---
title: "Cars and Their Apps Send Driver Data to Ad Firms, and Few Rules Stop It"
description: "Seven of 30 automaker apps sent VINs, emails or locations to ad and analytics firms, two years after G.M.’s data sales drew federal and state action"
author: "rews special report"
published: 2026-10-02T04:31:58.427Z
modified: 2026-10-02T10:28:12Z
url: https://rews.cc/a/connected-cars-send-driver-data-to-advertisers-and-trackers--af0be8
language: en
type: special report
tags: ["privacy", "data", "security", "automotive", "surveillance", "tech"]
publisher: "Rews (https://rews.cc)"
---

# Cars and Their Apps Send Driver Data to Ad Firms, and Few Rules Stop It

*Seven of 30 automaker apps sent VINs, emails or locations to ad and analytics firms, two years after G.M.’s data sales drew federal and state action*

Special report · By rews special report · October 2, 2026 · https://rews.cc/a/connected-cars-send-driver-data-to-advertisers-and-trackers--af0be8

## In brief

- Northeastern and Consumer Reports found 19 of 21 cars contacted third parties and seven of 30 apps sent VINs, emails or locations to trackers
- Honda alone changed course after disclosure, telling Amplitude to delete location data, while other automakers cited their contracts
- GM is under a 2026 FTC order and a $12.75 million California settlement over driving data it sold to brokers serving insurers
- No federal law specifically governs vehicle location data, and Utah’s automaker privacy rules take effect Jan. 1, 2027
- Drivers can file opt-out and deletion requests and request broker reports, but cutting connectivity can cost features

Nineteen of 21 late-model vehicles tested at Consumer Reports’ auto test center in Connecticut sent data to at least one outside company, and seven of 30 automaker phone apps passed drivers’ vehicle identification numbers, email addresses or precise locations to advertising and analytics firms, according to a [Northeastern University study](https://automatictransmission.khoury.northeastern.edu/index.html) [released Sept. 29](https://rews.cc/a/study-finds-connected-cars-send-data-to-advertisers-and-big--781661).

The four General Motors apps, myCadillac, myChevrolet, myBuick and myGMC, sent VINs to companies including Adobe, Google, Meta, Microsoft, Pinterest, Snap, Yahoo and the data broker Acxiom, according to [an account of the paper by Help Net Security](https://www.helpnetsecurity.com/2026/10/01/connected-car-apps-privacy-research/). HondaLink sent the VIN and precise location to Amplitude, an analytics company. MyNissan sent the VIN and an email address to a company called Alchemer. Ford’s Lincoln app sent the VIN to ContentSquare.

Those are not the flows that got G.M. in trouble. In March 2024, The New York Times reported that G.M. was passing customers’ driving behavior to data brokers who scored it for insurers. Since then the company has drawn a federal consent order, a $12.75 million California penalty and lawsuits from Texas, Nebraska and Arkansas, all of them about sales to consumer reporting agencies. The study traced something different. It found identifiers that tie one car to one owner moving through analytics code in the apps, under contracts that the automakers say forbid any other use.

For a driver who wants it to stop, every option on the record has a cost. Privacy requests go to the automaker, not to the vendors downstream. Switching off connected services can mean losing remote start and the app, and in some cars automatic crash notification. Tesla warns owners that refusing its data terms could leave a car inoperable. No federal law specifically governs vehicle location data, the Congressional Research Service has found.

## What the cars sent

A team of nine Northeastern researchers ran the tests between October 2024 and August 2025 on cars from model years 2022 to 2025, most of them electric, [Consumer Reports said](https://www.consumerreports.org/electronics/personal-information/your-car-is-sharing-data-with-big-tech-companies-study-finds-a4474820962/). They put a Raspberry Pi between each car’s Wi-Fi and the internet to log where every packet went. They drove the cars at 5 to 45 miles per hour, braking hard. They also drove 11 electric vehicles into a car-sized Faraday tent to cut off their cellular link. The authors estimated that buying such a fleet themselves would have cost more than $1.2 million.

