
The One Question Every Dealer Principal Should Ask Their Sales Team Right Now
At a recent NADA conference, a GM confessed he had hundreds of customer driver’s license photos on his personal phone.
Not in a compliant system. Not in a compliant digital deal jacket. On his phone alongside his family photos and group texts. He’s not alone. And that’s the problem.
The Question You Need to Ask Tomorrow Morning
Before your next sales meeting wraps up, ask this:
“Does anyone on this team have a customer’s personal information such as a driver’s license photo, insurance card, or pay stubs on their personal phone, in Gmail, or anywhere on a personal device?”
Then wait.
According to Doug Fusco, compliance expert and managing partner of compliance at Informativ, most sales teams will come clean if you give them the chance and the right conditions. His advice: offer a one-time amnesty. Tell your team they won’t be fired for having it. Clearly explain WHY it is an issue and what the risk is. But make clear that if it surfaces later and they didn’t raise their hand now, the conversation changes.
“At the sales kickoff meeting in the morning, give them one time to come clean,” Fusco says. “Raise your hand if you have personal information on your cell phone or in Gmail or in some other form on your personal device. You will not be fired for having it. However, if we find out afterwards and you didn’t say that, no promises.”
They’ll largely come clean. And then the real work begins.
Why This Matters: $53,000 Per Violation
This isn’t a housekeeping issue. Under the FTC Safeguards Rule, storing customer nonpublic personal information (NPI) which includes driver’s license data on unauthorized personal devices is a federal compliance violation. The fine? Up to $53,000 per violation.
Not per incident. Per violation.
A salesperson with 200 license photos on their phone isn’t one violation. Do the math.
And it doesn’t stop at phones. Fusco points out that the problem extends to Gmail accounts, personal email, text threads, anywhere customer data lands outside of a secure, controlled system. “It’s not just on their personal devices,” he says. “It’s in Gmail accounts too.”
Deleting It Isn’t Enough — But It’s the First Step
The natural instinct once you’ve surfaced the problem is to say “just delete it.” And yes, delete it immediately. Any license photos, insurance card images, or personal data sitting on personal devices need to go.
But deletion alone doesn’t fix the process that put it there.
The reason salespeople photograph licenses on their phones is almost always because it’s the path of least resistance. There’s no secure, fast, in-workflow alternative. So they default to what’s easy: camera app, snap, done.
That’s a process failure, not just a people failure. And it will happen again the next deal unless you replace the broken process with one that actually works.
The Real Fix: Give Your Team a Secure Way to Do It Right
Informativ eliminates the reason salespeople reach for their personal phones in the first place.
With Informativ’s compliance and fraud prevention platform (which includes a mobile app for sales teams and their mobile devices), customer identification is captured securely and checked for fraud, tied directly to the deal, stored in a compliant digital deal jacket, and never touches a personal device. The scan happens in the Informativ platform to protect the dealership from the showroom floor through the F&I close.
That workflow automatically runs Red Flags, OFAC checks, and fraud detection in the same motion. The result isn’t just compliance, it’s a faster, cleaner deal process with a complete audit trail that satisfies FTC Safeguards Rule requirements and holds up to scrutiny if regulators ever come knocking. And it occurs everytime… automatically.
No personal phones. No Gmail. No paper licenses or credit applications floating around the showroom. No $53,000 surprises.
What to Do This Week
- Ask the question. Run the amnesty conversation at your next morning meeting. Give your team a safe moment to surface what’s out there.
- Delete what surfaces. Any personal information on personal devices needs to be removed immediately and completely.
- Fix the process. Make the path of least resistance a compliant one. If your team doesn’t have a fast, secure way to capture and store customer identification, they’ll default to their camera app every time.
- Document that you did all three. The FTC doesn’t just care what you did. It cares what you can prove.
Frequently Asked Questions:
Yes. Under the FTC Safeguards Rule, dealerships are required to protect customer nonpublic personal information (NPI). Storing that data on unauthorized personal devices including employee phones and personal email accounts is a violation that can carry fines of up to $53,000 per instance.
Delete them immediately. This should happen as part of a structured, documented conversation with your sales team. Creating a record of the amnesty process and the corrective action you took can matter if your dealership is ever audited.
Through a secure, compliant platform integrated into your deal workflow, not a personal camera app. Informativ’s compliance solution includes a mobile app that scans IDs, checks for fraud, and  captures and stores customer identification within a documented, FTC-compliant process that automatically triggers required checks (Red Flags, OFAC, fraud detection) without any data touching a personal device.
Yes. Informativ integrates with VinSolutions, eLeads, Tekion, DealerTrack, RouteOne, DealerSocket, DriveCentric, and others. The compliance workflow fits into how your team already works.
Recent Posts
- My recent car purchase revealed exactly what needs to change
- 80% of Car Buyers Care About the Monthly Payment. Why Has the Industry Been Guessing?
- Compliant, Competitive, and Ready to Prove It: What I Took Home from CBT’s FTC Summit
- Seeing Red (Flags): The Credit Report Compliance Check Every Business Needs to Know
- Beyond Passwords: Why Smart Lenders Are Asking Questions Your Fraudster Can’t Google