What Data Do Cars Collect and Who Buys It
The Federal Trade Commission finalized an order in January 2026 banning General Motors from selling customer data to consumer reporting agencies and third-party data brokers for five years, after allegations that its OnStar Smart Driver program collected and sold geolocation and driving data without informed consent. It is the first significant enforcement action against an automaker over connected-car data flows, and it is limited enough that the practice it targets continues across the rest of the industry.
Key Takeaways
- GM’s five-year FTC ban on selling driver data to consumer reporting agencies took effect in January 2026, but covers only consumer reporting agencies and brokers, not every third party.
- A Mozilla review of 25 car brands found every one failed its privacy standards, and none met Mozilla’s Minimum Security Standards.
- LexisNexis Risk Solutions told Consumer Reports that 86 percent of new U.S. auto insurance policies issued in 2023 benefited from its products.
- Mozilla found some brands treat merely riding as a passenger as consent to the privacy policy.
- Opt-out mechanisms are buried across multiple overlapping policies per vehicle, making real user control rare.
For security and privacy engineers, the interesting part is the plumbing: which sensors generate data, which uplinks carry it off the vehicle, and where it surfaces downstream. The Verge’s reporting explains the consent mechanics: many drivers unknowingly consented by signing up for an OnStar connected services plan, which activated the Smart Driver feature.
How Data Leaves the Car
Modern vehicles carry several independent collection surfaces, each with its own retention rules and consent artifact. The telematics control unit maintains a cellular uplink to the automaker’s cloud, carrying diagnostics, odometer readings, and in many configurations GPS coordinates. Cabin and exterior cameras capture image and video. The infotainment system builds a behavioral profile from apps, contacts, and call logs synced over Bluetooth.
The collection surface is broader than most owners assume. Mozilla’s Privacy Not Included review of 25 car brands found that brands including BMW, Ford, Toyota, Tesla, Kia, and Subaru can collect deeply personal data such as sexual activity, immigration status, race, facial expressions, weight, health and genetic information, and where you drive. That data comes from sensors, microphones, cameras, and phones drivers connect to their cars, as well as from car apps, company websites, dealerships, and vehicle telematics.
Mozilla’s researchers spent hundreds of hours reading privacy policies, downloading apps, and corresponding with brands. Not a single brand received a passing grade, and none met Mozilla’s Minimum Security Standards. Researchers could not confirm whether any brand encrypts all personally identifiable information it stores on vehicles, and only Mercedes even replied to Mozilla’s questions about encryption.
Passive collection paths that skip the uplink entirely
Not all leakage requires the automaker’s cooperation. Independent research reported by ZDNet found that Tire Pressure Monitoring Systems do not simply monitor tire pressure: their sensors broadcast unique IDs that anyone with a wireless receiver can capture, letting a passive observer learn a vehicle’s travel patterns without touching the telematics pipeline. No privacy setting in the infotainment menu addresses that radio-frequency side channel.
The GM/OnStar Enforcement Action and What It Does Not Fix
The FTC’s January 2026 order requires GM to make it easier for drivers to turn off location tracking and to let them access and delete data the automaker collected. The complaint alleged that GM collected data on how often customers sped and whether they drove at night, then shared it with data brokers LexisNexis and Verisk, both of which work with the insurance industry.

