Most privacy arguments are about the individual: what a company knows about you, and what it does with it. The national security argument is different in kind. It is not about any one person's movements being sensitive. It is about what becomes visible when enough people's movements are collected in one place and that place is reachable.
Three documented episodes make the point, and only the third involves cars. They are worth reading in order, because each one answered a question the previous one raised.
In January 2018, Strava's global heat map — an aggregate visualization of routes recorded by its users — was found to reveal the layout of overseas military installations. The pattern was noticed by Australian researcher Nathan Ruser, who observed activity tracing clearly in otherwise empty terrain. ABC News reported that the map showed base perimeters, supply routes and patrol paths at sites in Syria, Iraq and Afghanistan, along with the daily rhythms of the people working there.
The Department of Defense opened a review of its GPS policies, as NPR reported at the time. In August 2018 it restricted the use of geolocation features on fitness trackers and similar devices for personnel in deployed and operational areas. Strava subsequently narrowed how much street-level detail the map exposed.
Several things about this case set the template:
The Strava case involved data a company gave away by accident. Five years later, researchers at Duke University's Sanford School of Public Policy tested whether the same category of information could just be bought.
Justin Sherman, Hayley Barton, Aden Klein, Brady Kruse and Anushka Srinivasan published Data Brokers and the Sale of Data on U.S. Military Personnel in November 2023. Their method was deliberately unexceptional: scrape hundreds of data broker websites for terms like “military” and “veteran”, then approach US brokers as an ordinary buyer — once from a US .org domain, and once from a .asia domain — and try to purchase.
They succeeded. Duke's summary of the study records a price as low as $0.12 per record, and data obtained that included health information, financial information and details of religious practice about active-duty personnel, their families and veterans. Location data was available for purchase, though the team did not buy it. CNN's coverage reported the findings at the time.
The finding that matters most is not the price. It is that identity verification was weak enough that the destination of the data barely mattered to the seller. The study frames the risk as a foreign actor acquiring such data for targeting, blackmail or influence operations — and that risk does not require a breach, a hack, or anything unlawful by the buyer.
A lawful purchase at twelve cents a head is a harder problem than a breach. There is no incident to disclose, no vulnerability to patch, and no obvious moment at which anyone did anything wrong.
The third episode brings it back to vehicles. In December 2024, the Chaos Computer Club reported that Cariad, Volkswagen's software subsidiary, had left location and personal data for roughly 800,000 electric vehicles in an unprotected cloud store. In about 466,000 cases the data was precise enough to reconstruct a daily routine.
The exposed set reportedly included German politicians, business figures, suspected intelligence service employees, and the entire electric fleet of the Hamburg police.
That last detail is the clearest illustration of the whole argument. A police fleet's movement history is operational information: where unmarked vehicles go, which addresses they visit, how patrols are distributed by hour. It was exposed not through espionage but because a cloud bucket was misconfigured, and the owners of those vehicles had no way to know, no way to check, and no setting that would have prevented it.
Full detail on that case, and the Subaru portal flaw that exposed a year of location history at roughly five-meter accuracy, is in When Connected Cars Get Hacked.
Compared with a phone or a fitness tracker, a connected car is an unusually good surveillance device, for reasons that have nothing to do with intent:
Point five is the one that converts a privacy issue into a security one. An individual's commute is not sensitive. Every vehicle belonging to one agency, in one system, is a different kind of object.
The Commerce Department's connected vehicle rule, effective March 2025, is the clearest official response. Its stated concern is that suppliers subject to a foreign government's direction could be compelled to hand over data or permit remote access — a framing about compulsion, not consent. We cover its scope and timeline in Who Builds the Box in Your Car.
Its limit is equally clear. The rule addresses foreign-linked suppliers in future model years. It says nothing about a domestic manufacturer selling driving data to a domestic broker, which is what California's $12.75 million settlement with General Motors in May 2026 concerned, and nothing about a broker selling to whoever asks, which is what the Duke study measured.
We should be straight about the ceiling here. If you are a service member, a government employee or a first responder, nothing on this page is solved by a personal opt-out, because the exposure comes from aggregation rather than from your own record. Reducing your own footprint is still worth doing — it is simply not a substitute for institutional policy.
What is in reach:
For the step-by-step requests, see How to Stop Car Companies From Collecting Your Data. For how the commercial pipeline fits together, start at Your Car Is Reporting on You.
The Duke researchers bought service member data from brokers for twelve cents a record. We send legal CCPA deletion demands to 1,475 data brokers and file FCRA disclosure requests with the consumer reporting agencies that hold driving data — so you can see what is on file and demand its removal. Automated 45-day re-checks. $9.95/month.
Start Your Free 7-Day TrialNo credit card required. Cancel anytime. We never sell your data.