How to Stop Car Companies From Collecting Your Data — The Complete Guide

Published September 27, 2026 | 14 min read

Key Takeaways

What Car Companies Actually Collect

A connected car is a sensor package with seats. The data it generates falls into four buckets, and they are worth separating because the opt-out for each is different.

The Mozilla finding, and the caveat most coverage drops

Mozilla's Privacy Not Included team reviewed 25 car brands and every one of them failed. Mozilla called cars "the official worst category of products for privacy that we have ever reviewed" — a category that already included mental health apps and smart speakers. Nissan drew the worst assessment, on the breadth of collection its privacy policy permitted.

The caveat: Mozilla assessed what the policies permit, not what each manufacturer demonstrably does. A permissive privacy policy is evidence of intent and legal cover, not proof of a specific practice. We keep those apart throughout this guide, because conflating them is how car-privacy coverage loses credibility. Where something is established — by an enforcement action or a company admission — we say so.

What is actually established

The FTC's order against GM and OnStar was finalised in January 2026: a five-year ban on sharing driver data with consumer reporting agencies, plus twenty years of consent requirements. GM sold driving data to LexisNexis Risk Solutions and Verisk Analytics — the same consumer reporting agencies that feed insurance underwriting. In January 2025 Texas sued Allstate and its subsidiary Arity over the driving data of more than 45 million Americans, naming Toyota, Lexus, Mazda and Stellantis brands as sources.

The 25 Brands in Mozilla's Review

Mozilla reviewed these 25 brands and all 25 failed. Requests do not go to the badge on the car — they go to the parent company that actually receives and processes them, which is why the table is grouped that way.

Parent companyBrands reviewedWhere a US request goes
General MotorsChevrolet, Buick, GMC, CadillacGM consumer privacy request form
Ford Motor CompanyFord, LincolnFord privacy request webform
Stellantis (FCA US)Chrysler, Dodge, Jeep, FiatFCA US privacy portal
ToyotaToyota, LexusToyota Privacy Hub
HondaHonda, AcuraHonda privacy choices, or by phone
Hyundai Motor GroupHyundai, KiaEach brand's own privacy page
NissanNissanNissan privacy rights webform
SubaruSubaruSubaru consumer privacy page
TeslaTeslaIn-car data sharing toggle
BMW GroupBMWBMW Privacy Center
Mercedes-BenzMercedes-BenzMercedes-Benz privacy statement
Volkswagen GroupVolkswagen, AudiVW privacy statement
Renault GroupRenault, DaciaNot sold in the United States

On the roster: Mozilla's category page is rendered entirely in the browser and refuses automated requests, so we could not machine-verify the exact 25 names against their live listing. The headline figure — 25 reviewed, 25 failed — is Mozilla's own and is not in dispute. Renault and Dacia are the two European brands in the set and are not sold in the US, which leaves 23 that matter to an American reader. If an exact brand-by-brand roster is load-bearing for you, check it against Mozilla's page directly.

Step by Step, Brand by Brand

Every link below was loaded and checked in September 2026. Where a manufacturer's own published page was broken, or where the form asks for something unexpected, it says so — that is usually the part that wastes your afternoon.

General Motors — Chevrolet, Buick, GMC, Cadillac

Where: gm.com/consumer-privacy — GM's "U.S. Consumer Privacy Request Form". GM's privacy statement also points at consumerprivacy.gm.com, which redirects to the same page.

Also do this: GM's telematics product is OnStar. Turning off data sharing inside your OnStar account is a separate action from the privacy request, and the request does not do it for you. OnStar support: 1-888-466-7827.

Worth knowing: GM is the one manufacturer where selling driver data to consumer reporting agencies is established rather than alleged, and the FTC order banning it runs five years from January 2026. That does not undo the sale — see the LexisNexis section for how to see what was handed over.

Toyota — Toyota, Lexus

Where: privacy.toyota.com — the Toyota Privacy Hub. Choose your State of Residence first; nothing else on the page works until you do. Then pick Delete My Personal Information. California residents get an extra step asking whether you are a Consumer, an employee, or a business partner — choose Consumer.

