This guide is about the plumbing of F&I: how a protection contract gets from the desk to the administrator and back, who owns the systems it passes through, and what the rules say about handling the customer’s data. CareGard® administers F&I programs, so we sit at one end of these connections. We receive rating requests, contract data and customer information from dealerships. Dealers should expect to perform the diligence described below on any administrator, including CareGard; the questions in this guide apply to us as much as to anyone.
It ranks no one. Named vendors are described from their own published material, court records or regulatory filings, with dates. Where we could not verify something, we say so.
Part 01, Evaluating an F&I Administrator, covers the basics in its section 07: eRating, eContracting, DMS write-back, aggregators, the June 2024 CDK Global attack and the service-provider duty in 16 C.F.R. § 314.4(f). This guide goes further. Menus, reporting and AI tools are in The F&I Technology Stack.
01One transaction, end to end
The table follows one financed vehicle service contract from the desk to its cancellation, possibly years later. The systems are categories; which vendor fills each slot varies by store.
| Step | What happens | Systems and parties involved | Customer data that moves | Where it tends to break |
|---|---|---|---|---|
| 1. Desk | Deal is structured. | DMS or desking tool | Name, address, VIN, mileage, deal terms | Data keyed twice and never reconciled |
| 2. Credit application | Sent to finance sources. | Credit network (e.g., RouteOne, Dealertrack) and lenders | SSN, income, employment, credit data | The most sensitive data now sits in several places |
| 3. Menu | Products are presented with prices. | Menu software pulling from the DMS | Deal and vehicle data | Menu and DMS disagree on the deal |
| 4. Rating call | Menu asks providers for eligibility and dealer cost. | Menu → aggregator or direct connection → administrator’s rating engine | VIN, odometer, in-service date, ZIP, deal type | Timeout at the desk; stale rate tables; wrong eligibility |
| 5. Contract generation | Contract form produced. | Aggregator or administrator eContracting | Customer name and address added | Wrong state form; contract number not returned |
| 6. Signature | Customer signs. | E-signature platform, menu or lender portal | Signed contract, consent records | Signed copy never reaches the administrator |
| 7. Financing | Product price goes on the retail installment contract (RISC). | Credit network, eContracting and eVault, lender | Full deal jacket | Price on the RISC does not match what was rated |
| 8. DMS posting | Deal is posted to accounting. | DMS | Sale, cost, reserve and gross by product | No write-back, so product data is rekeyed |
| 9. Registration | Administrator records the contract as sold. | Administrator system, via hub, portal or file | Contract, customer, vehicle | Contract sold but never registered |
| 10. Remittance | Dealer pays dealer cost; any reinsurance cession calculated. | Dealer accounting, administrator, bank | Payment and contract identifiers | Remittance and registration drift apart |
| 11. Claims | Repair facility verifies coverage, requests authorization. | Service drive, repair facility, administrator | Contract lookup, repair order, customer contact | Coverage cannot be confirmed because registration lagged |
| 12. Cancellation | Payoff, repossession, total loss or customer request. | Lender, dealer, administrator | Payoff date, mileage, refund calculation | Trigger event never reaches the administrator or dealer |
Two things follow. First, by funding, one customer’s nonpublic personal information may sit in six or more systems run by different companies. The Safeguards Rule defines a service provider as any person or entity that “receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution,” and requires a covered institution to select, contractually bind and periodically assess its service providers (16 C.F.R. §§ 314.2, 314.4(f)). Ask your counsel which of the companies in this chain that definition reaches. Second, failures that cost dealers money can happen in the less visible steps 8 through 12, where a contract is registered, paid for, claimed on and cancelled. Step 12 is covered in Cancellations, Refunds and Chargebacks.
