agent Entrepreneur logo
MenuMENU
SearchSEARCH

The Shoulder Bone Is Connected to the Back Bone

February 28, 2017
The Shoulder Bone Is Connected to the Back Bone

The Shoulder Bone Is Connected to the Back Bone

3 min to read


Many of you may be familiar with the children’s sing-along song called “Dem Bones” or “Dry Bones.” Most verses recite the connection between the bones: “Shoulder bone connected to the back bone, back bone connected to the hip bone,” and so on.


You may be wondering what, exactly, this has to do with you. Well, any agent who has an interest in keeping their dealers off the federal regulatory radar needs to understand the security measures those agencies are demanding and how to meet them.

Ad Loading...


Assembling the Skeleton


Well, the “back bone” of every dealership is the dealer management system (DMS). Connected to that “back bone” are lots of other “bones” such as the business development system (BDS), a customer relationship manager (CRM), menu sales tools, iPads, smartphones, laptops and other devices.


Contained in the DMS are pieces of nonpublic personal information (NPI) pertaining to clients and potential clients which can be part of this digitally interconnected skeleton. One variety of this digital interconnectivity is referred to as peer-to-peer (P2P) file-sharing technology.


The federal Safeguards Rule requires, among other things, that dealers have a written security plan that contains administrative, technical and physical safeguards of customer’s information. Customer’s information includes NPI, which includes information a customer provides to the dealer to obtain a financial product or service.


Think about your typical dealer client. How many points of access to the customer NPI in the DMS back bone are there? If a salesperson pulls up their CRM to call Charlie Customer, does he have access to the DMS with Charlie’s credit score, credit application, date of birth, driver’s license number and other pieces of NPI? Can the salesperson access the DMS from his or her laptop while offsite?


Aside from the “front of the house” type of issue of controlling digital interconnectivity, have you reviewed your dealers’ agreements with their finance sources lately? As you may be aware, as far as the CFPB is concerned, the dealership is what is called a “service provider” for Mr. Big Bank. That means that the bank can be held liable for any improper act that is committed by one of its dealers.

Ad Loading...


As a consequence, almost all dealer/finance source contracts have some pretty scary indemnity/chargeback language incorporating compliance addendums or similar language. What this means, as a practical matter, is that failure to secure NPI in the DMS “back bone” could not only create liability for any injuries that the customer may suffer and reputational risk for the dealer, but could seriously jeopardize the dealer’s financing source.


Case Study


Franklin Budget Car Sales of Statesboro, Ga., used a computer network to conduct business and collect customer information and data, including such items as online credit applications, outside lead information, customer automobile and payment records, and finance and insurance records.


Franklin also, unfortunately, had P2P software installed on a computer connected to its network. As a result, the NPI of 95,000 customers was made available on the P2P network. Anyone operating a computer containing compatible P2P software would have access to view or download any files shared on the P2P network.


The FTC found this practice to be a violation of the Safeguards Rule. No financial penalty was assessed; however, Franklin was required to completely overhaul its information security program and report to the FTC for a period of 20 years. Keep in mind that there was no allegation that any of the 95,000 affected customers’ NPI was actually used to the detriment of the customers, just that it was available on the P2P network.


So what is the takeaway here? Well, while the back bone may be connected to the hip bone, you should take appropriate steps to make sure that the NPI on your dealers’ DMS is properly secured, that their computer network (and all devices with access to their computer network) contain no P2P software, and that they maintain adequate “administrative, technical and physical safeguards” to protect the security, confidentiality and integrity of personal information collected from or about customers.

Topics:Industry
Subscribe to Our Newsletter

More Industry

Closeup photo of the front of a white car
Industryby Hannah MitchellMay 21, 2026

New-Vehicle Sales Picture Relative

A May forecast is complicated by last spring’s trade tariff effects on auto retail. Despite continued hard realities, many consumers took advantage of ways to bite the bullet.

Read More →
Nissan logo on front of building
Industryby Lauren LawrenceMay 21, 2026

Auto Group Acquires Third Nissan Rooftop

Iowa-based Coleman Automotive Group recently acquired its seventh dealership, McGrath Nissan, which it renamed Nissan of Elgin.

Read More →
Wooden people figures of different colors in a row, similar to board game pieces
IndustryMay 20, 2026

Building an Extraordinary F&I Agency

Work to determine your specialized talent, because that fact will determine everything about your agency’s future.

Read More →
Ad Loading...
Photo of new Chevrolet Bolt parked on a beach
Industryby Hannah MitchellMay 14, 2026

EVs Getting More Attractive

A growing percentage of U.S. consumers are open to switching and fewer are adverse to the idea, according to a recently completed survey. That’s despite the end of a tax break.

Read More →
Benchmark bar graph showing April 2026 EV Sales
Industryby Lauren LawrenceMay 14, 2026

EV Sales Drop in April Following Surge

North American electric-vehicle sales were down 28% year-over-year, a sharp contrast from global EV sales growth of 6%.

Read More →
Photo of a loan contract on a desk
Industryby Hannah MitchellMay 13, 2026

Auto Lenders, Consumers on a Tightrope

April borrowing data shows that more consumers are bending over backward to buy vehicles, though subprime lending cooled off for the month.

Read More →
Ad Loading...
Shifting Loan Demands A Sign of the Times, Loan Application paperwork with a pen and a car outline, Auto Dealer Today
Industryby Lauren LawrenceMay 8, 2026

Auto Loan Outlook Shows Cracks

Recent survey data shows that the overall demand for auto loans is down, but the demand for subprime loans is up as consumers face economic uncertainty and affordability pressures.

Read More →
Photo of buyer and seller representatives in Waco Mitsubishi sale outside the dealership
Industryby Hannah MitchellMay 7, 2026

Lone Star State Store Sells

The Mitsubishi location moves from one Texas automotive group to another, continuing this year’s spate of brisk buy-sell activity.

Read More →
2026 Mitsubishi Outlander in front of the company’s first national Gallery dealer facility
Industryby Lauren LawrenceMay 7, 2026

Mitsubishi Gallery Makes Progress

As part of its 2030 business plan, Mitsubishi's North America arm will soon open its first 'gallery' store in Tennessee, where customers can learn about the brand, vehicles and technology.

Read More →
Ad Loading...
hand signing paperwork on a clipboard on top of a desk with a gavel to the side

Senators Propose Chinese Connected Car Ban

Just weeks before President Trump is set to meet with the Chinese president, two U.S. senators proposed a bill with the aim of protecting Americans’ data.

Read More →