This is the data picture, not the stalking response
Your car knows where you’ve been covers what to do if you think a specific person — an ex, an abuser — is using a hidden GPS tracker or a connected-car app to follow you right now. Start there if that’s your situation. This guide is different: it’s about the ordinary data your car generates every time you drive it, who else gets to see it, and what you can do about it whether or not anyone is targeting you specifically.
Four systems matter here, and they’re mostly independent of each other: the crash recorder required by federal safety rules, the infotainment system that syncs with your phone, the telematics platform that can score how you drive, and the ecosystem of buyers — insurers, data brokers, marketers — that some of that data reaches.
The crash recorder: what an EDR actually captures
Many cars built in the last two decades have an event data recorder (EDR), sometimes called a “black box,” built into the airbag control module — NHTSA does not require every vehicle to carry one. Federal regulation 49 CFR Part 563 sets uniform requirements for what these devices record and how, applying to passenger cars and other light vehicles with a gross vehicle weight rating of 3,855 kilograms (8,500 pounds) or less that are equipped with one (49 CFR 563.3, Application).
Here’s the part people misunderstand most: an EDR is not a continuous trip logger. It’s a narrow, crash-specific device. NHTSA’s regulatory evaluation of the rule explains that it captures a vehicle’s dynamic data “during the time period just prior to a crash event… or during a crash event,” for retrieval after the fact — and by definition, event data “does not include audio and video data” (49 CFR 563.5, Definitions). A Subaru service bulletin filed in NHTSA’s public database, quoting the vehicle owner’s manual, is direct about the trigger condition: “EDR data is recorded by your vehicle only if a non-trivial crash situation occurs. No data is recorded by the EDR under normal driving conditions and no personal data (e.g. name, gender, age or crash location) are recorded” (Subaru service bulletin, filed with NHTSA).
What does get captured, when a crash-level event does trigger recording? The rule requires up to 15 essential data elements — vehicle speed, engine throttle position, whether the brake was applied, seat belt status, steering input, and airbag deployment timing among them — plus up to 30 additional elements where the vehicle already has the sensors, all in a standardized format (NHTSA regulatory evaluation). NHTSA’s technical review of how manufacturers implement the rule found the elements most commonly recorded include lateral delta-V (change in sideways velocity), engine RPM, seat belt status, and airbag timing, over a specified interval of “0 to 250 ms or 0 to End of Event Time plus 30 ms, whichever is shorter” (NHTSA, “Light-Vehicle Event Data Recorder Technologies”). The Subaru bulletin puts the recording window at “typically 30 seconds or less” around the event (Subaru service bulletin, filed with NHTSA).
Who owns this data, and who can pull it? There’s no single national answer — EDR ownership is governed state by state. Oregon’s statute, quoted in a NHTSA rulemaking docket comment compiling state EDR privacy laws, illustrates one state’s approach: “The data on a motor vehicle event data recorder is exclusively owned by the owner of the motor vehicle and may not be accessed or used by any person other than the owner of the motor vehicle without the written consent of the owner. If a motor vehicle is owned by more than one person, all owners must consent” (EPIC/privacy coalition comment to NHTSA, compiling state statutes). Other states word this differently, and law enforcement’s ability to obtain the data with a warrant varies by state too. In practice, EDR data is pulled almost exclusively after a crash, using a manufacturer-licensed retrieval tool, for insurance claims, litigation, or a criminal investigation — not day-to-day tracking.
The infotainment system is a different animal
The dashboard touchscreen that pairs with your phone is not the EDR, and it holds far more personal information for far longer. When you connect a phone by Bluetooth or USB, many infotainment systems cache data from it so the car can display a contact’s name on an incoming call or read a text aloud without a live connection every time.
The FTC has warned consumers about this directly, specifically in the rental-car context: “Many newer rental cars have so-called ‘infotainment’ tech that lets you connect your phone to the car directly… a rental car with these features might keep your personal information long after you’ve returned the car. This information might include locations you put into your GPS… your phone number, call and message logs, or even contacts and text messages. Unless you delete that data before you return the car, future renters or rental car employees may be able to see it” (FTC Consumer Advice, “Renting a Car”).
