What does your car know about you? Connected car data explained

A connected car is a computer with wheels, sensors and, often, its own mobile connection. Depending on the model and the services switched on, it can record where it went, when, how fast and how hard it braked. Its app can record who unlocked it, and its account can tie all of that to an email address, a phone and a payment method. In a US case finalised in January 2026, the Federal Trade Commission alleged that driving records from General Motors cars reached consumer reporting agencies and were used to price insurance. That is the problem in one line: the consequence can turn up a long way from the feature that collected the data.

The insurance report a driver did not expect

In January 2025 the US Federal Trade Commission announced an action against General Motors and its OnStar service. The FTC alleged that GM signed drivers up through a confusing enrolment process for OnStar and its Smart Driver feature, did not adequately disclose that it was collecting and selling their data, and collected precise location as often as every three seconds for some users.

According to the FTC, the Smart Driver record included hard braking, late-night driving and speeding. Consumer reporting agencies are the companies that compile reports on individuals, including credit reports. The FTC alleged that GM supplied this information to them, and that insurers used the resulting reports to deny insurance and set rates (the FTC’s 2025 announcement).

What ended, and what became final

In April 2024 GM announced that it would discontinue Smart Driver across all of its vehicles and unenrol every customer. It also said it had terminated its relationships with the third-party telematics companies LexisNexis and Verisk, and that any data sharing with those companies ended on 20 March 2024 (GM’s statement). It does not say whether copies already held were deleted, or what else a connected GM car still sends.

On 14 January 2026 the FTC finalised an order settling its allegations that GM and OnStar collected, used and sold precise location and driving-behaviour data from millions of vehicles without adequate notice and affirmative consent. The order bans GM for five years from disclosing drivers’ location and driving-behaviour data to consumer reporting agencies. For its 20-year life it also requires consent, access, deletion and opt-out mechanisms. Where the vehicle has the technology, GM must offer a way to disable precise location collection, subject to exceptions the order defines, such as emergency response (the FTC’s final order announcement).

Keep the pieces apart, because they are different kinds of fact.

PointKind of factWho said it
Location collected as often as every three seconds for some usersAllegation, settled without a trialFTC, January 2025
Reports built from GM data used to deny insurance and set ratesAllegation, settled without a trialFTC, January 2025
Sharing with LexisNexis and Verisk ended on 20 March 2024; Smart Driver discontinuedCompany statement about one programGM, April 2024
Five-year ban on disclosing location and driving-behaviour data to consumer reporting agencies; 20 years of consent, access, deletion, opt-out and location-disable dutiesFinal consent order, US onlyFTC, 14 January 2026
Consent needed before driving or precise-location data goes to General Motors Insurance for usage-based offers or rates; precise location kept up to three years for listed purposesCurrent vendor privacy statement, US onlyGM, June 2026

The GM matter is a documented US case study and a useful standard for consent. It does not give Australian drivers the same rights, and it does not prove that every manufacturer follows the same data path.

What data can a connected car create?

It depends on the model, the services installed, the account, the country, and whether the car is owned, leased, rented or part of a fleet.

GM’s US privacy statement, dated June 2026, shows the potential scope. For vehicles enrolled in OnStar it lists precise location, driver-behaviour information such as speed, braking, acceleration, seatbelt status and trip time and duration, vehicle diagnostics, mobile-app activity, voice recordings in specified interactions, external-camera and sensor information in defined circumstances, and AI assistant interaction information (GM’s US privacy statement). That last category may include the transcript of your interactions, the places you ask it to navigate to, your contacts, your call history and details of the topics discussed: not every car collects all of it, but one convenience feature can add a whole new category to the record.

GM’s list is not a claim about every manufacturer. Use it as a checklist for reading the policy for the car in your own driveway and testing what that car actually does: location, driving behaviour, vehicle state, account and app activity, interaction data, and images or sensor data where a system collects them.

How does the data leave the car?

A connected car usually has several ways out. The built-in telematics unit has its own mobile connection. The infotainment system may use Wi-Fi. The manufacturer’s phone app, and any navigation, music or charging service, each have their own terms. A dealer or fleet manager may receive maintenance data under a different arrangement again.

The usual path from sensor to recipient:

  1. A sensor in the car records an event.
  2. Software links the event to a vehicle or an account.
  3. The built-in modem, or a paired phone, transmits it.
  4. The manufacturer or service provider stores and analyses it.
  5. An affiliate, contractor, insurer, fleet owner or other authorised recipient receives a defined field or a derived result.

Who receives it?

The first recipient is usually the manufacturer or its connected-service operator, then its contractors, emergency services, navigation or entertainment providers, a fleet owner or rental company, an insurer where a driver has joined a usage-based product, and anyone with a valid legal demand.

GM’s current US notice says that disclosing driver-behaviour or precise location data to General Motors Insurance, for usage-based offers or rates, requires the driver’s affirmative consent, and it publishes retention periods for listed purposes, including up to three years for precise location. Those are GM’s current US statements, not an audit and not an industry-wide rule.

Useful processing is not automatically improper: the same data runs the emergency, navigation and maintenance features, helps diagnose faults, and prices insurance and fleet risk. Privacy turns on whether the collection was necessary, whether you were told and asked, who receives the data, how long it is kept, and whether it is reused for something you never expected. For why ordinary records have become more valuable, see AI has changed the value of your data.

