CARRUSLiNK

    Guide · Customer data & GDPR

    Customer data and GDPR in dealerships: a practical 2026 guide

    The auto industry sits on enormous amounts of personal data, addresses, national IDs, driving patterns, financing. Few industries have greater GDPR exposure, and few can win more by getting it right.

    Sidst opdateret:

    Short answer (TL;DR)

    GDPR in a dealership comes down to 4 things: data minimization, consent, retention and export/deletion. If you run on Excel, email and DMS without a unified system, you're almost certainly not compliant. CARRUSLiNK ships with a GDPR module, EU hosting, audit log and automated consent management.

    Where dealerships typically fail

    • Customer data sits in 5 different Excel files and personal inboxes
    • No control of marketing consent per channel
    • Salesperson walks out with the customer base on resignation
    • No audit log: you don't know who saw what when
    • Deletion on customer request takes 5 days and is manual
    • Data on closed leads is retained for years without purpose

    6 steps to GDPR compliance in a dealership

    1

    1. Centralize data in one place

    Pull everything from Excel, email and DMS into CARRUSLiNK. One customer card, one truth, so you can even show where data lives.

    2

    2. Define processing purposes

    For each data field: why are you holding it? Sales, accounting, warranty, marketing? We provide a processing register template.

    3

    3. Set retention periods

    Leads deleted automatically after 12 months without activity. Accounting data 5 years. Contracts 5 years post-termination. Auto-purge in the system.

    4

    4. Capture consent per channel

    SMS, email, phone. Each channel has its own toggle. The customer can unsubscribe in one click.

    5

    5. Audit log on everything

    Every view, edit and export is logged with user, time and IP. Ready for a DPA inspection.

    6

    6. Export and deletion in one click

    On customer request: export all data as PDF/JSON or delete the entire profile permanently. Done in 30 seconds.

    What you actually get

    GDPR compliance out of the box

    Processing register, consent log, audit log and deletion are part of the base package.

    EU hosting and encryption

    All data hosted in the EU. Encryption in transit and at rest. ISO 27001-based environment.

    One home for customer data

    No Excel on local drives. No salesperson walking out with the customer base.

    Data processing agreement ready

    DPA signed electronically at contract. No legal back-and-forth.

    Role-based access

    Sales sees own customers, management sees all, accounting sees contracts. Least-privilege by default.

    No third-country transfers

    We don't use US sub-processors on core data. Hosted in the EU, no Schrems II exposure.

    Frequently asked questions

    Get GDPR control of your customer data

    30 minutes. We walk through your current data flow and show where you're exposed today.