Steps 6 and 7 carry legal weight of their own. The E-SIGN Act bars denying a contract legal effect solely because it is electronic, but imposes consumer consent and disclosure requirements (15 U.S.C. § 7001(a), (c)). A lender buying an electronic RISC relies on UCC § 9-105, which in the pre-2022 versions we reviewed requires “a single authoritative copy” of the record. That is why eContracts sit in an eVault, and why fixing a product mismatch afterward is a lender process, not a keystroke. State versions vary, and several states have adopted the 2022 UCC amendments.
02The DMS landscape and how access is controlled
The dealer management system is the dealership’s system of record, and in practice a gate. A third party that wants to read deal data or write product data back usually goes through a program the DMS vendor runs, on terms it sets. The table covers the vendors whose ownership and access programs we could verify from their own material; we have left others out rather than describe them secondhand.
| DMS vendor | Ownership, as documented | Third-party access program, as the vendor describes it |
|---|---|---|
| CDK Global | Acquired by Brookfield Business Partners for about $8.3 billion (announced April 7, 2022; completed July 6, 2022). | The CDK Partner Program, which CDK said in July 2022 “now numbers more than 575 partner companies and 995 unique applications.” CDK’s partner page directs vendors to a “Third Party Access Application.” |
| Reynolds and Reynolds | Privately held since its 2006 merger with Universal Computer Systems, approved by shareholders October 24, 2006 at $40 per share (about $2.8 billion including debt). | The Reynolds Certified Interface (RCI) program. Reynolds states that vendors “apply to be a part of our network and go through a comprehensive certification process,” and that interfaces are “bi-directional, and tailored to the needs of each certified RCI Participant.” |
| Dealertrack DMS | Cox Automotive (a Cox Enterprises company) completed its acquisition of Dealertrack Technologies on October 1, 2015, at about $4 billion. | Opentrack. Dealertrack states its DMS “is built on an open platform that welcomes third-party integrations.” |
| Tekion | Founded 2016. Names investors including Index Ventures, Advent International and General Motors. Reports $200 million in growth equity raised in 2024. | Automotive Partner Cloud (APC), which Tekion says “empowers partners to collaborate easily and keeps dealers in control.” |
Whatever the program is called, it settles four things: which fields a vendor may read; whether it may write back, and to which records; what the vendor pays for access, and whether any of that reaches the dealer; and what the dealer must sign. The answer to “are you integrated with my DMS?” depends on all four, and can differ between two dealers on the same DMS.
A certified participant may be approved only for a narrow set of read-only data. Ask for the scope in writing: which DMS, which data, read or write, which rooftops.
Sources
- Brookfield Business Partners, CDK acquisition announcement, April 7, 2022 (SEC Exhibit 99.1), and Paul, Weiss client news on completion, July 2022; Business Wire, “GMS Joins CDK Global Partner Program,” July 19, 2022; cdkglobal.com/become-an-approved-partner
- Reynolds and Reynolds, Reynolds Certified Interface Program page; GlobeNewswire, Reynolds shareholders approve UCS merger, October 24, 2006
- Cox Automotive, Dealertrack acquisition completion, October 1, 2015; Dealertrack DMS platform page; Tekion “About Us” and APC pages (web pages accessed September 2026)
03How the access fight ended
The DMS access litigation Part 01 mentions has now largely settled, and the outcome explains why integration works the way it does. Authenticom, a data integrator that extracted data from dealers’ DMS accounts using login credentials the dealers gave it, sued CDK Global and Reynolds and Reynolds in 2017 and won a preliminary injunction requiring access. The Seventh Circuit vacated it, holding that “the proper remedy for a section 1 violation based on an agreement to restrain trade is to set the offending agreement aside” (Authenticom, Inc. v. CDK Global, LLC, 874 F.3d 1019 (7th Cir. 2017)). The DMS vendors’ programs remained the controlled route to the data.
