Last updated: 2026-06-13. Originally published 2026-01-09. The enforcement picture has changed dramatically since this article first went up: the FTC has finalized a settlement with GM over OnStar driving data, the California Privacy Protection Agency has run a three-case connected-car sweep that produced a record $12.75 million penalty, and Texas has filed the first state-AG action under its new privacy law against Allstate and Arity. The pipeline is the same. The legal ground beneath it is shifting.

TL;DR: Your car is collecting data on every trip you take: speed, location, braking, acceleration, time of day, routes driven. In March 2024, the New York Times revealed GM was secretly selling this data to LexisNexis and Verisk, which then fed it to insurance companies. Drivers saw their premiums spike with no explanation. One plaintiff discovered 331 recorded "events" in his LexisNexis file. Since then, Honda, Hyundai, Ford, and others have continued sharing data with Verisk, which claims access to telematics from automakers that represent nearly 50% of new vehicle sales in the U.S. The regulator response is now real: in May 2026 the California Privacy Protection Agency hit GM with a $12.75 million record penalty for selling OnStar driving data to LexisNexis and Verisk, the FTC finalized a parallel settlement, and in January 2025 Texas Attorney General Ken Paxton filed the first state-AG enforcement action under the Texas Data Privacy and Security Act against Allstate and Arity for tracking 45 million Americans through mobile-app SDKs. The market is growing fast: the insurance telematics industry is projected to hit tens of billions by the early 2030s.

What Your Car Collects

Modern cars collect more than 100 different data points. Some of this is mechanical, tire pressure and engine status. But much of it is about you.

Driving Behavior

Data Type What It Reveals
GPS location history Everywhere you've been, when, how long you stayed
Speed data How fast you drive, when you exceed limits
Hard braking events Every time you brake suddenly
Rapid acceleration Every time you accelerate quickly
Sharp turns/swerving Cornering behavior, lane changes
Trip times When you drive, late-night driving patterns
Mileage How much you drive
Seat belt use Whether you buckle up

Sensors and Cameras

Modern vehicles contain:

  • Interior cameras: Tesla, GM, and others have in-cabin cameras for "driver monitoring"
  • Exterior cameras: Dashcam footage, 360-degree views
  • Microphones: For voice commands, but always listening
  • Heart rate/fatigue detection: Some vehicles monitor biometrics

Connected Device Data

  • Synced contacts: Your entire phone contact list
  • Call logs: Who you called, when, how long
  • Text messages: If synced via Bluetooth
  • In-car conversations: If voice features are active, conversations can be recorded

When you sell your car, this data often stays on the vehicle. The next owner (or anyone with physical access) can potentially retrieve it.

The GM/OnStar Scandal

In March 2024, the New York Times published an investigation that shocked drivers: General Motors had been secretly sharing detailed driving behavior with data brokers, who then sold it to insurance companies.

How It Worked

  1. GM's OnStar Smart Driver program collected driving data
  2. Data included hard braking, speeding (over 80 mph), late-night driving, sudden acceleration
  3. GM sold this data to LexisNexis Risk Solutions and Verisk
  4. These data brokers created "risk scores" from driving behavior
  5. Insurance companies used the scores to adjust premiums, usually upward

What Drivers Discovered

Romeo Chicco, a Florida driver, found his insurance rates spiked with no explanation. He requested his LexisNexis consumer file and discovered:

  • 331 recorded driving events, including acceleration, speed, braking
  • Location data for where each event occurred
  • His Verisk file contained another 100+ recorded events

He claims he never signed up for OnStar or consented to data sharing. His insurance premium on his Chevy Equinox jumped 10% in 2024.

The Lawsuits

The original consolidated action in the Northern District of Georgia (MDL No. 3115) has since expanded. The 32 filings tracked as of November 2024 have grown into a class action with hundreds of thousands of California drivers represented, alleging that the data was sold for at least four years, from 2020 to 2024, without informed consent.

Senators alleged that automakers used "dark patterns" (deceptive interface design that nudges users toward data-sharing) to manipulate consumers into signing up for data-sharing programs. OnStar's privacy policy reportedly did not disclose that driving data would be sold to insurance-related data brokers.

