Federal regulators have handed General Motors one of the harshest consumer-privacy penalties ever imposed on an automaker: a five-year ban on selling customer data to consumer reporting agencies and third-party data brokers. The action, first reported and analyzed by The Verge in its weekly Stepback newsletter under the blunt headline “Your car is selling your data,” marks the first time the Federal Trade Commission has moved so aggressively against the data practices of a major car company.
The penalty caps a years-long controversy over the modern automobile's transformation into what critics call a smartphone on wheels — a device that logs location, speed, braking habits, and driving schedules, then shares that information with an opaque network of brokers and analytics firms.
How the data pipeline worked
According to The Verge, GM collected granular behavioral data from its customers for years, including how often a driver exceeded the speed limit and whether they drove at night. That information was then sold to third-party data brokers — the same intermediaries that feed consumer reporting agencies and insurance pricing models.
The mechanics are familiar to anyone who has activated a connected-services trial in a new vehicle. OnStar's Smart Driver program, marketed as a coaching tool that rewards safe habits, generated telematics scores. Those scores traveled through data brokers such as Verisk, which in turn supplied insurers with risk assessments that could shape what a driver pays for coverage — often without the driver realizing the connection.
The issue burst into public view in 2023, when Senator Ron Wyden's office published letters revealing that several automakers had shared driver data with brokers. Wyden's office noted that brokers could purchase detailed driving profiles for a trivial sum per vehicle — a striking mismatch between the value of the data and the price paid.
Why regulators moved now
The FTC's order is notable less for its fine than for its structural remedy. A five-year prohibition on sharing data with consumer reporting agencies and brokers is a direct hit on the business model rather than a rounding error on a balance sheet.
Consumer advocates have been pressing for exactly that. Mozilla's *Privacy Not Included research project, which rates connected products, delivered a verdict that has become a rallying cry:
Cars are the worst product category we have ever reviewed for privacy.
The rating reflected findings that automakers collect far more categories of personal data than most consumer electronics, and that many companies reserve broad rights to share it. Regulators in states with strong privacy statutes, including California, have opened parallel inquiries, and the combination of federal enforcement and state law has raised the cost of inaction for manufacturers.
The industry's broader exposure
GM is far from alone. Nearly every major automaker now ships vehicles with embedded modems and over-the-air update capability, creating always-on telemetry pipelines. Electric vehicles accelerate the trend: battery management, charging behavior, and range data all generate additional streams of information that can be monetized, insured, or bundled into fleet analytics.
That has turned privacy from a compliance footnote into a product-strategy question. Companies that spent a decade promising “personalized experiences” are now recalibrating consent screens, and some have quietly discontinued driver-scoring programs that fed third-party brokers.
The enforcement action also lands in the middle of a broader political fight over who controls the data generated by machines people own — a debate that extends well beyond cars.
The ownership problem: software, locks, and who really controls your car
Digital-rights advocates have argued for years that the line between a product and a service matters enormously. Free-software pioneer Richard Stallman has long contended that anti-circumvention rules such as the Digital Millennium Copyright Act's Section 1201 convert owners into licensees, stripping them of the ability to inspect, modify, or repair the devices they buy. The fight over tools like youtube-dl — briefly removed from GitHub before public pressure forced its restoration — became a case study in how copyright law can be used to control access to ordinary software.
The same logic now applies to vehicles. Automakers argue that locked firmware protects safety and security. Right-to-repair campaigners counter that locks mainly protect revenue from dealership service bays and data sales. As cars become software platforms, the two fights — privacy and ownership — are converging into a single question: after you buy a car, is it yours?
What happens next
For consumers, the practical effects will arrive slowly. Expect clearer opt-in language, more prominent disclosures, and renewed scrutiny of dealer-finance paperwork where telematics consent is often buried. Privacy advocates want consent to be affirmative rather than default, and they want brokers cut out of the loop entirely.
Industry groups are likely to lobby for a federal standard that preempts a patchwork of state rules, framing uniform regulation as simpler than compliance with dozens of regimes. That argument has failed repeatedly in Congress, where comprehensive privacy legislation has stalled for years.
The deeper signal is that the connected car has become the next frontier of the data economy — and regulators have now demonstrated a willingness to intervene directly in how that economy operates. For an industry investing hundreds of billions into software-defined vehicles, the message is unambiguous: the data your car generates is no longer free to sell.



