How connected vehicles turned driving into commercially valuable data, and why consumers often lost sight of where that data went.
I. The 258-Page Report
In 2022, Kenn Dahl opened his auto insurance bill and found his premium had jumped twenty one percent. He owned a software company near Seattle. He had no recent tickets. He had caused no accidents. He drove a leased Chevrolet Bolt EV for years.
He called other insurers for quotes. Every quote came back high.
An agent finally told him to pull his file from LexisNexis Risk Solutions, a data analytics firm that supplies risk scores to insurers nationwide. The report ran 258 pages. More than 130 of them detailed six months of driving, logging 640 separate trips. Start times. Stop times. Distance traveled. Every rapid acceleration. Every hard brake.
Dahl had never installed a tracking device. He had never downloaded a driving app from his insurer. The New York Times reported in March 2024 how the leak traced back to his own car. The sensors in his Bolt had recorded his driving. General Motors had passed that data, through its OnStar system, to LexisNexis.
The story exposed a shift that had been building for over a decade. Cars stopped being purely mechanical objects. They became networked computers on wheels. Along the way, ordinary driving became a commercial product, moving through automakers, data brokers, and insurance underwriters while most drivers never saw it happen.
II. Five Layers of Vehicle Telemetry
People talk about car data as one thing. It is not. Five separate stages sit between a car’s sensors and the outside world.
Sensor capability. What the hardware can physically measure. Wheel speed. Lateral acceleration. Steering angle. Throttle position. Seatbelt status.
Onboard collection. What the vehicle’s computer actually logs, even briefly. An anti lock braking system reads wheel speed constantly. Most of those readings never get written to permanent storage.
Data retention. What the automaker keeps. Diagnostic codes. Odometer readings. Charging cycles. Stored on the car’s flash memory or pulled into engineering databases.
Wireless transmission. What gets sent back to company servers. Sometimes it is a maintenance alert once a month. Sometimes it is a continuous trip log.
Third party commercial sharing. What the automaker licenses or sells outside the company. To analytics firms. To consumer reporting agencies. To business partners.
This distinction matters. Every modern car can sense a great deal. Not every modern car is broadcasting driver behavior to an insurance company. That depends on which programs a driver enrolled in, which subscriptions were active, and which contracts the automaker signed behind the scenes.
Location sits at the center of the risk. A car’s GPS and cellular modem can log where a person goes, how long they stay, and how often they return. Months of that data build a portrait. Clinics visited. Places of worship attended. Homes entered and left.
That portrait moves through a legal gap most drivers never think about. Law enforcement generally needs a warrant to compel this kind of tracking directly, under Fourth Amendment protections the Supreme Court extended to location data in Carpenter v. United States (2018). A commercial data broker generally does not. No court order, no probable cause, no judge in the loop. Most of it requires only a connected car and a contract most drivers never read.
III. The Economics of the Digital Dashboard
The pressure behind this system is financial, on both sides.
Automakers building electric and software defined vehicles face enormous capital costs. A car sale is a single transaction with often thin margins. Software is different. Subscriptions renew. Remote features renew. Licensed data renews. GM itself has told investors it expects software and related services, including OnStar, to generate up to $25 billion a year by 2030. Deferred software revenue already reached $5.4 billion in 2025, up 65 percent from the year before. For a manufacturer staring down billions in engineering costs, recurring revenue looked like relief.
Insurers had their own problem. Traditional underwriting leans on blunt proxies. Age. Gender. Credit history. Zip code. Past claims. These proxies miss the mark constantly. A careful twenty five year old pays more because of the average behavior of other twenty five year olds. A reckless driver with a clean recent record pays less because nothing has caught up with him yet.
Real time telemetry offered something sharper. Hard braking. Rapid acceleration. Driving between midnight and four in the morning. Cambridge Mobile Telematics, which supplies driving-behavior data to insurers, has estimated that targeting those specific behaviors can cut crash claim frequency by roughly 4 percent and claim dollars by roughly 7 percent. Insurers bet that signals like these would predict crashes better than any demographic category could.
Between the automaker and the insurer sat the intermediaries. LexisNexis built its Telematics Exchange. Verisk built its Data Exchange. Both took raw feeds from different manufacturers, standardized them across different sensor systems, and delivered finished risk scores straight into an insurer’s rating software.
