← IoT Privacy Database

Volvo Cars / Polestar Connected Vehicle

Volvo Cars · Connected Car

✓ Reviewed

4.8Surveillance
Index
Policy — what its policy permitsD
Evidence — what research provesD

Volvo and Polestar connected cars run Google built-in and a Volvo/Polestar account that collect precise location, driving and charging behavior, in-car voice, and (in newer models) driver-monitoring camera data, tied to your identity. Both firms' privacy notices acknowledge that sharing personal data with advertising, analytics and social partners may constitute a 'sale' under California law, though they do provide an opt-out. Compared with mass-market peers they are relatively transparent and offer clearer opt-out tooling, but the underlying data collection is still extensive.

Why this rating

Both notices concede sharing for advertising 'may be a sale' under CCPA (sells-data), disclose to analytics/social/advertising partners (broker-disclosure), and collect precise location and voice (sensitive-collection); a functional opt-out avoids the no-opt-out penalty and lifts the score above peers. Evidence: Volvo confirmed a 2021 breach in which R&D data was stolen (major-breach), but that was corporate IP, not customer telematics; there is otherwise little independent study of Volvo/Polestar consumer-data practices, so the consumer-privacy record is largely unstudied.

What it is

Manufacturer
Volvo Cars
Category
Connected Car
Model years
2021-present
Market status
Current
Companion app
Volvo Cars app / Polestar app

The evidence 2

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Ngo review · Mozilla Foundation · 2023-09

    Mozilla flunked all 25 car brands reviewed, including Volkswagen and Audi, for over-collection and selling/sharing personal data.

    Why it matters here: Category-level context for Volvo/Polestar's connected platform; not a brand-specific finding.

  2. Breach report · BleepingComputer · 2021-12

    The Snatch extortion group stole a limited amount of Volvo Cars R&D property from a file repository, which Volvo confirmed after samples were leaked.

    Why it matters here: Shows a data-protection failure at the manufacturer, though the stolen material was R&D IP rather than customer telematics data.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database