The related cases were consolidated as In re Dealer Management Systems Antitrust Litigation, MDL No. 2817 (N.D. Ill.). Dealers and vendors alleged that CDK and Reynolds conspired to restrain competition. CDK and Reynolds denied the claims, and the dealership-class settlement notice states that “the Court has not decided which side is right.” The resolutions we could verify:
| Parties | Resolution | Date |
|---|---|---|
| Dealership class v. Reynolds | $29.5 million settlement; final approval | Jan 23, 2019 |
| Authenticom v. CDK | Settled; terms not public (trade reporting) | Oct 2020 |
| Authenticom v. Reynolds | Settled; terms not public (trade reporting) | Jun 2022 |
| Dealership class v. CDK | $100 million settlement (dealership-class total $129.5 million); approved by the court | Feb 25, 2025 |
| Vendor class (Loop LLC, d/b/a AutoLoop) v. CDK | Settlement reached; the court granted preliminary approval (W.D. Wis.). We did not confirm later proceedings. | Apr 29, 2025 |
The Wisconsin court also noted that earlier individual suits against CDK by Authenticom, Cox Automotive and MVSC “all settled years ago.”
State dealer-data laws
| State | Law | What it does, in summary |
|---|---|---|
| Arizona | A.R.S. §§ 28-4651 to 28-4655 (2019) | Bars DMS providers from taking action “by contract, technical means or otherwise to prohibit or limit a dealer’s ability to protect, store, copy, share or use” protected dealer data, or unreasonably restricting dealer-authorized integrators that meet security standards. The Ninth Circuit affirmed denial of CDK’s and Reynolds’s preliminary-injunction request (CDK Global LLC v. Brnovich, No. 20-16469 (Oct. 25, 2021)); as of September 2026 we did not review later proceedings. |
| Oregon | ORS 650.123 (2019 c. 500) | Bars DMS providers from requiring payment for access, while allowing security conditions and requiring the dealer’s express written authorization. Dealers may revoke on 30 days’ notice, or immediately for good cause. Conflicting DMS contract terms are “void and unenforceable to the extent of the conflict.” |
| Montana | Mont. Code Ann. §§ 30-11-717 to -720 (2019, amended 2023) | Bars “third parties,” including DMS vendors, from limiting a dealer’s use of its data “by contract, technical means, or otherwise”; requires fees to be disclosed and justified; consent revocable on 30 days’ notice or for cause. |
As of September 2026, we found no comparable statute in California, and other states may have provisions we did not find. In these three states the statute limits what a DMS contract can restrict (Oregon’s expressly voids conflicting terms). How a given clause in your DMS contract is affected, in these states or elsewhere, is a question to ask your counsel before you promise a vendor access.
Sources
- Dealership class settlement FAQ; Dealership Class Plaintiffs’ motion for preliminary approval, MDL No. 2817 (N.D. Ill., Aug. 16, 2024); Loop LLC v. CDK Global, LLC, No. 3:24-cv-00571 (W.D. Wis. Apr. 29, 2025)
- The Banks Report, October 30, 2020 (CDK–Authenticom); Law360, June 1, 2022 (Reynolds–Authenticom)
04Aggregators and hubs, and who owns them now
Many administrators connect once to a hub, and the hub connects to menus and DMSs. Part 01 names the principal hubs. Since that list is often repeated without dates, here is what each company or its acquirer has published about ownership.