The cars’ traffic was encrypted, so the study can say where it went but not what it held. Tesla’s Model 3 reached 34 advertising, tracking or analytics domains and the Cybertruck 23, followed by the Cadillac Lyriq at 10 and the Lucid Air at nine. Ten vehicles, among them the Buick Envista, the Mercedes EQS and the Range Rover, reached none over Wi-Fi. Inside the tent, seven of the 11 cars contacted new destinations once cellular was blocked. The Model 3 alone added 27.

The apps were another matter. The team ran them on test iPhones whose traffic it could decrypt, and 28 of the 30 sent data to at least one outside advertising or analytics company. “For most vehicles in our dataset, the companion app at least doubles cumulative ATA exposure,” the authors wrote, using their shorthand for advertising, tracking and analytics. On its own, the Envista contacted none of those companies. Once its app was counted, it reached 20 or more.

David Choffnes is an associate professor, executive director of Northeastern’s Cybersecurity and Privacy Institute and one of the [paper’s](https://automatictransmission.khoury.northeastern.edu/paper.html) nine authors. He said the project began after the 2024 reports about G.M. He described the companies receiving the data to [Northeastern Global News](https://news.northeastern.edu/2026/09/29/connected-car-privacy-violation-research/), the university’s news service.

> We have these companies that have nothing to do with car functionality that are getting information about you
>
> — David Choffnes, associate professor at Northeastern University and an author of the study, [news.northeastern.edu](https://news.northeastern.edu/2026/09/29/connected-car-privacy-violation-research/)

## Who gets the data

The researchers worried most about the VIN. An advertising ID on a phone can be reset, but a VIN can’t, and the paper says pairing it with other personal data allows “cross-context tracking of users.” Consumer Reports wrote that the pairing lets companies match driving behavior to profiles that brokers and marketers compile and sell, including to insurers and banks.

What the recipients do with it is not in the data. “We don’t actually know what the companies are doing with that data, and that should become more apparent,” Dr. Choffnes said. Every automaker’s privacy policy says data may go to third parties, the university’s news service reported, but none says which ones or why.

The team sent its findings to 17 of the 18 manufacturers in the sample. Fisker, the 18th, had shut down. Fourteen answered, and all of them said the data flows matched their contracts. Five pointed to browsers inside the apps that load outside webpages, where other companies can set pixels and cookies. Three of those said the pages ask for cookie consent, but the researchers’ screen recordings showed that didn’t always happen. Seven said it was up to consumers to accept the terms of third-party software, including software installed at the factory. “The ongoing theme of all these responses was shifting the blame to the consumer,” the authors wrote.

G.M., Honda, Nissan and Stellantis said some recipients were contractually barred from using or selling the data on their own, [The Record reported](https://therecord.media/automakers-routinely-share-connected-car-data-third-parties). A G.M. spokesperson told Northeastern Global News that its providers may not “sell, share or use” the data for their “own purposes.” Honda went further than the rest. After the disclosure, it told Amplitude to delete the location data it had received and stopped sending geolocation from HondaLink. Andrew Quillin, a Honda spokesman, confirmed the findings and said the data was “never available for independent use or sale, as such use was prohibited by contractual agreement.” He said the app is optional.

Honda has faced regulators over data sharing before. In March 2025 the California Privacy Protection Agency [fined it $632,500](https://www.hunton.com/privacy-and-cybersecurity-law-blog/cppa-fines-honda-632-500-for-ccpa-violations). Among other things, the agency alleged that Honda had shared personal information with advertising technology companies without the contracts state law requires. The case grew out of [a review of connected-car makers](https://cppa.ca.gov/announcements/2023/20230731.html) that the agency opened in July 2023. A second case from that review, announced in March, [fined Ford $375,703](https://privacy.ca.gov/2026/03/ford-to-change-practices-pay-fine-for-adding-unnecessary-friction-to-opt-out-process/). Ford had made consumers confirm their email addresses before it would process requests to stop selling their data.

