Your Vendor Was Hacked. Could Your Business Be Liable?

When most small-business owners hear “data security,” they picture a major corporation, a sophisticated cyberattack, or millions of stolen credit-card numbers.
That isn’t the whole picture.
Every day, businesses in our industries collect and transmit information about customers, employees, vehicles, payments and transactions. Much of that information doesn’t remain inside the business. It passes through software companies, payment processors, financing providers, dispatch platforms, insurance systems, payroll companies, loyalty programs, cloud services and other vendors.
And that creates an important question:
When you give customer or employee information to another company, who is responsible for protecting it?
The answer may be closer to home than many business owners realize.
New York Places Responsibility on the Business, Too
New York’s SHIELD Act requires businesses that own or license computerized data containing New York residents’ private information to develop, implement and maintain reasonable safeguards to protect it.
Those safeguards aren’t limited to firewalls and passwords.
New York specifically identifies the selection and oversight of service providers as part of a reasonable data-security program. Businesses are expected to select providers capable of maintaining appropriate safeguards and require those safeguards by contract.
In other words:
Using a third-party company to handle information does not necessarily transfer your responsibility for protecting it to that company.
A vendor suffering a breach does not automatically mean your business violated the law. But if something goes wrong, one of the questions may be what reasonable steps your business took before entrusting that vendor with the information.
This Isn’t Just an Automotive Repair Issue
The information at risk looks different depending on the business.
Automotive Service Shops
A modern repair facility may send or store customer and vehicle information through:
- shop-management systems;
- online scheduling platforms;
- texting and CRM systems;
- payment processors;
- customer financing companies;
- diagnostic and scan-tool platforms;
- parts-ordering systems;
- connected-vehicle services;
- accounting and payroll software; and
- cloud backup providers.
A customer’s information can move through several systems during a single repair order.
The shop owner may not control those systems—but should know which companies have access to the information and what protections are in place.
Collision and Body Shops
Collision businesses can handle particularly extensive records.
An estimating or claims file may contain a customer’s name and contact information, VIN and vehicle information, insurance information, photographs, accident information, repair documentation and payment information.
That information may be shared among estimating platforms, insurers, DRP systems, rental companies, parts vendors, calibration providers, towing companies and other subcontractors.
The question isn’t simply, “Is my computer secure?”
It’s also:
Who can access this claim once I put it into the system?
significant information without thinking of themselves as businesses that collect data.
A dispatch or impound record may connect:
- a person’s name;
- telephone number;
- vehicle and VIN;
- vehicle location;
- pickup and destination information;
- roadside-assistance information;
- insurance information;
- law-enforcement information; and
- payment information.
Motor clubs, dispatch providers, GPS systems, payment processors, impound-management software and subcontractors can all become part of that information chain.
Location information deserves particular attention. Knowing where a vehicle was picked up, where it was taken and when can reveal information about an individual that goes well beyond a routine towing transaction.
Convenience Stores
Convenience stores may have one of the widest collections of data systems in our membership.
Consider what may be connected to the business:
- point-of-sale systems;
- payment processors;
- loyalty programs;
- mobile applications;
- online ordering;
- delivery platforms;
- ATMs;
- age-verification systems;
- surveillance systems;
- employee scheduling;
- payroll and HR systems; and
- accounting platforms.
A loyalty program can connect a customer’s identity with purchasing activity. A payment system handles financial information. An age-verification system may interact with identification information. Employee systems contain another category of sensitive records altogether.
For stores selling fuel, add:
- pay-at-the-pump systems;
- fuel-price systems;
- tank-monitoring technology;
- fleet-card systems;
- fuel-management platforms; and
- outside companies servicing that equipment.
The fact that a system is owned, operated or serviced by somebody else doesn’t mean the business should ignore what information passes through it.
Towing Companies
Towing businesses can accumulate significant information without thinking of themselves as businesses that collect data.
A dispatch or impound record may connect:
- a person’s name;
- telephone number;
- vehicle and VIN;
- vehicle location;
- pickup and destination information;
- roadside-assistance information;
- insurance information;
- law-enforcement information; and
- payment information.
Motor clubs, dispatch providers, GPS systems, payment processors, impound-management software and subcontractors can all become part of that information chain.
Location information deserves particular attention. Knowing where a vehicle was picked up, where it was taken and when can reveal information about an individual that goes well beyond a routine towing transaction.
Salvage and Reclamation Businesses
Salvage and reclamation facilities have another complicated combination of physical assets and information.
Businesses may maintain vehicle ownership and title records, VINs, seller and buyer information, payment records, auction information and records associated with dismantled vehicles and parts.
There is also another issue worth considering:
The vehicle itself may contain data.