| Hub or network | What it says it does | Ownership history, as published |
|---|---|---|
| PEN (Provider Exchange Network) | Connects product providers to dealer systems; cites “220+ Product Providers and Administrators” and “60+ Dealer-based systems.” | Acquired from MenuVantage by Open Dealer Exchange, LLC (ODE) in February 2010. ODE describes itself as “a joint venture founded by the two DMS providers CDK Global and Reynolds and Reynolds in 2009,” and presents PEN as one of its business lines. PEN’s own site does not name an owner. |
| F&I Express / F&I Aftermarket Network | Connects lenders, dealers and F&I providers. | Acquired by Cox Automotive October 1, 2018. The Express Aftermarket network was renamed “F&I Aftermarket Network” under the Dealertrack brand on October 1, 2024. |
| StoneEagle | Menu, reporting and service-drive products (retail unit); contract and claims administration software (enterprise unit). | Battery Ventures announced a majority investment in November 2020. On November 18, 2025, PCMI, a Thoma Bravo portfolio company, announced its acquisition of StoneEagle’s Enterprise Solutions unit. The release states that the retail unit continues operating independently under StoneEagle. |
| MaximTrak | F&I menu and digital retail. | Acquired by RouteOne, effective December 20, 2016. |
| Darwin Automotive | F&I menu and reporting. Dealertrack markets an “F&I eMenu Powered by Darwin Automotive.” | Acquired by J.D. Power, announced July 7, 2021. |
| RouteOne | Credit application, eContracting and F&I network. | “Formed in 2002 by Ally Financial, Ford Motor Credit Company, TD Auto Finance, and Toyota Financial Services.” |
| Dealertrack | Credit application network, DMS, F&I; Cox cites 1,500+ finance sources. | Cox Automotive, since October 1, 2015. |
Each hub here is owned by DMS vendors, a lender-founded network, a data and analytics company, or an investor-backed software company. That is a description, not a criticism: a hub’s priorities and pricing are not set by your administrator, and an outage or change of terms at a hub can affect contracts you sell through several providers at once.
Four of the seven entries changed hands at least once since 2016, and one was split in two in 2025. A slide listing “F&I Express” may be describing what Dealertrack now calls the F&I Aftermarket Network. Ask which network, under which current contract, and who supports it.
Sources
- F&I and Showroom, Open Dealer Exchange acquires PEN, February 23, 2010, and RouteOne acquires MaximTrak, December 20, 2016
- PR Newswire, “Cox Automotive Acquires F&I Express,” October 1, 2018; Dealertrack, Express Aftermarket transition FAQ, 2024
- Business Wire, Battery Ventures investment in StoneEagle, November 9, 2020; PCMI release on StoneEagle Enterprise Solutions, November 18, 2025; J.D. Power release on Darwin Automotive, July 7, 2021
- Web pages of Open Dealer Exchange, PEN, RouteOne, Dealertrack and Cox Automotive (accessed September 2026)
05API, batch, real-time: what the words mean
The same words describe very different mechanisms. This is what each usually means.
| Term | What it usually means | What to confirm |
|---|---|---|
| API (synchronous) | One system sends a request and waits for the answer, as in the rating call. | Timeout behavior; what the F&I manager sees when the call fails; how the connection is authenticated |
| Event or webhook | A system pushes a notice when something changes, such as a registration. | Which events are pushed, to whom, and what happens to a missed event |
| Batch | Records are sent as a file on a schedule, often overnight, commonly over SFTP. | Schedule; who confirms receipt; how rejected records are reported back |
| Portal | A person logs in and keys or uploads data. | Fallback or main path; MFA on every login |
| Credential-based extraction | A third party logs in with a user’s credentials and pulls data from screens or reports. This was the model at issue in Authenticom. | Whether your DMS contract permits it; whose credentials; whether that user has MFA |
| “Real-time” | A claim about speed. It says nothing about which mechanism is used. | Measured latency at the median and 95th percentile, for each step separately |
Integrations often combine these: rating by synchronous API, registration and remittance in a nightly file, and both called “integrated.” Neither design is wrong, but a contract rated in under a second may not exist in the administrator’s system until the next morning, and a cancellation may not reach the dealer until the next remittance cycle.
Ask for a monthly reconciliation of three lists: contracts posted in your DMS, registered by the administrator, and remitted. Any difference is a customer who may believe they are covered, a dealer who may have been billed for something never registered, or both. Who produces that report, and how often, tells you more than an architecture diagram.
If any vendor reaches your DMS or a lender portal using a login issued to one of your employees, that login is shared with a third party. The Safeguards Rule requires multi-factor authentication “for any individual accessing any information system” unless your Qualified Individual approves in writing a reasonably equivalent or more secure control (16 C.F.R. § 314.4(c)(5)). Ask whether shared credentials exist, and how your Qualified Individual has addressed them.