On Hacker News, a commenter who described owning Hondas built before the cars went online quoted the study site’s entry for HondaLink and wasn’t satisfied.

> I already like Honda and own models before they were connected to the cell network. But they are still not 100% there for current models
>
> — rdtsc on [Hacker News](https://news.ycombinator.com/item?id=49927058)

The site’s entry lists Amplitude receiving both the VIN and the location. As the researchers and Consumer Reports described it, Honda’s fix covered location. It was not clear whether HondaLink still sends the VIN to Amplitude.

## What G.M. sold

The enforcement that followed started with one man’s insurance bill. Kenn Dahl owns a software company near Seattle and drove a leased Chevrolet Bolt. His car insurance rose 21 percent in 2022. Kashmir Hill reported in The New York Times in March 2024 that when he asked LexisNexis for his file, he got a 258-page report. It logged 640 trips with their start and end times, distances and every instance of speeding, hard braking and sharp acceleration. The report said G.M. had supplied the trip data.

G.M. said on March 22, 2024, that it would stop sharing driving data with brokers. Verisk, the other broker that bought it, stopped receiving G.M. data on March 18, 2024, and Honda and Hyundai data on April 9. It then [shut down the driving-behavior product](https://therecord.media/data-broker-shuts-product-driver-patterns) it had sold to insurers.

That July, Senators Ron Wyden of Oregon and Edward J. Markey of Massachusetts, both Democrats, put prices on the trade. [Their letter to the F.T.C.](https://www.wyden.senate.gov/imo/media/doc/wyden-markey_auto_privacy_letter_to_ftc.pdf) said Verisk paid Honda $25,920 for data from 97,000 cars, or 26 cents a car, and paid Hyundai $1,043,315.69 for data from 1.7 million vehicles, or 61 cents each. Hyundai had automatically enrolled drivers who turned on their cars’ internet connection in its Driving Score program. G.M. told the senators’ staff that it shared location data on every driver who activated that connection, Smart Driver or not, [The Record reported](https://therecord.media/markey-wyden-ask-ftc-to-probe-car-company-data-practices).

G.M. would not tell the senators how much it had been paid. Months earlier, Ms. Hill had posted that a source put the figure in the low millions of dollars a year. California later put G.M.’s nationwide earnings from the two brokers at about $20 million.

> One more thing on this. Source told me GM makes low millions on this program per year. In a Dec. letter to @EdMarkey, GM called that “de minimis” to its overall 2022 revenue.
>
> Wild the company would do all this for what it considers chump change.
>
> letter:
>
> — **Kashmir Hill** @kashhill on X · [March 12, 2024](https://x.com/kashhill/status/1767561959136805019)

Mozilla had raised the alarm in September 2023. Its *Privacy Not Included* guide reviewed 25 car brands and failed every one of them, a first in the guide’s seven years. It found that Nissan’s privacy policy listed “sexual activity” among the kinds of data the company could collect. Jen Caltrider, who ran the guide for Mozilla, summed up the findings in [the foundation’s announcement](https://www.mozillafoundation.org/en/blog/privacy-nightmare-on-wheels-every-car-brand-reviewed-by-mozilla-including-ford-volkswagen-and-toyota-flunks-privacy-test/).

> All new cars today are privacy nightmares on wheels that collect huge amounts of personal information.
>
> — Jen Caltrider, who led Mozilla’s Privacy Not Included guide, [mozillafoundation.org](https://www.mozillafoundation.org/en/blog/privacy-nightmare-on-wheels-every-car-brand-reviewed-by-mozilla-including-ford-volkswagen-and-toyota-flunks-privacy-test/)

On Hacker News, a reader who described working at a company that uses this data to monitor its own vehicles wrote about how often the cars report in.

