Today’s vehicles are computers on wheels. They can collect far more than diagnostic information, including precise location, driving behavior, phone data, and activity through connected apps. Most customers probably do not think about all of that when they drive off the lot….Regulators are.
In May 2026, California announced a $12.75 million settlement with General Motors over allegations that GM unlawfully sold driving and location data collected through its OnStar connected-car service. California described it as the largest California Consumer Privacy Act penalty in state history to date and its first enforcement action involving data-minimization requirements.
That came just months after the Federal Trade Commission finalized an order resolving allegations that GM and OnStar collected and sold precise geolocation and driving-behavior data without adequately informed consumer consent. Among other requirements, the order restricts certain disclosures and requires greater transparency and consumer choice around connected-vehicle data. Those cases were aimed at GM and OnStar, not dealerships.
Still, dealers should pay attention because the dealership is often where customers first encounter these technologies. Employees help activate connected services, pair phones, set up manufacturer apps, and program garage-door codes. Dealers also take in trade-ins and manage loaner vehicles that may already contain someone else’s personal information. The dealership does not need to solve the entire connected-car privacy problem on its own. It does need to know where connected-vehicle data shows up in daily operations and whether those touchpoints are being handled correctly.
Here are five questions worth asking.
1. What information is the vehicle actually collecting?
Dealerships do not need a technical data map for every model on the lot. They should, however, have a basic understanding of the connected features their employees help customers activate. A vehicle may collect precise location, driving behavior, phone information, or activity through a manufacturer’s connected app. Some of that information can be sensitive. Precise location data, for example, can reveal where someone lives, works, or regularly visits.
For dealers, the practical issue is often what employees say about those features. A salesperson or delivery specialist should be careful about telling a customer, “The vehicle doesn’t track you,” or “That information stays in the car,” unless the dealership actually knows that to be true. Dealers do not need to explain every technical detail. They do need to avoid making promises about data practices they do not control.
2. Is the customer really choosing to activate the service?
Think about how much is happening during a typical vehicle delivery. The customer may be signing paperwork, connecting a phone, downloading an app, and learning several new features at once. Connected-service enrollment can quickly become one more screen to click through. That is where dealers should be careful. The GM enforcement actions focused in part on whether consumers understood how their information would be collected and used and whether meaningful consent had been obtained. The FTC’s final order requires affirmative express consent before GM collects, uses, or shares certain connected-vehicle data, subject to specified exceptions.
For a dealership, the lesson is simpler: if a service is optional, present it that way. Give the customer enough information to understand what is being activated and allow the customer to make the choice.
Dealers should also look at employee incentives. If staff are measured on connected-service activation rates, make sure those goals do not unintentionally encourage employees to rush customers through enrollment or make an optional service feel mandatory. The goal is not to turn vehicle delivery into a privacy seminar. It is to make sure the customer understands what they are agreeing to.
3. Does any of this information make its way into dealership systems?
This is where connected-car privacy can intersect with the dealership’s own information-security obligations.
Vehicle-generated data is not automatically customer information under the FTC Safeguards Rule. The Rule generally protects nonpublic personal information obtained in connection with a financial product or service, such as dealership-arranged financing or leasing. The FTC has also explained that ordinary service or maintenance records generally are not covered customer information unless they are combined with information protected by the Rule.
However, dealership technology does not always keep those categories neatly separated. A connected-service platform may integrate with a CRM, DMS, or another dealership system that also contains protected customer information. The FTC’s dealer guidance makes clear that Safeguards obligations extend to information systems containing customer information as well as systems connected to them. That makes the dealer’s job relatively straightforward: understand the connection points.
Know whether connected-vehicle information enters dealership systems, which employees can access those systems, and which vendors sit in the middle. Do not assume that because a technology started as a vehicle feature, it automatically—or permanently—sits outside the dealership’s information-security program.
4. What happens to the last driver’s information when the vehicle changes hands?
This may be the easiest connected-car privacy problem for a dealership to picture. A trade-in can arrive with the previous owner’s phone still paired and garage-door codes still stored. A loaner can retain someone’s recent navigation destinations. A vehicle may even remain connected to a former owner through a manufacturer app after it has been resold.
The FTC has specifically advised consumers to clear stored personal information and disconnect app connections when selling or trading in a vehicle. Dealerships should build the same concept into their own vehicle-handling and reconditioning processes. Before a trade is retailed, a loaner goes to another customer, or a demo is reassigned, someone should be responsible for checking and clearing personal information from the vehicle.
A factory reset of the infotainment system may help, but it may not remove every account or remote connection. Manufacturer instructions should be followed when available. Most importantly, assign responsibility. If sales assumes service handles it, service assumes recon handles it, and recon assumes the customer already did it, nobody actually owns the privacy risk.
5. Are connected-vehicle vendors part of your vendor-management process?
Connected-car technology can introduce another company into the dealership’s data environment. A dealer may rely on outside providers for telematics, loaner management, inventory tracking, or other connected-vehicle services. The important question is not how impressive the technology is. It is what information the vendor can access and what the vendor is allowed to do with it.
When a vendor receives, maintains, processes, or can access customer information protected by the Safeguards Rule while providing services to the dealership, the Rule’s service-provider requirements apply. Dealers must take reasonable steps to select capable providers, require appropriate safeguards by contract, and periodically assess those providers based on the risk they present.
For other connected-vehicle vendors, similar questions still make good privacy sense even when the Safeguards Rule may not apply. What information does the vendor receive? Why does it need it? Who else receives it? What happens to the information when the relationship ends? Cybersecurity is only part of the review. A vendor can do a good job protecting information from hackers and still use that information in ways the dealership or customer did not expect.
Connected-Car Privacy Is Becoming a Dealership Issue
The GM enforcement actions do not make dealerships responsible for every data practice of every automaker or connected-services provider. They do show where regulators are focused: sensitive vehicle data, meaningful consent, unexpected data sharing, and unnecessary retention. For dealers, the starting point does not need to be complicated. Bring together dealership leadership, IT, the Qualified Individual, sales, service, F&I, and legal counsel and ask one question: Where does connected-vehicle data touch our dealership?
Look at what employees activate, what dealership systems receive, which vendors can access the information, and what happens to personal data when a vehicle changes hands.
You do not need to understand every line of code inside a modern vehicle. But you do need to understand where your dealership touches the data.
This article is provided for informational purposes and is not legal advice. Dealerships should consult qualified legal counsel regarding their specific practices and applicable federal and state privacy requirements.