CipherWatch All articles
Data Privacy

Your Car Is Watching You: The Data Your Connected Vehicle Collects and Where It Goes

CipherWatch
Your Car Is Watching You: The Data Your Connected Vehicle Collects and Where It Goes

The automobile has long been a symbol of American freedom — the open road, the private journey, the autonomy of movement. That symbolism is increasingly at odds with the reality of what a modern connected vehicle actually is: a sophisticated data collection platform that records where you go, how you drive, what you say, and how you behave, then transmits that information to parties you have likely never heard of.

A 2023 investigation by Mozilla Foundation researchers examined the privacy policies of twenty-five major automakers and concluded that cars are "the worst product category we have ever reviewed for privacy." Every manufacturer studied collected more personal data than necessary, and most shared or sold that data to third parties. Sixteen of the twenty-five brands indicated they may share user data with government entities or law enforcement upon request — in some cases without requiring a warrant.

This is not a fringe concern. It is the documented operational reality of the connected vehicle market.

The Data Your Vehicle Generates

The scope of data collected by modern vehicles is substantially broader than most drivers appreciate. Telematics systems — the hardware and software that enable features like navigation, remote start, and emergency assistance — continuously generate data across multiple categories.

Location data is the most obvious category. GPS systems track and log precise route histories, including departure times, destinations, duration of stops, and the frequency with which specific locations are visited. This data is often retained for extended periods and, in some architectures, synchronized to manufacturer cloud servers in near real-time.

Driving behavior data encompasses speed, acceleration and braking patterns, cornering behavior, seatbelt usage, and — in vehicles with driver monitoring systems — eye-tracking and head-position data intended to detect fatigue or distraction. This is precisely the data that insurance companies find most commercially valuable.

Voice and in-cabin data presents a less-discussed dimension. Vehicles equipped with voice-activated assistants — whether manufacturer-built systems or integrated platforms like Apple CarPlay and Android Auto — process voice commands that may be stored and analyzed. Some manufacturer privacy policies explicitly disclose that voice interactions may be retained and reviewed by human quality-assurance personnel.

Device and pairing data is collected whenever a smartphone is connected via Bluetooth or USB. Depending on the vehicle's software architecture, this pairing may transfer contact lists, call logs, message metadata, and application data from the phone to the vehicle's infotainment system — where it may persist long after the vehicle is sold.

The Insurance Industry's Role

The intersection of connected vehicle data and auto insurance is one of the most consequential — and least transparent — aspects of automotive privacy. Usage-based insurance (UBI) programs, offered by major insurers including State Farm, Progressive, Allstate, and others, collect telematics data either through a dedicated OBD-II port device, a smartphone application, or — increasingly — directly from the vehicle's native telematics system through data-sharing agreements with manufacturers.

General Motors' OnStar subsidiary operated a data-sharing arrangement with insurance data aggregator LexisNexis Risk Solutions that was the subject of a significant investigative report by The New York Times in 2024. The reporting revealed that detailed driving behavior data — including hard-braking events and speed records — had been shared with LexisNexis and subsequently used by insurers to adjust premiums, in many cases without drivers' meaningful awareness that this data transfer was occurring.

GM subsequently announced it would discontinue the data-sharing program. However, the episode illustrated a structural dynamic that extends well beyond a single manufacturer: the commercial value of driving behavior data creates persistent incentive for automakers to monetize it, and the consent mechanisms governing that monetization are frequently embedded in lengthy terms-of-service agreements that few consumers read.

Law Enforcement Access and the Warrant Question

Vehicle location and behavioral data has become an increasingly common subject of law enforcement requests. Because this data is held by manufacturers and their affiliated service providers rather than by the driver, it may be accessible to investigators through subpoenas or court orders that do not meet the higher evidentiary standard required for a traditional warrant.

The Supreme Court's 2018 ruling in Carpenter v. United States established that the government generally requires a warrant to access historical cell-site location information. Legal scholars have debated whether and to what extent that precedent extends to vehicle telematics data. The answer is not yet settled, and in practice, manufacturers have varied significantly in their stated policies regarding law enforcement cooperation.

For drivers who operate in sensitive professional contexts — journalists, attorneys, healthcare workers, or anyone whose location history carries confidentiality implications — the data retention practices of their vehicle's manufacturer are not an abstract concern.

Emerging Regulatory Frameworks

The regulatory response to connected vehicle data collection is nascent but developing. The California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), provide California residents with rights to know what personal data is collected, to opt out of its sale, and to request its deletion. Several automakers have faced scrutiny from the California Privacy Protection Agency regarding the adequacy of their consent mechanisms.

At the federal level, the bipartisan Drivers Privacy Protection Act has historically governed the disclosure of information contained in motor vehicle records held by state DMVs, but it does not reach manufacturer-held telematics data. Legislation specifically addressing connected vehicle data — including a 2024 proposal by the Federal Trade Commission to scrutinize automaker data practices — reflects growing regulatory attention, though comprehensive federal rules remain pending.

The National Highway Traffic Safety Administration has also initiated rulemaking processes that may impose data minimization requirements on vehicle systems, though the timeline for final rules is uncertain.

What Drivers Can Do Now

Complete data privacy in a modern connected vehicle is not realistically achievable without significant inconvenience. However, several steps can meaningfully reduce exposure.

Review your manufacturer's privacy policy and connected services agreement with specific attention to data-sharing and retention provisions. Most major manufacturers publish these documents online; search for your vehicle brand alongside the terms "privacy policy" and "connected services."

Opt out of data-sharing programs where the option exists. Many manufacturers provide a connected services portal — accessible through the vehicle's infotainment system or a companion website — that includes controls for telematics data sharing. These controls are often not prominently surfaced.

Avoid syncing your smartphone's full contact list or message history with the vehicle's infotainment system unless you have reviewed how that data is stored and whether it persists after unpairing.

If you are selling or trading in a vehicle, perform a factory reset of the infotainment system before transfer. Consult the owner's manual for the specific procedure; this step is not always performed by dealers.

For drivers with heightened privacy needs, consider whether the connected features of your vehicle — remote start, embedded navigation, emergency call systems — are worth the data exposure they entail. Disabling cellular connectivity through the manufacturer's connected services portal is possible on some platforms, though it will disable associated features.

The open road remains. What has changed is who is riding along.

All Articles

Related Articles

Prove Yourself at Your Own Risk: The Hidden Dangers Inside Online Identity Verification

Prove Yourself at Your Own Risk: The Hidden Dangers Inside Online Identity Verification

Sold in Milliseconds: The Hidden Marketplace Trading Your Browsing Habits Right Now

Sold in Milliseconds: The Hidden Marketplace Trading Your Browsing Habits Right Now

The Data You Forgot You Gave Them: Why Companies Lose Track of Your Personal Information

The Data You Forgot You Gave Them: Why Companies Lose Track of Your Personal Information