06The Safeguards Rule as amended
The FTC states that the Safeguards Rule covers automobile dealers that extend credit through a retail installment contract, arrange financing or leasing for personal, family or household use, or lease vehicles for more than 90 days (FTC dealer FAQ, June 2025). The rule was substantially amended in 2021, with most new elements in force from June 9, 2023 after an FTC extension, and a notification requirement added effective May 13, 2024. Part 01 covers § 314.4(f).
| Requirement | Section | What it means for integrations |
|---|---|---|
| Qualified Individual | § 314.4(a) | One named person oversees the program; may work for an affiliate or service provider, in which case the rule says the institution retains responsibility. |
| Written risk assessment | § 314.4(b) | Ask whether yours covers each system in section 01 holding customer information, vendors’ included. |
| Encryption | § 314.4(c)(3) | Customer information in transit over external networks and at rest, unless infeasible and the Qualified Individual approves a compensating control. Ask how batch files and exports are handled. |
| Multi-factor authentication | § 314.4(c)(5) | The rule says “for any individual accessing any information system.” Ask how vendor portals your staff use are addressed. |
| Secure disposal | § 314.4(c)(6) | No later than two years after last use, subject to exceptions for business need, legal retention and infeasibility. Matters on termination (section 10). |
| Monitoring and logging | § 314.4(c)(8) | Authorized users’ activity monitored and logged. Ask whether vendor access to your data is logged where you can see it. |
| Testing | § 314.4(d)(2) | Continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months. |
| Incident response plan | § 314.4(h) | Written. Ask whether yours names the vendors you would need to reach, and how, if your systems were down. |
| Annual report | § 314.4(i) | In writing, at least annually, to the board or equivalent, or else to a senior officer responsible for the program. |
The rule exempts an institution holding customer information on fewer than 5,000 consumers from § 314.4(b)(1), (d)(2), (h) and (i), but nothing else (16 C.F.R. § 314.6).
The notification requirement
Since May 13, 2024, a financial institution must notify the FTC “as soon as possible, and no later than 30 days after discovery” of a notification event involving the information of at least 500 consumers (§ 314.4(j)). A notification event is the “acquisition of unencrypted customer information without the authorization of the individual to which the information pertains.” Information counts as unencrypted if the encryption key was also accessed, and unauthorized access is presumed to be acquisition unless the institution has reliable evidence otherwise (§ 314.2). The FTC has said it intends to put the reports in a publicly available database (88 Fed. Reg. 77499 (Nov. 13, 2023)). Section 314.4(j) provides for notice to the FTC. Notice to consumers is addressed by state breach statutes, which differ in triggers, deadlines and content; ask your counsel which apply to you.
Ask your counsel how § 314.4(j) applies if an incident occurs at a vendor holding your customers’ data, and who would file. Ask each vendor how quickly, and with what information, it will tell you about an incident, and whether that is in the contract.
Separately, for dealers within the FTC’s jurisdiction, the FTC’s Privacy Rule (16 C.F.R. Part 313), which the FTC’s 2025 dealer FAQ continues to point dealers to, governs sharing nonpublic personal information with nonaffiliated companies; some dealers may instead be subject to the CFPB’s Regulation P. The FTC’s Privacy Rule guidance for dealers describes exceptions for service providers under contract and for processing a transaction the consumer requested. Ask your counsel how those exceptions apply to the information you send to administrators, hubs and other vendors. This is a summary, not legal advice.
