KPA – Complete, Continuous Compliance for All Automotive Industries
Manage compliance risk across your business with software, consulting, and training in one place.
The leading solution for OSHA, EPA, and environmental health and safety compliance.
Protect your business with compliance solutions for data privacy and cybersecurity.
Stay compliant from your advertising to your deal jackets.
Support your workforce with HR compliance solutions, from wage rules to paid leave.
Simplify tracking and make smarter, data-driven compliance decisions.
Trusted consultants who help you navigate compliance with clarity and confidence.
Award-winning compliance training and certifications your team will actually retain.
Compliance solutions built for modern dealerships.
Compliance for auto maintenance shops like oil & lube, tire centers, and more.
eBooks, checklists, and guides to help you stay compliant.
Insights into how regulations are evolving across the automotive industry.
See how businesses like yours reduce risk and stay compliant with KPA.
Our approach to security, privacy, and data protection.
Manage compliance risk across your business with software, consulting, and training in one place.
The leading solution for OSHA, EPA, and environmental health and safety compliance.
Protect your business with compliance solutions for data privacy and cybersecurity.
Stay compliant from your advertising to your deal jackets.
Support your workforce with HR compliance solutions, from wage rules to paid leave.
Simplify tracking and make smarter, data-driven compliance decisions.
Trusted consultants who help you navigate compliance with clarity and confidence.
Award-winning compliance training and certifications your team will actually retain.
Compliance solutions built for modern dealerships.
Compliance for auto maintenance shops like oil & lube, tire centers, and more.
eBooks, checklists, and guides to help you stay compliant.
Insights into how regulations are evolving across the automotive industry.
See how businesses like yours reduce risk and stay compliant with KPA.
Our approach to security, privacy, and data protection.
KPA's blog covers the compliance topics that matter most to automotive businesses, from OSHA updates and FTC enforcement to HR best practices and cybersecurity requirements.
Cal/OSHA released a revised draft rule for possible workplace violence prevention requirements. There’s a new proposed scope, a clarified small-employer exemption, and 12 required plan elements. A final vote is expected this summer with a January 1, 2027, implementation deadline.Cal/OSHA released a revised draft rule for possible workplace violence prevention requirements. There’s a new proposed scope, a clarified small-employer exemption, and 12 required plan elements. A final vote is expected this summer with a January 1, 2027, implementation deadline.
KPA
May 11, 2026
FTC enforcement around dealer advertising has been getting a lot of attention lately, and for good reason. It is visible, customer-facing, and directly tied to sales practices. But as dealers focus on advertising compliance, there is a risk of losing sight of another area the FTC has already addressed in detail: data security.
Less than a year ago, in June 2025, the FTC issued dealer-specific FAQs explaining how the GLBA Safeguards Rule applies to motor vehicle dealers. That guidance did not create new obligations. It clarified what regulators expect to already be in place.
That timing matters. The guidance is recent enough that it should still be top of mind, but long enough ago that regulators are unlikely to view it as something dealers are still “working toward.” The expectation now is that these requirements are implemented and operating.
Many data security failures come down to basic control gaps rather than complex cyberattacks.
Common issues include:
These are not technical edge cases. They are core elements of the Safeguards Rule. When they are missing, regulators tend to view it as a breakdown in management and oversight. For dealerships, the point is straightforward. Customer information should be treated with the same level of care as financial data, because that is exactly what it is.
A dealership’s GLBA compliance starts with a written information security program that reflects how the business actually operates. It should be tied to a risk assessment, assign clear responsibility to a qualified individual, and include regular reporting to ownership or senior leadership. Beyond that, regulators expect to see controls that are both documented and working. That includes:
These are not aspirational goals. They are established expectations. The same is true for system testing and monitoring. Whether a dealership relies on continuous monitoring or periodic testing, the key question is whether those controls are effective in practice. Regulators are increasingly focused on evidence, not just policy. Vendor oversight is another area that deserves attention. Many dealers rely heavily on third-party systems, but that does not shift responsibility. Dealers are expected to vet service providers, require safeguards by contract, and periodically assess whether those safeguards are actually in place. If a vendor has access to dealership systems, multi-factor authentication should be required. If they store customer data, encryption should be part of the requirement.
It is easy to prioritize what regulators are talking about most in the moment. Right now, that is advertising. But enforcement does not happen in only one area
at a time. The updated FTC’s Safeguards Rule requirements have been in effect for multiple years, and the 2025 FAQs made the expectations even clearer for dealerships. Less than a year later, the question is no longer whether dealers are aware of those expectations. It is whether they can demonstrate that their controls are in
place and working. There is also increasing pressure from outside the FTC. Lenders, insurers, OEMs, and business partners are asking more questions about data security as part of normal business relationships. In many cases, dealers are expected to show proof, not just provide assurances.
Dealers that take a proactive approach to GLBA compliance tend to be in a much stronger position. They can respond more quickly when issues arise, manage vendor relationships more effectively, and demonstrate that data security is being handled deliberately. This does not have to become a manual or reactive process. With the right structure, tools, and workflows, compliance can be part of day-to-day operations rather than something that only surfaces during an audit or investigation. At KPA, the message is simple. The FTC has already made its expectations clear. Even with attention on advertising, dealers should not lose sight of data security requirements that were clarified less than a year ago and are very much in effect today.
2569 Park Lane
Suite 108
Lafayette, CO 80026
© 2026 KPA | All Rights Reserved | Privacy Policy | Consent Preferences