2026 Pub. 8 Issue 2

On enforcement: There’s no private right of action. Only the Attorney General can bring enforcement actions. A 60-day cure period was available through the end of 2025, but as of January 2026, any right to cure is discretionary. Violations are treated as unfair or deceptive acts. III. THE 700CREDIT BREACH: A CAUTIONARY TALE In December 2025, 700Credit — a leading provider of credit and compliance solutions to the automotive industry — confirmed that a breach had occurred within its systems between May and October 2025, affecting over 5.8 million individuals across approximately 18,000 dealerships and exposing unencrypted names, addresses and Social Security numbers. This was the latest in a series of high-profile breaches at dealer vendors and this incident delivered several key lessons. First, breach notification obligations vary significantly by state — some regulators permitted 700Credit to submit agency and consumer notices on dealers’ behalf as an authorized agent. Others did not, requiring dealers to file independently or through their state dealer association. The National Automobile Dealers Association (NADA) coordinated a consolidated filing with the FTC on behalf of affected dealers, but this was an accommodation, not a standard right, and it does not relieve dealers of individual state-level obligations. Second, and most importantly: The dealership — not its vendor — retains ultimate legal responsibility for regulatory compliance. While a vendor may manage the notification process, the dealer owns the underlying legal obligation. Third, vendor oversight is a real-time legal duty under the Safeguards Rule, not a one-time contract exercise. Dealers must maintain current vendor inventories, written safeguard provisions and pre-established incident response plans before the next event occurs. Between lessons learned from the 700Credit breach, the 2024 CDK breach and several highly publicized breaches at dealerships themselves, it is critical to understand your vendors, their data security posture and your potential obligations in the event of a breach. IV. COOKIE BANNERS AND WEBSITE TRACKING Every New Hampshire dealership website is a data collection environment, quietly routing visitor information to third-party advertising and analytics platforms through tracking technologies most dealers never think about. That’s a problem for several reasons. State privacy laws treat the use of these tools as a data processing activity subject to opt-out rights. Federal and state UDAP laws create additional exposure. But the most immediate risk for most dealers right now is litigation. Demand letters and lawsuits are being filed across the country, all centered on the same basic allegation that the website collected or shared user data without meaningful consent, allegedly violating a state or federal law against wiretapping or recording. A cookie banner that merely discloses the existence of cookies, without providing a functional and accessible opt-out, does not satisfy state or federal requirements and will not protect you from these claims. Unfortunately, these claims are currently widespread nationwide, not limited to California or other high-risk jurisdictions. Dealers need to take three steps. First, ensure your website has a functional, compliant cookie consent banner, not just one that checks a box. Second, audit your website’s data flows to understand what information is being collected and where it is going. Third, ensure the vendor managing your consent platform has both the necessary legal knowledge and technical capabilities. These are not the same thing, and many vendors have one without the other. This is a complicated area of law. ComplyAuto offers tools specifically designed to give dealers visibility into and control over what is happening on their websites. Learn more at complyauto.com. V. THE IMPERATIVE OF PROACTIVE DATA SECURITY Every framework points to the same conclusion: Businesses entrusted with consumer data must proactively protect it. A defensible program begins with a current data inventory — knowing what personal data is collected, where it is stored, with whom it is shared and how long it is retained. Technical controls must include encryption, multi-factor authentication, least-privilege access, monitoring and patch management. Employee training on phishing and data handling is both legally expected and practically essential. And a tested incident response plan — with outside counsel and forensic resources pre-identified — can mean the difference between a manageable event and a regulatory catastrophe. New Hampshire dealers are operating in an environment where the stakes keep rising. Federal obligations under the Safeguards Rule, a new state privacy law with an Attorney General’s office empowered to enforce it, and a rapidly evolving threat landscape mean that doing nothing is no longer a viable option. The cost of building a strong data security program is a fraction of what a major breach or an enforcement action will cost you. ComplyAuto can help you get there. This article is for general informational purposes only and does not constitute legal advice. Consult qualified legal counsel regarding your specific obligations. 15

RkJQdWJsaXNoZXIy ODQxMjUw