IV. The General Motors and OnStar Reckoning
The clearest documented example of that pipeline is the case against General Motors.
In 2019, LexisNexis announced that GM had chosen its Telematics Exchange to manage connected car data. The goal was to normalize driving data across GM’s brands and feed it into insurance rating programs, with driver approval assumed.
After the 2024 reporting, regulators asked a harder question. Had drivers actually approved anything.
Two separate investigations answered that question, and both answered no.
The Federal Trade Commission filed its complaint in January 2025. It finalized the order in January 2026, on a 2 to 0 vote. The FTC alleged that GM and OnStar had collected precise geolocation data and detailed driving behavior, in some cases as often as every three seconds, and sold it to consumer reporting agencies without adequate disclosure. The final order bars GM from sharing that data with reporting agencies for five years. It runs under a twenty year compliance framework. Affirmative consent is now required. Consumers get access to their data. Consumers get deletion rights. GM must destroy previously collected data within 180 days.
California moved separately. On May 8, 2026, the state’s Attorney General announced a $12.75 million settlement, the largest civil penalty in the history of the California Consumer Privacy Act. Investigators found that between 2020 and 2024, GM sold names, contact information, geolocation data, and driving metrics belonging to hundreds of thousands of Californians to LexisNexis and Verisk. Investigators estimated GM earned roughly $20 million nationwide from those sales. The settlement bars further sales to reporting agencies for five years and orders deletion of retained data.
One detail from the California case stands out. Investigators found that California drivers were largely shielded from the financial fallout. Under Proposition 103, state law restricts the factors insurers can use to set auto rates to safety record, annual mileage, and driving experience. Unapproved telematics scores could not legally move the needle on a Californian’s premium, even while the data was being sold.
GM had already ended its Smart Driver program in 2024, cut ties with LexisNexis and Verisk, and expanded privacy controls across its apps, citing customer feedback.
V. The Consent Gap in Practice
Automakers point to consent as their legal shield. The record shows how thin that shield was.
The FTC’s complaint documented consumers who had no idea their driving was being logged and sold. Smart Driver enrollment happened at the dealership, often during delivery, on a screen that promised drivers a chance to “become a smarter, safer driver” through fuel efficiency scores and digital badges.
Nowhere on that screen did it say the same data would be packaged and sold to companies that set insurance premiums. That detail lived inside lengthy terms of service and linked privacy notices. The FTC alleged that GM gave consumers false assurance their data would be used only for their own benefit, while sharing radio station preferences, speeds over eighty miles per hour, and seatbelt use with third parties who used it to deny coverage, raise premiums, and build advertising profiles.
Consent for unrelated features got bundled together. A driver agreeing to unlock a remote start function had no reasonable way to separate that from an agreement to sell their braking history. That’s the practical test worth applying: when informed consent requires a law degree to locate inside a phone app, it has stopped functioning as consent.
VI. What Connected Vehicles Do Well
None of this makes vehicle connectivity a mistake. It began largely as a safety and diagnostics tool, and it still works as one.
Automatic crash notification, through OnStar in North America and eCall in Europe, uses impact sensors and GPS to summon first responders within seconds of a severe collision. The European Commission has estimated that widespread eCall deployment cuts road fatalities by roughly 4 percent and the severity of injuries by roughly 6 percent, mainly by shaving minutes off response time when a driver can’t call for help.
Predictive maintenance catches battery degradation, brake pressure loss, and powertrain wear before they cause a breakdown at highway speed. Dedicated stolen-vehicle tracking systems can meaningfully outperform that baseline: LoJack, the longest-running provider, claims a recovery rate above 90 percent for equipped vehicles, against a national recovery rate the FBI and National Insurance Crime Bureau put at roughly 45 to 56 percent depending on the year. Independent, vendor-neutral data on tracking-system effectiveness is harder to come by than the industry’s own marketing suggests. Fleet management systems help delivery companies route trucks efficiently and catch driver fatigue before it causes a crash.
The goal is not to unplug the car. The goal is to keep the safety wiring intact while cutting the commercial wiring that grew alongside it without anyone’s knowledge.
