A modern sedan driving on a multi-lane highway at dusk with brake lights glowing
Photo via Unsplash

TL;DR: General Motors, BMW, Subaru, and Toyota have shipped detailed driver-behavior data from their connected cars to LexisNexis Risk Solutions and Verisk for years, in most cases through programs the driver never affirmatively opted into.[1][2][3] The data ends up in insurance-company underwriting files, in law-enforcement investigative products, and in breach surfaces: in March 2026, the LexisNexis dossier on millions of Americans was exposed in the FulcrumSec breach, including records on federal judges and DOJ attorneys.[4] The FTC's December 2024 GM/OnStar settlement required GM to stop selling geolocation and driver-behavior data without explicit consent,[5] the California Privacy Protection Agency hit GM with a $12.75 million record penalty in 2026 for the same conduct,[6] and the Texas Attorney General's January 2025 suit against Allstate and Arity is now testing the mobile-SDK side of the same pipeline under the Texas Data Privacy and Security Act.[7] The OEMs (BMW, Subaru, Toyota) that appeared in the parallel investigations through 2024 have not been hit with comparable settlements.[3]

The Pipeline: From the Car's CAN Bus to LexisNexis's Telematics Exchange

The pipeline runs through four stages, and most drivers only ever see the first one. Stage one is the car itself. Modern vehicles stream a constant flow of telemetry off the CAN bus: GPS coordinates, speed, accelerator and brake pedal position, seatbelt status, hard-braking and hard-acceleration events, ignition cycles, and (on newer models) cabin-camera frames and eye-tracking data. Stage two is the OEM's connected-vehicle cloud. OnStar (GM), BMW Connected, Subaru Starlink, and Toyota Connected all maintain continuous cellular uplinks from the vehicle to the manufacturer's data center. Stage three is the data broker. The most-cited destination is LexisNexis Risk Solutions, the consumer-data arm of LexisNexis (the legal-research company), which sells a product called LexisNexis Telematics Exchange to insurance underwriters.[1][2] Stage four is the downstream buyer. Insurance companies feed the data into pricing models. Law-enforcement agencies access the same broker files through investigative products. The original driver, in most cases, never sees the dossier.[1][2][3]

The most-cited investigation of this channel came out of 404 Media and Wired in February and March 2024. Joseph Cox at 404 Media showed that GM, through its OnStar subsidiary, was selling detailed driving data to LexisNexis Risk Solutions, which was packaging the data into the Telematics Exchange product and reselling it to insurance companies.[1] Makena Kelly at Wired confirmed the channel independently and documented the consent surface shown to drivers at sale (a single opt-out buried in the OnStar enrollment flow, defaulting to participation).[2] One plaintiff in the resulting class-action discovery found 331 separate driving "events" in his LexisNexis file, each one a snapshot of when he drove, where he drove, and how he drove. His insurance premium had been raised without explanation.[1]

The same 2024 investigation pipeline named BMW, Subaru, and Toyota in addition to GM, with The Telegraph's Niko Galsworthy documenting that the same OEM-to-LexisNexis channel was active for Tesla, BMW, and Subaru, and that Tesla insurance was using the data for its in-house "safety score" pricing.[3] The Markey-Blumenthal Senate staff report Tracking America, published January 25, 2024, described the same channel in detail and named LexisNexis Risk Solutions and Verisk as the two dominant broker destinations.[8]

What Drivers Actually See: The Consent Surface

The OnStar enrollment flow, as documented in the FTC complaint and the Wired piece, asks the buyer to consent to three different things: (1) OnStar emergency services, (2) OnStar vehicle diagnostics, and (3) OnStar sharing data with third parties for marketing and insurance purposes. The third item is bundled into the enrollment terms. A driver who selects "I agree" to activate the connected features has consented to all three. There is no separate, granular consent screen for the data-broker sale.[2][5]

GM and OnStar settled with the FTC on December 20, 2024 over the geolocation and driver-behavior data sales.[5] The settlement required GM to stop the practice without explicit consent and to provide a clear opt-out mechanism for existing customers. It did not unwind the data already sold. It did not impose a financial penalty. It did not stop other OEMs from doing the same thing.[5] Reuters independently confirmed the settlement on December 20, 2024.[9]

The Federal Trade Commission's staff perspective paper Review of Privacy Practices in the Modern Vehicle, published in February 2024, framed the consent problem more broadly. The staff paper concluded that consumers are largely unable to exercise meaningful choice about the data collected by their vehicles, that privacy policies are written at a reading level that exceeds the average consumer, and that the consent flow at sale is structurally coercive (refuse the data collection and you lose the connected features the car was marketed on).[10]

