It is a common refrain in the auto industry: modern cars are essentially smartphones on wheels. But just like the device in your pocket, the vehicle in your driveway quietly collects huge volumes of information — tracking driving routes, acceleration patterns, braking intensity, and even how aggressively a driver turns. The legality of this data harvesting, however, remains hotly debated.
Last year, the Federal Trade Commission penalized General Motors for illegally collecting and selling precise location and driving behavior data without obtaining informed consent from customers. Other automakers have also drawn scrutiny. Ford and Honda each received fines from privacy regulators for adding unnecessary friction to the opt-out process, making it difficult for consumers to stop their data from being shared.
Despite these actions, a recent study (published by Northeastern University and reported by The Verge) indicates that the scope of data collection and sharing by automakers is far broader than many consumers anticipate. The study echoes concerns that the current regulatory framework is insufficient to protect driver privacy.
Industry responses have been mixed. Automakers argue that data collection enables safety features, navigation improvements, and vehicle diagnostics. Critics counter that the data is often used for revenue generation — such as selling driving profiles to insurance companies — without clear consumer benefit. Privacy advocates call for stronger, simpler consent mechanisms and a default opt-in model.
The issue highlights a growing gap between rapid technological adoption and the slow pace of consumer protection laws. As more connected vehicles hit the road, regulators face pressure to set clearer rules on what data can be collected, how it can be used, and what level of transparency automakers must provide.