Your car is spying—and selling: GM slammed as states crack down on data profiteering

The gist
General Motors got caught selling your car’s secrets—without telling you—and regulators from California to Texas are slamming the brakes on this data gold rush.
What to know
- The FTC hit GM and OnStar with a landmark consent order after they sold granular driving data from 14 million vehicles to brokers like LexisNexis, raking in $20 million without clear driver consent.
- A whopping 82% of connected car drivers had no clue about the data collected, while 96% believe they should fully own and control it—yet only patchwork state laws offer protection as federal rules lag.
- Insurance premiums have spiked as much as 80% thanks to automaker data sharing, and new services like Privacy4Cars are racing to help consumers wipe their digital trails clean.
States Battle Data Profiteering
States are aggressively suing automakers and tech giants, imposing record fines and bans as they rush to fill the federal privacy void and rein in unchecked vehicle data sales.
By early 2026, regulatory bodies have intensified scrutiny over connected car data privacy, exemplified by the FTC's landmark consent order against General Motors and its OnStar subsidiary for selling granular driving data from over 14 million vehicles to data brokers like Verisk Analytics and LexisNexis. This action revealed GM earned approximately $20 million by monetizing sensitive information such as geolocation every three seconds, hard braking, and seatbelt usage—often without explicit driver consent—signaling a pivotal shift in legal expectations for automakers' data practices.
The regulatory landscape is further complicated by a patchwork of state-level interventions, with Maryland, Oregon, and Virginia enacting bans on automaker data collection and California imposing a record $12.75 million CCPA penalty on GM for privacy violations. Meanwhile, the Texas Attorney General has launched lawsuits against multiple automakers impacting 45 million consumers, underscoring how, in the absence of comprehensive federal legislation, states are aggressively filling the regulatory void to protect consumer data rights.
Beyond automakers, the Department of Justice's subpoenas to tech giants Apple, Google, Amazon, and Walmart demanding personal data on over 100,000 users of EZ Lynk’s car tuning app highlight escalating government efforts to enforce environmental and data regulations in the connected car ecosystem. However, the ensuing legal pushback from Apple and Google, coupled with privacy advocates’ concerns over Fourth Amendment infringements and overly broad data demands, illustrates the fraught tension between regulatory enforcement and consumer privacy protections in this rapidly evolving legal arena.
This regulatory focus on connected car data privacy is part of a broader legal framework increasingly addressing data practices across the entire connected device ecosystem, extending concerns beyond vehicles to household devices. Such expansion reflects growing governmental recognition of the pervasive privacy risks posed by data monetization and surveillance in our interconnected digital lives.
Drivers in the Dark
Most drivers unknowingly trigger massive data sharing by simply tapping 'Agree,' leaving them vulnerable to higher insurance rates and privacy risks they never anticipated.
By early 2026, a striking 82% of connected car drivers were unaware of the volume of data their vehicles collected, with 40% not even realizing their connected services were active. This widespread ignorance is compounded by the fact that many consumers unknowingly consent to extensive data sharing simply by tapping “Agree” during vehicle setup, underscoring the critical need for heightened awareness and proactive management of privacy settings. Consumers can reclaim control by requesting detailed reports from data brokers like LexisNexis, adjusting their car’s privacy settings, opting out of data sharing through manufacturer apps or direct contact, and engaging insurers about the use of telematics data in rate calculations.
Consumers overwhelmingly assert ownership over the data generated by their vehicles, with 96% believing they should control this information. This demand for transparency and control is fueled by tangible financial and privacy harms: the FTC revealed that GM sold detailed driving data from over 14 million vehicles, leading to insurance premium hikes ranging from 21% to 80% for some drivers and even outright coverage denials, as in the case of one driver rejected by seven insurers. Such consequences highlight the urgent need for consumers to understand their rights to access, dispute, and opt out of data sharing, leveraging tools like Privacy4Cars to monitor and manage how their driving data is disseminated.
Consent Isn’t a Checkbox
True telematics consent demands ongoing transparency and user control, forcing automakers to rethink privacy as an ethical obligation—not just a legal hurdle.
Informed consent in telematics transcends mere legal formality, embodying a fundamental ethical commitment that places users firmly in control of their data privacy. As highlighted in the 2026 Explainer on telematics ethics, consent is not just a checkbox but a dynamic process that requires companies to offer granular options for users to tailor their data collection preferences, thereby reinforcing autonomy and respect for individual privacy.
Maintaining user trust in telematics demands continuous communication and transparency as systems evolve, ensuring users are regularly updated about any changes in data collection and security practices. This ongoing dialogue is crucial not only for compliance but also for establishing companies as ethical leaders who prioritize user awareness and trust above the regulatory baseline, as emphasized in the June 2026 analysis.
Data Deletion Goes Mainstream
Automotive data-wiping services are now industry standard, with certified deletion and GDPR compliance becoming must-haves for fleets and used car sellers.
By mid-2026, Engineius’s DataClear service, powered by Privacy4Cars technology, emerged as a leading solution for securely erasing personal data from vehicles, addressing growing privacy concerns in the automotive remarketing sector. This service not only ensures strict GDPR compliance but also meets the rigorous standards set by the UK National Association of Motor Auctions (NAMA), providing users with an auditable certificate that verifies data deletion. The collaboration between Engineius and Privacy4Cars underscores a broader industry commitment to integrating technological safeguards that promote safety, security, and ethical data governance within fleet management and automotive controllers, as emphasized by their CEOs.
Data Profits, Consumer Losses
Automakers reap millions from selling granular driving data, while drivers face soaring premiums and detailed tracking—often without realizing their car is watching.
By early 2026, automakers like General Motors had embedded cellular connections in over 14 million vehicles, enabling the continuous collection of highly granular driving data—including precise geolocation every three seconds, hard braking, speeding, and seatbelt usage. This data was monetized through sales to data brokers such as Verisk Analytics and LexisNexis Risk Solutions, often without consumer knowledge or consent, as highlighted by an FTC consent order against GM and its OnStar subsidiary. Despite the extensive data harvesting, a striking 82% of connected car drivers remained unaware of the volume of data collected, and 40% did not even know their connected services were active, while 96% believed they should own their vehicle-generated data, underscoring a profound disconnect between industry practices and consumer expectations.
The financial dynamics reveal a complex imbalance: manufacturers earn modest sums per vehicle—GM reportedly made around $20 million from data sales, while Honda earned approximately $0.26 per car—yet the downstream consequences for drivers can be severe. Insurers leverage these detailed profiles to adjust premiums, sometimes resulting in dramatic increases; The New York Times documented cases where premiums rose by 21% to 80% after data sharing without driver consent. Moreover, data brokers compile exhaustive records, such as a 258-page LexisNexis report chronicling months of a single driver’s trips, with studies showing only 31% of telematics program participants benefit from lower premiums, while 24% pay more, revealing a system that often disadvantages consumers financially while enriching intermediaries.