This isn’t hypothetical. Peer-reviewed forensic research on the NTG5-generation Mercedes-Benz infotainment platform — deployed in Mercedes-Benz vehicles from 2013 to 2019 — found investigators could extract geographic locations and vehicle events like door openings “dating back to the previous 8 months,” cross-referenced “to precisely identify the activities and habits of the driver,” including data the system had already logically deleted (Stabili, Valgimigli & Marchetti, “I know where you have been last summer,” Forensic Science International: Digital Investigation (2025)). That’s also why the Department of Homeland Security funded Project iVe, a commercial forensic toolkit for law enforcement: DHS describes it as able to “acquire data from mobile devices such as smartphones, media players, USB drives and SD cards that have been connected to a supported vehicle’s infotainment system,” separate from the crash-specific EDR (DHS Science and Technology fact sheet, Project iVe).
Telematics: the always-on layer
Beyond the crash recorder and the infotainment cache, many new vehicles from major automakers now ship with a telematics platform — a cellular-connected system that can report location, trip history, and vehicle diagnostics continuously, tied to an account rather than a crash trigger. That’s a meaningfully different design from the EDR, which only activates in a crash-level event and doesn’t record audio or video; telematics can transmit continuously as long as the connected service is active. Your car knows where you’ve been covers how that account-based access becomes a tracking risk when someone else controls the login. The data-privacy angle is what that connection makes possible at scale: driving-behavior scoring, and the sale of that scoring to insurers.
How driving data ends up affecting your insurance bill
In March 2024, the New York Times reported that a Cadillac owner named Mr. Dahl was surprised by a 21 percent jump in his car insurance premium, and traced it to a 258-page “consumer disclosure report” from LexisNexis — a legally mandated disclosure under the Fair Credit Reporting Act — that included “over 130 pages” detailing nearly every trip he or his wife had taken in their Chevy Bolt: “the number of trips, the start and end times, the distance traveled, as well as records of any rapid accelerations, hard braking, or sudden speed increases” (New York Times, “Automakers Are Sharing Consumers’ Driving Behavior With Insurance Companies”). The source was GM’s OnStar Smart Driver feature — a “complimentary gamified” feature inside GM’s brand apps that awards badges like “brake genius” for good driving habits, per the same Times investigation.
GM confirmed to the Times that it shared “select insights” — hard braking, rapid acceleration, speeding over 80 mph, and drive time — from Smart Driver participants with LexisNexis and with a second data broker, Verisk, and that customers could opt out of Smart Driver at any time. Some GM drivers said they’d been tracked even though they hadn’t activated Smart Driver themselves, resulting in higher rates, and the Times found eight insurance companies had requested information about Mr. Dahl from LexisNexis in a single month. GM wasn’t the only automaker involved, and the two brokers had separate relationships: Kia, Subaru, and Mitsubishi also contributed driving data to LexisNexis’ “Telematics Exchange” platform, while Verisk separately had partnerships with automakers including Ford, Honda, and Hyundai.
The federal government followed up on the underlying practice, not just the headline. In a settlement finalized in January 2026, the FTC alleged that GM and OnStar had “collected, used, and sold consumers’ precise geolocation data and driving behavior data from millions of vehicles without adequately notifying consumers and obtaining their affirmative consent,” via a misleading enrollment process for OnStar and Smart Driver. The final order bans GM from disclosing geolocation and driving-behavior data to consumer reporting agencies for five years, and for the full 20-year life of the order requires GM to get affirmative express consent before collecting or sharing connected-vehicle data, let consumers request and delete their data, and offer a way to disable precise geolocation collection (FTC press release, January 2026).