The FTC Settlement

In January 2025, the Federal Trade Commission finalized a settlement with GM in which the company agreed to stop selling driver geolocation and driving-behavior data to consumer reporting agencies (Verisk, LexisNexis) and to obtain separate, affirmative consent before sharing sensitive telematics with any third party [10]. The order also requires GM to delete data already collected from drivers who had not provided express consent, and bars the company from making misleading statements about its privacy practices. The FTC called the practice the largest auto-privacy enforcement in the agency's history at the time of the settlement.

The CPPA Record Penalty

In May 2026, the California Privacy Protection Agency hit GM with a $12.75 million civil penalty for selling OnStar driving data to LexisNexis and Verisk, the largest CCPA penalty ever assessed [11]. The settlement resolved a complaint that the company had collected geolocation and driving behavior from hundreds of thousands of California drivers, packaged it into driver-rating products for insurers, and made the opt-out effectively impossible to use. The fine, by GM's own admission in the settlement documents, was the largest privacy penalty any U.S. state regulator has imposed on an automaker.

GM's Public Response

GM ended the OnStar Smart Driver data-sharing program on April 24, 2024. A spokesperson stated: "Customer trust is a priority for us, and we are actively evaluating our privacy processes and policies."

Translation: we got caught, and the regulators are now fining us for it.

It's Not Just GM

GM stopped after the scandal and after the FTC and CPPA penalties. Others have not stopped; they have been fined for it.

Verisk claims access to "telematics data from millions of connected vehicles" from "multiple leading automakers that represent nearly 50% of new vehicle sales in the U.S."

Confirmed data-sharing relationships include:

  • Honda/Acura: Shares driving data with Verisk; CPPA-settled March 12, 2025 for $632,500 over the opt-out minefield [12]
  • Ford: Collects telematics data; opt-out required; CPPA-settled March 5, 2026 for $375,703 over the email-verification step [13]
  • Hyundai: Has telematics data-sharing arrangements
  • Stellantis (Dodge/Chrysler/Jeep): Requires online account to opt out

The CPPA Connected-Car Sweep

The California Privacy Protection Agency opened a review of data privacy practices by connected vehicle manufacturers on July 31, 2023 [14]. It has now produced three written decisions, all under the same review:

  • Honda, March 12, 2025: $632,500 for excessive verification, asymmetric privacy choices, blocked authorized agents, and ad-tech sharing without compliant contracts [12].
  • Ford, March 5, 2026: $375,703 for requiring email verification before processing opt-out requests from connected-vehicle services [13].
  • GM, May 2026: $12.75 million record penalty for selling OnStar driving data to LexisNexis and Verisk [11].

Read left to right, the fines are a sliding scale tied to the severity of the underlying conduct. Honda and Ford were fined for making privacy rights hard to use. GM was fined for monetizing the data the connected car collected. The next manufacturer that runs an opt-out flow with a friction step the agency has already called "unnecessary" is going to be the next settlement, and the fine is going to be larger.

The Texas AG v. Allstate/Arity Case

In January 2025, Texas Attorney General Ken Paxton filed suit against Allstate and its data subsidiary Arity, alleging the two companies secretly harvested the driving data of more than 45 million Americans through mobile-app SDKs embedded in apps including Routely, Fuel Rewards, GasBuddy, and Life360, then sold the data to insurance companies for use in underwriting [15].

This is not even from the car itself. It is from apps on your phone that have Arity's tracking code embedded without disclosure. The case is the first enforcement action brought by a state Attorney General under the Texas Data Privacy and Security Act, which took effect July 1, 2024, and it seeks civil penalties of up to $10,000 per violation plus a court order requiring Allstate and Arity to delete all improperly obtained driving data.

The Toyota Opt-Out Class Action

A separate private class action accuses Toyota of selling drivers' location, speed, and cornering-event data to third parties, including Progressive Insurance, after the driver had explicitly opted out through the Toyota app. The Florida plaintiff in the case (a RAV4 owner) says he toggled the in-app opt-off, got a confirmation, and then discovered Progressive already had his driving data. The case hit a major procedural moment in February 2026 [16]. Toyota denies the allegations.

