Court Rules
All enforcement actions
SettlementCritical Risk

General Motors Privacy Settlement for Connected Vehicle Data Sharing

General MotorsMay 1, 2026California Privacy Protection Agency

Penalty Amount

$12,750,000

Summary

CalPrivacy and the California Attorney General secured a $12.75 million settlement from General Motors for data sharing practices from connected vehicles. The settlement includes injunctive terms to change business practices.

Remedy

General Motors must pay a $12.75 million civil penalty and comply with injunctive terms to address data sharing practices from connected vehicles.

Monetary PenaltyInjunction

Contract Impact

In-house legal teams should review vendor agreements with telematics providers, connected vehicle service providers, and data processors to ensure data sharing practices are clearly disclosed and authorized. Key clauses to examine include data processing agreements, consent mechanisms, opt-out procedures, and any provisions allowing sharing of vehicle data with third parties. Contracts should be updated to align with CCPA requirements, including explicit consumer consent for data sharing and robust opt-out mechanisms.

Contract Search Terms

connected vehicle datadata sharing agreementtelematics dataconsumer consentopt-out mechanismprivacy policydata processing agreementvehicle data collection

Laws Cited

CCPACalifornia Consumer Privacy Act

Violation Types

Entity Details

Entity

General Motors

Industry

Automotive

Official Sources

Source Evidence

Entity Name
"General Motors"
Fine Amount
"$12.75 million civil penalty"
Violation Types
"data sharing practices from connected vehicles"

Related Enforcement Actions

CA

General Motors

$12.8M

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.

TX

General Motors

Texas Attorney General Ken Paxton filed a lawsuit against General Motors for unlawfully collecting private driving data from over 1.5 million Texas drivers without consent and selling the data to third parties including insurance companies. GM allegedly deceived customers into enrolling in products like OnStar Smart Driver by falsely claiming enrollment was required to retain vehicle safety features, while concealing that enrollment authorized systematic collection and sale of detailed driving data. The action follows an investigation launched in June 2024 as part of the Texas AG’s data privacy initiative, and seeks to hold GM accountable for violating state privacy laws.

CPPA

Data brokers (unspecified - advisory applies to all businesses registered with California's data broker registry)

CalPrivacy (the California Privacy Protection Agency) issued Enforcement Advisory 2026-01 warning data brokers that providing incorrect information in their annual registration with California's data broker registry carries liability of a $200 fine per day. The advisory observes that the Enforcement Division has already brought multiple enforcement actions over reporting errors, and emphasizes that accurate registry disclosures are what make the newly launched Delete Request and Opt-Out Platform (DROP) work for Californians. No specific company was named and no penalty was imposed by the advisory itself; it functions as forward-looking guidance.

CPPA

SalesIntel Research, Inc.

$36K

The California Privacy Protection Agency Board issued a Decision and Final Stipulated Order requiring Virginia-based data broker SalesIntel Research, Inc. to pay a $36,400 fine for operating as a data broker without registering by the 2025 deadline under the Delete Act. SalesIntel sells consumer personal information, including more than 200 million professional contacts and de-anonymized website traffic data, for targeted advertising. In addition to the fine, the company must post privacy rights metrics on its website, integrate with CalPrivacy's Delete Request and Opt-out Platform (DROP), and process future deletion requests through that system.

CPPA

Data brokers registered on California's DROP platform (654)

The California Privacy Protection Agency announced that more than 500,000 Californians have registered for the Delete Request and Opt-out Platform (DROP) since its January 1, 2026 launch. After the August 1, 2026 deadline for brokers to begin processing requests, 654 data brokers are in the system and approximately 25% have reported processing deletion requests, with tens of millions of records already deleted. No enforcement action has been announced yet; the agency warned that brokers who fail to delete eligible personal information face significant fines.

CPPA

Cybba, Inc.

$52K

The California Privacy Protection Agency Board issued an Order of Decision and Stipulated Final Order requiring Boston-based data broker Cybba, Inc. to pay a $52,400 fine for failing to register with the Agency's Data Broker Registry by the 2025 deadline, as required by the Delete Act. The order also requires Cybba to post metrics about privacy rights on its website, access the Agency's Delete Request and Opt-Out Platform (DROP), and process future deletion requests through that system. This is CalPrivacy's second data broker enforcement action announced in less than a week, following its action against LocateSmarter.