Modern vehicles can retain paired phones, contact information, navigation destinations, garage-door information, account credentials and other electronic information depending on the vehicle and its systems.
A vehicle arriving at the end of its useful life doesn’t necessarily arrive empty of its previous owner’s information.
Auction companies, title-processing systems, transportation companies, parts marketplaces and other vendors can add additional points where information is exchanged.
RSGDA Member Resources:
RSGDA has developed industry-specific Know Your Vendors Checklists for:
Employee Information Counts, Too
Customer information gets most of the attention, but businesses should also consider what they maintain about employees.
Payroll, benefits, workers’ compensation, employment applications and HR systems can contain Social Security numbers, banking information, addresses, identification documents and other sensitive information.
Those records are frequently transmitted to outside payroll processors, insurance companies, benefits administrators, accountants and other service providers.
Your vendor review therefore shouldn’t stop at customer-facing systems.
Ask who has access to employee information as well.
What Does New York Consider Private Information?
The SHIELD Act covers specific categories of private information rather than every piece of information a business possesses.
Depending on how information is collected and combined, protected information can include Social Security numbers, driver’s-license and other identification numbers, financial account information, biometric information and online account credentials.
The law also expanded the concept of a breach beyond information actually being stolen. Unauthorized access to protected computerized data can potentially trigger the law as well.
The Vendor Breach Problem Is Already Getting Regulatory Attention
This isn’t a hypothetical concern.
In September 2026, the New York Attorney General announced a multistate settlement involving Labcorp following a breach at an outside debt-collection company.
The breach occurred at the vendor, but the resulting settlement required Labcorp to make substantial changes to its own vendor-risk management.
Those requirements included improving vendor oversight, minimizing data shared with vendors, strengthening contractual cybersecurity requirements, assessing and auditing vendors and developing procedures for responding to vendor security incidents.
The case involved a much larger organization and substantially more sensitive information than most independent businesses handle. But the underlying lesson translates:
Regulators are looking at what a business did to oversee the companies it trusted with customer information.
“We’re a Small Business” Doesn’t Mean “This Doesn’t Apply”
New York does recognize that reasonable cybersecurity for a small independent business will look different from cybersecurity at a national corporation.
The SHIELD Act allows safeguards to be appropriate to the size and complexity of the business, the nature and scope of its activities and the sensitivity of the information involved.
That’s important.
A ten-person repair facility isn’t expected to operate a Fortune 500 cybersecurity department.
But small businesses aren’t simply exempt.
The objective is reasonable protection appropriate to your operation.
Start With One Simple Exercise
You don’t need to become a cybersecurity professional.
Start by sitting down and answering this question:
Where does our information go?
Write down every outside company that receives, stores or can access customer or employee information.
Then ask:
- What information do they receive?
- Do they actually need all of it?
- How long do they keep it?
- Who else can they share it with?
- What security requirements are in our contract?
- How will they notify us if something happens?
- What happens to our information if we stop using them?
You may discover that information is being held in systems you haven’t thought about in years.
Collect Less. Keep Less. Share Less.
One of the simplest ways to reduce exposure is also one of the most overlooked:
Don’t maintain information you don’t need.
New York’s guidance encourages businesses to understand where consumer information is stored and dispose of private information within a reasonable period after it is no longer needed for business purposes.
That principle can be applied practically.
If an old vendor still has customer records from five years ago, ask why.
If software is collecting information you never use, ask whether it needs to.
If former employees still have accounts, remove them.
If everyone in the company uses the same login, change that practice.
If an outside provider has access to information it doesn’t need to perform its job, question the access.
Cybersecurity doesn’t begin with expensive technology.
It begins with knowing what you have, where it goes and who can reach it.
And Yes—Know Your Physical Vendors, Too
There is a parallel lesson on the product side.
NHTSA is currently warning the automotive industry about illegally imported DTN60DB replacement airbag inflators associated with deaths and serious injuries.
For businesses handling vehicles and safety-critical components, that raises another version of the same vendor-management question:
Do you know who you’re buying from?
Parts provenance matters. So does documentation.
But parts are only one piece of a much larger vendor-risk issue.
Whether you’re buying a safety-critical automotive component, hiring a payroll company, accepting payments through a processor, sending vehicles through an auction, using a towing dispatch platform or enrolling customers in a loyalty program, your business is placing some degree of trust in another company.
Know Who You’re Trusting
Most independent businesses couldn’t operate without third-party vendors.
The answer isn’t to stop using them.
It’s to understand the relationship.
Know which companies have access to your customers.
Know which companies have access to your employees.
Know what information you’re giving them.
Know what your contracts require.
Know how long the information is being kept.
And know what happens if something goes wrong.
Your vendor may operate the system.
Your customer still knows your business’s name.
That alone makes vendor security worth paying attention to.