DeSpy Privacy Academy Lesson 2

August 4, 2026

Connected Vehicles

Vehicle data, tracking, and your right to drive private.

Lesson 2 of 6 · Estimated read: 12 minutes · Level: everyone

A modern car is a computer network with wheels. It has more processors than your house, its own cellular connection, and a manufacturer relationship that continues long after you drive off the lot.

In 2023, Mozilla reviewed the privacy practices of 25 car brands for its Privacy Not Included guide. All 25 failed, the only product category where every single entrant flunked. Cars collect more than your phone does, share it more freely, and give you less control.

This lesson covers what’s actually being recorded, where it goes, and the specific steps that work.

In this lesson

  1. How your vehicle collects and transmits data
  2. Connected car privacy risks
  3. Location tracking & driving behavior
  4. Data sharing with manufacturers and third parties
  5. Protecting your privacy on the road
  6. Security, updates, and remote access
  7. Your rights & choices as a driver

1. How your vehicle collects and transmits data

The basics

Your car collects data through three separate systems that people tend to blur together:

Go deeper

What most people don’t know

The car’s cellular connection is independent of your phone. Two consequences people find genuinely surprising.

First, deleting the manufacturer’s app, or never installing it, does not stop the vehicle from transmitting. The modem is in the car, and it reports whether or not you’ve ever opened an app.

Second, pairing your phone copies data into the vehicle’s storage. Contacts, call history, and in many cases text messages are stored on the head unit, where they persist. This is why rental cars and resold vehicles routinely contain previous drivers’ personal data. Consumer advocates have documented this repeatedly: people return a rental and leave their entire address book behind. Removing the Bluetooth pairing doesn’t necessarily remove the stored data; that generally requires a factory reset of the infotainment system.

Do this today

2. Connected car privacy risks

The basics

Vehicle data is unusually sensitive because location plus time reveals things no one volunteers: where you worship, which doctor you see, whose house you stayed at, whether you attended a protest, how you drive when you think no one’s watching.

Go deeper

What most people don’t know

Connected car apps have become a tool in domestic abuse, and the account structure makes it hard to escape.

The manufacturer’s app can typically locate the vehicle, unlock it, start it, and review trip history. When a relationship ends, whoever controls the connected-services account retains those capabilities, even if the other person drives the car daily and holds the title. Journalists have documented cases where survivors were tracked this way for months, and found that transferring or removing an account often required navigating a customer service process that wasn’t built for the situation.

If this applies to you, the practical move is to contact the manufacturer’s connected-services line directly and ask specifically about removing all other authorized users and resetting the account tied to the VIN. Local domestic violence advocates increasingly know these procedures. The Safety Net project at the National Network to End Domestic Violence maintains guidance on vehicle technology.

Do this today

3. Location tracking & driving behavior

The basics

Two distinct things get recorded. Location is where the car has been, often as a trip-by-trip log with timestamps. Behavior is how it was driven: hard braking, rapid acceleration, sharp cornering, speed relative to limits, seatbelt use, sometimes late-night driving as its own flagged category.

Go deeper

What most people don’t know

Driving behavior data was flowing to insurers, and drivers found out because their premiums went up.

In 2024, reporting in The New York Times documented that General Motors had been sharing driving data, including hard braking and acceleration events and trip details, with LexisNexis Risk Solutions and Verisk, data brokers that in turn compiled it into reports sold to insurance companies. Drivers described being quoted higher rates or denied coverage without understanding why. Many said they had never knowingly enrolled; in some accounts the feature was activated during the dealership sales process.

The fallout: GM ended those data-sharing arrangements and later discontinued the driving-score program entirely. The Texas Attorney General sued GM. U.S. senators referred multiple automakers to the FTC. Class actions followed.

The lesson generalizes past GM. The mechanism, OEM to broker to insurer with consent buried in a dealership signature, is structural rather than one company’s mistake.

Do this today

4. Data sharing with manufacturers and third parties

The basics

Data leaves your vehicle along more paths than most drivers picture: to the manufacturer, to its corporate affiliates, to analytics and mapping vendors, to dealerships, to data brokers, and to whoever those brokers sell to.