A route can become a sensitive inference

A coordinate is not a diagnosis, but repeated coordinates say a great deal. Nightly stops suggest home, weekday patterns suggest work, and repeated visits can point to a school, a place of worship, a clinic, a union office, a refuge or a relationship. Speed and braking events can be read as risk indicators, and joined to a customer account, an app record or a commercial dataset, a vehicle trail becomes much easier to attach to a named person.

These are possible inferences, not established facts: a car parked near a clinic does not prove the driver was a patient, and inference systems can be wrong and still affect people. The location data industry guide follows the same chain from app signal to audience and risk profile.

In Australia, connected car privacy can be a safety issue

Australia’s eSafety Commissioner has pointed to a danger that commercial privacy discussions often miss: linked vehicle accounts and “find my” tools can be used in coercive control. Its November 2025 guidance says trip histories, device pings and geofence alerts can expose routines and locations such as home, school, work or a refuge, and that shared credentials can allow remote commands or alerts. It is safety guidance for family and domestic violence situations, not a measure of how often this happens, and it shows that an account setting can have immediate physical-safety consequences (eSafety Commissioner).

The ACCC’s March 2024 interim report adds the wider context: Australian data firms combine volunteered and observed data with other information to create inferred products, often without any direct relationship with the people described (ACCC interim report).

What you can do about it

Before buying or subscribing

After delivery

When someone else drives the car

Tell regular drivers which connected services are active, since a family member or employee can generate data through an account they never set up. In a rental or fleet car, avoid syncing contacts and messages, and remove your phone and profile when you hand it back.

Before selling or returning it

Sign out of the apps, remove paired phones, delete saved destinations and contacts, clear any garage-door codes, cancel or transfer the connected-service account, and follow the manufacturer’s documented factory reset. Then confirm the car no longer appears in your own app. Where there is a personal-safety risk, do not make a conspicuous account change without a safety plan; the eSafety Commissioner’s guidance takes priority over any checklist, including this one.

Why a home Pi-hole or VLAN cannot control the car’s own connection

Pi-hole is an internet address book with a blocklist, and it only answers the devices on the network you control. A car’s built-in modem can send its data through the mobile carrier without ever joining your home Wi-Fi, so that traffic never asks the Pi-hole in your house for anything.

Even when the car does join your Wi-Fi, DNS filtering has its usual limits: encrypted or hard-coded lookups, connections straight to an IP address, first-party domains the car needs, and endpoints used for updates or safety functions. A DNS log also cannot tell you what an encrypted upload contained.

A VLAN is a separate room for a group of devices, and the firewall is the rules on the doors between that room, the rest of the house and the internet. The room alone blocks nothing; the door rules decide what those devices can reach. That is worth doing for the garage charger, the cameras and the other connected gear at home; the Australian Cyber Security Centre recommends a separate Wi-Fi network for IoT devices (ACSC guidance). Those rules do not reach a modem on a carrier network, and Alien IT does not sell it as control over your car, because it is not. The Pi-hole guide and the IoT network guide cover the equipment that does live on your network.

What cannot be switched off cleanly

Some collection supports crash response, stolen-vehicle recovery, battery safety, warranty, diagnostics or a legal duty. Closing the account can remove features you paid for, and emergency exceptions can remain after you change a location setting. Separate the essential operation of the car from optional scoring, advertising, research and disclosure, write down the trade-off, and revisit it when the policy or the ownership changes. The goal is informed reduction, not a networked car that becomes invisible while every connected feature keeps working.

Alien IT cannot change what your car sends over its own mobile connection; that sits with the manufacturer’s settings and privacy process. We can help with the home-network side: the garage charger, cameras and other connected equipment in their own room on the network, maintained DNS filtering, and a plain written note of what it does and does not cover. Call 02 9707 0999 or use the contact page.

Frequently asked questions

Is GM still sharing Smart Driver data with LexisNexis and Verisk?

GM says no. It stated that sharing with those companies ended on 20 March 2024 and that Smart Driver would be discontinued. The FTC’s related order became final on 14 January 2026.

Did every GM vehicle send its location every three seconds?

No. The FTC alleged that rate for some users; it should not be generalised to every driver, model or service.

Can connected car data affect my insurance?

It can. In the GM matter the FTC alleged that reports built from GM data were used by insurers to set rates and deny insurance. Voluntary usage-based insurance can also use driving data under terms you agree to.

Will disconnecting my phone stop the car tracking?

Not necessarily. A car with a built-in modem communicates on its own; removing your phone may stop the phone-derived data and app functions, but not the telematics unit.

Can Pi-hole block my car’s telemetry?

Only traffic that actually passes through the network Pi-hole serves and uses DNS it can see. It cannot control the car’s separate mobile connection.

Should I disable all the connected safety features?

Not automatically. Work out what each feature collects and what it gives you, then turn off the secondary uses you do not need and keep the functions you chose.

What should I do before selling a connected car?

Remove the accounts, paired devices, contacts, destinations and remote access; cancel or transfer the services; run the documented factory reset; and check that the car no longer appears in your app.

Sources behind this guide