The Data-Broker Pipeline: How Telematics Becomes Insurance Risk Scores

The automaker does not sell your driving data directly to your insurance company. There is a broker layer in the middle, and that broker layer is where the money is made.

How the Pipeline Actually Works

  1. The car collects. Your telematics control unit logs speed, location, hard-braking events, accelerations, cornering, time of day, and trip start/end. Some manufacturers collect at 1 Hz (one sample per second); others sample less often, but the data is detailed enough to infer driver behavior over time.
  2. The automaker packages. Connected-services programs (OnStar, HondaLink, FordPass, Toyota Connected, Hyundai Bluelink) aggregate the raw data, often tagged to a vehicle identification number (VIN) and a customer account.
  3. The broker buys and re-packages. LexisNexis Risk Solutions and Verisk buy (or receive) the data, attach it to a consumer file keyed by name and address, score it, and produce a "driving behavior" or "telematics risk" product.
  4. The insurer buys the product. Insurance carriers (not just the automakers' own insurance arms) license the broker's product and use the score in underwriting, pricing, renewal, and claims investigation. A driver who has never opted in to a usage-based insurance program can find their rates increased based on data they did not know existed.
  5. The driver is left to discover it. The consumer is not a party to any of these transactions. There is no notice. There is rarely a privacy policy that names the broker. The first time a driver learns their data was used is when their premium increases, or when they request their LexisNexis consumer disclosure and find hundreds of "events" they do not remember.

LexisNexis Risk Solutions

LexisNexis is best known for legal and public-records databases. The Risk Solutions division also maintains a consumer file on roughly 300 million U.S. adults, and the file has, since at least 2024, included a "Telematics" section. Drivers who request their consumer disclosure (free, at consumer.risk.lexisnexis.com/request) can see how many "events" LexisNexis has on file, with timestamps and locations. The Romeo Chicco case, which became the public face of the GM scandal, found 331 such events in his file.

Verisk

Verisk is the other major U.S. insurance-data broker. It sells a telematics product to carriers that scores drivers using data sourced from "multiple leading automakers that represent nearly 50% of new vehicle sales in the U.S." [per Verisk's own marketing]. The scoring inputs are not publicly disclosed in detail, which is the kind of opacity that makes consumer pushback structurally difficult. The Verisk consumer disclosure process exists, but the time-to-data is longer than LexisNexis and the format is less standardized.

Who Buys the Scored File

The primary buyers are insurance companies. They use the data to:

  • Adjust premiums based on driving behavior
  • Deny coverage for "risky" drivers
  • Cancel policies at renewal
  • Investigate claims, especially crash reconstructions

You might never know your premium increase was based on telematics data. Insurance companies are not required to disclose the specific data sources behind rate decisions, and a broker-sourced driving score is not a category insurance regulators currently force carriers to break out.

Law Enforcement

Police can access vehicle data through multiple paths:

  • Court orders/warrants: Request data from carmakers directly
  • Data brokers: Purchase data without warrants (no legal requirement for warrants when buying from private companies)
  • Berla iVe device: Physical extraction of data from vehicle systems
  • Border Patrol: In November 2025, AP exposed a secretive program monitoring millions of drivers through connected vehicle data in real-time

The Warrant Gap

Here is the legal problem: In United States v. Jones (2012), the Supreme Court ruled police need a warrant to track your car with GPS. But that only applies to government surveillance.

When private companies collect the data first, the rules change. Police can often:

  • Buy data from commercial brokers without a warrant
  • Access data stored by manufacturers without Fourth Amendment protections
  • Extract data from vehicles under the "automobile exception" without warrants

One insurer representative admitted: "If a driver is involved in a serious crash and the police suspect they were exceeding the speed limit, they may ask to see the telematics data. We would only hand this over with a court order." That is one insurer. Others may be less cautious.

