The FTC Safeguards Rule applies to you
Because dealerships arrange financing, the FTC treats them as financial institutions under the Gramm-Leach-Bliley Act. That means you're required to maintain a written information security program, name a qualified individual responsible for it, and — the part that matters here — oversee your service providers and hold them to it by contract.
If a system I build touches credit applications, Social Security numbers, or anything else that counts as customer non-public personal information, I become one of those service providers and belong inside that program. I'd expect you to hold me to it, and I'll put in writing which services process what.
Plenty of high-value work sits outside that boundary entirely — lead response, service scheduling, inventory and merchandising all run on data that isn't NPI. If you'd rather keep the first project clear of your Safeguards scope, say so and we'll scope it that way.
Ask any vendor this
Ask where their system stores credit application data and who else can see it. If a vendor can't answer that in one sentence, they're a gap in your Safeguards program.
How data is actually handled, including every subprocessor: data handling →