This is a map rather than a manifesto. Each claim below links to the document, order or research paper it comes from, so you can check it rather than take our word for it. Where something is contested or unverifiable, it says so.
Five questions organize it: what the car collects, where that data goes, how it escapes even when nobody sold it, who builds the hardware, and why governments now treat this as a security matter rather than a consumer-privacy one. Each section is a summary with a link to the detailed article.
In September 2023 the Mozilla Foundation published a review of 25 car brands as part of its *Privacy Not Included series. Every one of the 25 failed. Mozilla also reported that none of the brands met its Minimum Security Standards, and that it could not confirm whether any of them encrypted the personal information held on the vehicle. It singled out Nissan's policy as the most expansive it had read, and described Renault as the least problematic of the group without awarding it a passing grade.
Eighteen months later, Consumer Reports looked at the question from the other end: not what the policies permit, but what the companies actually do. Its March 2025 investigation of 15 automakers found that nearly every major automaker selling cars in the United States collects and shares driver behavior data. The measurements it lists are specific: acceleration, braking force, cornering speed, precise location, nighttime driving, and discrete "speeding events" and hard-braking incidents.
The important point is the unit of measurement. This is not a monthly odometer figure. It is a stream of individual events, each with a time and a place attached, which is what makes it useful to someone pricing risk.
For what each brand's policy permits and which settings exist in each app, see Every Car Brand That Sells Your Driving Data.
The route from a dashboard to an insurance quote runs through companies most drivers have never heard of. Kashmir Hill's reporting for The New York Times in March 2024, syndicated here by the Seattle Times, described drivers who discovered their premiums had risen because behavioral data from their own cars had reached their insurer through an intermediary.
Telematics hardware records location and driving events and sends them to the manufacturer, usually through a built-in cellular connection rather than your phone.
The manufacturer passes data to a consumer reporting agency. California named LexisNexis Risk Solutions and Verisk Analytics as the recipients in the GM case.
The broker sells a risk product built from that data. The insurer prices your policy using it.
Two regulators have now documented this with GM, and it is worth keeping them apart because both imposed a five-year restriction and they are easy to confuse.
The federal action. The Federal Trade Commission proposed an order against General Motors and OnStar in January 2025 and finalized it on January 14, 2026. It is a 20-year consent order containing a five-year prohibition on sharing precise location and driver behavior data with consumer reporting agencies, a requirement to obtain consent before collecting it, and a requirement to let drivers get a copy, request deletion, and switch off precise location collection. The FTC's own announcement of the proposed order describes collection as frequent as every three seconds. No monetary penalty was imposed; the order sets a figure of up to $51,744 per future violation.
The California action. Separately, the California Attorney General and the Los Angeles County District Attorney settled with GM for $12.75 million on May 12, 2026, reported as the largest penalty under the California Consumer Privacy Act to date and analyzed here by Finnegan. Alongside the payment it requires a five-year ban on selling driving data to consumer reporting agencies, deletion of retained driving data within 180 days absent express consent, a request to LexisNexis and Verisk to delete what they already received, and a privacy program with reporting to California. Prosecutors put GM's nationwide revenue from the sales at roughly $20 million.
The apps, not just the cars. In January 2025 the Texas Attorney General sued Allstate and its subsidiary Arity, alleging data on 45 million Americans was collected through tracking software embedded in ordinary phone apps, including GasBuddy, Life360, MyRadar and SiriusXM, sampling location and motion every 15 seconds or less. Texas described it as the first enforcement action by a state attorney general under a comprehensive state privacy law. Your phone can feed the same pipeline as your dashboard.
A separate 2026 settlement is often folded into this story and should not be. In March 2026 the California Privacy Protection Agency settled with Ford for $375,703. That case was about opt-out mechanics rather than vehicle telematics: Ford required people to confirm an email link before it would process an opt-out, which the agency treated as imposing a verification requirement the CCPA does not allow, and requests left unconfirmed went unprocessed while sharing continued. DLA Piper's write-up places it in a run of CalPrivacy enforcement. It matters here because it is evidence that the opt-out process itself can be the failure point.
