications. Tie account deactivation to your offboarding checklist so departed staff lose access the same day.

How do opt outs work across departments?

Opt out status sits on the customer record and applies across the platform, not per campaign or per department. A customer who unsubscribes from service marketing will not then receive a sales text, which is both a compliance requirement and a basic trust issue.

Is this page legal advice, or does it make us compliant?

Neither. It is an operational framework. No software makes a dealership compliant, and any vendor claiming to certify you against a regulation deserves a hard read of the fine print. Use this to build the operational spine, then work the legal specifics with your own counsel.

More Resources from LeadLocate

Make the governance you already claim actually enforceable

We will walk your permissions, consent handling, opt out flow and retention gaps with you, and show what the platform enforces on its own. Month to month, no long term contract.

LeadLocate
Accepted credit cards: Visa, MasterCard, American Express and Discover
LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.

Answers to your questions:

What is LeadLocate?

LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.

Accepted credit cards: Visa, MasterCard, American Express and Discover
LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.

Answers to your questions:

What is LeadLocate?

LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.