> Many brand collect your GPS position every 10 to 30 seconds, they know where you shop, how fast you drive, how often you go out for a drink or to the gym.
>
> — stymaar on [Hacker News](https://news.ycombinator.com/item?id=49931439)

That account could not be independently verified, and the public record points to even closer tracking. The F.T.C. alleged that Smart Driver collected precise geolocation and driving behavior every three seconds, according to [the commission’s analysis of its proposed order](https://www.federalregister.gov/documents/2025/01/30/2025-01940/general-motors-and-onstar-llc-analysis-of-proposed-consent-order-to-aid-public-comment). Phones collect it too. In January 2025, Texas [sued Allstate and its Arity unit](https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-sues-allstate-and-arity-unlawfully-collecting-using-and-selling-over-45). The state alleges that Arity paid app makers to embed its tracking code, which gathered driving data on more than 45 million Americans as often as every 15 seconds. Allstate has denied the allegations. On March 3, a federal judge in Chicago let wiretap and credit-reporting claims proceed in a related class action, [The National Law Review reported](https://natlawreview.com/article/massive-win-plaintiffs-federal-court-keeps-wiretap-and-fcra-claims-alive).

## What the penalties covered

The F.T.C. announced its complaint against G.M. and OnStar in January 2025. It alleged that G.M. had used a misleading enrollment process to sign people up for OnStar and Smart Driver. Lina Khan, then the commission’s chair, posted about the case.

> Today @FTC announced an action against General Motors for collecting and selling drivers’ precise geolocation data and driving behavior information from millions of vehicles—data that can be used to set insurance rates—without obtaining consent.
>
> — **Lina Khan** @linamkhan on X · [January 16, 2025](https://x.com/linamkhan/status/1880021876501803209)

The commission approved the [final order](https://www.ftc.gov/news-events/news/press-releases/2026/01/ftc-finalizes-order-settling-allegations-gm-onstar-collected-sold-geolocation-data-without-consumers) 2-0 on Jan. 14. It bars G.M. for five years from disclosing geolocation and driver-behavior data to consumer reporting agencies. For 20 years, G.M. must get affirmative express consent before collecting, using or sharing connected-vehicle data, with exceptions such as sending a location to first responders. It must let owners request copies of their data and its deletion, and let them turn off precise geolocation where the car allows it. The commission called the five-year ban appropriate given “GM’s egregious betrayal of consumers’ trust.” The order carries no fine.

California brought a fine. On May 8, Attorney General Rob Bonta and four county district attorneys [announced a $12.75 million settlement](https://privacy.ca.gov/2026/05/when-it-comes-to-data-privacy-consumers-must-be-in-the-drivers-seat-attorney-general-bonta-partners-secure-12-75-million-general-motors-privacy-settlement/), the largest penalty yet under the state’s consumer privacy law. The state alleged that from 2020 to 2024, G.M. sold LexisNexis Risk Solutions and Verisk the data of hundreds of thousands of Californians. California’s insurance rules bar insurers from setting rates on that kind of data, so drivers in the state apparently did not pay more, the announcement said. Drivers in other states did.

> General Motors sold the data of California drivers without their knowledge or consent
>
> — Rob Bonta, California’s attorney general, [privacy.ca.gov](https://privacy.ca.gov/2026/05/when-it-comes-to-data-privacy-consumers-must-be-in-the-drivers-seat-attorney-general-bonta-partners-secure-12-75-million-general-motors-privacy-settlement/)

G.M. said the settlement “addresses Smart Driver, a product we discontinued in 2024, and reinforces steps we’ve taken to strengthen our privacy practices.” The [final judgment](https://oag.ca.gov/system/files/attachments/press-docs/June%2030%202026%20Court%20Approved%20Amended%20Judgment%20People%20v.%20GM.pdf), entered in Napa County, was posted by the attorney general’s office as court-approved on June 30. It requires G.M. to delete retained driving data within 180 days unless drivers expressly consent, and to ask LexisNexis and Verisk to delete what they hold. It also keeps G.M. from selling driving data to consumer reporting agencies for five years.