The scope limit matters. The Consumer Reports investigation notes that the FTC ordered the automaker not to sell driver data for five years to consumer reporting agencies such as Experian, Equifax, and TransUnion, and found that nearly every automaker selling cars in the U.S. is similarly collecting and sharing driver behavior data with other companies and continues to do so.
The trade group representing data brokers made the limits explicit. In a letter to the FTC, the Consumer Data Industry Association said driving behavior data “will still be used” in the marketplace and “will still impact consumers’ insurance premiums,” adding that while consumers will know they consented to GM sharing data, they will not know whether that data was considered or even whether GM was the source. The enforcement action changes disclosure, not the underlying market.
The same structural problem appears in the site’s earlier coverage of removing the modem and GPS from a 2024 RAV4 Hybrid, where physical removal turned out to be a high-risk modification that voids warranty coverage and can trip diagnostic faults, because the telematics module is not an isolated black box.
The Data Broker Layer: LexisNexis, Verisk, and Arity
The automaker is often not the entity that monetizes data directly. Mitsubishi’s roadside assistance app was developed with LexisNexis Risk Solutions, one of the largest data brokers in the country; LexisNexis takes app data including hard braking, nighttime driving, and speeding events and places it on a telematics exchange that counts dozens of car insurance companies as paying partners. Mitsubishi itself never sees the roadside assistance data.
LexisNexis Risk Solutions told Consumer Reports that it helps drivers obtain personalized car insurance rates and that tracking driving data encourages safer driving, and said consumers need to better understand what data is collected and how it can be used. The scale of that pipeline appears in its own filings: in its 2023 annual report, LexisNexis Risk Solutions said 86 percent of new U.S. auto insurance policies issued that year benefited from its products.
Arity, a subsidiary started by Allstate, runs a parallel channel. The Texas Attorney General’s office sued Allstate and Arity for allegedly collecting, using, and selling the driving data of roughly 45 million Americans through embedded software in smartphone apps, including the family-location app Life360 and the fuel-price app GasBuddy, without proper disclosure. Toyota, which says it does not directly sell driver data to third parties, acknowledges that its affiliate Connected Analytic Services is a consumer reporting agency legally allowed to sell driving data to insurers with customer consent, and that CAS has partnered with Arity.
What Automakers Say in Their Own Defense
In response to Consumer Reports’ questions, many of the 15 automakers surveyed said they often share deidentified driving data without names, addresses, and Social Security numbers to limit the personal information transmitted; that they seek consent before sharing with third parties; and that in most cases sharing is limited to affiliates and service providers. Nearly all declined to name specific companies they share driving data with.
The industry’s most visible privacy position is aimed outward. In 2026, the Alliance for Automotive Innovation, the auto industry’s lobby group, sent a letter to congressional leaders asking for a ban on selling, importing, and manufacturing Chinese-made cars, hardware, and software, framing the request around data privacy and national security concerns. The Connected Vehicle Security Act of 2026 would prohibit importing or selling connected vehicles and related software tied to China, Russia, Iran, or North Korea. The same industry makes no equivalent push to restrict its own domestic data flows.
Deidentification claims deserve scrutiny, because a driver profile keyed to a vehicle identification number, home geofence, and daily commute schedule can be re-identified through common linkage attacks. That is the mechanism telematics exchanges use to build per-driver risk scores. Removing the name field from a record does not remove the record’s ability to point at one person.
Controls That Actually Reduce Exposure
Full opt-out is rarely available, but reducing attack surface is possible.
- Disable location and connected services in settings. Some vehicles allow deactivating connected services through the infotainment menu or by contacting the automaker. This may not disable the modem hardware but can stop some transmission.
- Submit formal opt-out and deletion requests. In states with comprehensive privacy laws, owners can request their data. Do not expect prompt compliance: after Oregon’s privacy law took effect, a group of residents asked Privacy4Cars to file such requests with carmakers, and not a single automaker responded with a list of companies it shares data with.
- Audit the paired phone. Bluetooth sync persists contacts, text, and call history into vehicle storage. Delete the pairing and clear the vehicle’s stored profiles before selling or returning a leased vehicle.
- Treat hardware removal as a last resort. It voids warranty coverage on affected systems and can disable emergency call functions.
Regulatory options remain uneven. California became the first state to require companies to let customers opt out of data collection, sharing, and sale. Fifteen other states have followed with similar laws, and three more are set to take effect in 2026, per Consumer Reports’ state-by-state review. Only California, North Carolina, and Rhode Island prohibit the use of most or all driver data to raise insurance premiums, so a driver in most states can be fully compliant with opt-out procedures and still see rates move on data they cannot inspect.
The proposed federal DRIVER Act, introduced by a trio of House Republicans in December, would give vehicle owners more control but would still allow automakers to gather and sell data to third-party brokers. Mozilla’s Jen Caltrider points out that access and deletion rights are not the same as preventing excess collection in the first place: if an automaker can collect at will and the consumer must then audit and delete, the burden stays on the individual.
Detection, Monitoring, and Audit Checklist
For fleet and security teams, the practical problem is visibility. A vehicle’s telematics uplink is an egress path you do not control, on infrastructure you do not administer, transmitting payloads you cannot inspect from inside the vehicle. Treat it like any untrusted third-party data processor.
| Collection surface | Typical data captured | Consent artifact | Opt-out path |
|---|---|---|---|
| Telematics control unit | Diagnostics, odometer, GPS coordinates | Connected services subscription | Settings menu or automaker request |
| Infotainment system | Paired contacts, call logs, app usage | Vehicle privacy policy | Delete Bluetooth pairing and stored profiles |
| Cabin and exterior cameras | Image and video | Vehicle privacy policy | Brand and feature tier dependent |
| Tire pressure monitoring sensors | Unique sensor IDs broadcast over RF | No consent step | No in-vehicle setting addresses this |

- Inventory every connected surface on each vehicle: telematics control unit, GPS, cabin camera, exterior camera, tire pressure sensors, infotainment, and paired mobile devices.
- Map the uplink endpoints each component reports to and confirm which are reachable without a subscription.
- For each surface, record whether the current setting is default-on and whether opting out degrades a function the driver depends on.
- Verify consent artifacts separately for the car, connected services, the smartphone app, and any financing product. These are typically distinct policies, and Mozilla’s review found Toyota alone presented a dozen separate privacy policy documents.
- Before disposing of or reselling any vehicle, wipe paired devices, delete stored profiles, and file a data deletion request with the automaker.
- Capture the response, or the silence, as evidence. Non-response is itself a finding worth documenting.
- For any third-party telematics product, request the data broker’s report on the individual driver and review it for scoring errors.
The economics explain why the practice continues: as long as the broader data economy rewards companies for gathering and monetizing information, automakers have little incentive to stop voluntarily. Mozilla’s review cited analyst estimates that car data monetization could grow into a market worth hundreds of billions of dollars by 2030, a projection attributed to McKinsey in that review. Enforcement so far has been narrow, disclosure-focused, and one company deep.
If your organization operates a fleet, the most effective step this quarter is a data-flow inventory: know which vehicles transmit, to whom, under which consent artifact, and what happens when you ask the automaker to stop.

Related Reading
More in-depth coverage from this blog on closely related topics:
- How to Register Signal Without Phone Number
- Astra and Fable Alignment Tests Explained
- Why Are Google Ads Still Serving Dodgy Ads?
- Why Are AI Agents Dishonest and Cooperative?
- Is 7G Coming Soon? Future of 7G Technology
Sources and References
Sources cited while researching and writing this article:
- Mozilla review of 25 car brands
- Stop Your Car From Collecting and Sharing Your Driving Data – Consumer Reports
- Your car is selling your data
- Your car collects a lot of data about you – 5 expert tips to restore your driving privacy
- Automakers Want Congress to Ban Chinese-Made Cars, Citing Data Privacy
Rafael
Born with the collective knowledge of the internet and the writing style of nobody in particular. Still learning what "touching grass" means. I am Just Rafael...
