Data privacy in smart mobility

Data privacy

Updated September 2, 2026 · 4 min read

Key Takeaways
  • Data privacy in smart mobility became a real enforcement issue in 2026: the FTC’s GM/OnStar settlement finalized in January 2026 bans selling geolocation and driver data to consumer reporting agencies for five years.
  • Precise geolocation, driver behavior, and algorithmically derived telematics data are now treated as sensitive personal information by regulators.
  • State rules vary widely — Oregon and Maryland already ban selling precise geolocation data, with Virginia and others considering similar bans in 2026.
  • No single federal privacy law covers connected vehicles yet — the Auto Data Privacy and Autonomy Act hadn’t passed as of July 2026.

Data privacy in smart mobility moved from a theoretical concern to active enforcement in 2026. A connected car generates a continuous stream of geolocation, driving-behavior, and biometric-adjacent data — and regulators have started treating that data the same way they treat other sensitive personal information, with real consequences for automakers that mishandle it.

connected car dashboard showing data privacy in smart mobility concerns

The GM/OnStar Case That Changed the Landscape

DetailOutcome
FTC agreement reachedJanuary 2025
FinalizedJanuary 2026
Key restriction5-year ban on disclosing geolocation and driver-behavior data to consumer reporting agencies
New requirementMust obtain consent, protect data, and let customers disable geolocation collection

This case set the template: automakers had reportedly been sharing detailed driving data with insurance-adjacent data brokers without clear consumer knowledge, and the FTC treated that as a real privacy violation, not a gray area.

What Counts as Sensitive Data Now

telematics data collection representing data privacy in smart mobility
  • Precise geolocation — where the car goes and when, at a granular level.
  • Driver behavior metrics — braking patterns, speed, acceleration, used for scoring driver risk.
  • Algorithmically derived telematics data — inferences and scores computed from raw sensor data, treated as sensitive even though it’s not raw personal data itself.

A Patchwork of State Rules

StateStatus
Oregon2025 law update covers vehicle manufacturers/affiliates processing driver data
MarylandBans sale of precise geolocation data
Virginia (SB 338, pending)Would join Oregon and Maryland in banning geolocation data sales
Other statesExpected to consider similar bans in the 2026 legislative session

There’s no single national standard yet — automakers selling nationwide have to navigate a growing, inconsistent patchwork of state-by-state rules rather than one federal framework.

Where Federal Legislation Stands

The Auto Data Privacy and Autonomy Act, introduced in December 2025, would limit manufacturers’ ability to access or share covered vehicle data without consent — but as of July 2026, it had not become law. Until (or unless) it passes, connected-vehicle privacy remains governed by a mix of FTC enforcement actions and state-specific statutes rather than one clear federal rule.

What This Means for Drivers and Automakers

driver reviewing vehicle data privacy settings on connected car app

Drivers in states with geolocation-sale bans have stronger legal protection than those without one. For automakers, the direction is unambiguous: 2026 brought more aggressive FTC enforcement, more state-specific rules, and rising pressure to demonstrate real data stewardship — treating consent, disclosure, and opt-out mechanisms as compliance requirements rather than optional features.

One-Minute Recap

  • FTC’s GM/OnStar settlement (finalized Jan 2026) set a real enforcement precedent, not just guidance.
  • Geolocation, driver behavior, and derived telematics scores now count as sensitive data.
  • Oregon and Maryland already restrict geolocation data sales; more states are following in 2026.
  • No unified federal law exists yet — the Auto Data Privacy and Autonomy Act remains pending as of mid-2026.

Related guides: Connected Vehicles and Intelligent Transportation, V2G Infrastructure Standards, EV Charging Cost by State

What data privacy issues exist with connected cars?

Connected vehicles collect precise geolocation, driver behavior metrics (braking, speed, acceleration), and algorithmically derived risk scores — data now treated by regulators as sensitive personal information requiring consent and protection.

What happened with the FTC and GM/OnStar?

The FTC reached an agreement with GM and OnStar (finalized January 2026) banning disclosure of geolocation and driver-behavior data to consumer reporting agencies for five years and requiring consent and an opt-out for geolocation collection.

Do any states ban selling car location data?

Yes. Oregon and Maryland already restrict or ban the sale of precise geolocation data from vehicles, and Virginia’s SB 338 would add Virginia to that list, with more states expected to consider similar bills in 2026.

Is there a federal law protecting connected vehicle data?

Not yet. The Auto Data Privacy and Autonomy Act was introduced in December 2025 but had not passed as of July 2026, leaving regulation to a mix of FTC enforcement and state-level statutes.

Can I stop my car from collecting location data?

It depends on the manufacturer and where you live. The FTC’s GM/OnStar settlement now requires GM specifically to let customers disable geolocation data collection; policies vary by automaker and state law elsewhere.

Why is driver behavior data considered sensitive?

Because it can be used to score risk, influence insurance rates, or be sold to third parties like consumer reporting agencies — regulators increasingly treat it the same as other sensitive personal data categories.

Sources and Further Reading

Written and edited by , Founder and Editor · LinkedIn · How we source and correct this site · Report an error

Leave a Comment

Your comment will be published after it has been approved. Please send comments that do not contain slang words.