Data Brokers Beyond LexisNexis and Verisk

LexisNexis and Verisk are the two largest insurance-data brokers in the U.S., but they are not the only ones. Arity (an Allstate subsidiary) collects driving data from mobile-app SDKs and packages it for insurance carriers. The Texas AG's January 2025 lawsuit alleges Arity tracked 45 million Americans through embedded SDKs in apps including GasBuddy, Fuel Rewards, Routely, and Life360 [15]. Other brokers in the space include CCC Intelligent Solutions, Mitchell International, and a long tail of regional aggregators that specialize in a single carrier relationship. The market is fragmented enough that an automaker selling to one broker is functionally selling to all of them through the secondary market.

OBD Dongles: The Plug-In Surveillance Device

The OBD-II port (On-Board Diagnostics) is a standard connector in all vehicles since 1996. It was designed for mechanics to diagnose problems. Now it's a surveillance access point.

Insurance Dongles

Many insurers offer "usage-based insurance" programs that require you to plug a device into your OBD port:

  • Progressive Snapshot
  • State Farm Drive Safe & Save
  • Allstate Drivewise
  • USAA SafePilot

These devices collect:

  • Speed and acceleration patterns
  • Braking behavior
  • Time of day you drive
  • Miles driven
  • Location (some devices)

The promise is a discount. The reality is permanent behavioral surveillance.

App-Based Tracking

Smartphone apps are replacing physical dongles. You install an app that uses your phone's GPS and accelerometer to track driving.

Problems:

  • Can't distinguish between drivers (who's actually driving?)
  • Less accurate than OBD data
  • Tracks you even when not in the car
  • May contain third-party tracking code (like Arity)

The Market Is Exploding

The global insurance telematics market was valued at roughly $9 billion in 2025 and is projected to grow at a compound annual rate near 19% through the early 2030s, putting the market on a trajectory to clear $25 billion within the decade [9]. The OBD dongle market alone is a multi-billion-dollar segment, and consumer smartphone-based telematics (apps from Progressive Snapshot, GEICO, Root, and the Allstate/Arity SDK embedded in third-party apps) now account for a growing share of new data ingestion at the carriers.

This is not going away. It is expanding into a broker-driven ecosystem where a single trip in your car can flow through the manufacturer, the broker, the insurer, and the secondary market in the same week.

How to Opt Out (Brand by Brand)

The bad news: it is nearly impossible to fully disable telematics. Even if you opt out, data may still be collected when you visit a dealership. The CPPA's 2025-2026 enforcement sweep is now drawing a line on what counts as a legal opt-out, and the line is: friction is a violation. You can use that.

Global Privacy Control (the New Lever)

If you live in a state with a comprehensive privacy law (California, Colorado, Connecticut, Oregon, Texas, Virginia, and a growing list of others), the Global Privacy Control (GPC) is now the lever. GPC is a browser-level signal that expresses a universal opt-out, and CCPA-covered businesses are required to honor it. The CPPA's March 2026 Ford settlement specifically required Ford to audit its tracking technologies for GPC compliance [13]. The same audit standard is going to apply to every other connected-car maker on the agency's radar. Enable GPC in your browser, and the carrier-side and broker-side flows are supposed to honor it.

What Counts as a Friction Violation

The CPPA's three-case connected-car sweep gives consumers a working definition of illegal opt-out friction. The agency has now fined, in writing, for:

  • Excessive personal information required to opt out (Honda, 2025) [12]
  • Asymmetric privacy choices (the opt-out hidden behind more clicks than the opt-in) (Honda, 2025) [12]
  • Blocking authorized agents (preventing a third party from submitting the opt-out on the consumer's behalf) (Honda, 2025) [12]
  • Email verification before processing the opt-out (Ford, 2026) [13]

If your automaker's opt-out process imposes any of these, you can file a complaint with the CPPA (California residents) or your state AG, and you can request your data deletion in the same submission.

Toyota

Easiest of the major brands:

  1. Press the SOS button in your car
  2. Ask the representative to opt out of Connected Services
  3. Or call Customer Care
  4. Or use the Toyota App

Ford

Disable from infotainment system:

  1. Select Settings on SYNC screen
  2. Choose Connectivity
  3. Tap Connected Vehicle Features
  4. Toggle Share Vehicle Data to Off
  5. Press Continue on confirmation

General Motors

GM ended OnStar Smart Driver data sharing in March 2024 after the scandal and the FTC settlement. For now, GM vehicles appear not to collect behavioral data for third-party sharing, and the May 2026 CPPA record penalty is a clear signal that any backsliding will be expensive. But verify through your OnStar account, and re-verify after any dealer visit or software update.

