Skip to content
All insights

Data governance

Dealership Data Governance and GDPR Guide

A dealership needs customer and vehicle context to serve people well. Governance makes that context purposeful, accurate, limited, protected and explainable.

Dealership data team governing customer, vehicle and transaction records
Short answer:

Govern dealership data by purpose. Map each sales, service, warranty, connected-vehicle and marketing process to its data, lawful basis, controller or processor role, users, recipients and retention. Assign business owners, limit access, preserve consent and source history, support individual rights and test deletion. Treat vehicle-generated data as potentially personal whenever it can be linked to a driver, owner or user.

1. Inventory purposes before systems

The same person may be a lead, buyer, borrower, vehicle user, service customer, complainant or employee. The same VIN may appear in appraisal, registration, finance, insurance, warranty, repair, roadside assistance and connected services. A system inventory alone cannot show whether reuse is lawful or expected.

Create a processing map by purpose. For each activity, record data subjects, categories, source, lawful basis, recipients, transfers, retention, security, automated decisions and owner. Link it to the Article 30 record of processing where applicable. Distinguish data needed to perform a contract from optional marketing and analytics. Do not bundle unrelated purposes into one consent.

GDPR requires lawfulness, fairness and transparency; purpose limitation; minimisation; accuracy; storage limitation; security; and accountability. [1] These principles are not documentation-only requirements. They should change which CRM fields are mandatory, which roles can export a customer list and when stale lead data is removed.

Purpose-led dealership data lifecycleControls follow data from collection through deletion.
Collectnotice, minimumUsepurpose, accessSharerole, contractRetainschedule, holdDeleteverify, evidenceRights, security, lineage and accountability across every stage

2. Classify customer and vehicle data in context

Names, personal email addresses, phone numbers, signatures and finance details are clearly personal data. Vehicle data needs contextual analysis. A VIN, registration, location trace, driving pattern, service history or in-car identifier can relate to an identifiable owner, keeper, driver or passenger. Pseudonymisation reduces risk but does not necessarily take data outside GDPR if re-identification remains possible.

The European Data Protection Board's connected-vehicle guidance emphasises that much vehicle-generated data is personal and highlights location, biometric data and offence-related data as particularly sensitive categories in context. It favours local processing where possible and user control over collection. [2]

Classify fields by sensitivity and purpose, not by application. Record data may be ordinary in one workflow and revealing when combined. Free-text notes are especially risky because staff can enter health, family, financial or complaint details without structure. Use prompts, training and restricted fields to reduce unnecessary collection.

3. Resolve roles across dealer, group, OEM and suppliers

A dealer is often controller for sales and service activity, but relationships vary. An OEM may be an independent controller for warranty or connected services, a joint controller for a jointly determined campaign, or receive data under another defined arrangement. A DMS provider commonly acts as processor for hosted dealer data but may be controller for its own account administration or security logs.

Do not copy a role label from a contract without testing reality. Ask who decides purpose and essential means, who answers rights requests, who notifies whom of a breach, which subprocessors are involved and whether data is used to train models or benchmark customers. Document sharing grounds and data minimisation at each interface.

Connected-vehicle access now also intersects with the EU Data Act. The European Commission's 2025 non-binding automotive guidance explains how Data Act concepts apply to vehicle data, while stressing that GDPR continues to apply to personal data. [3] A right to access or share product data is not a blanket permission to ignore privacy law.

4. Design lawful basis and transparency around the journey

Illustrative governance questions by dealership activity
ActivityPossible basis to assessKey control
Respond to vehicle enquiryPre-contractual steps or legitimate interestsLimit data and define lead retention
Complete sale and invoiceContract and legal obligationsSeparate transaction from marketing
Service reminderContract or legitimate interests depending on factsExpectation, opt-out and accurate ownership
Promotional campaignConsent or permitted national e-privacy routeChannel-specific preference and evidence
Connected diagnosticsPurpose-specific assessmentUser information, access and minimisation
Fraud or security monitoringLegitimate interests or legal requirementNecessity, access and limited retention

This table is a starting point, not a legal determination. E-privacy and direct-marketing rules vary by channel and national implementation. Consent must be freely given, specific, informed, unambiguous and withdrawable. Legitimate interests require purpose, necessity and balancing assessments.

Provide layered notices at meaningful moments, not one remote privacy page. Explain essential processing at enquiry, test drive, purchase, service and app connection. Make preferences easy to change and propagate withdrawal to every relevant campaign system.

5. Control identity, accuracy, access and retention

Customer matching helps continuity but can also combine two people incorrectly. Use verified identifiers, confidence levels, review for consequential merges and a reversible audit trail. Preserve which source supplied a value. A dealer should be able to explain why a person received a message and correct an ownership change quickly.

Implement role-based access and separation of duties. A salesperson may need current contact and deal context, not unrestricted exports or payroll. Group reporting may need aggregated branch data rather than customer-level detail. Review privileged roles and dormant accounts. Record access to high-risk datasets and investigate bulk exports.

Set retention by record and purpose. Tax documents, contracts, warranty evidence, unsuccessful leads, call recordings, location data and model-training samples need different periods. Account for limitation periods and legal holds, then delete or anonymise. Test backups and downstream integrations so a front-end deletion is not merely cosmetic.

6. Operationalise rights, DPIAs and incidents

Build a verified intake process for access, rectification, erasure, restriction, objection and portability requests. Search by customer and vehicle identifiers across CRM, DMS, call, document and marketing systems. Review third-party data and the rights of other people before disclosure. Record the decision and response date.

Use a data-protection impact assessment where processing is likely to create high risk, especially systematic monitoring, novel connected data or significant automated decisions. A DPIA should influence design before launch. It is not a retrospective approval form.

Prepare breach triage. Staff should recognise misdirected invoices, exposed exports, account compromise and ransomware as possible personal-data incidents. Capture facts quickly, contain access, preserve evidence and support the controller's assessment of notification obligations. GDPR sets a 72-hour supervisory-authority notification period where the applicable risk threshold is met. [1]

Where Omnetic fits

Omnetic's documented modules bring customer, vehicle, deal, communication, inspection, stock and pricing context into operational workflows. That continuity can support accuracy, source visibility and fewer uncontrolled handoffs. It does not by itself establish GDPR compliance.

Dealers should ask Omnetic for controller and processor roles, data locations, subprocessors, retention and deletion behaviour, access controls, audit logs, export support, incident terms and AI processing details. Country, package and deployment choices may change the answer.

Limitations

This is not legal advice. Lawful basis, retention and role allocation depend on facts, contracts and national law, including e-privacy rules. The Commission's vehicle-data guidance is non-binding. Consult qualified privacy counsel and the relevant supervisory authority where needed.

Frequently asked questions

Choose your market and language

International