# General Motors Settles $12.75M California Privacy Violation Over Unauthorized Driver Data Sales
Record enforcement action targets automaker's secret data broker deals and marks California's first major data minimization enforcement
General Motors has agreed to pay $12.75 million—the largest civil penalty in California history for privacy violations—to settle allegations that it illegally collected and sold Californians' sensitive driving and location data to insurance-related data brokers without their knowledge or consent.
California Attorney General Rob Bonta announced the settlement on May 11, 2026, concluding a two-year investigation into GM's data practices spanning 2020 to 2024. The case marks the first enforcement action in the state specifically focused on data minimization—a legal requirement that companies retain personal information only as long as necessary for stated purposes.
"General Motors sold the data of California drivers without their knowledge or consent and despite numerous statements reassuring drivers that it would not do so," Bonta said in a statement. "This trove of information included precise and personal location data that could identify the everyday habits and movements of Californians."
## The Settlement: Record Penalties and Sweeping Restrictions
The $12.75 million penalty represents California's largest enforcement action against a single company for privacy violations under the California Consumer Privacy Act (CCPA). Beyond the financial penalty, the settlement imposes five years of operational restrictions on GM:
The settlement applies specifically to GM, GMC, Cadillac, Chevrolet, and Buick vehicles, which collectively represent millions of registered vehicles in California.
## How the Violations Occurred: OnStar and Smart Driver Systems
GM's data collection occurred through two primary pathways:
OnStar: GM's connected vehicle platform, which provides real-time location tracking, roadside assistance, and diagnostic services to millions of drivers.
Smart Driver Program: A specific feature within GM vehicles designed to monitor and score driver behavior, ostensibly to provide feedback on driving habits and safety.
Customers who activated these services were told the data would remain private and support vehicle diagnostics and safety improvements. Instead, the company systematically extracted precise location and driving behavior data and sold it to third-party data brokers who incorporated it into driver-scoring products marketed to insurance companies.
## The Data Sold: Location, Behavior, and Movement Patterns
The data transmitted to Verisk Analytics and LexisNexis included:
| Data Category | Details |
|---|---|
| Real-time location | GPS coordinates at frequent intervals, enabling tracking of daily movements |
| Driving behavior | Acceleration patterns, braking intensity, speed violations, cornering behavior |
| Geolocation history | Detailed routes, destinations visited, time spent at locations |
| Movement patterns | Commute routes, recurring destinations, travel frequency and timing |
This granular behavioral data enabled insurance underwriters to create risk profiles far more detailed than traditional driving records. Brokers repackaged the data into proprietary scoring algorithms sold to insurers—creating what investigators described as a surveillance-derived pricing model.
Nationally, GM generated $20 million in revenue from these data sales between 2020 and 2024. California, which represents approximately one-third of the U.S. automotive market, accounted for a proportional portion of that revenue.
## Regulatory Violations: Consent and Data Minimization
Investigators identified multiple violations of California's privacy law:
1. Lack of informed consent: GM failed to clearly disclose to consumers that their data would be sold to insurance brokers or used for driver-scoring products. While some user agreements mentioned data sharing, they did not specifically identify the scope, recipients, or purpose.
2. Retention beyond necessity: GM retained driving and location data indefinitely and re-purposed it for commercial sales—far longer than necessary to operate OnStar and Smart Driver services.
3. Failure to honor opt-out: Consumers were not provided clear, accessible mechanisms to prevent data collection or sale, despite GM's public statements promising privacy protection.
4. Violation of CCPA rights: The CCPA grants California consumers the right to know, delete, and opt-out of the sale of their personal information. GM denied these rights through inadequate disclosures and limited deletion mechanisms.
## The FTC Connection: Building a Pattern
This settlement follows a November 2024 Federal Trade Commission enforcement action against GM on identical allegations. The FTC issued a five-year ban on GM selling driving data, citing deception and unfair practices.
California's separate enforcement—and larger financial penalty—signals that state-level privacy regulators are moving independently of federal authorities to close enforcement gaps. The state's $12.75 million penalty demonstrates that regulators view data sales as a serious violation warranting record-breaking fines.
## Consumer Impact: Why Californians Largely Escaped Insurance Harm
One key detail distinguishes California from other states: California law prohibits insurers from using data-driven behavioral scoring to set insurance rates. While GM's data sales violated privacy law, California insurance regulations prevented the most direct consumer harm—premium increases based on purchased behavioral data.
However, authorities note this does not diminish the privacy violation or the value of sold data. Data brokers marketed the datasets to insurers in other states where such pricing is legal, and sophisticated behavioral scoring may still influence underwriting decisions indirectly.
## Broader Industry Implications: Other Automakers Under Scrutiny
GM is not the only automaker engaged in data sales. Media investigations in 2024 revealed that BMW, Hyundai, Kia, Mercedes-Benz, and other manufacturers sell driving and location data to insurers and data brokers. Several of these cases are reportedly under investigation by state regulators and the FTC.
The GM settlement signals that:
## What GM Must Do: Implementation Timeline
Over the next 18 months, GM must:
1. Immediate halt to new data sales agreements with brokers
2. Delete historical data retained beyond 180 days by August 2026
3. Request third-party deletion from LexisNexis and Verisk
4. Develop and submit a comprehensive privacy compliance program within 60 days
5. File quarterly attestations for five years confirming compliance with sale restrictions
Failure to comply will subject GM to additional civil penalties and enforcement action.
---
## HackWire Analysis
This settlement represents a watershed moment in how regulators treat automotive data. For years, connected vehicle data has existed in a gray zone—automakers treated it as proprietary business data rather than consumer personal information requiring protection. The scale of GM's penalty signals a fundamental shift.
What's particularly significant is the data minimization angle. California didn't just penalize deception; they penalized the company for retaining data longer than necessary and re-purposing it for unrelated commercial sales. This is the regulatory framework privacy advocates have long advocated for—and courts and regulators are now enforcing it.
The pattern extends beyond GM. When multiple automakers were revealed to be selling data, the FTC responded with GM specifically. Now California is filing separately with a higher penalty, suggesting coordinated enforcement across agencies. We should expect similar settlements from other states and potentially additional automakers.
For defenders and privacy-conscious organizations, the key lesson: audit data retention policies immediately. If your company collects data for stated purposes (diagnostics, safety), verify that you're actually deleting it after those purposes conclude. The fine-print that says "we retain data for X months" or "for business purposes" is exactly what regulators are targeting. This case also underscores why vehicle owners should actively review and disable telemetry and location sharing in vehicle settings—consent withdrawal is now a legal right, even if systems don't make it obvious.
— HackWire Editorial
---
## Related Coverage