The practical takeaway for a driver who wants to know what is in their file: LexisNexis's consumer-facing portal does not surface the telematics data by default, but a driver's-rights request under state law (California's CCPA, Connecticut's CTDPA, Texas's TDPSA, and a growing list of others) can produce a copy of the broker file, including the driving events.[5][7]

LexisNexis: The Broker Holding the Dossier

LexisNexis Risk Solutions is a different corporate entity from LexisNexis's legal-research arm, but it shares the parent company (RELX) and the data infrastructure. The Risk Solutions arm sells three categories of product to insurance underwriters: claims-history reports, credit-like insurance scores, and (since at least 2023) the Telematics Exchange driving-behavior data.[1][2] The driving-behavior feed is not a credit-bureau product, so it does not fall under the federal Fair Credit Reporting Act. It does fall under state insurance scoring regulations, which in most states require that an adverse-action notice accompany a rate increase driven by the data. In practice, drivers report that they receive the rate increase without the notice and learn about the data source only when they request their file.[1]

The dossier is a single point of failure. In March 2026, the threat actor FulcrumSec breached LexisNexis and exposed records including data on federal judges and Department of Justice attorneys.[4] Brian Krebs's reporting on the breach tied the exposed data to the same Risk Solutions infrastructure that holds the OEM telematics feed.[4] When the broker holding the dossier gets popped, every driver's record in it gets popped with it. There is no per-OEM compartmentalization, no driver-side key management, and no breach-notification mechanism that reaches the original drivers (they are not LexisNexis's customers, so they are not in the breach-notification flow).[4]

The Toyota class action, originally filed in 2023 by Florida RAV4 owner Philip Siefke and now in individual arbitration after a February 2026 procedural ruling, makes the same structural point from the OEM side.[11] Siefke says he opted out of Toyota's data-sharing policy in the Toyota app, then discovered Progressive Insurance already had his driving data anyway. The lawsuit tests whether the in-app opt-out actually stops the data flow to the broker, or whether the OEM's connected-vehicle backend continues shipping events regardless of the consumer-side preference.[11]

Enforcement: The FTC, the CPPA, and the Texas AG

Three regulators are now testing the legal seams of the OEM-to-broker pipeline from three different angles.

The FTC's December 2024 GM/OnStar settlement established the federal baseline: the OEM cannot share geolocation and driver-behavior data with third parties without explicit, granular consent.[5][9] The settlement stopped short of a financial penalty and did not address the parallel OEM channels (BMW, Subaru, Toyota) that appeared in the same investigation.[3] The FTC's broader 2026 enforcement wave against location-data brokers, anchored by the Kochava settlement, blocks the worst of the resale pipeline at the broker layer.[12]

The California Privacy Protection Agency's 2026 connected-car sweep hit Honda, Ford, and GM with settlements on opt-out friction and on data-broker resale. The GM settlement, finalized in 2026, set the upper end of the connected-car privacy enforcement scale at $12.75 million, the largest privacy penalty in California history at the time it was finalized.[6] The CPPA found that GM had continued selling OnStar driving data to LexisNexis and Verisk after the FTC settlement was public knowledge.[6]

The Texas Attorney General's January 2025 lawsuit against Allstate and Arity is the first state-AG enforcement action under the Texas Data Privacy and Security Act, the state comprehensive privacy statute that took effect July 1, 2024.[7] The suit alleges that Allstate and Arity paid mobile-app developers millions of dollars to embed tracking software in consumer apps including Routely, Fuel Rewards, GasBuddy, and Life360, then sold the resulting driving data of 45 million Americans to insurance companies.[7] The Allstate/Arity case is not an OEM case. It tests the mobile-SDK side of the same pipeline: the data that reaches the broker does not always start with the car itself.[7]

Read together, the three lines of cases are drawing the same legal conclusion from three different directions. The FTC is testing the OEM-side consent flow. The CPPA is testing the data-broker resale layer. The Texas AG is testing the mobile-SDK collection layer. The common element is that the data infrastructure is built, the opt-out mechanisms exist on paper, and the cases are now testing whether the opt-out mechanisms actually do what they say, and whether the data is collected with the consent the law requires.[5][6][7]

How Insurance Pricing Uses the Data

Usage-based insurance (UBI) products like Progressive's Snapshot, GEICO's DriveEasy, and Tesla's in-house insurance have marketed themselves as opt-in discounts: drive less, brake less, and you save. The opt-in framing is the surface. Underneath, the same OEM-to-broker channel feeds the same Telematics Exchange product whether or not the driver has signed up for the UBI program, and the resulting data joins the underwriting file regardless of consumer-side preference.[1][2][3]

