MenuMENU
SearchSEARCH

Stay Safe: Your Choice of Service Providers Matters

June 11, 2018
Stay Safe: Your Choice of Service Providers Matters

Stay Safe: Your Choice of Service Providers Matters

3 min to read


Service, service providers and lip service are all connected. Starting with service, we all know the importance of service to our businesses. What are the qualities of good service? Value, trustworthiness, integrity and respect are good touchpoints. What is meant by the term “service provider”? Well, if you are a finance source, this is defined as “Any party that is permitted to access a financial institution’s customer information through the provision of services directly to the institution.”


Customer information is generally defined as any record containing nonpublic personal information (NPI), which means personally identifiable financial information (PIFI) and any list derived using PIFI. Does your dealership have any vendors who can access customer records containing NPI or any list derived from the use of NPI?


In a traditional dealership, the relationship looks like this:


Finance source <--------->Dealer (service provider)


Dealers, in turn, have vendors of their own, which are service providers’ service providers (SPSP):


Finance Source--------->Dealer (service provider)------------>Dealer vendors (SPSP)


Some common dealer vendors (SPSPs) would include:

  • DMS

  • CMS

  • IT/cloud

  • Menu

  • Marketing (mailers/email)

  • TPA

  • Copiers

Each of these SPSPs most likely has access to the financial institution’s “customer information.” Under the Gramm-Leach-Bliley Act (GLB), finance sources are required to secure customer information through administrative, procedural and technical safeguards. If you look at the typical finance source contract that you signed, you will find some sort of compliance clause. They usually require you (the dealership) to comply with all applicable laws because the finance source can be liable if you (the dealership) fail to comply with the law. There are plenty of examples of this in the CFPB, FTC, class actions and even in state court actions brought by local attorneys general. So what can you do to protect yourself?


First, you should have a compliance management system (CMS) in place and, as part of that CMS, you should have written policies and procedures. What do your policies and procedures say about NPI? Is there a clear expectation for dealership personnel regarding privacy, passwords and securing desktops and computer screens? What due diligence have you performed in selecting your dealership vendors? For instance, do they have written cyber security policies, do they restrict access to NPI, do they have an incident response plan? Where is the hosted server which has the NPI stored? Is the physical facility secured? Does your contract with your dealership vendor set forth compliance expectations and penalties for noncompliance?


So the takeaway here is that there is much risk and it is up to you to manage that risk. Are you taking affirmative steps to safeguard your customer’s NPI, or are you merely giving lip service to say you have protections in place? Henry Ford once said, “Most people spend more time and energy going around problems than in trying to solve them.” What time and energy have you spent to safeguard your customer’s NPI in your shop and in your dealership vendor’s shops? If you don’t care about your client, why should your client care about you? Remember, if you don’t take care of your customers, someone else will!

Topics:F&I
Subscribe to Our Newsletter
No form configuration provided. Please set either Form ID or Form Script.

More F&I

F&Iby Hannah MitchellJanuary 12, 2026

Auto Credit Access Loosens

December brought some of the best borrowing availability for consumers in years, though lenders tightened their reins on riskier segments of the market.

Read More →
TrainingDecember 10, 2025

Accountable Is as Accountable Does

Auto dealerships work better when all staffers own their duties.

Read More →
StoneEagle logo beside a headshot of Cindy Allen, CEO, on a pink background with a stylized upward-trending chart.
Industryby StaffDecember 5, 2025

EV Surge Shows AI Steadied Softer Q3

StoneEagleData reveals the gross reality behind the rise in EV leasing and the steady role F&I offices played.

Read More →
Ad Loading...
F&IDecember 3, 2025

The No. 1 Enemy of F&I Success

Instead of succumbing to it, keep your skills and knowledge sharp.

Read More →
Two people signing auto insurance paperwork
Industryby Lauren LawrenceNovember 26, 2025

Auto Insurance Rates Dip

Insurers are shifting their focus from raising rates to customer satisfaction.

Read More →
F&Iby Hannah MitchellNovember 11, 2025

Autos With the Lowest Insurance Costs

Ranking intuitive in many ways, but there are many factors

Read More →
Ad Loading...
F&INovember 10, 2025

Singing a Gospel Song Backward

Crime and punishment in auto retail and how to avoid them

Read More →
Industryby Hannah MitchellNovember 3, 2025

Q3 Auto Loans Reveal Stress

Data reflect growing finance activity on the extreme ends of credit risk scale

Read More →
IndustryOctober 30, 2025

The Code Beneath the Hood

Help dealer-clients’ F&I managers convince consumers VSCs are no longer nice-to-haves

Read More →
Ad Loading...
F&Iby Hannah MitchellOctober 29, 2025

The It Factor in F&I

What this valuable trait looks like in the day-to-day work of the sector

Read More →