Your car is selling your data
The FTC issued an unprecedented penalty against GM, banning it for five years from selling customer driving data to consumer reporting agencies and third-party data brokers Every major automaker collects and shares "driver behavior data" with third parties, but privacy controls are fragmented across multiple systems and policies, making them nearly impossible for consumers to navigate Proposed legislation like the DRIVER Act and "Freedom Car" concept provides only partial remedies, allowing cont
Analysis
TL;DR
- The FTC issued an unprecedented penalty against GM, banning it for five years from selling customer driving data to consumer reporting agencies and third-party data brokers
- Every major automaker collects and shares "driver behavior data" with third parties, but privacy controls are fragmented across multiple systems and policies, making them nearly impossible for consumers to navigate
- Proposed legislation like the DRIVER Act and "Freedom Car" concept provides only partial remedies, allowing continued data collection while shifting the burden of deletion to individual consumers
- Automakers have strong financial incentives to keep collecting and monetizing vehicle data, and without structural regulatory change, voluntary compliance is unlikely
Why It Matters
This story sits at the intersection of AI, automotive technology, and consumer privacy—three domains that are rapidly converging as vehicles become increasingly connected and data-driven. For AI practitioners and researchers working on autonomous vehicles, smart transportation, or connected car ecosystems, the regulatory landscape around data collection will directly shape what data can be gathered, how it can be used, and what business models are viable. The lack of clear privacy frameworks in the automotive sector mirrors challenges seen in other emerging tech domains, making this a case study in how policy struggles to keep pace with technological deployment.
Technical Details
- GM's "Smart Driver" feature, activated through OnStar connected services plans, collected granular driving data including speeding frequency and nighttime driving patterns, which was then sold to data brokers LexisNexis and Verisk for insurance risk profiling
- Mozilla Foundation researchers examined privacy policies across all major automakers and found uniformly poor privacy and security practices, with consumers forced to accept overlapping policies spanning the vehicle itself, connected services, smartphone apps, and financial services
- The proposed DRIVER Act would grant vehicle owners access and deletion rights but explicitly allows continued data collection and sales to third-party brokers, a compromise rejected by privacy advocates as insufficient
- Consumer-reported investigations found that opting out of data collection requires navigating complex, legally dense privacy pages buried across multiple platforms, with no standardized industry approach
Industry Insight
- Automakers should proactively adopt privacy-by-design principles rather than reacting to regulatory penalties; companies that establish transparent, user-friendly data practices early will gain consumer trust as privacy becomes a purchasing decision factor
- The "right to disconnect" narrative gaining traction in policy circles suggests a growing market segment for simpler, less-connected vehicles—companies that can offer bare-bones transportation without surveillance infrastructure may capture this demand
- Data brokers serving the insurance industry should anticipate tighter regulations and begin diversifying their data sourcing strategies, as the current model of purchasing driving behavior data from automakers faces increasing legal and political risk
Disclaimer: The above content is generated by AI and is for reference only.