Other cases remain open. Texas [sued G.M. in August 2024](https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-sues-general-motors-unlawfully-collecting-drivers-private-data-and), alleging that it had collected data from more than 14 million vehicles. In October 2025, a federal bankruptcy court [ruled](https://www.whiteandwilliams.com/restructuring-perspectives/bankruptcy-court-orders-texas-to-strike-allegations-in-state-data-privacy-suit-against-general-motors) that Texas could not base its claims on conduct by the company that existed before G.M.’s 2009 bankruptcy. Nebraska [sued in July 2025](https://ago.nebraska.gov/attorney-general-mike-hilgers-files-lawsuit-against-general-motors-deceptive-collection-and-sale), and Arkansas has also filed suit. On April 22, a federal judge in Atlanta [let wiretap and privacy claims go forward](https://dicellolevitt.com/court-allows-gm-onstar-vehicle-data-privacy-lawsuit-to-move-forward/) in consolidated class actions. In its annual report in January, G.M. said it was “not able to estimate any reasonably possible or probable material loss or range of loss,” the auto reporter Phoebe Wall Howard [wrote in her newsletter](https://phoebewallhoward.substack.com/p/gm-warns-of-unlimited-litigation), *Shifting Gears*.

[![General Motors to pay $12.75 million in driver data privacy settlement](https://i.ytimg.com/vi/KvdMFxMQssE/hqdefault.jpg)](https://www.youtube.com/watch?v=KvdMFxMQssE)

CBS 8 San Diego reports on General Motors’ $12.75 million settlement with California over the sale of driver data. Video: CBS 8 San Diego · YouTube

All of these actions are about G.M., and all of them turn on driving data sold to brokers who scored drivers for insurers. The F.T.C. order binds G.M. alone. Its 20-year consent requirement covers the sharing of connected-vehicle data. It was not clear whether regulators would read that requirement to cover the analytics code the Northeastern team found in G.M.’s four apps. G.M. describes those companies as providers working on its behalf.

## The gaps in the law

No federal law specifically governs how vehicle location data is collected and used, the Congressional Research Service found in [a report](https://www.everycrsreport.com/reports/R48736.html) first issued in November 2025 and updated this year. It listed stalking, domestic violence and foreign adversaries among the risks of location tracking. It also noted that drivers who decline optional location sharing may not realize they are giving up features.

Automakers point to their own rules. Under [privacy principles](https://www.autosinnovate.org/privacy) that the industry’s trade group adopted in 2014, members promise affirmative consent before sharing location or driver-behavior data “with unaffiliated third parties for their own use.” The last four words do the work. In the companies’ telling, a vendor that receives a VIN under contract to analyze an app is not using it for its own purposes. That is the defense G.M., Honda, Nissan and Stellantis gave the researchers.

States have moved faster than Congress. On March 19, Gov. Spencer Cox of Utah signed [a bill](https://le.utah.gov/Session/2026/bills/enrolled/HB0357.pdf) that brings automakers under the state’s consumer privacy law on Jan. 1, 2027, whatever their size. Starting with model year 2030, it requires in-car controls that show what data a car collects and who receives it, [according to the law firm Hunton](https://www.hunton.com/privacy-and-cybersecurity-law-blog/utah-governor-signs-spate-of-privacy-bills-into-law). Virginia’s ban on selling precise geolocation data took effect July 1, the law firm Venable [wrote](https://www.venable.com/insights/publications/2026/07/2026-mid-year-state-privacy-law-update). In Washington, Senators Mike Lee, Republican of Utah, and Jeff Merkley, Democrat of Oregon, [introduced a bill in December 2024](https://www.lee.senate.gov/2024/12/lee-merkley-introduces-the-auto-data-privacy-and-autonomy-act) that would make vehicle data collection opt-in. It has not become law.

