Federal and state regulators have spent the past two years building an actual paper trail showing that modern cars collect driving behavior data and route it to insurers and data brokers — frequently without owners realizing they ever agreed to it. The cases aren’t hypothetical anymore. They’re settled, fined, and sitting in official government filings. Here’s what regulators have actually documented, case by case.

The FTC just banned General Motors from doing this exact thing for the next five years. In a finalized order from January 2026, the Federal Trade Commission concluded that GM and its OnStar unit used a deceptive enrollment process for the OnStar Smart Driver feature, collecting precise geolocation and driving-behavior data and selling it to third parties without clear consumer consent. The order bars GM from sharing that data with consumer reporting agencies for five years and imposes a 20-year requirement to get affirmative, explicit consent before collecting or sharing connected-vehicle data going forward.

Texas said more than 1.5 million of its own drivers had their data sold without their knowledge. A year earlier, Texas Attorney General Ken Paxton sued GM directly, alleging the company sold detailed driving data on more than 1.5 million Texans to firms that generated “Driving Scores” later purchased by insurance companies. “Millions of American drivers wanted to buy a car, not a comprehensive surveillance system that unlawfully records information about every drive they take and sells their data to any company willing to pay for it,” Paxton said in the announcement.

California hit GM with the largest privacy fine of its kind ever issued in the state. In May 2026, California Attorney General Rob Bonta announced a record $12.75 million settlement with GM over violations of the state’s Consumer Privacy Act tied to the same driving-data practices — the largest CCPA penalty California regulators have secured to date.

Close-up of a modern car's digital dashboard display

Every single one of 25 major car brands failed a 2026 privacy review — the first time that’s happened in the guide’s seven-year history. The Mozilla Foundation’s “Privacy Not Included” research found that none of the 25 brands it evaluated met its minimum security standards, and researchers could not confirm that any manufacturer encrypts personal data stored in the vehicle. Mozilla singled out Nissan as the worst offender, noting the automaker’s own privacy policy admits to sharing customers’ “preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes” with data brokers and law enforcement. Hyundai and Kia’s policies allow sharing with law enforcement on request, formal or informal. Mozilla cites industry projections that the market for monetizing car data could reach $750 billion by 2030.

Two data brokers, not the automaker itself, are often the ones actually scoring your driving. Reporting confirmed by ABC11 identified LexisNexis Risk Solutions and Verisk as the firms that received OnStar Smart Driver data and converted it into risk scores sold to insurance companies — a pipeline GM shut down for new enrollments after the public backlash, according to Forbes, though the FTC and state cases cover the years the program was active.

You can actually check, and in some cases opt out. Under the federal Fair Credit Reporting Act, both LexisNexis and Verisk are required to provide consumers a free copy of their file on request — that disclosure will show whether driving-behavior or “risk score” data has been collected. Newer state privacy laws in California, Texas, and elsewhere now require automakers to offer a way to request what connected-vehicle data they hold and to delete or opt out of some of it, typically through the automaker’s own privacy or account portal rather than the infotainment screen. The FTC’s GM order goes further, requiring an opt-out specifically for geolocation and driver-behavior collection going forward.

The pattern across every one of these cases is the same: the data collection was real, the enforcement is now real too, and it’s arrived years after the vehicles that generated it were already on the road. Regulators are still working through complaints tied to older infotainment and telematics systems while automakers keep shipping new vehicles with more sensors, more connectivity, and more data leaving the car than the generation before it — which is exactly why checking your own vehicle’s data settings is worth doing now rather than after the next headline.

Leave a Reply

Your email address will not be published. Required fields are marked *