Sources
- 16 C.F.R. §§ 314.2, 314.4, 314.6; FTC, Final Rule, Standards for Safeguarding Customer Information, 88 Fed. Reg. 77499 (Nov. 13, 2023), effective May 13, 2024
- FTC press release extending the compliance deadline, November 2022
- FTC, Automobile Dealers and the FTC’s Safeguards Rule: Frequently Asked Questions (June 2025); FTC, The FTC’s Privacy Rule and Auto Dealers: Frequently Asked Questions
07State privacy laws and the GLBA exemption
Dealers often assume GLBA coverage takes them outside state consumer privacy laws. That depends on the state and on how its law is written. An entity-level exemption removes the whole business. A data-level exemption removes only GLBA-covered information and leaves other personal information subject to the state law.
California’s CCPA, for example, applies to businesses above statutory thresholds, including $26,625,000 in annual gross revenue as adjusted January 1, 2025; its provision on GLBA-covered information is Cal. Civ. Code § 1798.145(e). Other states’ exemptions may differ and may have changed, and we have not summarized them here because we could not confirm them against enacted text. Check the current statute in each state where you operate.
Under a data-level exemption, some of the data moving through section 01 may be exempt and some may not. Ask your counsel which of that data is covered by an exemption in each state where you operate, rather than assuming the whole deal jacket is.
Sources
- Cal. Civ. Code § 1798.145(e); California Privacy Protection Agency, “Updated Monetary Thresholds in CCPA” (December 2024)
08SOC 2 reports: what they tell you and what they do not
Part 01 recommends asking for a SOC 2 Type II report. A SOC 2 report is an independent CPA firm’s examination of a service organization’s controls against the AICPA’s Trust Services Criteria. Security is always in scope; availability, processing integrity, confidentiality and privacy are optional, chosen by the organization.
| Type I | Type II | |
|---|---|---|
| What is tested | Whether controls are suitably designed and implemented | Design, and whether the controls operated effectively |
| Time covered | A single date | A period, typically three to twelve months |
| What it can show | The controls were designed and in place on that date, not that they worked over time | How the controls performed over the period, with any testing exceptions reported |
Where to look in the report
- The system description. A report on corporate IT says little about the rating or claims platform your data passes through.
- The categories. A security-only report does not address availability, which matters if you need claims lookup working on a Monday morning.
- The opinion. Unqualified, qualified, adverse or a disclaimer. Read which one it is.
- Testing exceptions. Listed control by control in a Type II. A small number is common; read what they were and management’s response.
- Complementary user entity controls. Controls the report assumes you have in place. If you have not implemented them, its conclusions may not hold for your use.
- Subservice organizations. Under the carve-out method, the vendor’s own vendors, such as a cloud host or hub, are excluded; under the inclusive method, included. Carve-outs are common and legitimate, but mark the report’s edge.
- The period. If it ended months ago, ask for a bridge letter.
It is not a certification, a rating or a promise that incidents will not happen. It is an auditor’s opinion on specified controls, for a specified system and period, and it does not examine your integration. It can be one input to the periodic assessment of service providers described in § 314.4(f), not the whole of it.
Sources
- Maryland Association of CPAs, “Complete Guide to SOC 2 Reports”; Linford & Co., “SOC Review Guidance: How to Read SOC 1 & SOC 2 Reports” (both accessed September 2026)
09CDK, June 2024: what the public record adds
Part 01 summarizes the attack on CDK Global that began June 18, 2024 (roughly 15,000 dealer locations affected, about sixteen days to restore, one outside estimate of more than $1 billion in collective dealer cost). CDK is privately held, so much of the public record is what others filed. Beyond Part 01, we could verify:
- Public dealer groups disclosed it to the SEC. Filers in June 2024 included Lithia Motors, Group 1 Automotive, Sonic Automotive and Penske Automotive, according to trade reporting. Group 1’s June 24, 2024 exhibit stated that the incident “has disrupted Group 1’s business applications and processes in its U.S. operations” and that its U.S. dealerships “continue to conduct business using alternative processes.” Sonic Automotive later said, as reported by Cybersecurity Dive, that the incident was “reasonably likely to have a material impact” on its results.
