
Give every vendor agent a named CRM account, protected by multi-factor authentication, with only the access the job needs. Never share a login. Know how accounts are closed when an agent leaves, where recordings and exports are stored, and how your data comes back at exit. Under the FTC Safeguards Rule the vendor is your service provider, and overseeing it is your job.
Why a BDC Vendor Counts as a Service Provider
This page is general information, not legal advice. It was checked against the linked sources in October 2026; confirm how it applies to your store with your counsel and your IT provider. It is part of the Dealership BDC Guide.
The FTC says dealers who finance, or facilitate the financing of, vehicles for consumers are financial institutions under the Safeguards Rule, as are dealers who lease vehicles for longer than 90 days (FTC, Automobile Dealers and the Safeguards Rule FAQ). The rule defines a service provider as “any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution,” 16 CFR 314.2 (16 CFR Part 314, eCFR). An outside phone room logging into your CRM is permitted access. That is the definition.
Our article on the FTC Safeguards Rule and dealership marketing covers the full program. This one is about the day-to-day mechanics of letting an outside team into the CRM.
Named Accounts, Never a Shared Login
The fastest way to start a vendor is to hand over one username, “bdc@yourstore,” and let twelve people use it. Do not. The rule tells you to authenticate users and permit access only to authorized users, 16 CFR 314.4(c)(1). You cannot authorize a person you cannot name.
A shared login also fails in three ordinary ways. When a note is wrong, the CRM cannot tell you who wrote it. When one agent leaves, you cannot shut off that agent without locking out the rest. And when a password is known to twelve people, it is known to everyone they have told.
So: one account per person, in that person’s real name, with the vendor named in the title or team field so your managers can filter by it. Ask the vendor for a roster and match it to your user list before launch.
Least Privilege: What a BDC Agent Needs
The same paragraph of the rule says to “limit authorized users’ access only to customer information that they need to perform their duties and functions.” A BDC agent sets appointments. That needs less of the CRM than most stores hand out.
| Area of the CRM | BDC agent | Why |
|---|---|---|
| Lead and customer contact records | Yes | Cannot work a lead without them. |
| Appointment calendar or service scheduler | Yes | Booking is the job. |
| Inventory | View only | To confirm the vehicle is there. |
| Notes, tasks, call and text logging | Yes | So your managers see every touch. |
| Credit applications and credit reports | No | Not needed to set an appointment. |
| Desking, deal structure, F&I | No | The desk owns numbers. |
| Bulk export and report downloads | No, or the vendor’s manager only | An export is a copy of your database. |
| User setup and system settings | No | The store controls who gets in. |
Ask your CRM provider to build a role that matches this, and assign vendor users to it. If the CRM cannot separate these areas, tell the vendor and your counsel, and write down the compensating steps you took. Process topics such as note templates and pipeline stages are in CRM mastery for automotive BDC teams.
Multi-Factor Authentication for Every Vendor User
The rule says to “implement multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls,” 16 CFR 314.4(c)(5). Multi-factor means at least two of three kinds of proof: something the person knows, something the person has, something the person is (16 CFR 314.2).
“Any individual” includes the vendor’s agents. Two points for the launch checklist. First, the second factor must belong to the individual agent, not to a shared team phone or mailbox, or you have rebuilt the shared login. Second, a small store is not excused: the exception in 16 CFR 314.6 for institutions holding information on fewer than 5,000 consumers lifts four requirements (the written risk assessment, penetration testing and vulnerability scans, the written incident response plan and the board report). Multi-factor authentication, service provider oversight and FTC breach notice are not among them.
When a Vendor Agent Leaves
Phone rooms turn people over, and the agent who quit on Friday still has a working login on Monday unless someone removes it. The store controls the CRM, so the store has to know.
- Require the vendor to tell you the same day an agent with access leaves or is reassigned.
- Name the person at the store who disables the account, and a backup.
- Once a month, pull the CRM user list and compare it to the vendor’s current roster. Disable anything that does not match.
- Look at last-login dates. An account unused for weeks should be closed.
Set this up in the first week, alongside the rest of outsourced BDC onboarding.