VII. Three Different Fights Over the Same Data
Governments are not converging on one answer. Three different strategies have emerged, and they reveal three different sets of priorities.
The United States relies on enforcement after the fact. The FTC uses Section 5 of the FTC Act to punish deceptive practices once the harm has already occurred. States fill in the gaps. California leads, with statutory privacy rights and insurance rating limits, and other states are starting to follow. Oregon amended its privacy law in 2025 specifically to cover motor vehicle manufacturers, removing the usual minimum-processing threshold that lets smaller companies skip compliance, so that automotive data gets no exemption regardless of a company’s size.
The European Union took a structural approach. The EU Data Act, applicable since September 2025, does not wait for a scandal. It grants users of connected products, not only owners but anyone with a right to use the vehicle, a direct right to access the data it generates and to share it with independent repair shops, parts suppliers, and outside service providers on fair terms. The law strips automakers of their position as the sole gatekeeper of the data their cars generate.
China treats the data as a matter of state security. Its rules on automotive data, layered under the Data Security Law and the Personal Information Protection Law, require in cabin processing by default. Sensitive categories like geographic coordinates, traffic patterns, and exterior camera footage must stay inside the country. Moving that data across a border requires a formal government security review.
Tesla shows what that looks like in practice. The company built a data center in Shanghai in 2021 to store Chinese vehicle data inside the country, and in 2024 the China Association of Automobile Manufacturers confirmed Tesla had met the country’s data-security requirements, including in-vehicle processing of cabin data and anonymizing footage of faces outside the car. Tesla began offering a supervised version of Full Self Driving in China in May 2026, years after the same software was running in the United States. Full nationwide clearance was still pending as this was written, with Tesla’s own leadership targeting the third quarter of 2026, a deadline that had already slipped once. Diplomatic timing, local mapping partnerships, and China’s broader review process for autonomous driving all played a part in that delay. But clearing the country’s data localization rules was one of the conditions Tesla had to meet before any of the rest mattered.
Three governments. Three theories of what the data is and who should control it.
VIII. What Drivers Can Actually Check
Drivers are not powerless here. Four principles cover most of what matters.
- Know what’s already been reported. Request a consumer disclosure report directly from LexisNexis under the Fair Credit Reporting Act. If a car’s program shared telemetry with the company, the trip logs show up in that file. Verisk offers the same request process for its own records. Expect a wait. LexisNexis is required to fulfill the request within fifteen days once your identity is verified, and in practice it can take closer to a month.
- Control the app, not just the car. Open the automaker’s companion app, such as FordPass, MySubaru, or MyHyundai. Look for modules labeled Driver Feedback, Trip Tracking, or Connected Services, and turn off anything that shares data with outside partners. In GM’s apps, such as myChevrolet or myGMC, this sits under the account icon in the top corner, then Settings, then the connected-services toggles.
- Check the vehicle’s own settings. Most modern vehicles bury a Privacy or Data Management menu inside System Settings on the infotainment screen. Some let a driver disable location tracking entirely. Others tie that option to features like emergency crash notification, so read carefully before switching anything off.
- Clear local storage before handing off the car. Before selling or returning a leased vehicle, run a factory reset. It clears paired contacts, call logs, saved destinations, and garage door codes from local storage. It will not touch anything the automaker holds in the cloud. That requires a separate request through the account portal.
IX. The Machine in the Driveway
A car feels private. Glass, steel, four doors that close. A person gets in and assumes the cabin is theirs alone.
That assumption was never guaranteed, only untested. The processors under the dashboard can measure a driver’s every turn, every stop, every address where the car sits overnight. Whether any of that gets collected, stored, or sold still depends on which programs a driver enrolled in and which contracts an automaker signed. But the capability sits in nearly every new car sold today, waiting on a subscription renewal or a software update to switch it on.
The GM enforcement actions show something specific. Turning driving behavior into a hidden product now carries real legal exposure. Whether that risk is enough to outweigh the financial incentive is still an open question. The next paragraph is the honest answer.
The financial incentive to monetize that data has not gone away. More sensors, more driver assistance systems, and more cloud connectivity are all coming.
The question left standing is simple. Can a driver keep the freedom of the car without becoming a party to a transaction they never agreed to make?