- CDK filed a breach notice with the Maine Attorney General. CDK Global LLC’s notice reports an external system breach (hacking) occurring June 14–20, 2024, discovered June 19, with written consumer notice on September 20, 2024. It lists 36 total persons affected, one of them a Maine resident. It records that notification only; it does not describe whose information was involved or the scope of the outage, and we have not inferred either.
The lesson we draw is narrow. The dealers whose disclosures we read kept selling by working around the DMS. The question is not which vendor was attacked but whether each step in section 01 still works when the DMS does not. If a step has no path around the DMS, find that out before an outage does.
Sources
- Group 1 Automotive, Inc., Exhibit 99.1 to Form 8-K, June 24, 2024 (SEC EDGAR)
- The Record (Recorded Future News), “Multiple car dealers report disruptions to SEC due to cyberattack on software company,” June 2024; Cybersecurity Dive, “Sonic Automotive’s sales dip as CDK cyberattack causes material impact,” July 2024
- Maine Attorney General, Data Breach Notifications, CDK Global LLC entry
10Data ownership and portability on termination
Different rules govern different bodies of data.
| Data | Who holds it | What governs it |
|---|---|---|
| Deal and customer data in your DMS | Your DMS vendor, on your behalf | Your DMS contract; in Arizona, Oregon and Montana, dealer-data statutes as well (section 03) |
| Contract, claims and cancellation records | The administrator and provider | State service-contract law. Texas, for example, requires providers, and administrators appointed to keep their records, to retain contract and claims records “until at least the first anniversary of the expiration date” of coverage (Tex. Occ. Code § 1304.155) |
| Reporting and reinsurance data | The administrator; your reinsurance entity | Your administration and reinsurance agreements. See Dealer Reinsurance and Profit Participation, Explained |
| Copies held by hubs and menu vendors | Each vendor | Each vendor’s contract with you |
Two points to consider when a relationship ends. First, an administrator may be required by state law to retain records (Texas § 1304.155 is one example), so ask what it must keep, for how long, and whether it will provide a complete export. Second, § 314.4(c)(6) calls for procedures to dispose of customer information no later than two years after its last use, subject to exceptions for business need, legal retention and infeasibility. Ask your counsel how that applies to copies held by former vendors, and ask each vendor which copies it will retain and which it will dispose of.
In-force contracts outlive the administration agreement. Ask how any termination arrangement preserves the customer’s ability to get a claim paid and your ability to process cancellations and reconcile what you are owed. See Cancellations, Refunds and Chargebacks and, for programs carrying your name, White-Label and Private-Label F&I Programs.
Where CareGard sits
For disclosure: CareGard’s programs are administered on TRONIX, the platform CareGard uses to administer its programs. As described on caregard.com/technology, its functions include OEM integrations, dealer and agent portals, reporting, program administration (rate tables, contract issuance, cancellation management and reinsurance accounting) and data exchange. That is a description of functions, not a claim about security or speed; ask us the questions in section 11 as you would any administrator. We mention it so you know where we sit in section 01. The questions in this guide apply to us as much as to anyone.
11An integration due-diligence checklist
These extend Part 01’s technology questions. Ask for the answers in writing.
Ask — the connection
- Draw the path from my menu to your system of record, naming every company in between and which legs are API, file or portal.
- For my DMS: are you, or your hub, a certified participant in the DMS vendor’s program? What is the scope: read or write, which data, which rooftops?
- What does any DMS or hub access cost, and is any of it billed to me directly or indirectly?
- Will you produce a monthly reconciliation of contracts posted in my DMS, registered with you and remitted? Who resolves differences, and in how many days?
- Does any part of the integration rely on credentials issued to my employees? If so, is MFA enforced on them?
Ask — the data and its protection
- List every subservice organization (hosting, hubs, e-signature, claims tools) that will receive my customers’ information.
- For your SOC 2 report: which system, categories, period, opinion, exceptions and carve-outs, and which user entity controls do you expect of me?