Recordings, Exports and Other Copies
The CRM is the copy you can see. The ones to ask about are the copies you cannot.
- Call recordings. Stored by the vendor’s phone system, usually outside your CRM. Ask where, who can play them and how long they are kept. See call recording laws for dealerships for the consent side.
- The vendor’s own platform. If agents work in the vendor’s dialer or software and push notes back, your customer list is in that system too.
- Exports. Call lists pulled to a spreadsheet for an outbound campaign, then emailed. Ask how lists are sent and when they are deleted.
- Texting and email tools. Each holds names, numbers and conversation history.
The rule calls for customer information to be encrypted in transit over external networks and at rest, or protected by approved compensating controls, 16 CFR 314.4(c)(3). Ask the vendor to confirm both, in writing, for each of those four places. Where the agents and the data physically sit is its own question, covered in US-based vs offshore BDC.
The Contract, the Assessment and the Breach Clock
Section 314.4(f) gives the dealer three duties toward a service provider: take reasonable steps to select and retain providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess providers based on the risk they present. The FTC adds a limit worth knowing: overseeing a provider “does not mean that you have to get the service provider to agree to meet all of the Safeguards Rule requirements.” You need appropriate safeguards for the information that vendor touches, in writing, and a dated check that they are still in place.
Then there is the clock. Under 16 CFR 314.4(j), a notification event (unauthorized acquisition of unencrypted customer information) involving at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery. If the event happens at the vendor, you can only meet that deadline if the vendor tells you quickly, so put a prompt notice requirement in the agreement. The clauses to ask for are listed in outsourced BDC contract terms.
Getting Your Data Back at Exit
If the vendor worked inside your CRM, most of the data never left, and exit is mostly a matter of disabling accounts. The rest needs a list:
- All vendor accounts disabled on the last day, confirmed against the roster.
- Recordings delivered in a format you can play without the vendor’s software.
- Any notes, dispositions or history held only in the vendor’s platform exported to you.
- Campaign lists and exports deleted, with written confirmation.
- Phone numbers and call forwarding returned to the store’s control.
We are one of these vendors. Before launch, BDC On Demand learns a store’s brands, CRM workflows, appointment process and service menu, which means our agents need access to do the work. Hold our outsourced call center for dealerships to this page the way you would hold anyone, and use the dealership compliance library for the related rules.
Frequently Asked Questions
Can an outsourced BDC share one CRM login?
It should not. The Safeguards Rule calls for authenticating users and permitting access only to authorized users, and a shared login cannot show who did what or be turned off for one person. Issue a named account for each agent and match the list to the vendor’s roster.
Does the Safeguards Rule require MFA for a vendor’s agents?
The rule requires multi-factor authentication for any individual accessing any information system, unless the dealership’s Qualified Individual has approved an equivalent or more secure control in writing (16 CFR 314.4(c)(5)). Vendor agents logging into your CRM are individuals accessing it. This is general information; confirm with counsel.
Are small dealerships exempt from overseeing vendors?
No. The exception for institutions holding information on fewer than 5,000 consumers removes four items: the written risk assessment, penetration testing and vulnerability scans, the written incident response plan and the board report. Service provider oversight, multi-factor authentication and FTC breach notice still apply.
Does a BDC agent need to see credit applications?
Not to set an appointment. The rule says to limit users to the customer information they need for their duties. A BDC agent needs contact records, the appointment calendar, inventory and notes. Credit applications, deal structure and bulk exports can stay with store staff.
What should happen to CRM access when we end the contract?
Every vendor account is disabled on the last day and checked against the roster. Recordings and any history held in the vendor’s systems are delivered to you in a usable format, campaign lists and exports are deleted with written confirmation, and phone numbers and call forwarding return to the store.
Summary
A BDC vendor with CRM access is a service provider under the FTC Safeguards Rule. Issue named accounts, limit each to what an appointment setter needs, require multi-factor authentication tied to the individual, close accounts the day an agent leaves, and find every copy of your data that sits outside the CRM. Put safeguards, prompt incident notice and data return in the contract. This is general information checked in October 2026, not legal advice; confirm it with counsel.



