# Customer data and GDPR in dealerships: a practical 2026 guide

> The auto industry sits on enormous amounts of personal data, addresses, national IDs, driving patterns, financing. Few industries have greater GDPR exposure, and few can win more by getting it right.

**Source:** https://carruslink.com/en/guides/kundedata-gdpr-bilhuse
**Sidst opdateret:** 2026-05-25

## Short answer (TL;DR)

GDPR in a dealership comes down to 4 things: data minimization, consent, retention and export/deletion. If you run on Excel, email and DMS without a unified system, you're almost certainly not compliant. CARRUSLiNK ships with a GDPR module, EU hosting, audit log and automated consent management.

## Where dealerships typically fail

- Customer data sits in 5 different Excel files and personal inboxes
- No control of marketing consent per channel
- Salesperson walks out with the customer base on resignation
- No audit log: you don't know who saw what when
- Deletion on customer request takes 5 days and is manual
- Data on closed leads is retained for years without purpose

## 6 steps to GDPR compliance in a dealership

### 1. Centralize data in one place

Pull everything from Excel, email and DMS into CARRUSLiNK. One customer card, one truth, so you can even show where data lives.

### 2. Define processing purposes

For each data field: why are you holding it? Sales, accounting, warranty, marketing? We provide a processing register template.

### 3. Set retention periods

Leads deleted automatically after 12 months without activity. Accounting data 5 years. Contracts 5 years post-termination. Auto-purge in the system.

### 4. Capture consent per channel

SMS, email, phone. Each channel has its own toggle. The customer can unsubscribe in one click.

### 5. Audit log on everything

Every view, edit and export is logged with user, time and IP. Ready for a DPA inspection.

### 6. Export and deletion in one click

On customer request: export all data as PDF/JSON or delete the entire profile permanently. Done in 30 seconds.

## What you actually get

- **GDPR compliance out of the box** — Processing register, consent log, audit log and deletion are part of the base package.
- **EU hosting and encryption** — All data hosted in the EU. Encryption in transit and at rest. ISO 27001-based environment.
- **One home for customer data** — No Excel on local drives. No salesperson walking out with the customer base.
- **Data processing agreement ready** — DPA signed electronically at contract. No legal back-and-forth.
- **Role-based access** — Sales sees own customers, management sees all, accounting sees contracts. Least-privilege by default.
- **No third-country transfers** — We don't use US sub-processors on core data. Hosted in the EU, no Schrems II exposure.

## Frequently asked questions

### Are Excel and email GDPR-compliant?

Technically they can be, but in practice almost never. You can't show who saw what, can't delete across systems in one click, can't guarantee retention periods and can't pull an audit log. Data protection authorities have fined multiple dealers for exactly this.

### Where is our data stored?

Inside the EU. We don't use US core sub-processors. Backups are also in the EU. That means no Schrems II exposure and full control of where data physically lives.

### What happens when a customer requests deletion?

You open the customer card, click 'delete permanently', confirm and data is gone in 30 seconds, including underlying logs, contracts and communication. Accounting records are retained for the legally mandated 5 years, anonymized.

### What about national IDs?

National IDs are encrypted and accessible only to the staff with a concrete need (typically accounting and financing). We support national ID login for customers who want to view their own data and contracts.

### Do we get a data processing agreement (DPA)?

Yes. The standard DPA is part of the contract and can be signed electronically. Tailored terms are available for larger customers.

## Get GDPR control of your customer data

30 minutes. We walk through your current data flow and show where you're exposed today.

— CARRUSLiNK · https://carruslink.com/en/guides/kundedata-gdpr-bilhuse