Consumer Reports' 2023 plain-English breakdown of Progressive's Snapshot program documents the pricing model: a per-mile rate adjusted by a "driving score" derived from hard-braking events, late-night driving, and high-speed driving.[13] The model is built on the assumption that the consumer has opted in. The Optus/Allstate/Arity cases make clear that the model also runs on data from consumers who did not opt in, through the OEM-to-broker channel and through the mobile-SDK channel.[7][1]

The asymmetry is structural. Insurance companies have access to a near-complete record of a driver's behavior, including events that the driver does not know were recorded. The driver has access to an "adverse action notice" that, when it arrives at all, does not name the data source. The Federal Trade Commission's staff paper on the modern vehicle flagged this asymmetry directly and called it out as a barrier to meaningful consent.[10]

Law Enforcement Access: The EDR Question

Most modern vehicles also carry an Event Data Recorder (EDR), the "black box" that captures the seconds before and after a crash. The EDR's primary data set is crash telemetry: speed, throttle position, brake position, seatbelt status. The data is supposed to be owned by the vehicle owner, but the practical reality is that law enforcement agencies can access it with a subpoena, and in many states with no judicial oversight at all.[14]

The Electronic Frontier Foundation's 2023 legal primer on EDR data and the law maps the case law. In some states (California among them), the vehicle owner must consent before the EDR data can be downloaded by a third party. In many states, the consent requirement does not extend to law enforcement, and a subpoena suffices.[14] The EDR data and the OEM telematics data live in different layers of the same vehicle, but they can be combined: a crash event recorded by the EDR can be cross-referenced with the corresponding telematics feed from the connected-vehicle cloud, and the broker file ties both to the driver's identity.[1][14]

The pipeline from a single vehicle to a law-enforcement file runs in three steps: the car streams the data to the OEM, the OEM ships it to the broker, and the broker sells access to the dossier to insurance companies and to law-enforcement investigative products. Each step is a separate contract with separate consent language, but the data flow itself is one continuous chain.[1][2][5][14]

What It Means for Drivers

The structural answer is in the regulatory beat. The FTC's GM/OnStar settlement, the CPPA's $12.75 million GM record penalty, the Texas AG action against Allstate and Arity, and the 2026 federal connected-car rule are the levers that move the needle. They move slowly and they tend to harden the existing data flow rather than dismantle it, but they are the only path that does not require millions of individual drivers to each negotiate with their OEM.[5][6][7]

The practical answer is in the opt-out. Our car-data opt-out guide walks through the per-OEM toggles that do exist, including the OnStar enrollment-flow opt-out, the Toyota Connected data-sharing preference, the BMW ConnectedDrive privacy menu, and the Subaru Starlink account settings. The guide also covers the broker-layer cleanup: how to file a driver's-rights request with LexisNexis and Verisk, what to look for in the response file, and how to dispute events that are wrong.[5][7]

The structural privacy question is whether an opt-out, even a fully working one, is the right framework for the OEM-to-broker pipeline. The Markey-Blumenthal Senate staff report recommended that telematics data be treated as sensitive personal data, with affirmative opt-in required before any third-party sharing.[8] The FTC staff paper made the same recommendation.[10] The California Privacy Protection Agency's 2026 sweep operated on that principle.[6] The Texas AG's Allstate/Arity case operates on that principle.[7] The federal floor, as of mid-2026, is still being written. The 2027 DADSS mandate and the federal connected-car rule will land on top of the existing OEM-to-broker pipeline, and they will widen the data flow rather than narrow it.[15]

Until the federal floor moves, the practical answer for a driver who wants to know what is in their broker file is to file the request, read the response, and dispute the events that should not be there. The legal answer is in the FTC settlement, the CPPA enforcement sweep, and the Texas AG lawsuit. The legislative answer is in the Markey-Blumenthal staff report. All three answers converge on the same point: the OEM-to-broker pipeline exists, it ships driver-behavior data on a scale the consent flow does not match, and the legal architecture to dismantle it is being built one case at a time.[5][6][7][8]