European drivers have more protection on paper. Mozilla named Renault the least troubling brand in 2023 and credited Europe’s General Data Protection Regulation. In August, France’s data protection authority published final recommendations on connected vehicles and location data, [Taylor Wessing reported](https://www.taylorwessing.com/en/insights-and-events/insights/2026/08/connected-vehicles-and-geolocation-data). The Northeastern authors cautioned that their sample covers only the American market.

## The objections

The automakers’ case rests on choice. Several told Consumer Reports that many of their apps and services are opt-in, and Honda noted that its app is optional. The researchers accepted every permission prompt and agreement during testing, so their numbers show what happens when an owner says yes to everything. On Hacker News, a reader pointed out that the authors noted Tesla’s in-car privacy options but did not measure what they change.

> Would have been interesting to see how enabling privacy features changes things.
>
> — bnc319 on [Hacker News](https://news.ycombinator.com/item?id=49927021)

The paper doesn’t answer that question, but it understates in other ways. The authors call their counts a lower bound. They could not decrypt the cars’ traffic, could watch cellular traffic on only one Tesla Model 3, and could not see what passes between servers once data reaches an automaker. Tesla’s own warning to owners who decline its data-sharing terms says the choice “may result in your vehicle suffering from reduced functionality, serious damage, or inoperability.”

The researchers had listed an owner’s choices, ending with giving up the car. The sharpest objection came from a Hacker News reader who picked the middle option, giving up the connected features.

> Easy, I take #2. Is that it? This whole time I thought the article was talking about telemetry the car sends regardless.
>
> — mahboi on [Hacker News](https://news.ycombinator.com/item?id=49927219)

The study shows that the car does send some of it regardless. Eleven of the 21 cars reached advertising, tracking or analytics domains from the vehicle itself, before any app was counted. Hyundai enrolled drivers in its scoring program as soon as they turned on connectivity, according to the senators’ letter, and G.M. shared location for everyone who activated the connection. Owners who decline face a worse trade, Dr. Choffnes said: “if they opt out of this kind of data collection, they mostly brick their cars.”

## What a driver can do

Consumer Reports questioned 15 automakers for [a guide](https://www.consumerreports.org/electronics/personal-information/how-to-stop-your-car-from-collecting-sharing-driving-data-a1233378612/) published in March 2025. It recommends sending each automaker three requests: opt out of sale or sharing, limit the use of sensitive personal information, and delete. Many automakers accept these through a privacy portal or the app from drivers in any state, even where no state law requires it, the group found. It also suggests turning off location tracking and other collection in the car’s settings. It warns that drivers may lose features such as remote door locking and crash detection.

[![Your new vehicle could be collecting your data](https://i.ytimg.com/vi/0URnofL-uCY/hqdefault.jpg)](https://www.youtube.com/watch?v=0URnofL-uCY)

KVUE, an Austin television station, reports on Consumer Reports’ findings that automakers may be sharing new-car owners’ driving data. Video: KVUE · YouTube

The broker files are another place to check. LexisNexis Risk Solutions still reports driving-behavior data for auto insurance pricing under the name Telematics OnDemand, according to [the Consumer Financial Protection Bureau’s listing](https://www.consumerfinance.gov/consumer-tools/credit-reports-and-scores/consumer-reporting-companies/companies-list/comprehensive-loss-underwriting-exchange/). The listing says the company provides one free report every 12 months and will freeze a file on request. Verisk still [takes requests](https://fcra.verisk.com/) for the driving reports it holds. Drivers can dispute errors in either under the Fair Credit Reporting Act. Those files show what brokers sold to insurers, not what an analytics vendor received from an app.

Turning off connected features doesn’t always make the prompts stop. On Hacker News, an Audi A3 owner described what happened after declining remote data.