- Is my customers’ information encrypted in transit and at rest in every system on that list, including batch files, backups and exports?
- Can you show me a log of your staff’s and vendors’ access to my customers’ records?
- Which state privacy laws do you treat as applying to the data you hold for my stores, and on what basis?
Ask — when something goes wrong
- Within how many hours of discovering an incident involving my customers’ data will you notify me, with what content? Is that in the contract?
- If my DMS is down, how do I rate, issue, register and cancel contracts, and how does my service drive confirm coverage?
- If your hub is down, what is the fallback, and how are outage contracts reconciled?
Ask — at the end
- On termination, what exactly will you export (fields, format, frequency), within what time, and at what charge?
- How will claims, cancellations and refund calculations on my in-force book be handled afterward, and how will I see them?
- Which records must you retain by law, for how long, and will you certify disposal of the rest?
- Who tells the hubs and menu vendors to cut the connection, and who confirms it has been cut?
12How we built this, and what we could not verify
We used primary sources wherever they exist, and labelled trade reporting and other secondary sources as such. What we could not verify:
- Later proceedings in the vendor-class settlement. We confirmed preliminary approval (April 29, 2025) only.
- Terms of the Authenticom settlements with CDK (2020) and Reynolds (2022).
- Dealer-data laws beyond Arizona, Oregon and Montana, and GLBA treatment under state privacy laws other than California’s.
- DMS market shares and typical integration timelines. We found no independent, current source.
- How § 314.4(j) applies to an event at a service provider. We leave that to your counsel.
Ownership statements are accurate as of their stated dates and September 2026; check again before relying on them. This is not legal advice. These rules and statutes apply differently to different businesses, and several changed in 2025 and 2026. Use this guide to ask better questions of your counsel and vendors, not in place of them. We intend to review it annually. If something here is wrong, we would like to know.
Primary sources
- 16 C.F.R. Part 314 (§§ 314.2, 314.4, 314.6); FTC Final Rule, 88 Fed. Reg. 77499 (Nov. 13, 2023); FTC compliance-deadline extension, November 2022
- FTC, Automobile Dealers and the FTC’s Safeguards Rule: Frequently Asked Questions (June 2025); FTC, The FTC’s Privacy Rule and Auto Dealers: FAQs
- Authenticom, Inc. v. CDK Global, LLC, 874 F.3d 1019 (7th Cir. 2017); In re Dealer Management Systems Antitrust Litigation, MDL No. 2817 (N.D. Ill.); Loop LLC v. CDK Global, LLC, No. 3:24-cv-00571 (W.D. Wis. Apr. 29, 2025); Dealership class settlement FAQ
- CDK Global LLC v. Brnovich, No. 20-16469 (9th Cir. Oct. 25, 2021); A.R.S. §§ 28-4651 to 28-4655; ORS 650.123; Mont. Code Ann. § 30-11-718 and §§ 30-11-717 to 30-11-720
- Cal. Civ. Code § 1798.145; California Privacy Protection Agency, monetary thresholds; Tex. Occ. Code § 1304.155
- Group 1 Automotive, Inc., Exhibit 99.1, June 24, 2024; Maine Attorney General, Data Breach Notifications (CDK Global LLC)
- Brookfield Business Partners, CDK acquisition announcement, April 7, 2022; Reynolds and Reynolds, Reynolds Certified Interface Program; Cox Automotive, Dealertrack acquisition completion, October 1, 2015; Tekion, Automotive Partner Cloud
- Cox Automotive Acquires F&I Express (October 1, 2018); Dealertrack, Express Aftermarket transition FAQ (2024); PCMI / StoneEagle Enterprise Solutions (November 18, 2025); J.D. Power / Darwin Automotive (July 7, 2021); RouteOne, About; Open Dealer Exchange; Provider Exchange Network
- 15 U.S.C. § 7001 (E-SIGN); UCC § 9-105, as enacted by the states