For the insurer end of the pipeline in detail, see How Insurance Companies Use Your Driving Data Against You.
Contracts and settlements only govern the data a company meant to share. A second body of evidence concerns data that moved because something broke.
The precedent is the 2015 Jeep Cherokee demonstration, in which two researchers reached a moving vehicle's accelerator and brakes and Fiat Chrysler recalled about 1.4 million vehicles. More recent cases are about data rather than steering: a flaw in Subaru's Starlink portal exposed a year of location history at roughly five-meter accuracy, and a misconfigured cloud bucket at Volkswagen's software subsidiary exposed location data for around 800,000 electric vehicles, including an entire municipal police fleet.
Full detail, researchers and timelines: When Connected Cars Get Hacked.
The modem, the telematics unit and the software stack are usually not built by the company whose badge is on the grille. In January 2025 the Commerce Department's Bureau of Industry and Security finalized a rule restricting connected-vehicle hardware and software linked to China and Russia, effective March 17, 2025, with software prohibitions beginning with model year 2027 and hardware prohibitions with model year 2030. The stated concern is that a supplier subject to a foreign government's direction could be compelled to hand over data or permit remote access.
What the rule covers, who is exempt, and what it implies about the supply chain: Who Builds the Box in Your Car.
Aggregated location data has already exposed sensitive government activity once, through a fitness app rather than a car. In January 2018 Strava's global heat map was found to trace the perimeters, supply routes and daily movement patterns of overseas military sites, and the Department of Defense restricted geolocation features for deployed personnel later that year. In November 2023 researchers at Duke University bought sensitive data on US service members from brokers for as little as $0.12 per record, in one case through a .asia domain.
Why vehicle data raises the same problem: Driving Data as a National Security Problem.
Consumer Reports frames the practical work as three distinct requests, and the distinction matters because companies treat them differently:
A reasonable rhythm is to opt out once and re-send the deletion request quarterly. Opt-outs are meant to persist; deletion only ever covers what existed when you asked.
Then check the receiving end rather than trusting the sending end. LexisNexis and Verisk are consumer reporting agencies, which means you can request your file and dispute what is in it. If driving data reached them, that is where it will show.
The Electronic Frontier Foundation published a practical walkthrough in March 2024 covering manufacturer request portals, driver-scoring features to look for in each app, and what to expect back. It is also candid about the ceiling:
“Without a national law that puts privacy first, there is little that most people can do to stop this sort of data sharing.”
“Moreover, the steps above clearly require far too much effort for most people to take.”
— Electronic Frontier Foundation, "How to Figure Out What Your Car Knows About You", used under CC BY
We agree with both sentences, which is why this site exists and why we are explicit about what it does not fix.
For the brand-by-brand route, including which forms ask for what and which states are offered no deletion right, use How to Stop Car Companies From Collecting Your Data — The Complete Guide. That guide is the step-by-step companion to this page.
Honesty about the limits is part of the point.
When a company announces that it has stopped a practice, there is no public mechanism for confirming it. Nobody outside the company can inspect the data flows. Two checks are available to an individual, and both are indirect: a vehicle with no active cellular modem cannot transmit, and a consumer report from LexisNexis or Verisk shows whether driving data has arrived at the broker end. Neither proves a negative.
Deletion has a similar limit. A company can delete its copy and the copies already sold onward remain where they are, which is precisely why California's GM settlement had to separately require GM to ask LexisNexis and Verisk to delete what they had received. A promise to stop selling is not a recall of what was sold.
We also do not claim to verify removals we cannot see. Where a broker confirms a deletion, that is a statement by the broker, not an independent audit.
Opting out of your car is one surface. We send legal CCPA deletion demands to 1,475 data brokers and file FCRA disclosure requests with the consumer reporting agencies that hold driving data — so you can see what is on file and demand its removal. Automated 45-day re-checks. $9.95/month.
Start Your Free 7-Day TrialNo credit card required. Cancel anytime. We never sell your data.
No signup, no card, no data kept.