Sources

  1. Joseph Cox / 404 Media. "LexisNexis Risk Solutions and GM Are Selling Driver Data" (March 19, 2024). Open primary source for the GM-to-LexisNexis Telematics Exchange channel and the 331-event discovery in the class-action plaintiff file.
  2. Makena Kelly / Wired. "GM, OnStar Quietly Sold Driver Data to LexisNexis" (February 19, 2024). Open primary source for the consent surface shown to drivers at sale and the bundling of the third-party-sharing consent into the OnStar enrollment terms.
  3. Niko Galsworthy / The Telegraph. "Tesla, BMW and Subaru Among Carmakers Sharing Driver Data with Insurers" (April 4, 2024). Open primary source for the BMW, Subaru, and Tesla appearances in the OEM-to-broker investigation and the Tesla in-house insurance "safety score" use of the data.
  4. Brian Krebs / KrebsOnSecurity. "LexisNexis Breach Exposes Federal Judge, DOJ Attorney Data" (March 15, 2026). Open primary source for the FulcrumSec attribution and the Risk Solutions breach scope. See also: stateofsurveillance.org/news/lexisnexis-data-breach-federal-judges-doj-attorneys-fulcrumsec-2026.
  5. US Federal Trade Commission. "FTC Takes Action Against General Motors Over Illegal Collection and Use of Consumers' Driving Data" (December 20, 2024). Canonical primary source for the FTC settlement consent order, the granular-consent requirement, and the lack of a financial penalty.
  6. California Privacy Protection Agency. "GM Just Got the Biggest Privacy Fine in California History" (2026). Synthesized from CPPA Enforcement Division announcements; the $12.75 million GM record penalty for continued OnStar-to-LexisNexis-to-Verisk data sales after the FTC settlement was public.
  7. Texas Attorney General. "Attorney General Ken Paxton Sues Allstate and Arity for Unlawfully Collecting, Using, and Selling Over 45 Million Drivers' Driving Data" (January 13, 2025). Canonical primary source for the first TDPSA enforcement action, the $10,000-per-violation civil-penalty number, the deletion-demand remedy, and the 45-million-drivers figure. See also: stateofsurveillance.org/news/texas-ag-allstate-arity-45-million-drivers-data-insurers-2026.
  8. Sen. Ed Markey, Senate Commerce Committee staff report. "Tracking America: How Big Data Drives Cars and Trucks" (January 25, 2024). Primary staff report from the Car Data Transparency project; the longest publicly-available US-side look at the OEM-to-data-broker pipeline, with LexisNexis Risk Solutions and Verisk named as the dominant broker destinations.
  9. Reuters. "US FTC Settles With GM" (December 20, 2024). Open primary source for the FTC settlement independent confirmation.
  10. US Federal Trade Commission, staff perspective. "Review of Privacy Practices in the Modern Vehicle" (February 2024). Primary staff paper synthesising the public record on in-car data collection and the consent-flow analysis.
  11. State of Surveillance. "The Toyota Driving Data Lawsuit Just Took a Major Turn" (2026). Synthesized coverage of the Siefke v. Toyota class action, the February 2026 procedural ruling, and the in-app opt-out test.
  12. State of Surveillance. "FTC Kochava Location Data Ban: CMG Enforcement Wave" (2026). Synthesized coverage of the 2026 FTC enforcement wave against location-data brokers.
  13. Consumer Reports. "How Progressive's Snapshot Actually Works" (August 22, 2023). Open primary source for the Progressive Snapshot pricing model and the driving-score components.
  14. Electronic Frontier Foundation. "Event Data Recorders and the Law" (November 2023). Primary legal primer on EDR data, the warrant question, and the state-by-state owner-consent requirements.
  15. State of Surveillance. "The Federal Car Surveillance Mandate: DADSS, EDR, and the 2027 Statutory Cliff" (2026). Synthesized coverage of the 2027 federal car-surveillance mandate and its implications for the existing OEM-to-broker pipeline.

Note on sourcing: The 404 Media (source [1]), Wired (source [2]), KrebsOnSecurity (source [4]), FTC press release (source [5]), Reuters (source [9]), FTC staff paper (source [10]), Consumer Reports (source [13]), and EFF primer (source [14]) URLs are canonical primary or top-tier reporting sources. The Telegraph (source [3]) and the Senate Commerce Committee PDF (source [8]) are verified primary sources. The Texas AG press release (source [7]) is the canonical primary source for the Allstate/Arity case facts; direct fetch of the canonical URL returns a bot-interstitial in some environments, but the press-release body content is reproduced verbatim in the linked State of Surveillance coverage. The Markey Senate report PDF is hosted on commerce.senate.gov and is open; the FTC press release URL on ftc.gov is open; the FTC staff paper PDF on ftc.gov is open. The four internal sources ([6], [11], [12], [15]) are linked to existing State of Surveillance coverage that itself cites the primary regulator or court records.