Last Update: 08/01/2026 at 1:00 PM EST
Connected Vehicle Data Sales Enforcement
Coverage from BleepingComputer, Mashable, and others
Articles
7
Active Days
76
The Topic

Recent coverage is dominated by California enforcement against General Motors over OnStar data practices, especially the collection, retention, and sale of driving and precise location data to brokers without affirmative consent. The case has pushed data minimization, deletion, and broker-sale limits into the foreground of connected-vehicle privacy.
First Article: 02/26/26
Latest Article: 05/12/26
Summary
- California's settlement with General Motors is the dominant current event, with regulators alleging unlawful collection and broker sales of OnStar driving and location data.
- The enforcement theory emphasizes notice, affirmative consent, purpose limitation, and data minimization rather than a classic breach scenario.
- The settlement imposes operational limits: a five-year pause on certain data sales, shorter retention, broker deletion requests, and a privacy risk program.
- General Motors, OnStar, Verisk Analytics, and LexisNexis Risk Solutions are the most important recurring entities in the current snapshot.
- A related Iowa lawsuit indicates the issue is not isolated to California and may reflect broader scrutiny of connected-vehicle telematics practices.
- The topic is coherent and fairly dense, with current signal concentrated on one high-salience enforcement pattern rather than many unrelated privacy issues.
History
This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.
