Privacy Risk in the Connect Vehicle Era - Insight Vol. 36
- Phil Villegas

- 5 days ago
- 4 min read

BY ERIK ACOSTA
As a Dealership Consultant working in internal auditing, I spend a significant amount of time evaluating risks that are not apparent. One that has recent mass attention and appears to have been slightly underestimated is client privacy particularly related downloaded manufacturer applications and the trade-in process.
Dealership groups have made tremendous progress in operational efficiency and client data protection. However, one control gap continues to surface: the lapse in properly disconnecting prior owners from vehicles that are traded in. This oversight exposes dealership groups to operational, reputational, and potential legal and financial risk... and they might not even be aware.
Trade-in Client Privacy
Most vehicles nowadays are not simply vehicles to get you from point A to point B. They are traveling data machines. And through downloaded manufacturer applications and other connected services, customers can:
View live vehicle location
Remotely lock or unlock, and start the engine
Access routes, driving history, and vehicle health
Control various climate features
If an electric vehicle, access charging schedules and preset limits
Move the vehicle's location with full self driving capabilities
When a client trades in a vehicle, the “digital” relationship does not automatically stop. From personal experience, unless someone at the dealership proactively removes or unassigns access from the customers application or other connected services, they will continue to have access to the vehicle, long after ownership has ended.
This is not a “hypothetical risk,” I have seen cases where prior owners have retained access to all the features over six months after the vehicle is no longer theirs.
Unlike traditional data privacy concerns like DMS data breaches, connected vehicles risks cross the path of physical safety, control, and consumer trust.
Two Main Potential Implications of Not Disconnecting Applications
Customer Safety
If the prior owner can track and access a vehicle that is now owned by another client, the dealership can potentially face claims related to negligence, especially if tracking results in harm. Additionally, for electric vehicles, there are several other risks to consider, particularly related to charging schedules, which may limit vehicle range and overall accessibility.
Reputational Damage
Privacy breaches can erode trust quickly. A single incident shared online or escalated to the manufacturer can damage the dealership group brand.
Why I Believe This Is a Growing Risk
This concern will continue to grow as more vehicles become electronically connected to their owners. Vehicles are more connected, applications are more powerful, and customers are more aware of their rights related to privacy.
Without intentional controls, likelihood of an error will continue to increase. And what concerns me the most is not that mistakes happen, as we are humans and they will occur. However, that many dealership groups do not have a standardized process for this at all! If there is no control, there is nothing to follow or a guideline for employees to abide.
If You Want to Be Proactive
In my line of work, we see many dealership groups, some that manage risk effectively and others that do not. Those that do, however, tend to share the following practices:
Clear Ownership
In this case, responsibility for disconnecting vehicles is explicitly assigned, often to the pre-owned department or the team that is assisting in bringing this vehicle into inventory, while the client is at the dealership.
Checklists
Trade-in and acquisition checklists should include a mandatory step to remove prior owners from manufacturer apps and connected services. This process should be documented, trainable, and auditable, with employee names and signatures recorded. Equally important, employees should understand why this step matters.
Internal Auditing
Some dealership groups include a periodic audit of their checklist to ensure the guide is being followed and to ensure the control is being consistently used.
Beyond Trade-Ins
This should be viewed as a broader part of client privacy. This includes handling of driver data stored in infotainment systems, driver data stored in the vehicle while in use as a loaner. Addressing the trade-in portion noted throughout this article is only the beginning for strengthening overall privacy.
My Final Recommendation
From an auditor’s perspective, the question is not whether there is an actual risk; rather, it is whether your leadership team has taken reasonable steps to identify, mitigate, and monitor that risk.
You should be asking your team:
Do we have a documented process to disconnect trade-in vehicles?
Is responsibility clearly assigned and enforced?
Can we provide proof of compliance with the process, if audited?
If their response to any of the above is not a confident yes, that is an area that requires further attention to limit risks to your dealership group and clients.
Client privacy is no longer an abstract concept confined to IT departments. In today’s era of connected vehicles, client data is tangible, traceable, and increasingly consequential. For proactive dealership groups, the goal is not awareness alone, but action.
If any of the points discussed here sparked new ideas or reinforced existing practices, this article has served its purpose: to help strengthen the client data privacy framework within our industry and protect dealerships and customers from potential harm.






Comments