Parties
Full legal names, DBA names, and contact details for the data owner and the recipient. Include a liaison name, phone, and email for operational follow-up and incident response.
A concise DTA reduces compliance risk, confirms consent for access to customer and sales records, and creates an auditable trail for integrations and reporting.
The Sales CDK DTA Document is completed by business owners and authorized representatives responsible for dealer data and integrations.
Signatures are recorded from authorized signers and receiving-party representatives to ensure accountability and a clear chain of custody.
Full legal names, DBA names, and contact details for the data owner and the recipient. Include a liaison name, phone, and email for operational follow-up and incident response.
A specific list of data elements authorized for transfer (for example, VIN, buyer name, sales price, financing terms). Avoid vague phrases like 'sales data' without field-level detail.
Describe exactly what the recipient may do with the data (reporting, marketing, loan processing) and explicitly forbid unauthorized resale or repurposing.
State required protections such as encryption in transit/storage, access controls, and any required attestations or certifications the recipient must maintain.
Specify how long the recipient may retain data, deletion or return procedures on termination, and evidence required to verify deletion or destruction.
Signature blocks for authorized signers, printed names, titles, and date fields. Include a space for a witness or notary if state rules or internal policy require notarization.
| Field | Configuration |
|---|---|
| Party fields | Separate signer roles for Owner | Recipient | IT Approver |
| Conditional routing | Route to legal if high-risk data or cross-border transfer |
| Authentication | Use email + SMS or stronger MFA for recipient verification |
| Audit capture | Enable timestamps, IP logging, and download copies |
Electronic completion supports secure signing, evidence capture, and integration with dealer systems.
Ensure the chosen platform captures an audit trail and retains a tamper-evident record for compliance and dispute resolution.
The documented effective date starts contractual obligations and triggers technical work.
Schedule exports within a defined window, commonly 1–10 business days after authorization.
Allow up to 48–72 hours for revoked credentials to be disabled.
Confirm deletion or return within the agreed retention period.
Set a 10–30 business day SLA for addressing data use disputes.