LICENSEWARE

Authenticom v. CDK Global

This article is about the 2017 preliminary injunction proceedings in Authenticom's antitrust suit against CDK Global and Reynolds and Reynolds, which concerned third-party access to dealer data held in licensed dealer management systems. It covers only the two decisions on the injunction, not the later stages of the litigation. It is not legal advice.

On This Page

Authenticom v. CDK Global was an antitrust case brought in 2017 in the Western District of Wisconsin by Authenticom, a company that pulls dealer data out of the dealer management systems (DMS) that car dealers license, against the two largest DMS providers, CDK Global and The Reynolds and Reynolds Company. It is not a licence-audit case, but it turns on what a software licence lets a customer, and a customer’s agent, do with the system and its data, and on what a vendor may do to stop automated access. The district court granted Authenticom a preliminary injunction on 14 July 2017, and the Seventh Circuit set it aside on 6 November 2017.[1][2]

This article covers only those two decisions. Neither decided the merits, and both courts said so.[2]

Background

The district court described a DMS as the software package a dealer uses to manage everything from vehicle and parts inventory to service appointments and payroll. CDK and Reynolds supplied the DMS to roughly three-quarters of United States dealers, ran the servers that held each dealer’s data, and a dealer typically paid USD 8,000 to 10,000 a month for its DMS. The court found that the data belongs to the dealer.[1]

Dealers also use add-on applications from third-party vendors, typically 10 to 15 of them, and those applications need data from the DMS. Many dealers authorised the vendors to collect it directly or through a data integrator such as Authenticom. With the dealer’s consent, Authenticom logged in to the dealer’s DMS account with a user name and password the dealer supplied, captured the data by “screen scraping”, reformatted it and sent it to the vendor; the court recorded that a vendor typically paid it about USD 50 a month per dealer.[1]

The two vendors differed on access. The Seventh Circuit noted that Reynolds had always forbidden such data harvesting in its system licences, while CDK until 2015 placed no restrictions on third-party integrators, and then decided to move to a closed system.[2] Reynolds allowed third-party access only with its own approval, preferably through its Reynolds Certified Interface (RCI), and CDK’s equivalent was its 3PA programme.[1]

The dispute

The 2015 agreements. In February 2015 CDK and Reynolds signed three agreements: a Data Exchange Agreement under which CDK wound down its own integration subsidiaries’ unauthorised access to Reynolds systems, and two agreements giving each other’s applications access to their systems through their in-house interfaces. In the Data Exchange Agreement each also agreed not to assist anyone attempting to access or integrate with the other’s DMS.[1] The Seventh Circuit observed that nothing in the three agreements required either company to block third-party access to its own system.[2]

The claims. Authenticom sued in May 2017, arguing that the agreements, together with alleged statements by the defendants’ executives that they would shut third-party integrators out, amounted to a horizontal conspiracy in breach of section 1 of the Sherman Act, and that the defendants’ vendor contracts, which required vendors to use the in-house interfaces, were exclusive dealing.[1][2] The defendants said they closed access for security reasons and to protect their systems and work product.[1]

Prices and access terms. The district court recorded vendor evidence that the monthly price of integration through the defendants’ interfaces had risen sharply: for example, a vendor paid USD 247 per dealer per month for RCI in 2011 and would pay USD 893 by September 2017, and CDK’s 3PA price for another vendor went from about USD 160 in 2014 to USD 735 in July 2017. It also recorded that Reynolds’ standard RCI vendor contract prohibited the vendor from discussing RCI costs, and that CDK prevented vendors from showing 3PA charges as a line item on their bills.[1]

Decision or outcome

District court, 14 July 2017. The court found that Authenticom had shown at least a moderate chance of success on its Sherman Act claim and that it was at risk of going under, and it found the defendants’ security concerns unpersuasive because they already allowed many exceptions to their “no hostile integration” policies and no evidence showed that Authenticom had caused a breach. It granted a preliminary injunction.[1] As the Seventh Circuit later described it, the injunctions barred the defendants from blocking Authenticom’s use of log-in credentials from dealers it served on 1 May 2017, required each defendant to configure Authenticom-specific credentials, and set a USD 1 million bond.[2]

Seventh Circuit, 6 November 2017. The court of appeals set the injunction aside. It assumed, generously to Authenticom, that irreparable harm, inadequate remedy at law and some likelihood of success were shown, but held that the injunction went beyond the alleged violation: the proper preliminary remedy for an agreement in restraint of trade would be to bar the 2015 agreements, not to order the defendants into a new dealing arrangement with Authenticom, which was inconsistent with the Supreme Court’s decision in Verizon v. Trinko.[2] It said that nothing it wrote should be taken as presaging the outcome at trial, and urged the district court to expedite final judgment.[2]

Significance for software licensing and SAM practice

The case is a reminder that the licence a dealer signs, not only the law of data ownership, shapes who may touch a system. The Seventh Circuit treated the licence terms that forbid sharing credentials with, or scraping by, third parties as part of the commercial background of the dispute, while the district court stressed that the dealers’ data belonged to them.[1][2] For licence managers it shows how a change in a vendor’s access model, and the price of its official interface, can change what a licensed system costs to integrate with, without any change in the licence fee itself.

Because the appeal decided only the scope of interim relief, the case is not authority on whether the 2015 agreements were unlawful or on whether a vendor may block credential-based access.

Lessons learned

  • Read the access and credential clauses. The licences at issue forbade third-party access, and the vendors used that to block automated log-ins; an integration built on a customer’s own credentials is only as safe as the licence allows.[2]
  • Data ownership and system access are different rights. The district court found the data belonged to the dealer, yet the dealer still depended on the vendor’s system and rules to get it out.[1]
  • Official interfaces can be repriced. The record shows integration fees through the vendors’ own interfaces rising several-fold in a few years, so seek a contractual export route and price protection for it.[1]
  • Watch clauses that restrict disclosure of interface pricing. The record includes vendor contract terms that limited discussing or itemising interface charges, which makes comparison harder.[1]

References

  1. Authenticom, Inc. v. CDK Global, LLC, No. 17-cv-318-jdp, Opinion and Order (W.D. Wis. July 14, 2017)District court opinion on the motion for preliminary injunction, as filed in the multidistrict docket (N.D. Ill. No. 1:18-cv-00868, Document 172). govinfo.gov, U.S. Government Publishing OfficeEffective 2017-07-14. Retrieved 2026-10-08.
  2. Authenticom, Inc. v. CDK Global, LLC, Nos. 17-2540 and 17-2541 (7th Cir. Nov. 6, 2017)Seventh Circuit opinion of Chief Judge Wood on the interlocutory appeal. govinfo.gov, U.S. Government Publishing OfficeEffective 2017-11-06. Retrieved 2026-10-08.

See also

Esc