The good news: no CAPTCHA anywhere in Toyota's flow, and Toyota serves every state, including states with no consumer privacy law of their own. Of the nine manufacturers here, Toyota's is the most usable form.

The catch: Toyota's own wording is that the request covers Toyota Motor Sales U.S.A. and Toyota Motor North America and their wholly owned subsidiaries. It does not reach Toyota, Lexus or Scion dealers, local dealer associations, private distributors, or Toyota Financial Services. Those are separate companies and separate requests. Phone: 855-226-4048.

BMW

Where: my.bmwusa.com/privacy-center, then "Delete My Personal Information" — which lands on a short form asking only first name, last name and email, behind a reCAPTCHA.

Worth knowing: BMW is the clearest of the nine about authorised agents — it does not accept them through the web form at all and asks you to email bmwprivacy@bmwusa.com instead. Third-party disclosures and appeals are handled by phone: (855) 811-2309.

Honda — Honda, Acura

Where: honda.com/privacy/your-privacy-choices.

Be warned: Honda's privacy pages are the least stable of the nine. The URL that privacy guides have cited for years, honda.com/privacy/california-privacy, now returns "Document Not Found" from Honda's own server. Honda also refuses automated requests, so we could not confirm the current page's contents — only that the path above is live while the old one is gone.

The reliable route: phone. 1-800-999-1009, and ask to be removed from data sharing programmes. Honda has no in-car toggle for this.

Nissan — Nissan, Infiniti

Where: Nissan runs two separate forms and picking the wrong one gets you the wrong outcome.

Worth knowing: both forms start by asking which state you are a current resident of, and both list the states they serve. The rights form carries a reCAPTCHA and lets you attach supporting documents — but the attach button stays greyed out until you solve the CAPTCHA, which catches people out.

Ford — Ford, Lincoln

Where: ford.com/help/privacy/ccpa — Ford's "California Consumer Privacy Act (CCPA) Forms" page, which carries the request forms themselves rather than the policy text.

Worth knowing: Ford runs three separate webforms on one platform — a consumer request form, a general privacy inquiry form, and an authorised agent form. The agent form is the most thorough of any manufacturer here: it wants the agent's name, company, email and phone, the data subject's full address, and a file upload of signed permission, all behind a reCAPTCHA. If you are helping a family member, that is the form to use.

Dodge — and Chrysler, Jeep, Fiat (Stellantis / FCA US)

Where: the FCA US privacy portal. Stellantis' corporate privacy page has no form on it; this is the form.

Read this before you start: the first question is your state, and your answer decides which rights you are offered. Residents of states with a comprehensive consumer privacy law get up to nine, including Right to Delete. Residents of states without one — North Dakota and Georgia, for two — are offered exactly one option: opt out of direct marketing. There is no deletion available to them on this form, and no authorised agent option either.

Have your VIN ready: the form takes a 17-character VIN, and it is the strongest identifier it accepts — it ties the request to your vehicle record rather than to a name-and-address match. It is on your insurance card and registration.

Do not skip the email: for deletion, access, correction or appeal requests, FCA emails you a "Confirm Email" link and will not process the request until you click it. It expires after 30 days and the request is then cancelled. Check your spam folder. Phone: (800) 777-3600.

Mazda

Where: privacy.mazdausa.com — Mazda's "Request Opt Out Form".

Worth knowing: Mazda was named in the Texas action against Allstate and Arity as a source of driving data, so the LexisNexis step is worth doing if you drive one.

Volkswagen — Volkswagen, Audi

Where: vw.com/en/privacy.html — VW's privacy statement, which carries the request routes. (vw.com/privacy redirects here.)

Worth knowing: Audi requests are handled separately from Volkswagen ones despite the shared parent, so if you own both you are filing twice.

How to Check Your LexisNexis File for Driving Data

This is the step almost everyone skips, and it is the one that shows you the damage. When a manufacturer sells driving behaviour, a common buyer is a consumer reporting agency — LexisNexis Risk Solutions or Verisk. Because they are consumer reporting agencies under the Fair Credit Reporting Act, you have a right to see what they hold on you, and to get it free.

