How Insurance Companies Use Your Driving Data Against You

Published August 13, 2026 | 9 min read

Key Takeaways

The Pipeline: From Your Car to Your Insurance Premium

Here is how your driving data becomes a higher insurance bill without your knowledge.

Your car's telematics unit — the cellular modem built into every modern connected vehicle — continuously records your GPS location, driving speed, acceleration patterns, braking force, cornering aggressiveness, time of day you drive, and total miles traveled. This data is transmitted from your car through a cellular connection to the manufacturer's servers.

In GM's case, this data was sold to two companies: LexisNexis Risk Solutions and Verisk Analytics. These are among the largest data analytics companies in the insurance industry. They took the raw driving behavior data and processed it into standardized "driver rating products" — essentially scorecards that grade your driving behavior on a scale that insurance underwriters can use.

Insurance companies purchased these driver rating products and used them to adjust premiums. If LexisNexis scored you as an aggressive driver based on your car's telematics data, your insurance company could raise your rate — without ever telling you why, without disclosing the data source, and without giving you a chance to dispute the information.

This pipeline operated for four years before California's Privacy Protection Agency shut it down with the largest CCPA fine in history.

What Data Your Car Sends to Insurance Companies

The specific data points that feed into insurance risk scores include hard braking events — how often and how aggressively you stop. Rapid acceleration — how quickly you accelerate from stops. High-speed driving — whether you exceed speed limits and by how much. Cornering force — how aggressively you take turns. Night driving — how often you drive between midnight and 4 AM, which correlates with higher accident risk. Total mileage — how much you drive overall. Trip patterns — commute distance, highway versus city driving, and route consistency.

Each of these data points feeds into an algorithm that produces a risk score. That score can increase or decrease your insurance premium — often by hundreds of dollars per year — without you ever knowing the data existed.

Programs You May Have "Consented" To

Car manufacturers market telematics data sharing under various brand names designed to sound beneficial. GM calls it Smart Driver. Ford calls it Driver Score. Honda calls it Driver Feedback. Toyota calls it Insure Connect. Hyundai calls it Driving Score.

In many cases, these programs are enabled by default or buried deep in the infotainment system settings that most drivers never realize they are active. Honda's actual CCPA violation, per the CPPA's 2025 settlement, was different but no less telling: their online privacy-rights request form unlawfully demanded up to eight pieces of personal data for every type of request — including simple opt-outs that don't require identity verification at all — and Honda couldn't produce compliant contracts with the ad-tech vendors it shared driver data with.

The "consent" for data sharing is typically buried in the terms of service you agreed to when you activated your connected vehicle services — a document that almost nobody reads. California regulators found that this consent was not meaningful or informed, which is why GM, Ford, and Honda were all fined.

How to Check If This Happened to You

1 Request your LexisNexis consumer disclosure report at consumer.risk.lexisnexis.com. This is free under the FCRA. It will show what data LexisNexis has about you, including any driving behavior data from your car manufacturer.

2 Request your Verisk A-PLUS auto disclosure report through Verisk's own consumer request system at fcra.verisk.com, or by calling their Consumer Report Request Line at 1-800-627-3487. This is a separate system from LexisNexis and covers loss-history and claims data that may include telematics scores.

3 Check your insurance renewal notice for unexplained premium increases. If your rates went up and you have no accidents, tickets, or changes in coverage, telematics data may be the reason.

4 Ask your insurance company directly whether they use telematics data or driver behavior scores in their underwriting. They are required to disclose the factors that affect your premium.

5 Check your car's connected service settings for any active driver scoring or data sharing programs. Disable them immediately.

How to Stop It

First, disable all driver scoring and data sharing programs in your vehicle's infotainment system and connected services app. Look for Smart Driver, Driver Score, Driver Feedback, Insure Connect, or any similar program. Turn them off.

Second, submit a privacy request to your car manufacturer requesting deletion of all driving behavior data. Use the manufacturer's privacy request page and cite your VIN. Explicitly request that they delete data shared with third parties including LexisNexis and Verisk.

Third, submit a deletion request directly to LexisNexis and Verisk requesting removal of any telematics-derived driver behavior data. These companies are CCPA-covered businesses and must comply with deletion requests.

Fourth, consider canceling your connected vehicle subscription if you do not need remote start, stolen vehicle tracking, or other connected services. Without an active subscription, the telematics modem in your car typically cannot transmit data.

Fifth, check the Vehicle Privacy Report at vehicleprivacyreport.com by entering your VIN. This tool shows what data your specific vehicle model collects and shares.

GM was banned from selling driver data for 5 years as part of their $12.75 million settlement. But the ban only covers sales to consumer reporting agencies. GM can still collect the data and use it for other purposes. And every other manufacturer is still operating without similar restrictions until they get caught.

The Bigger Problem

GM is not unique. They are simply the first manufacturer to face consequences. The data pipeline from car to broker to insurer exists at virtually every major manufacturer. The California Privacy Protection Agency's connected vehicle investigation examined multiple manufacturers, and enforcement actions against Honda and Ford followed the same investigation. More are likely coming.

Federal legislation could address this comprehensively, but progress has been slow. The NHTSA DADSS mandate requires advanced impaired driving detection technology in all new vehicles by 2027 — technology that will collect even more behavioral data from inside the cabin. Without accompanying privacy protections, this mandate will create a new layer of surveillance that feeds the same data pipeline.

Until the law catches up, the only protection available is individual action: disabling data sharing, submitting deletion requests, and holding manufacturers accountable through the privacy rights that do exist.

We Fight the Car-to-Insurer Data Pipeline

Vigilant Privacy sends CCPA deletion demands to car manufacturers AND to the data brokers they share with — LexisNexis, Verisk, and others. We target the entire pipeline, not just one link. $9.95/month.

Start Your Free 7-Day Trial

No credit card required. Cancel anytime. We never sell your data.