Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > US Auto Dealers Face Tougher Data Privacy Rules as State Laws Expand

US Auto Dealers Face Tougher Data Privacy Rules as State Laws Expand

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 25, 2026

Human Written
US Auto Dealers Face Tougher Data Privacy Rules as State Laws Expand
  • 23 states have enacted broad privacy laws. Only 20 are in force today.

  • Dealers are adding staff training, audits and legal help as rules change.

  • Federal rules also require many dealers to protect customer data.

Auto dealers in the US are spending more time on privacy and data security as states keep adding new privacy laws. Federal rules also determine how dealers handle client data.

Dealers hold a lot of personal and financial data, and they must keep it safe while also complying with rules that can change from state to state. That has made legal and compliance teams more useful. It has also led dealers to review daily work, which may include how staff store driver’s licenses and how staff handle customer files.

This push isn’t just targeting big auto dealer groups. Smaller dealerships also face pressure to train workers, control access to customer records, and keep sensitive info secure.

The regulatory landscape is becoming harder to manage because the requirements vary from state to state. A 2026 Dealertrack Compliance Guide, made with law firm BakerHostetler, flags data security and fraud as key risks. It also calls for strong controls and staff training.

State Privacy Laws Create Bigger Compliance Work for Big Dealers

Several states in the US have now enacted comprehensive consumer privacy laws. Oklahoma joined the league as the 20th state to pass a comprehensive privacy law with its Senate Bill 546. Gov. Kevin Stitt signed this bill into law on March 20, 2026, and it’ll take effect starting January 1, 2027.

The 21st state to pass its privacy law (HB 351) is Alabama. Gov. Kay Ivey signed the law on April 17, and it’ll become effective starting May 1, 2027.

Also, Louisiana enacted its own SB 386 on May 29, making it the 22nd state to roll out a comprehensive privacy law. It’ll take effect in July 2027. Vermont came on board as the 23rd to introduce its Data Privacy and Online Surveillance Act in June.

So that makes it  23 states that have enacted broader privacy laws. But only 20 states have their laws already in effect.

These 20 states include: 

  • California 
  • Colorado 
  • Connecticut 
  • Florida
  • Delaware 
  • Indiana 
  • Kentucky
  • Iowa
  • Maryland
  • Montana 

And the rest include Minnesota, Nebraska, New Hampshire, Oregon, New Jersey, Rhode Island, Texas, Tennessee, Utah, and Virginia.

The laws aren’t all the same. Still, many of them give people rights over their data. Those rights may include access, correction and deletion. Some laws also let people opt out of data sales or targeted ads. This creates more work for dealer groups with stores in many states.

A dealer group may need to follow different rules depending on where a customer lives and where the business operates. A process that works in one state may need changes in another.

California remains a key state in this area. Its privacy law gives people broad rights over their personal data. Amendments to the California Consumer Privacy Act took effect in January 2026. The regulation covers opt-out requests, consumer data requests, and the handling of sensitive data.

Federal Rules Also Control How Auto Dealers Handle Customer Data

State laws are only one part of the job. Federal rules like the Gramm-Leach-Bliley Act also set key duties for auto dealers.

The FTC says its Safeguards Rule covers most dealers that finance or lease cars. Covered dealers must have a written plan to protect customer data. The plan must fit the dealer and the data it holds. It must also look at risks and set steps to lower them to better protect customer information.

Moreover, the FTC updated its auto dealer guide in 2025. It covers access limits, encryption, login security, testing, training and vendor checks.

The rule also has a breach report duty. Covered firms must report some data incidents to the FTC. This report is due within 30 days after the firm finds the incident. It applies to certain events that involve at least 500 consumers’ unencrypted data.

The FTC Privacy Rule adds another duty. Dealers that give credit or arrange loans or leases must give privacy notices. The notice tells customers what data the dealer collects. It also says who may get the data and how the dealer protects it.

Privacy Compliance is Moving into Daily Tasks 

Privacy cannot sit only with lawyers or IT teams. Staff who handle customer files also have a role. Flagstaff Chevrolet in Arizona runs yearly privacy training, finance director Mindy Fouts told Auto Finance News. The training centers on customer data. The dealer also stopped keeping paper copies of driver’s licenses.

Fouts said the dealer now handles that data in digital form. That leaves fewer paper records in the office. Simple steps like this can lower risk. They can also make it easier to limit access to data. Staff still need clear rules. They need to know what data they can see. They need to know where to store it.

As dealers move more customer data online, browser-based privacy tools can help protect sensitive interactions. Mozilla recently introduced a free built-in VPN in Firefox that offers 50GB of encrypted browsing per month, masking IP addresses and location while users access banking, customer records, or dealership portals on public networks.

Dealer Groups are Adding more Checks

Byrider has built a formal compliance team. The company’s CEO, Mike Onda, told Auto Finance News that the firm has five full-time legal and compliance staff.

The team helps 35 franchisees across about 100 stores in 25 states. It also takes calls from dealer leaders. Byrider also runs yearly audits. Onda said auditors visit stores and review their work.

Other dealer groups are also adding more training. LaFontaine Automotive Group in Michigan holds yearly group training with state regulators, finance director David Lawrence told Auto Finance News.

Lawrence said the group may move to training twice a year. He cited the rise in enforcement as a reason.

The Privacy Compliance Work will not Slow Down

The privacy map is still changing. Oklahoma and Alabama show that more states can join the list. For dealers, one policy will not solve every issue. They need regular checks and staff training. Employees need clear rules for customer data. That includes data used in sales, finance, leases, marketing and data sharing.

Dealers also need to know which laws apply to each part of the business. The FTC’s guidance points to the same basic task. Covered dealers must check their risks and keep their safeguards up to date. That makes privacy part of daily dealer work. It is no longer just a task for an audit.

Dealers that build good habits now may have an easier time later. New state laws and federal rules can then be easier to manage.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.