Hyundai

  1. Go to Bluelink in infotainment settings
  2. Select "Deactivate Bluelink"
  3. Reset to factory settings
  4. Also: Cancel subscription via Bluelink App, My Account, Terminate My Account

Stellantis (Dodge/Chrysler/Jeep/Ram)

More difficult:

  • Must opt out through online Connected Services account
  • Disabling services does not stop collection of "de-identified or aggregate data"

Honda/Acura

Most difficult, and the one with the worst track record:

  • No in-car option to disable
  • Must contact Honda directly to disable data sharing
  • Honda actively shares data with Verisk
  • The CPPA's March 2025 settlement [12] required Honda to redesign its opt-out flow with a UX designer; the new flow should now offer symmetrical privacy choices, accept authorized agents, and not require excessive verification, so the opt-out process is meaningfully better than it was in 2024

Nuclear Option: Physical Disconnection

Some owners disconnect the telematics antenna (the "shark fin" on the roof):

  • Contains GPS, cellular, WiFi, and SXM antennas
  • Disconnecting stops transmission but may trigger dashboard warnings
  • Some vehicles route speakers/microphone through telematics module, so disconnecting kills audio

This is technically possible but may void warranties or disable features you actually want.

Check What Data Exists About You

You can request your files from the major data brokers:

LexisNexis

  1. Visit consumer.risk.lexisnexis.com/request
  2. Request your consumer disclosure
  3. Look for the "Telematics" section
  4. You'll see driving events with dates, times, and locations

Verisk

  1. Visit Verisk's consumer disclosure page
  2. Request your driving data file
  3. Compare with LexisNexis: they may have different data

This won't change what's already collected, but at least you'll know what exists.

Regulatory Response

FTC v. GM: From Warning to Settlement

In May 2024, the FTC published a statement warning that it "will take action to protect consumers against the illegal collection, use, and disclosure of their personal data" from connected vehicles. The warning was the precursor to the January 2025 settlement with GM [10], which formalized the prohibition on selling driver geolocation and driving-behavior data to consumer reporting agencies (Verisk, LexisNexis) and required affirmative, separate consent for any future sharing of sensitive telematics. The FTC also required GM to delete data already collected from drivers who had not provided express consent.

California Privacy Protection Agency: The Sweep

The CPPA's three-case connected-car sweep is now the single most concentrated privacy enforcement effort in the United States, and the most useful tool consumers have for forcing a working opt-out:

  • Honda, March 12, 2025: $632,500 for excessive verification, asymmetric privacy choices, blocked authorized agents, and ad-tech sharing without compliant contracts [12].
  • Ford, March 5, 2026: $375,703 for requiring email verification before processing opt-out requests from connected-vehicle services [13].
  • GM, May 2026: $12.75 million record penalty for selling OnStar driving data to LexisNexis and Verisk [11].

The Ford settlement's Global Privacy Control audit requirement [13] is the part that matters most for the future: the GPC is a browser-level signal that lets a consumer express an opt-out once, and the audit is going to tell us whether Ford's data flows are GPC-compliant at the network level, or only at the consumer-facing preference center. If the audit finds that GPC works at the preference-center layer but not at the in-vehicle telematics layer, the next settlement is going to be a large one.

Texas AG v. Allstate/Arity

On January 13, 2025, Texas Attorney General Ken Paxton filed the first state-AG enforcement action under the Texas Data Privacy and Security Act (TDPSA), against Allstate Insurance Company and its data subsidiary Arity, alleging the two companies secretly harvested the driving data of more than 45 million Americans through mobile-app SDKs and sold it to insurance carriers [15]. The TDPSA authorizes civil penalties of up to $10,000 per violation, which when multiplied by the 45 million driver figure gives the case a theoretical multi-billion-dollar exposure. The complaint also seeks injunctive relief, including a court order requiring Allstate and Arity to delete all improperly obtained driving data from Texas residents. Allstate and Arity deny the allegations.