Go deeper

What most people don’t know

There is off-the-shelf forensic hardware for extracting your car’s memory, and it isn’t restricted to police.

Vehicle forensics tools, the best-known being Berla’s iVe system, connect to a car’s infotainment and telematics modules and extract stored data: location history and trip logs, paired device identifiers, contacts and call logs pulled from phones, door and ignition events, sometimes even track names. Investigators use it to reconstruct where a vehicle went and who was in it, and it’s marketed to police, private investigators, and insurance investigators.

The security-professional insight here: your car is a device with unencrypted local storage and a physical access port, and the tooling to image it is commercially mature. If you think about disk encryption on your laptop, your vehicle’s infotainment module is a comparable data store with none of the protection.

Do this today

5. Protecting your privacy on the road

The basics

You can’t unplug a modern car’s modem without consequences, since it typically also powers emergency crash notification. So the realistic strategy is limiting what you feed it and controlling the accounts around it.

Go deeper

What most people don’t know

Rental and shared vehicles are the highest-risk category, and almost no one resets them.

A rental car’s infotainment often holds a stack of previous drivers’ contact lists, phone numbers, and navigation history. When you pair, yours joins the pile and stays after you return the keys. The same applies to car-sharing services, loaners from the dealership, and any vehicle you drive for a few days.

Fixing it is quick if you know where to look: before returning the vehicle, go into Bluetooth settings, delete your device, and if the system offers a factory reset, use it. And take one look at what’s already stored. Seeing three strangers’ address books in a rental Nissan is the kind of thing that changes behavior permanently.

Do this today

6. Security, updates, and remote access

The basics

A connected car is remotely reachable, which means it has an attack surface. Install updates. Over-the-air updates are how manufacturers close the holes, and declining them leaves known vulnerabilities in place.

Go deeper

What most people don’t know

Your manufacturer app account is, functionally, a spare key.

Whoever holds those credentials can locate the vehicle, unlock it, and in many models start it. That makes your car’s security dependent on the same password hygiene as your email, and most people have never thought of it in those terms.

This is also the used-car gap. When ownership changes, the digital relationship often doesn’t cleanly transfer. A previous owner whose account was never unlinked may retain remote access to a car that is no longer theirs, indefinitely, without doing anything wrong or even realizing it.

Do this today

7. Your rights & choices as a driver

The basics

In the U.S. there’s no comprehensive federal vehicle privacy law. What you have is a patchwork: state consumer privacy laws, federal fair-credit rules that apply when data affects your insurance or credit, and whatever the manufacturer’s own policy grants.

Go deeper

What most people don’t know

If driving data affected your insurance, federal law is on your side in a specific and useful way.

When a company uses a consumer report to raise your rate or deny you coverage, the federal Fair Credit Reporting Act gives you two things: the right to be told (an adverse action notice) and the right to see the file. The brokers compiling driving behavior into insurance reports are consumer reporting agencies for this purpose, which means you can demand your file for free, once a year, and dispute inaccuracies in it.

Most drivers affected by the telematics-to-insurer pipeline never invoked this, because they didn’t know the report existed. Requesting your file is the closest thing to an audit log for your own driving history.

Do this today

Recap

Key terms

Check your understanding

1. You never installed your car’s app. Is your vehicle transmitting data to the manufacturer? Almost certainly yes. The cellular modem is built into the car and operates independently of any app you install or skip.

2. You’re returning a rental car tomorrow. You paired your phone on day one. What should you do? Delete your device from the car’s Bluetooth list and run a factory reset of the infotainment system if the option exists. Your contacts and call history are stored on the vehicle, not just linked to it.

3. Your insurance premium jumped and you suspect driving data was involved. What are you entitled to? An explanation, and a free copy of the consumer file used to make that decision. Request your file from the data brokers compiling driving behavior. Under federal fair-credit law, you can see it and dispute errors.

Next lesson: AI & Digital Identity — digital twins, AI profiling, facial recognition, and more.