privacydeep-dive

Your Car Collects More Data Than Your Phone

Modern connected cars track location, driving habits, voice commands, and more — then sell it to data brokers. What's collected and how to limit it.

The average smartphone feels like an obvious privacy device — you know it has GPS, a camera, and a microphone, and you’ve probably thought at least once about what apps have access to those sensors. The average new car, built with a permanent internet connection, collects significantly more personal data than your phone, from significantly more sensors, and does so more continuously — but almost no one gives it the same scrutiny.

That’s changing. In January 2025, the Federal Trade Commission settled with General Motors and its OnStar subsidiary for collecting and sharing location and driving data without proper consumer consent. In March 2026, the California Privacy Protection Agency fined Ford for making its data opt-out process “needlessly difficult to use.” And a 2024 assessment by Mozilla’s Privacy Not Included project reviewed the privacy practices of 25 major automobile brands and found that all 25 collected more personal data than necessary, with 84% sharing or selling data to third parties.


What Your Car Actually Tracks

Modern connected vehicles are, in effect, sensor platforms generating a continuous stream of behavioral data. Here is what a typical connected car with standard telematics collects:

Location and movement

  • GPS coordinates, updated continuously while the vehicle is on
  • Complete route history — where you drove, when, and how often
  • Frequent locations inferred from patterns: home, workplace, places of worship, medical facilities

Driving behavior

  • Speed and acceleration patterns
  • Hard braking events
  • Seatbelt usage
  • Hours of operation and mileage

In-cabin data

  • Voice commands sent to the vehicle’s assistant
  • Contacts synced from paired phones via Bluetooth or USB
  • Call logs from paired devices
  • Music, podcast, and streaming listening history
  • Seat occupancy sensors that can infer the number of passengers

Connectivity and device data

  • Wi-Fi networks the vehicle has connected to
  • Mobile devices paired to the car’s Bluetooth
  • Cellular network identifiers

Not every vehicle collects all of this — the extent depends on the manufacturer, the model, and which connected services are active. But the list above reflects what’s technically possible and commercially practiced across the industry today.


Where That Data Goes

The FTC’s case against GM and OnStar revealed a specific commercial practice: GM sold customer location and driving-behavior data to LexisNexis Risk Solutions and Verisk, two data brokers that aggregate consumer information for use by insurance companies. Customers whose data was shared reported receiving higher auto insurance quotes — sometimes substantially higher — without being told why or having any meaningful opportunity to consent to the data sharing.

This is the most immediately tangible consequence of vehicle data collection: it can directly affect your insurance premiums, and until the FTC action, most affected customers had no idea it was happening.

The insurance channel is the most direct harm, but it’s not the only destination. Vehicle data collected by manufacturers is sold into a data broker ecosystem that repackages it for a wide range of secondary uses. Your car’s regular location data combined with your home address makes it possible to infer where you worship, which medical facilities you visit, which political events you attend, and what hours you work. States including Maryland and Oregon passed laws in 2025-2026 restricting the sale of precise geolocation data specifically because of how revealing this inference can become when combined with other consumer data sets.


The fundamental issue with connected vehicle data collection isn’t that it happens — it’s that most consumers don’t know the extent of it when they agree to it.

Vehicle privacy policies are long, dense, and presented in a documentation stack at purchase or on a screen during setup. The OnStar terms at issue in the FTC case ran to thousands of words and buried the data-sharing provisions in language that would not have alerted a typical buyer to what was being agreed to.

The California fine against Ford addressed a different but related problem: not that Ford was collecting data it had no right to collect, but that it had made the opt-out process “needlessly difficult to use.” This reflects an emerging regulatory principle — that meaningful consent requires the opt-out to be as accessible as the opt-in — and signals that regulators are now examining automotive data practices with sustained attention.

There’s also an inherent bundling problem. Some data collection is genuinely necessary for safety features. Automatic emergency braking requires real-time sensor processing. OnStar’s emergency response service requires location data. Most people want these features — and they’re typically bundled in the same data stream as commercial telemetry that most people don’t realize they’ve separately agreed to.


2026 Regulatory Developments

Several significant legal developments are reshaping what automakers can do with vehicle data.