State AG Action Beyond Texas

Other state AGs with comprehensive privacy statutes (California, Connecticut, Oregon) are now watching the Allstate/Arity case as a template. The CPPA's three-case sweep has already produced its own template, and the FTC's GM order adds the federal layer. State-action privacy enforcement on telematics is no longer theoretical.

Federal Legislation

In 2024, a bipartisan Senate bill was introduced to:

  • Prevent vehicle manufacturers from accessing or selling specific driver data
  • Establish a secure vehicle interface framework

It has not passed. The auto-industry lobby is significant, and Congress has not yet produced a federal comprehensive privacy law that would preempt the state-by-state enforcement now happening in California, Texas, and elsewhere.

The Bottom Line

Your car is a surveillance device on wheels. It knows where you go, how fast you drive, how hard you brake, and what time you are on the road. This data is being collected, sold to data brokers (LexisNexis, Verisk, Arity, and a long tail of secondary aggregators), and used to raise your insurance rates, often without your meaningful consent.

GM got caught and stopped, then got hit by the FTC settlement and the CPPA's record $12.75 million penalty. But Honda, Hyundai, Ford, and others continue sharing data with Verisk, which covers nearly half the new car market, and the same regulators who hit GM are now hitting the others (Honda $632,500, Ford $375,703, with more decisions to come). Police can often access this data without warrants by purchasing it from private brokers.

The insurance telematics market is on track to clear $25 billion within the decade. Car manufacturers see your driving data as a revenue stream. Insurance companies see it as a way to personalize (raise) rates. Law enforcement sees it as a surveillance goldmine. The data brokers in the middle are the ones who have made a market out of the gap between what your car knows and what you consented to.

You can opt out, sort of. The opt-out processes are deliberately difficult, vary by manufacturer, and may not stop all data collection. The truly paranoid can disconnect telematics hardware, but this may void warranties or break features. The good news is that the 2025-2026 enforcement wave is starting to define what counts as a legal opt-out: symmetrical privacy choices, no excessive verification, accepted authorized agents, and a Global Privacy Control that a covered business must honor. The bad news is that the same enforcement wave took until mid-2026 to produce the first record penalty, and the data brokers are still one step ahead of the opt-out button.

Your car rats you out to insurance companies. Now you have a regulator with a budget, a state AG with a privacy-law template, and a private right of action that works. The pipeline is the same. The legal ground beneath it is finally shifting.

References

  1. FTC: Cars & Consumer Data, On Unlawful Collection & Use
  2. The Markup: Who Is Collecting Data from Your Car?
  3. AboutLawsuits: GM OnStar Lawsuit
  4. Insurance Journal: Suit Says OnStar, LexisNexis Shared Driving Data
  5. Consumer Reports: How to Stop Your Car From Collecting Data
  6. DisappearMe: Complete Guide to Disabling Vehicle Telemetry
  7. S.T.O.P.: Wiretaps On Wheels
  8. Governing: Police Don't Need Warrants to Pull Personal Data from Cars
  9. GM Insights: Insurance Telematics Market Size 2025-2034
  10. Consumer Reports: FTC Finalizes GM/OnStar Settlement (January 2025)
  11. California Attorney General: CPPA and General Motors Reach $12.75 Million Settlement (May 11, 2026)
  12. CPPA: Honda Settles With CPPA Over Privacy Violations (March 12, 2025)
  13. CalPrivacy: Ford to Change Practices, Pay Fine for Adding Unnecessary Friction to Opt-Out Process (March 5, 2026)
  14. CPPA: Enforcement Division Sweep of Connected Vehicle Manufacturer Privacy Practices (July 31, 2023)
  15. Texas Attorney General: Paxton Sues Allstate and Arity for Unlawfully Collecting, Using, and Selling Over 45 Million Drivers' Driving Data (January 13, 2025)
  16. State of Surveillance: Toyota driving data lawsuit major turn (February 2026)
  17. Insurance Business America: Texas sues Allstate, Arity over 45 million drivers' data collection (January 13, 2025)