Mozilla’s verdict: cars are the worst product category it has ever reviewed
In September 2023, Mozilla’s Privacy Not Included project reviewed the privacy practices of 25 major car brands and gave every single one its warning label — a first in the buyer’s guide’s history. Mozilla’s summary is blunt: “All 25 car brands we researched earned our *Privacy Not Included warning label — making cars the official worst category of products for privacy that we have ever reviewed” (Mozilla Foundation, “It’s Official: Cars Are Terrible at Privacy and Security”).
The findings, in Mozilla’s words:
- All 25 brands collect more personal data than necessary to operate the vehicle or manage the customer relationship.
- 84 percent say they can share personal data with service providers, data brokers, or other businesses; 76 percent (“nineteen”) say they can sell it outright.
- 56 percent say they’ll share data with government or law enforcement on request — and the bar for some brands is not a court order but, in Mozilla’s words, an “informal request.”
- 92 percent give drivers little to no meaningful control over their own data; only Renault and Dacia (Europe-only, GDPR) said all drivers can have their data deleted.
- Researchers “couldn’t confirm whether any of the brands meet our Minimum Security Standards” — including whether any brand encrypts all personal data stored on the vehicle.
The categories went well beyond driving itself. Mozilla found Nissan’s privacy policy included “sexual activity” among the “creepiest categories of data” it reviewed, and that Kia’s policy “also mentions they can collect information about your ‘sex life’” (Mozilla Foundation, “It’s Official: Cars Are Terrible at Privacy and Security”). Consent is often presumed, too — Subaru’s own policy states: “The moment you sit in the passenger seat of a Subaru that uses connected services, you’ve consented to allow them to use — and maybe even sell — your personal information” (Mozilla Foundation, Subaru review).
What you can actually do
There’s no single setting for all of this — it’s four separate systems, and the response differs for each.
You generally can’t opt out of the EDR itself. By rule, it records only during a crash-like event and doesn’t capture audio or video (49 CFR 563.5), and in many states, statutes give ownership of that data to you as the owner (EPIC/privacy coalition comment to NHTSA) — that’s separate from telematics, which can report continuously while a connected service is active. There’s little to manage on the EDR day to day; your telematics settings are where the ongoing exposure lives.
Check your telematics privacy settings and connected-services enrollment. Automaker apps (myChevrolet, myGMC, myBuick, myCadillac, and equivalents from other brands) typically have a settings or “Data & Privacy” menu where you can review and disable features like OnStar Smart Driver — worth doing even if you don’t remember signing up, since dealership enrollment at purchase is common. If someone else controls that account against you, Your car knows where you’ve been walks through that scenario, and Safety first: before you remove anything covers the tradeoffs of acting on a shared account before you’re ready.
Before you sell, trade in, or return a rental car, clear the infotainment system. The FTC’s rental-car guidance applies just as well to a car you’re giving up permanently: avoid connecting your phone just for charging (a cigarette lighter adapter avoids the USB data link entirely); if you do connect, grant only the permissions you need; and before handing over the car, find the list of paired devices in settings and delete yours (FTC Consumer Advice, “Renting a Car”). Consumer Reports echoes the core step — unpair all Bluetooth devices before you hand over the keys — and recommends your owner’s manual for model-specific instructions, since the menu path varies by manufacturer (Consumer Reports, “Wipe Data From Your Car Before Selling It”). Some automakers publish their own deletion guidance; Toyota’s UK owner support page, for example, walks through deleting personal data — contacts, call history, saved destinations — from its navigation systems and disconnecting the MyToyota account before a sale (Toyota UK, “Personal Data Deletion”); US owners should check Toyota’s US app and owner’s-manual guidance, since menus differ by market.
Treat rental cars the same way going in, not just coming out. The FTC’s advice cuts both directions: the data left behind by a prior renter is exactly the risk you’re taking on if you pair your own phone. Skip the sync if you don’t need it, and delete the pairing before you return the keys.
Most of what your car collects is never going to be used against you specifically. But between a federal crash-data rule that only some people realize exists, an infotainment cache that holds far more than most drivers expect, and a driving-score pipeline that reached insurers without most customers’ clear understanding, “connected car” has quietly become a data business with your commute as the product.