Carmakers face privacy reckoning over data sharing

The gist
Carmakers are facing a seismic privacy reckoning, as regulators crack down on unauthorized vehicle data sharing and surveillance tech, forcing sweeping industry changes.
What to know
- General Motors was hit with a $12.75 million settlement and a five-year ban for selling OnStar driving data without consent under California’s CCPA in May 2026.
- Police and private firms are expanding ALPR surveillance and data retention, raising alarm bells over transparency and compliance with federal privacy laws like the DPPA.
- New enforcement actions, tech innovations like AiDEN’s privacy-first platforms, and a wave of legislative battles are upending how automakers and agencies handle your car’s data.
GM Case Sets New Precedent
California’s $12.75 million penalty against GM sparked a wave of multi-agency crackdowns and consumer empowerment tools, signaling an era of aggressive vehicle data privacy enforcement.
General Motors’ $12.75 million settlement in May 2026, prompted by California Attorney General Rob Bonta, marked a watershed moment in vehicle data privacy enforcement by spotlighting unauthorized collection and sale of OnStar “Smart Driver” data to brokers like LexisNexis and Verisk without consumer consent. This case, the first major enforcement under California’s data minimization rules and the California Consumer Privacy Act (CCPA), imposed stringent compliance mandates including a five-year ban on selling driving data to brokers and mandatory deletion of retained data absent explicit consent, underscoring regulators’ intensifying focus on transparency and consumer control over sensitive vehicle-generated information.
The GM settlement exemplifies a broader, coordinated crackdown on vehicle data privacy violations, involving multiple California district attorneys, the Department of Justice, and the Federal Trade Commission, which simultaneously finalized a 20-year order against GM for similar infractions. This multi-agency collaboration signals an escalating federal and state enforcement synergy aimed at curbing unlawful data sharing practices and enforcing laws like California’s Unfair Competition Law alongside the CCPA, while innovative tools such as CalPrivacy’s DROP platform empower consumers to exercise deletion rights with data brokers, reflecting a regulatory ecosystem increasingly centered on data minimization and consumer empowerment.
Beyond California, federal regulators are amplifying scrutiny of vehicle and location data privacy, as illustrated by the Federal Trade Commission’s proposed settlement with Kochava in June 2026, which mandates affirmative consumer consent and rigorous data handling protocols for precise location data. This federal momentum complements state-level actions and signals a tightening regulatory environment where companies must navigate complex consent requirements and heightened accountability to avoid enforcement actions.
Simultaneously, the Driver’s Privacy Protection Act (DPPA) has emerged as a potent legal tool leveraged by plaintiffs to target a broad spectrum of businesses handling DMV-sourced vehicle and driver data, including those indirectly accessing such information through technologies like Automated License Plate Readers (ALPR). With liquidated damages starting at $2,500 plus punitive damages and legal fees, and courts offering inconsistent interpretations of key DPPA provisions, companies face mounting litigation risks and compliance challenges, necessitating rigorous assessment of data use against narrowly defined permitted purposes or securing explicit written consent to mitigate exposure.
ALPR Surveillance Raises Stakes
Police adoption of long-term license plate tracking and secretive data sharing is fueling legal challenges and public backlash, as new privacy frameworks try to rein in unchecked surveillance.
By mid-2026, the Cullman Police Department's expansion of its Flock Safety ALPR system, including increased camera installations and a shift in data retention from 30 days to up to five years, has intensified privacy concerns. While the department restricts data access to authorized law enforcement personnel and employs the system broadly for public safety without requiring reasonable suspicion, significant operational details such as camera locations and interagency data sharing remain undisclosed, fueling public unease over oversight and transparency.
In response to mounting public backlash and regulatory scrutiny, Rekor Systems introduced a Privacy and Evidence Architecture for ALPR technology that aims to safeguard privacy without compromising public safety. This framework advocates for default privacy protections on non-relevant data, purpose-based and auditable retention policies, and leverages Go-Secure.Video technology to authenticate video evidence, positioning itself as a pragmatic solution for lawmakers and agencies striving to balance surveillance benefits with data protection.
