Auto dealers are bolstering internal compliance access and employee training to stay on top of evolving oversight of consumer data privacy.
A “constantly shifting” regulatory environment has made in-house legal and compliance support indispensable to individual dealerships, Mike Onda, chief executive of Carmel, Ind. based buy here, pay here dealership network Byrider, told Auto Finance News.
Analysis of state privacy acts shows regulators are looking more closely at:
- Opt-out mechanisms for selling and sharing consumer data;
- Consumers’ right to access, then correct or delete stored personal data within explicit timeframes; and
- Enforcement of physical and digital data protection procedures across departments.
Byrider employs five full-time legal and compliance team members, all of whom have worked in those fields on behalf of the company for 15 to 35 years, Onda said.
The team takes compliance-related calls from dealership leaders and visits Byrider’s 35 franchisees across 100 rooftops in 25 states, he said.
“We have annual compliance audits [with auditors that] go into the dealerships and look at everything,” he said. “It’s extremely valuable in the buy here, pay here [industry and] in any subprime industry these days.”
Recent regulatory shifts and the rise of fraud are giving dealers reason to strengthen data security practices and risk mitigation, according to Dealertrack’s 2026 Compliance Guide published in collaboration with law firm BakerHostetler.
California continues to be at the forefront of state-level consumer privacy governance, Joey Yates, associate vice president of business services for Dealertrack’s finance and insurance platform, told AFN.
The state’s Consumer Privacy Act and the California Privacy Rights Act complement and expand on oversite by the FTC, the Fair Credit Reporting Act, Gramm-Leach-Bliley and others that exist at the federal level, he said.
Other states that have enacted new data privacy and security laws in the past four years include Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, New York, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, Yates said, citing the 2026 guide.
Day-to-day protocol
For consumer-facing employees, turning compliance policies into daily practice is key.
For example, Flagstaff Chevrolet in Arizona follows a compliance program that every employee participates in each year, Mindy Fouts, the dealership’s director of finance, told AFN.
The training focuses on protecting customers’ personal data, Fouts said.
“We used to have [photo]copies of driver’s licenses,” she said. “Now we don’t. Everything is digital. There’s nothing lying out.”
Staying ‘ahead of the curve’
Beyond in-house training, regional dealership groups are monitoring oversight developments.
For example, Highland, Mich.-based LaFontaine Automotive Group holds annual groupwide training with state regulators, Director of Finance David Lawrence told AFN.
But the dealership group is “probably going to step it up to twice a year as enforcement has increased,” Lawrence said. “We want to be ahead of the curve.”
Auto Finance Summit, the premier industry event for auto lending and leasing, returns October 5-7 at Caesars Palace Las Vegas, featuring executive insights from institutions including Chase Auto, Carvana, Capital One, Hyundai Capital America and Wells Fargo. To learn more about the 2026 event and register, visit www.AutoFinance.live/AFS.






