Think about an ordinary drive to work: you drive in, park, drive home.
Here’s what a connected car can record from that trip. Where you were, all the time, with times. How fast you went, and where. Every time you braked hard enough to count as “harsh”. Every time you sped up quickly enough to count as “rapid”. Whether your seatbelt was on. What was playing. What you said to the voice assistant, including the false starts. And if you connected your phone (and you did, because that’s what the screen is for), it may copy your contacts, call history and messages into the car for hands-free calling.
You wouldn’t accept a phone app that asked for all that. In a car you don’t install it. It’s already there when you get in.
The people who read the small print
In 2023 the Mozilla Foundation spent around 600 hours on the privacy policies of 25 car brands for its Privacy Not Included guide. All 25 failed. Cars scored worse than any product type the project had ever reviewed, below smart speakers, doorbell cameras and reproductive-health apps.
Some details from the policies, because they are hard to believe otherwise. Nissan’s said it could collect information including sexual activity, health diagnoses and genetic data. Kia’s mentioned “sex life”. Hyundai’s said data could be shared with the police on the basis of informal requests. And Tesla warned that switching off vehicle data collection could leave the car less capable, damaged or unusable: an opt-out written as a threat.
Nobody reads a privacy policy at a car dealership. That isn’t a personal failing. It’s by design.
- 01you drive to workthe only part of this you actually notice
- 02the car records itwhere you were, speed, braking, cornering, seatbelt, what was playing
- 03it goes to the car makersent over the car's own connection, so you can't see it leave
- 04it is packaged and solddata brokers and insurers pay for it, which is why step 02 happens
You never see the file. For most drivers this has happened to, the first sign it existed was an insurance renewal quote.
When it stopped being “what if”
For years this was a “could” story. Then, in early 2024, the New York Times reported what General Motors (GM) had been doing with Smart Driver, a free driving-score feature in its connected-car apps.
According to a later complaint by the FTC (the US consumer regulator), GM collected some drivers’ locations as often as every three seconds. It sold driving data on millions of cars to two data brokers (firms that trade in personal data), LexisNexis and Verisk, whose customers include insurers. One driver’s LexisNexis file ran to 258 pages and listed 640 separate trips, with start and end times. Drivers saw insurance prices jump for no reason they could see, by around 80 per cent in one reported case. Nobody had told them their brake pedal was now a data source.
Many of those drivers never knowingly signed up at all. Regulators found the sign-up misleading, and often rushed at the dealership.
The fallout is still coming. GM dropped Smart Driver in April 2024, days after the reports. In January 2026 the FTC finalised an order banning GM from sharing drivers’ behaviour and location data with consumer reporting agencies for five years. It also requires clear, active consent for connected-car data collection for twenty years. In May 2026, California announced a $12.75 million settlement over the same behaviour, noting GM had made about $20 million across the US from the sales. Texas has gone after the insurance side of the chain as well as car makers.
GM is simply the company caught first and best documented. The brokers it sold to are in the business of buying.
So who owns it?
Morally, most people think the answer is obvious. When the FIA (a global body for motoring clubs) asked drivers about connected cars, nine in ten felt the data belonged to them. About as many wanted a switch to turn the connection off. Almost no car has that switch.
Legally, the UK is better placed than the US. Data about you is personal data under UK GDPR, the UK’s data protection law. You can ask any car maker for a copy of what they hold, have it corrected or deleted, and object to its use. They have a month to reply. Sharing how you drive with an insurer needs a proper legal reason, not a paragraph hidden in the small print. These rights are real, and asking a car maker what it holds on you just once is an eye-opener.
But rights you have to use one request at a time, against a setup that collects everything by default, aren’t ownership. In practice, whoever holds the servers owns the data. That’s the whole disagreement.
To be fair to the car
Connected features in cars aren’t a con. Automatic emergency calls after a crash save lives. Tracking stolen cars works. Updates sent over the air save a garage visit, and a monitored, serviced car really is safer.
The problem isn’t the feature. It’s that it came with a data-selling business you were never really asked about. And opting out, where possible at all, is hidden, penalised, or written as a warning.
So what can you do? Treat the connected-services screens at handover as a contract, because they are one. Say no where you can. Ask the car maker what it holds on you. In the UK, that request has legal force. And notice what you can simply take back. Location history is the most sensitive data a car produces, and you can keep it in a private app instead of in a car maker’s cloud: recorded by you, readable by you, sold to nobody.
A car that phones home is fine. A car that feeds someone else’s business, using your fuel, is worth objecting to. The first step is knowing the call is being made at all.