State geolocation restrictions. Maryland and Oregon passed laws restricting the sale of precise geolocation data, with Maryland’s law specifically naming connected vehicles as a category of concern. These laws don’t prohibit collection but restrict the secondary sale that turns manufacturer data into broker data and ultimately into insurance-underwriting input.

A “fair and reasonable” processing standard. Regulatory reforms in some jurisdictions have introduced a requirement that data processing be objectively fair and reasonable in context — not just consented to. Under this standard, collecting GPS data to provide roadside assistance is clearly reasonable. Continuously tracking a vehicle’s proximity to medical clinics and making that data available to data brokers is likely to fail the test, regardless of whether a consent checkbox was ticked during setup.

Automotive data as a dedicated regulatory target. The FTC, the California Privacy Protection Agency, and several Congressional hearings in 2025-2026 have specifically identified connected vehicle data as a priority enforcement area. The GM and Ford actions are likely precursors to continued enforcement, not isolated incidents.


What You Can Actually Do

Limiting connected vehicle data collection is harder than adjusting a smartphone setting, but there are concrete steps that reduce your exposure.

Review your connected services subscriptions. Most data-sharing occurs through optional connected services — telematics, remote start apps, navigation, in-car Wi-Fi. Each has a separate terms-of-service governing data use. Disable services you don’t actively need, and check whether disabling the app also stops the data collection or only removes your access.

Submit a data deletion request. Under CCPA (if you’re in California) or applicable state law, you may be able to request a copy of what your manufacturer has collected and ask for it to be deleted. GM, Ford, and Toyota all have formal processes for this. The FTC settlement against GM requires OnStar to honor deletion requests going forward.

Check whether your insurer receives vehicle data directly. Some insurers receive telematics data directly from manufacturers — as in the OnStar case — rather than through a separate telematics program you deliberately enrolled in. Ask your insurer whether they receive data from your vehicle manufacturer, and if so, on what basis. This matters both for your insurance pricing and for understanding what data flows are already in motion.

Read the consent screens during setup. If you’re setting up a new vehicle or a major firmware update triggers a consent flow, read it carefully. Look specifically for language about “connected services,” “data sharing,” “third-party partners,” and anything that bundles optional commercial telemetry with mandatory safety features.

Limit phone pairing where possible. When you pair your phone via Bluetooth, many vehicles automatically sync contacts and call logs. Review what’s synced in your vehicle’s Bluetooth settings. Android Auto and Apple CarPlay give manufacturers more defined, narrower data access than native Bluetooth pairing — they’re worth using as the default for calls and navigation.

For EVs: understand charging data. Electric vehicle charging generates an additional data stream: where you charge, how often, when, and how much energy was used. This data is particularly sensitive because charging patterns reveal daily movement patterns with high precision and can indicate home address with near certainty.


The connected car data landscape reflects a broader pattern: consent mechanisms designed around the assumption that few people will actually read and engage with what they’re agreeing to.

A privacy policy that runs to thirty pages and is presented at a high-stress moment — during vehicle purchase, after a firmware update, in a setup wizard — is technically adequate for legal purposes in most jurisdictions. It’s functionally unintelligible to most people in the moment they’d need to act on it.

The FTC’s enforcement actions and the California fine signal that “technically adequate” is no longer the ceiling regulators are willing to accept. The standard is shifting toward consent that’s actually meaningful — clear enough that a typical consumer would understand what they’re agreeing to without a law degree and a careful reading.

That shift will take time to change industry practices. Until it does, the practical response is to treat your vehicle’s privacy settings with the same attention you’d give your phone: check what’s enabled, disable what you don’t need, and revisit after software updates.


A Different Kind of Data Trail

The data your phone collects about you is largely data you generate through deliberate actions — searches, apps you open, messages you send. The data your car generates is more passive: it reflects where you go, not what you’re looking for. In some ways that’s less intimate. In other ways it’s more revealing — because location patterns over time expose the structure of a person’s life in ways that can’t be managed or curated the way a social media feed can.

How you protect that data is different from how you protect a photo archive or a document store. But the underlying principle is the same: data generated about you shouldn’t flow to third parties without your actual awareness and meaningful consent. The fact that it happens automatically, silently, and from a device you’re not accustomed to thinking of as a data collection platform makes it more worth thinking about, not less.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts