The Machine That Records Everything
How the car became a round-the-clock source of data — and why it hits your wallet.
A bill 21% higher
Kenn Dahl drives carefully. No accidents. No fines. Decades behind the wheel. Two years ago the insurance on his Chevrolet Bolt rose by 21%. Without explanation. Without warning. Just a new bill. Dahl began to look into it. He requested his data from the broker LexisNexis. He received a 130-page report. One hundred and thirty pages. About his trips. Over six months. Everything was there. Routes. Departure and return times. Speed on every segment. Moments of hard braking. Instances of hard acceleration. Seat-belt data. He did not sign up for surveillance. He bought a car. He pressed the OnStar button on first start-up — and somewhere in a long user agreement that no one reads, he gave consent to the transfer of trip data to third parties. General Motors sold this data to LexisNexis and Verisk. They sold it to insurance companies. The insurers raised the tariff. Dahl told the New York Times: they take information he did not know he was transmitting and hit him with it in the wallet. This is not an isolated case. It is a system.
A computer with wheels
A modern car is not a vehicle with a computer. It is a computer with wheels. And like any computer connected to a network, it collects data. Constantly. By default. Regardless of whether you know about it or not. What exactly a connected car collects. Real-time geolocation. Every point of the route. Departure time. Arrival time. Stops — where, for how long. Regular routes: work, home, shop, hospital, church. Driving telematics. Speed on every segment of the route. Hard braking — when, where, how often. Hard acceleration. Exceeding the speed limit — by how much and for how long. Seat-belt use by each passenger on each trip. Driving style. The time of day when you drive. Night trips. Long trips. The frequency of car use. The average distance. Vehicle data. Fuel consumption. Tyre pressure. Diagnostic codes. Engine condition. When and where you refuelled. Media consumption. What music you listen to. Which radio stations. Which podcasts. What you search for via the voice assistant. And in some new models — data about the driver themselves. An infrared camera pointed at the face. Gaze analysis. State analysis: fatigue, distraction. In some systems — determining the driver’s weight through seat sensors. In 2023 Mozilla studied the privacy policies of 25 car brands. The conclusion was unambiguous: cars were named the worst category of device from a privacy standpoint of all those studied. Worse than phones. Worse than smart speakers. Worse than wearable devices. Nineteen of the twenty-five companies reserved the right to sell drivers’ data to third parties. According to McKinsey, in 2021 half the cars on the roads had an internet connection. By 2030 — up to 95%. Ninety-five percent of cars as a constantly operating network of sensors. Each records routes, speed, driver behaviour. Each transmits data. This is not the future — it is the direction the industry is moving in now.
The story that changed everything
March 2024. The New York Times publishes an investigation. Since 2016 General Motors had been selling data about its customers’ trips to two brokers — LexisNexis Risk Solutions and Verisk Analytics. They sold the data to insurance companies. The insurers used it to calculate tariffs. The programme was called OnStar Smart Driver. It was promoted as a tool for improving driving style: automatic emergency calls, roadside assistance, stolen-vehicle location. According to the lawsuits, GM did not adequately disclose that it was compiling detailed profiles of its customers’ driving habits. By some estimates, the data of up to eight million drivers may have been transferred to insurers. The data included the GPS coordinates of every trip, moments of hard braking, hard acceleration, speeding. On their basis LexisNexis assigned drivers a risk score. Insurance companies used this score to calculate the tariff. The result — drivers with a clean history, without accidents and fines, received an insurance increase. Because the algorithm decided they were risky. On the basis of data whose transfer they did not know about. GM earned about 20 million dollars from selling this data from 2020 to 2024. After the publication GM announced that it was stopping the transfer of data to LexisNexis and Verisk. But only after it became publicly known. Before the investigation the programme ran for eight years.
The arithmetic of a violation
The story did not end with the publication. On 9 June 2026 the California Attorney General announced that General Motors had agreed to pay 12.75 million dollars to settle an investigation under the CCPA — the largest fine in the history of that law. The US Federal Trade Commission concluded its own settlement in parallel: GM is prohibited from collecting and selling drivers’ data for five years. But here there is a detail that is easy to miss. The fine — 12.75 million. Earned from selling the data — 20 million. In total, GM came out ahead by 7.25 million even after a record penalty. This is the economics of a violation. When the fine is less than the profit, violating is profitable. The settlement does not include compensation to private individuals. Drivers whose tariffs rose because of OnStar data will not receive automatic compensation. Kenn Dahl paid increased insurance. General Motors paid a fine less than its profit. LexisNexis and Verisk continue to operate.
GM was not alone
This is important to understand. GM is not an exception, but the most public case. New York Times journalists discovered that Kia, Mitsubishi, Hyundai, Honda and Acura have analogous programmes. After GM, Honda, Hyundai, Ford and others continued to transfer data to Verisk, which claims access to telematics from manufacturers representing almost half of new car sales in the US. Half of new cars. Trip data. Going to brokers. By default. In Europe the situation is regulated more strictly: the GDPR requires explicit consent for such a transfer. But this does not mean the data is not collected. It means the legal framing is different. The GDPR’s requirements apply to any company processing the data of EU residents, regardless of where the company itself is located. In theory. In practice, every car manufacturer has its own terms of use, its own privacy policy, its own wording of consent. And most are written so as to cover the possibilities for using the data as broadly as possible while giving the user minimal real information.
The last personal space
Behind all these figures and fines stands a question that is not measured in figures. A car has always been a special space. Not a home — a home is something else. Not a public place, despite the public roads. Something in between. A personal space in motion. There you can belt out your favourite song at the top of your voice. Cry after a hard conversation. Think out loud. Say on the phone things you would not say in the office. Just drive in silence. This space existed because there were no witnesses in it. Now there are. Invisible. Constant. Recording. Not a person — a system. It records not what you think and not what you say, but where you drive, when, how fast, how often you stop and where exactly. Geolocation is not merely knowledge of a route. It is knowledge of the patterns of your life. Regular trips to one place every week at a certain time may mean work, a doctor, a church, a support group, a lawyer. The system does not know what exactly. But it knows that this is an important place, and how often you go there. Night trips. Trips at unusual hours. Routes that differ from the usual. In the hands of an algorithm all of this turns into conclusions about you. Privacy researcher Jen Caltrider puts it precisely: the data collected allows conclusions to be drawn about a person’s habits, psychological profile and even political views. The car does not ask you about your political views. It simply knows where you drive. The algorithm draws the conclusions.
An insurance tariff as a mirror of the algorithm
Telematics insurance requires a separate discussion. The idea is beautiful at first glance. The insurance is calculated not by statistical categories such as «man 25–35, such-and-such region», but by the real behaviour of a specific driver. Drive carefully — pay less. Logical and fair. In practice it is more complicated. According to data from Maryland, among drivers participating in telematics programmes, tariffs fell for 31%, rose for 24%, and did not change for 45%. That is, for the majority of participants there is no benefit. For a quarter — an increase. And this is in a voluntary programme that people joined consciously. The GM story is different. There the drivers did not sign up for telematics insurance. They simply used the car’s built-in services. Their data went to insurers without their knowledge. Here there is a fundamental legal question. Is consent obtained through a long user agreement that no one reads — consent? From the GDPR’s standpoint, no. Consent must be free, specific, informed and unambiguous. An «OK, continue» button does not equal consent to sell trip data to insurance companies. US senators stated that the commission should hold accountable both the manufacturers who transferred customers’ data without informed consent, and the brokers who resold what they obtained unlawfully.
What remains in the car after a sale
There is a detail that almost no one thinks about. When you sell a car, the data often remains on it. Years of trips. Routes. Geolocation history. A phone book synced via Bluetooth. Call logs. Messages that the system read aloud through the speakers. The next owner gets the car. And with it — the digital trail of the previous one. This is not a theoretical threat. Researchers have repeatedly demonstrated that purchased used cars contain the data of previous owners, including contacts, call history and home addresses saved in the navigator. A factory reset helps, but not always fully. And most people do not remember it when selling.
What the GDPR says
The European regulator has taken connected cars seriously. The EDPB developed guidelines on the processing of personal data in the context of connected vehicles. The guidelines indicate that the collection of geolocation data should happen only when the user launches a function requiring the car’s location — rather than being activated by default and continuously at every engine start. There should also be the possibility of disabling geolocation. This is an important position. Geolocation by default at engine start is a violation. Geolocation on the user’s request for a specific function is permissible. But between the regulator’s position and the reality of the cars on the roads there is a distance. Most connected cars collect data by default. Disabling this fully is either impossible or requires giving up functions you paid for at purchase. Want navigation — put up with geolocation. Want automatic emergency calls — accept constant monitoring. This is called forced bundling: consent to the main function automatically means consent to additional data collection. Article 7(4) of the GDPR explicitly prohibits such bundling. But applying this prohibition to cars is work that is only beginning.
One more recipient of the data
Insurance companies are not the only ones interested in your car’s data. Police can gain access to it. Whether this requires a court warrant remains legally debatable in different jurisdictions. Data on a car’s geolocation can be used as evidence in criminal cases. This works both ways: sometimes it helps establish an alibi, sometimes it proves presence at a certain place at a certain time. In the US cases have been recorded where prosecutors requested data from manufacturers without the owners’ knowledge. Tesla, for example, transmitted data about speed and the state of the autopilot in investigations of road accidents. In itself this is not necessarily bad — evidence in the investigation of a fatal accident has an obvious public interest. The question is different. Do you know that your car can be a witness against you? Do you understand that the data it collects can be requested without your consent? Did you take this into account when you bought a car with connected services? Most people — no.
What really helps
Giving up a car is not an option. Buying a car without an internet connection becomes harder every year. But there are actions that change the level of risk.
Car privacy settings
Most modern cars have a «Privacy» or «Data» section in the menu. There you can see what exactly is being collected, and some functions can be disabled. Not everything, but some. Geolocation, transfer of data to the manufacturer, «product improvement» — are often disableable. Automatic emergency calls, as a rule, are not, and should not be.
Manufacturer app settings
If the car manufacturer’s app is installed on your phone, open its settings. Look at what permissions it requests, what data it collects by its own statement, whether there is a possibility to limit the transfer.
Caution with telematics programmes
Insurers offer a discount in exchange for installing a device or app that tracks driving. Before consenting, read the terms: what exactly is collected, to whom it is transferred, how long it is stored, whether consent can be withdrawn and what happens to the data afterwards. The discount may be real. But the data you transfer stays with the broker longer than the policy is in force.
Requesting your data from brokers
LexisNexis and Verisk are the largest brokers of driver data in the US. In the EU there are analogous structures. Under Article 15 of the GDPR you have the right to request what data about you is being processed. This is exactly what Kenn Dahl did. And he got 130 pages. Knowing what is known about you is already information you can use.
Resetting data on a sale
A factory reset through the car’s menu. Separately — checking that Bluetooth devices are unpaired, the navigation history is cleared, accounts are logged out.
About consent that was not given
Kenn Dahl did not sign up to sell his data to insurers. He bought a car. Eight million GM drivers — by the lawsuits’ estimates — may have ended up in the same situation. Their data was sold. Their insurance rose. They did not know why. GM earned 20 million. Paid 12.75 in a fine. Continues to sell cars. LexisNexis and Verisk continue to operate. With data from Honda, Hyundai, Ford and others. By 2028, almost 44 million telematics insurance policies are expected in Europe and North America. The market is growing. The enclosed cabin you considered a personal space has long ceased to be only yours. Not because someone forced their way in. Because you pressed «OK». And no one explained what exactly you had permitted.