Your modern car is collecting and selling your data
Major automakers are harvesting driver behavior data and selling it to insurance brokers, triggering FTC penalties and regulatory scrutiny.

Stock photo for illustration only, not from the actual event
- Modern cars collect massive amounts of driving data and sell it to third parties.
- General Motors received a 5-year FTC ban for selling customer data to insurance brokers.
- Many drivers unknowingly consented to data collection by signing up for OnStar services.
- Proposed legislation like the DRIVER Act still allows automakers to harvest data.
Vehicles today are no longer just modes of transportation; they function as rolling computers that quietly harvest vast amounts of personal data from their operators, often sharing and selling that information without the vehicle owner ever realizing it.
Earlier this year, the Federal Trade Commission issued an unprecedented penalty against General Motors, handing down a five-year ban that blocks the automaker from selling customer data to consumer reporting agencies and third-party data brokers.

Stock photo for illustration only, not from the actual event
For years, GM accumulated all sorts of detailed metrics on its customers, such as frequency of speeding or nighttime driving habits, turning around to sell those insights to brokers who build risk profiles for insurance companies. Most drivers remained completely unaware that their data was actively being gathered through connected service plans like OnStar and its embedded Smart Driver feature.
This opaque process was brought to light by a landmark 2024 investigative report from The New York Times, which revealed that numerous drivers experienced unexpected spikes in their insurance rates as a direct consequence of this data collection. Under the FTC settlement terms, GM is now required to simplify the process for disabling location tracking while giving drivers proper access to view and delete the data gathered by the manufacturer.
The ongoing controversy over automotive data highlights a massive regulatory blind spot in the connected car ecosystem. Unlike smartphones where privacy dashboards are easily accessible, vehicles bury data collection clauses deep inside convoluted service agreements, leaving consumers with virtually no meaningful way to opt out initially.
However, GM is far from being the sole offender vacuuming up driver metrics. A research team from the Mozilla Foundation spent months examining privacy policies across all major automotive brands for a 2023 report, ultimately concluding that every single company studied had atrocious privacy and security practices, according to study co-author Jen Caltrider.
Furthermore, consumers are forced to navigate a confusing maze of overlapping policies covering the vehicle itself, connected services, companion smartphone apps, and financial lending services, each containing data harvesting provisions.
"And so it was really overwhelming trying to understand what was going on"
Jen Caltrider
A separate investigation published last year by Consumer Reports corroborated these findings, concluding that nearly every automaker selling cars in the United States routinely collects and shares driver behavior data with external corporations.
Following the regulatory action taken against GM, automotive data privacy has finally attracted the attention of policymakers, though legislative efforts appear to miss the mark. Last December, three House Republicans introduced the DRIVER Act, championing the principle that vehicle owners should rightfully own the data generated by their cars.
Despite giving vehicle owners slightly more administrative control, the proposed bill would still permit automakers to continue gathering and selling data to third-party brokers, rendering it a nonstarter for privacy advocates who argue that deletion rights do not substitute for halting excessive data collection at the source.
Source: The Verge
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment