Skip to content

GM Faces Record $12.75M CCPA Settlement Over Connected Vehicle Data

May 16, 20262 minute read

$12.75 million penalty.
Hundreds of thousands of drivers affected.
Largest CCPA settlement in California history.

General Motors is facing the consequences of treating connected vehicle data as a monetization asset instead of a regulated liability.

California regulators allege GM collected and sold highly sensitive driver data through its OnStar Smart Driver services — including:
• Precise geolocation data
• Driving behavior data (speed, braking, acceleration)
• Contact information and identifiers

The data was allegedly shared with brokers including LexisNexis Risk Solutions and Verisk Analytics without valid consumer consent. Regulators also claim customers were reassured their data would remain private while GM generated an estimated $20M from these data-sharing practices.

The settlement goes beyond the fine:
• 5-year ban on selling driver data to brokers
• Deletion obligations for collected data
• Increased transparency and consent requirements
• Stronger enforcement focus on data minimization and purpose limitation

This case matters far beyond the automotive industry.

Every connected product is now a compliance surface:
• Mobile apps
• IoT devices
• SaaS platforms
• Connected vehicles
• AI-driven analytics systems

The core compliance failure was not just “data sharing.”
It was:
• Weak consent governance
• Poor visibility into downstream data flows
• Misalignment between stated privacy commitments and operational reality
• Lack of control over third-party data transfers and usage

For DPOs, Legal Counsel, CTOs, and CISOs, the message is clear:
If you cannot clearly answer:
• What data is collected
• Why it is collected
• Where it flows
• Who receives it
• Under what legal basis
• How consent is captured and enforced
…then your organization is already exposed.

At S8fe.ai, we help organizations operationalize data compliance before regulators do it for them.

Our platform helps companies:
• Map sensitive and cross-border data flows
• Identify high-risk data-sharing practices
• Maintain compliance evidence and governance controls
• Detect regulatory exposure before it becomes an enforcement case

Connected systems generate compliance risk at machine speed.

Governance can no longer rely on spreadsheets, static policies, or assumptions.

Sources:
• https://iapp.org/news/a/california-authorities-announce-largest-ccpa-fine-to-date
• https://calmatters.org/economy/technology/2026/05/gm-record-california-penalty-onstar-data/

Share this article

Back To Top