TL;DR: California Attorney General Rob Bonta announced a $12.75 million settlement with General Motors on May 8, the largest penalty ever imposed under the California Consumer Privacy Act. From 2020 to 2024, GM secretly collected geolocation and driving behavior data from hundreds of thousands of California drivers through OnStar, then sold it to data brokers LexisNexis and Verisk Analytics. Those brokers packaged the data into driver-rating products for insurance companies. GM made roughly $20 million from the sales. The penalty is nearly five times the prior CCPA record. GM must stop selling driving data for five years, delete what it kept, and ask LexisNexis and Verisk to delete their copies too.

The Scheme: Four Years of Secret Data Sales

Here's what GM was doing while telling you OnStar was about safety and navigation [1][2].

Between 2020 and 2024, GM collected detailed driving profiles through its OnStar system: precise geolocation, trip routes, speeding frequency, hard braking events, rapid acceleration. The kind of data that paints a minute-by-minute portrait of how and where you drive.

Then they sold it. To two companies: Verisk Analytics and LexisNexis Risk Solutions. Both are consumer reporting agencies, the same industry that generates your credit score.

What did Verisk and LexisNexis do with it? They built driver-rating products and marketed them to auto insurers. The entire pipeline existed to help insurance companies price your risk, using data you never agreed to share [2][3].

GM made approximately $20 million nationwide from these sales [1][3]. The fine ($12.75 million) doesn't even cover what they earned.

GM's Privacy Policy Said They Wouldn't Do This

This is the part that stings. GM's own privacy policies told drivers their data wouldn't be sold. Attorney General Bonta put it bluntly: "General Motors sold the data of California drivers without their knowledge or consent" [1].

The product behind the collection was OnStar Smart Driver, pitched to consumers as a tool to "improve your driving habits." What the marketing left out: it was a pipeline feeding your driving data to insurance industry data brokers [2].

GM killed the Smart Driver product in April 2024, but only after The New York Times exposed the data-selling scheme. By then, four years of driver profiles had already been harvested and sold [3][4].

Largest CCPA Penalty Ever, By a Wide Margin

The $12.75 million penalty is nearly five times the prior CCPA record, a $2.75 million settlement with Disney earlier in 2026 [3][5].

It's also the eighth CCPA enforcement action overall and the first data minimization case, meaning California is now enforcing the rule that companies can't just hoard data and find new ways to monetize it later [1].

That matters. Data minimization is the principle that companies should only collect and retain data for the purpose they told you about. GM collected driving data for OnStar services, then sold it for an entirely different purpose. California just said that's not allowed [1][2].

AG Bonta framed it: "Companies can't just hold on to data and use it later for another purpose" [1].

GM Isn't Alone. It's an Industry Pattern

This is the third California enforcement action against an automaker in 14 months [3][5]:

  • Honda: $632,500 CPPA settlement (March 2025) for making consumers hand over excessive personal data just to exercise their privacy rights [6].
  • Ford: $375,703 CPPA fine (March 2026) for requiring email verification before consumers could opt out of data sales, adding deliberate friction to a process that's supposed to be easy [7].
  • GM: $12.75 million (May 2026) for the data sales scheme.

Three automakers, three different privacy violations, one common theme: the connected car is a surveillance device that happens to have wheels.

GM also settled with the Federal Trade Commission earlier in 2026 over the same data practices, resulting in a separate ban on data sales and a 20-year consent requirement for future data collection [4].

What the Settlement Requires

The injunctive terms go beyond just writing a check [1][2]:

  • Five-year ban on selling driving data to any consumer reporting agencies, including LexisNexis and Verisk.
  • Delete all retained driving data within 180 days, unless individual consumers give explicit consent for limited internal uses.
  • Request deletion from Verisk and LexisNexis: GM must ask the brokers to destroy their copies of the data.
  • Privacy program overhaul: develop and maintain a compliance program that assesses, mitigates, and documents risks of OnStar data collection.
  • Report to enforcement agencies: submit regular privacy assessments to the California AG and district attorneys.

Enforcement came from a coalition: the California Attorney General's office, the California Privacy Protection Agency, and district attorneys from San Francisco, Los Angeles, Napa, and Sonoma counties [1].

The Insurance Connection

One detail stands out: California state law actually prohibits insurers from using this type of data to set rates. So in California specifically, the driving data GM sold may not have directly increased anyone's premiums [2].

But that's California. In the other 49 states where GM sold the same data to the same brokers? No such protection exists. Verisk and LexisNexis marketed these driver-rating products to insurers nationwide. If you drove a GM vehicle with OnStar between 2020 and 2024 outside California, your driving profile may have already been used to set your insurance rates, and you'd never know [3][4].

What You Should Do

  • Check your LexisNexis file. You can request a free copy of your consumer disclosure report at consumer.risk.lexisnexis.com. If GM shared your driving data, it may appear here.
  • Request your Verisk report. Verisk's consumer disclosure is available through their Auto Plus product. Ask for a copy and see what driving data they have on you.
  • Opt out of OnStar data sharing. If you still drive a GM vehicle, go into OnStar settings and disable all optional data sharing. Do it today.
  • Check your insurance history. If your premiums went up between 2020 and 2024 without an accident or ticket, driving data may have been a factor (outside California).
  • Exercise your CCPA rights. California residents can submit a data deletion request directly to GM at their privacy portal. Make them prove they've actually deleted your data.

The Bigger Picture

GM made $20 million selling driver data. The penalty is $12.75 million. Quick math: that's still a profit, even after getting caught. The FTC settlement adds to the cost, but GM is a $170 billion company. These fines are parking tickets.

What actually matters is the precedent. California just established that the CCPA's data minimization provisions have teeth. Companies can't collect data for one purpose and sell it for another. That's a rule every company handling personal data in California now has to take seriously.

And the auto industry is on notice. Three settlements in 14 months. Honda, Ford, and GM. If your car connects to the internet, the company that made it is probably collecting more data than you realize, and the question isn't whether they'll try to monetize it, but whether they'll get caught.

Sources

  1. California Attorney General: $12.75 Million General Motors Privacy Settlement Press Release (May 8, 2026)
  2. TechCrunch: GM Agrees to Pay $12.75M in California Driver Privacy Settlement (May 9, 2026)
  3. CalMatters: GM Just Paid a Record Penalty for Breaking California Privacy Law (May 2026)
  4. The Record: GM to Pay Over $12 Million in California Privacy Settlement (May 2026)
  5. ComplianceHub: California's CPPA Is Fining Real Companies Now: Lessons from Disney, Ford, Honda, and Tractor Supply (2026)
  6. CPPA: Honda Settles Over Privacy Violations (March 2025)
  7. CalPrivacy: Ford to Change Practices, Pay Fine for Opt-Out Friction (March 2026)