The rapid proliferation of ALPR technology has also escalated legal risks under the Driver’s Privacy Protection Act (DPPA), as plaintiffs increasingly target not only state DMVs but also private businesses handling DMV-sourced driver or vehicle data. Particularly concerning is the practice of matching ALPR-captured license plates with DMV records to identify vehicle owners for enforcement or commercial purposes, which courts are scrutinizing under both federal DPPA and emerging state ALPR laws, creating a complex and evolving compliance landscape for industry participants.
Privacy Tech Shifts Auto Industry
Automakers are racing to embed patented, consent-driven data platforms as privacy compliance becomes the backbone of next-generation vehicle ecosystems.
By mid-2026, AiDEN Automotive emerged as a pioneer in embedding privacy-first frameworks within vehicle ecosystems, securing U.S. and Japan patents for its innovative real-time data sharing, consent management, and payment-token technologies. CEO Niclas Gyllenram highlighted that these patents not only validate AiDEN’s platform strategy to complement OEMs but also establish a foundational software layer for software-defined vehicles that ensures compliance with stringent regulations like GDPR. This advancement underscores a broader industry momentum toward integrating secure, auditable, and consent-based data exchange mechanisms directly into next-generation mobility services, a sentiment echoed by HERE Technologies’ Petter Djerf who emphasized the critical role of privacy-enhancing technologies in future mobility.
Lawmaker Gridlock Meets Tech Risks
Regulators and legislators are battling to define vehicle data privacy as high-profile breaches, stalled bills, and industry lobbying expose the gap between innovation and consumer protection.
By mid-2026, legislative efforts at both federal and state levels have intensified around vehicle data privacy, emphasizing consumer consent and stringent data handling protocols. The FTC’s proposed settlement with Kochava marked a pivotal expansion of federal enforcement on precise location data, mandating affirmative consent, while states like Connecticut and California enacted laws banning geolocation data sales and levied hefty penalties—California’s $12.75 million CCPA fine against GM being a prime example. However, regulatory uncertainty persists, as seen in Colorado’s postponement and scaling back of its AI Act, reflecting the challenges lawmakers face in defining and enforcing privacy standards amid rapid technological innovation.
The Australian dashcam firm’s unauthorized live broadcasting of video and location data starkly exposed the vulnerabilities in connected vehicle technologies and the difficulty of ensuring compliance with privacy laws like the Australian Privacy Act. This incident crystallizes the tension between advancing vehicle data innovations and safeguarding consumer privacy, underscoring calls for robust legislative frameworks such as California’s telematics opt-in bill. Experts’ recommendations to disable remote viewing and revert to local storage until secure firmware updates are available illustrate practical, immediate responses to these evolving privacy risks.
California’s AB 311 debate encapsulates the complex balancing act between incentivizing safer driving through telematics data sharing and protecting consumers from privacy infringements and regulatory gaps. While the bill proposes allowing drivers to opt in to telematics monitoring for insurance discounts, opposition from the California Department of Insurance and consumer advocates highlights concerns over conflicts with Proposition 103 and the risks posed by unregulated third-party telematics vendors. This legislative friction reflects broader challenges in harmonizing public safety goals with stringent privacy protections in vehicle data use.
The Driver’s Privacy Protection Act (DPPA), though over three decades old, has surged to the forefront of privacy litigation, with plaintiffs targeting a wide array of businesses handling DMV-sourced vehicle and driver data. Liability under the DPPA now extends beyond direct recipients to downstream users who knowingly misuse motor vehicle record information, exposing companies to liquidated damages starting at $2,500 plus punitive damages and legal fees. The rapid adoption of automated license plate reader (ALPR) technology by private entities further complicates compliance, as linking license plate data to DMV records triggers DPPA risks. Consequently, businesses must rigorously assess whether their data practices involve motor vehicle records, ensure each use aligns with permitted DPPA purposes, and maintain robust contractual and record-keeping safeguards to mitigate escalating litigation threats.
