Every Car Brand That Sells Your Driving Data (2026 Updated List)

Published September 5, 2026 | 12 min read

Key Takeaways

What Changed in 2025 and 2026

For years the connected-car privacy problem was a research finding. It is now an enforcement record. Two developments turned it into one.

The first was federal. In January 2025 the Federal Trade Commission took action against General Motors and OnStar over the collection and sale of precise geolocation and driving behaviour data. The order was finalised in January 2026. It bars GM from sharing certain consumer data with consumer reporting agencies for five years, and for twenty years requires the company to obtain permission before collecting, using or sharing connected vehicle data, to let consumers request a copy of their data and seek its deletion, and to provide a way to disable precise location collection.

It is worth being precise about what the order is and is not. It carries no monetary penalty. It is a conduct order — a set of obligations, not a fine. Anyone citing a dollar figure for the FTC's GM action is describing something else.

The second was state-level, and arguably sharper. On 13 January 2025 the Texas Attorney General sued Allstate and its data analytics subsidiary Arity, alleging they unlawfully collected, used and sold the driving data of more than 45 million Americans. It was the first lawsuit brought by a state attorney general to enforce a comprehensive state privacy law.

The Texas filing matters for a reason beyond Allstate. It names where the data came from. According to the state's allegations, Allstate purchased driver data sourced from Toyota, Lexus, Mazda, Chrysler, Dodge, Fiat, Jeep, Maserati and Ram. Separately, the Texas AG issued civil investigative demands to Kia, General Motors, Subaru and Mitsubishi.

The Mozilla Finding That Started the Conversation

Mozilla's Privacy Not Included team reviewed 25 car brands and every one of them failed. Mozilla called cars "the official worst category of products for privacy that we have ever reviewed" — a category that includes mental health apps and smart speakers.

Two findings did most of the damage. All 25 brands collected more personal data than the product required, and every brand used that data for something other than operating the vehicle. Mozilla found brands whose policies reserved the right to collect categories including health and genetic information, immigration status, race, and sexual activity.

Nissan drew the worst assessment. Its privacy policy disclosed collection of categories including sexual activity, health diagnosis data and genetic data, alongside language permitting sharing and sale to data brokers, law enforcement and other third parties.

One caveat that most coverage omits: Mozilla assessed what the policies permit, not what each manufacturer demonstrably does. A permissive privacy policy is evidence of intent and legal cover, not proof of a specific practice. That distinction matters — and it is exactly why the enforcement actions above are more damning than the report. They describe conduct, not language.

Brand-by-Brand: What Is Documented

Each entry below separates what is established by enforcement action or company admission from what is only disclosed in a privacy policy as permitted. Those are very different standards of proof, and conflating them is how car-privacy coverage loses credibility.

General Motors — Chevrolet, GMC, Cadillac, Buick

Toyota and Lexus

Stellantis — Chrysler, Dodge, Jeep, Ram, Fiat, Maserati

Mazda

Subaru

Kia and Hyundai

Mitsubishi

Nissan

Honda and Acura

Ford and Lincoln

Tesla, BMW, Volkswagen, Mercedes-Benz, Audi and others

What opting out actually costs you. Manufacturers rarely lead with this. Disabling connected-services data collection commonly disables remote start, remote lock and unlock, stolen vehicle tracking, and — most seriously — automatic crash notification, which calls emergency services when your airbags deploy. That is a real safety trade-off, not a marketing threat. Decide deliberately rather than by default in either direction.

What Opting Out Does Not Reach

Turning off collection at the vehicle stops the flow going forward. It does nothing about data already sold, and nothing about the parallel pipeline that never went through your car at all.

The Texas case against Allstate and Arity is the clearest illustration. The data at issue there was allegedly collected through mobile apps — accelerometer, GPS, speed and location harvested via software development kits embedded in ordinary phone apps — not solely through vehicle telematics. Disabling OnStar does not touch that. Neither does cancelling Starlink.

And once driving data has reached a consumer reporting agency such as LexisNexis Risk Solutions, it sits in a file about you that is governed by the Fair Credit Reporting Act. You have a right to request that file and to dispute what is in it — a separate exercise from any manufacturer opt-out, and one most drivers never perform.

Delete Your Data from 1,493 Data Brokers

Opting out at the manufacturer stops new collection. It does not remove the driving and location data already sold to data brokers and consumer reporting agencies. We send legal CCPA deletion demands to 1,493 data brokers — including LexisNexis Risk Solutions and Verisk — and file FCRA disclosure requests so you can see what is already in your file. Continuous 45-day resubmission. $9.95/month.

Start Your Free 7-Day Trial

No credit card required. Cancel anytime. We never sell your data.