> Every time I turn the car on, it puts up a dialog that warns me that I’ve made the terrible, terrible decision to not allow remote data and forces me to say, “no, do not turn it on for me now,” before I can do anything else on the screen. Every, single, time.
>
> — technothrasher on [Hacker News](https://news.ycombinator.com/item?id=49927254)

Some owners go further and pull the fuse. Members of a [Ford Mustang owners’ forum](https://www.mustang6g.com/forums/threads/4g-modem-disabling-instructions.146860/) have posted instructions for cutting power to the car’s modem. Pulling it also disables the app and the remote features, and owners on such forums describe side effects that vary by model, from stored fault codes to the loss of automatic crash notification.

A Hacker News reader who drives a mid-2000s Ford truck described shopping for a minivan and finding that every model on the market sent telemetry.

> Worse, I’m aware that the absence of data is data itself. Is my insurance going raise my rates because my vehicle won’t provide telemetry for them to buy?
>
> — hattar on [Hacker News](https://news.ycombinator.com/item?id=49927018)

Nothing in the public record answers that. A LexisNexis spokesman told The Times in 2024 that insurers use its driving score as “one factor of many.” In California, the attorney general’s office said, insurers may not use driving data to set rates at all.

## What comes next

The authors present the paper on Oct. 16 at the Internet Measurement Conference in Karlsruhe, Germany, according to [the conference program](https://conferences.sigcomm.org/imc/2026/program/). Utah’s law reaches automakers on Jan. 1, 2027. Starting with model year 2027, the Commerce Department [bars the sale](https://www.bis.gov/press-release/commerce-finalizes-rule-secure-connected-vehicle-supply-chains-foreign-adversary-threats) of connected cars carrying software tied to China or Russia. That rule targets foreign governments, not advertisers. Texas’s suit against G.M. and the class actions in Atlanta are still pending.

Sarah Elizabeth Gillespie, one of the study’s authors, described the market for new cars to Consumer Reports: “It does not appear that a customer can buy a new car that does not track you.”

## Join the discussion

- [Automatic Transmission – a data-privacy study of connected vehicles](https://news.ycombinator.com/item?id=49926628) — Hacker News · 192 points · 166 comments

## See also

- [Your Driving Data for the Price of a Gumball](https://www.mozillafoundation.org/en/privacynotincluded/articles/your-driving-data-for-the-price-of-a-gumball-what-we-learned-from-two-us-senators-bonkers-new-letter-to-the-ftc/) — mozillafoundation.org · Mozilla's walk-through of the Wyden-Markey letter and the per-car prices it revealed
- [Senators Expose Car Companies' Terrible Data Privacy Practices](https://www.eff.org/deeplinks/2024/07/senators-expose-car-companies-terrible-data-privacy-practices) — eff.org · The Electronic Frontier Foundation on the 2024 Senate findings
- [California's GM Settlement: Has Data Minimization Finally Arrived?](https://privacymatters.dlapiper.com/2026/05/californias-gm-settlement-has-data-minimization-finally-arrived/) — privacymatters.dlapiper.com · DLA Piper's legal analysis of the first data-minimization case under California's privacy law
- [GM just paid a record penalty for breaking California privacy law](https://calmatters.org/economy/technology/2026/05/gm-record-california-penalty-onstar-data/) — calmatters.org · CalMatters on the $12.75 million OnStar settlement
- [Wyden applauds FTC settlement with GM](https://www.wyden.senate.gov/news/press-releases/wyden-applauds-ftc-settlement-with-gm-over-tracking-driver-locations-and-selling-data-to-insurance-companies) — wyden.senate.gov · Senator Wyden's January 2025 statement on the FTC's proposed GM order
- [Your car and its mobile app are probably handing over all kinds of data to tech companies](https://techcrunch.com/2026/09/29/your-car-and-its-mobile-app-are-probably-handing-over-all-kinds-of-data-to-tech-companies/) — techcrunch.com · TechCrunch's report on the Northeastern study