1Go to consumer.risk.lexisnexis.com/request and order your Consumer Disclosure Report.

2You will need to verify your identity. The report covers far more than driving — insurance claims history, addresses, and more — so read all of it, not just the vehicle sections.

3Look specifically for trip-level or driving-behaviour entries sourced from a manufacturer or a telematics programme. That is the data that raises premiums.

4If something is wrong, dispute it in writing. FCRA gives you the right to have inaccurate information corrected, and a disputed entry has to be reinvestigated.

Verisk ran a similar driving-data programme and shut it down in 2024 after the GM reporting. Request your file from them as well if you want the full picture. We cover the insurance side of this in How Insurance Companies Use Your Driving Data Against You.

How to File a CCPA Deletion Demand

A web form is the manufacturer's preferred channel because it is the one they control. A written deletion demand citing the statute is a stronger instrument: it creates a dated record, it starts a statutory clock, and it does not depend on a form staying online.

You do not have to live in California to try. Several manufacturers process deletion requests from any US resident rather than maintaining separate workflows per state — though as the Stellantis form shows, some hold the line strictly on residency. We cover that asymmetry in CCPA Rights From Any State — Here's How to Use Them.

A workable demand contains all of the following. Leave any of it out and you invite a request for clarification that restarts the clock.

What Vigilant Privacy does with this automatically

Being straight about the split, because it is not "we press one button":

How to Disconnect Vehicle Telematics

A privacy request addresses data they already have. Disconnecting telematics is what stops the next trip being recorded. They are different jobs and you need both.

1Turn off data sharing in the manufacturer's connected-services account — OnStar for GM, FordPass for Ford, Toyota App, NissanConnect, MyBMW, HondaLink. This is an account setting, not a car setting, and it is usually buried two or three levels into a privacy or data submenu.

2Cancel the connected services subscription outright if you do not use it. A lapsed subscription is a cleaner state than a subscription with a toggle you are trusting.

3Decline any insurance telematics programme — the safe-driving discount ones. These are voluntary and separately consented, and they are the most direct path from your driving to your premium.

4Delete paired phones and factory-reset the infotainment system before selling or returning a car, and after any rental. Contacts, call logs, messages and saved destinations survive a simple unpair.

5Opt out at the dealer too. Dealers run their own marketing data operations, separate from the manufacturer, and a manufacturer request does not touch them — Toyota says so explicitly on its own form.

Removing the modem is not the move. Physically disabling the telematics unit can disable emergency crash notification and stolen-vehicle tracking, may void warranty coverage, and on some vehicles interferes with systems you want working. Use the account-level controls.

What opting out actually costs you

Manufacturers rarely say this up front, so: opting out usually costs features. Remote start, remote lock and unlock, stolen-vehicle tracking, automatic crash notification, over-the-air updates and app-based climate control commonly depend on the same connection. That is a real trade-off and it is yours to make — but you should make it knowing what goes away, rather than finding out in January when remote start stops working.

The Order to Do This In

  1. Turn off data sharing in your connected-services account, so the flow stops while everything else is in progress.
  2. File the manufacturer privacy request using the brand section above — and if yours emails a confirmation link, click it.
  3. Order your LexisNexis Consumer Disclosure Report and read the driving entries.
  4. Dispute anything inaccurate in that file in writing.
  5. Send a written CCPA deletion demand with your VIN for anything the web form would not cover.
  6. Re-check in 45 days. Data reappears, and the only way to know is to look again.

Or skip the manual work

Vigilant Privacy sends legal deletion demands to the major car data collectors — GM, Ford, Toyota, Honda, Nissan, BMW, Mercedes-Benz, Volkswagen, Hyundai, Tesla, Kia and Subaru — and fills in the portal-only forms for you, for $9.95/month. You keep the final click where the law says it belongs.

Start free — no card required

Free privacy tools

No signup, no card, no data kept.