HeadlinesBriefing favicon HeadlinesBriefing.com

FTC Penalties GM Data Sales, Car Privacy Crisis Deepens

Hacker News •
×

Earlier this year, the Federal Trade Commission issued an unprecedented penalty against General Motors: a five-year ban on selling customer data to consumer reporting agencies and third-party data brokers. For years, GM had been collecting data on customers, such as how often they sped or whether they drove at night, and selling it to brokers to generate risk profiles for insurance companies. More often than not, drivers were unaware of the degree to which their data was being collected.

Many had unknowingly consented to it by signing up for an On Star connected services plan, which activated a feature called Smart Driver that collected their driving data. GM was then turning around and sharing that data with two data brokers, Lexis Nexis and Verisk, both of which work with the insurance industry. In a 2024 blockbuster investigative report by The New York Times, some drivers said their insurance rates went up as a result of the data collection.

The enrollment process was so confusing that many vehicle owners had no idea their data was being shared. Under the settlement with the FTC, GM has to make it easier for drivers to turn off location tracking, as well as enable them to access and delete their data collected by the automaker. But GM isn't the only automaker vacuuming up data on its customers.

A team of researchers from the Mozilla Foundation spent months examining the privacy policies of all the major car companies for a report they were working on in 2023. Their conclusion: Every single one had "horrible privacy and security," said Jen Caltrider, who helped author the study. Not only that, but customers were forced to accept overlapping policies for the car, the connected services, the smartphone app, and the financial services through which they received their loan — all of which included data collection provisions.

There has been plenty of corroborating evidence for this. Consumer Reports published its own investigation last year that concluded nearly every automaker that sells cars in the U.S. is similarly collecting and sharing so-called driver behavior data with other companies and continues to do so. Cars are particularly problematic compared to phones because the privacy controls are less intuitive.

A smartphone owner can generally find and tweak their privacy settings. With a vehicle, the data collection is spread across multiple systems and policies, making it much harder for consumers to understand what is happening. It feels like a free-for-all because automakers are collecting enormous amounts of information without much public scrutiny.

After GM was penalized as a result of the Times investigation, the issue of data privacy and cars appears to finally be getting some scrutiny. But as is often the case, policymakers may be missing the mark on how to address it. Last December, a trio of House Republicans introduced the Data Rights for Information and Vehicle Electronics in Real-time, or DRIVER, Act.

According to these lawmakers, the bill reaffirms a basic principle: if you own the vehicle, you should own the data it generates. But while the bill would give vehicle owners a bit more control over their data, it would also allow automakers to continue gathering and selling it to third-party data brokers, which makes it a nonstarter for privacy advocates. As Caltrider notes, access and deletion rights are not the same thing as preventing excess collection in the first place.