A driver activates a connected driving feature after buying a new vehicle.
The dashboard promises personalized driving insights.
Everything feels like a feature designed to help.
Months later, they learn their driving behavior and location data could be shared beyond the vehicle itself — including with companies that support insurance risk assessment.
That is when a convenience feature starts looking like a data governance problem.
You Consented to the Feature. Not the Business Model.
Most people believe they are consenting to a product feature.
Few realize they may also be consenting to an entirely different data ecosystem.
That distinction is now the basis of two separate enforcement actions against the same company — one federal, one state — and both centering on what consumers actually understood when they clicked accept.
Two Regulators, Two Orders, One Theory
In January 2026, the U.S. Federal Trade Commission finalized an order resolving allegations that General Motors and OnStar collected, used, and shared drivers' precise geolocation and driving behavior data without obtaining adequate consumer consent. The order imposes a five-year ban on GM disclosing consumers' geolocation and driving behavior data to consumer reporting agencies, requires affirmative express consent before collecting or sharing certain connected vehicle data in the future, and imposes privacy program, transparency, and data deletion obligations that remain in effect for 20 years.
Separately, on May 8, 2026, California Attorney General Rob Bonta — joined by four district attorneys and the California Privacy Protection Agency — announced a $12.75 million settlement with GM over connected vehicle privacy practices, including a five-year ban on selling driving data to data brokers. The $12.75 million penalty is the largest in CCPA history — nearly five times the prior record — and this is also the first CCPA settlement focused on data minimization and purpose limitation requirements, not just consent mechanics.
Taken together, the federal and state actions establish that regulators are treating connected vehicle data as sensitive personal data and consent architecture as a core compliance obligation — not a product design afterthought.
Five Signs Your Consent Flow Is Doing More Than Users Realize
Users understand what the feature does. They do not understand who else receives the resulting data or how it may be used. The blind spot is assuming feature transparency automatically creates data transparency.
Customers activate multiple connected services during setup with little opportunity to distinguish essential functionality from optional data sharing. The blind spot is treating convenience as informed consent.
Customers believe the feature exists to improve their driving experience. The organization increasingly treats the resulting data as a business asset for unrelated downstream uses. The blind spot is allowing the commercial value of data to quietly expand beyond the original customer expectation.
Engineering builds functionality. Legal writes disclosures. Marketing designs enrollment. Nobody owns whether an ordinary customer truly understands the decision they are making. The blind spot is treating consent as documentation instead of user comprehension.
If users only learn how their data is used after reading the news or seeing an unexpected outcome, the consent process has already failed. The blind spot is measuring opt-in rates instead of informed decision-making.
Who This Affects and How
Product and Business Teams
The biggest design challenge is no longer adding privacy disclosures. It is creating consent experiences that accurately communicate how data will move beyond the feature itself. The GM/OnStar enforcement actions make clear that regulators will assess the full user journey — not just the legal text of the privacy policy.
Privacy, Legal, and Compliance Teams
Regulators are increasingly examining whether consent reflects genuine understanding rather than simply capturing a checkbox. The California settlement is significant not just for its size but for its theory: this is the first CCPA enforcement action premised on data minimization and purpose limitation violations. That theory will travel to other sectors and other products.
Consumers
Most drivers expect connected vehicle features to improve safety or convenience. Few expect those same features to become part of a broader ecosystem that may influence decisions about them outside the vehicle — including insurance pricing. If you have enrolled in a connected driving program, review your privacy settings and confirm what you have consented to share, and with whom.
For Organizations
- Review every consent screen for connected products and identify downstream data recipients — map the full data flow, not just the feature description.
- Separate optional data-sharing choices from core product activation so consumers can meaningfully distinguish between the two.
- Confirm vendors clearly document how shared data is used, retained, and with whom it is further shared.
- Test whether ordinary users can accurately explain what they agreed to — if they cannot, the consent architecture has failed regardless of what the legal text says.
- Reevaluate whether the commercial value of customer data has expanded beyond what consumers originally understood when they enrolled.
For Individuals
- Review connected vehicle privacy settings and confirm what data-sharing programs you are currently enrolled in.
- Disable optional data-sharing programs you did not intentionally activate or no longer want.
- Request copies of your personal data from connected vehicle service providers where applicable.
- Ask whether your driving data is shared with third parties beyond the manufacturer — and specifically whether it is shared with insurance-related companies or data brokers.
Unpopular Opinion
Most consent failures begin long before anyone clicks "Accept." They begin when the product team designs the enrollment flow and nobody asks: will an ordinary user understand not just what this feature does, but what happens to the data it generates?
Myth vs Reality
Myth: If users accepted the terms, consent was meaningful.
Reality: Consent is difficult to defend when users understand the feature but not how their data will actually be used. The GM enforcement actions — from both the FTC and California — are built on exactly that distinction.
If customers understand the product but not the data ecosystem behind it, have they really given informed consent — and how would your organization answer that question if a regulator asked?
Poll
What is the biggest weakness in digital consent today?