HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

GM Settles $12.75 M for Illegal Sale of California Drivers’ Location Data

California Attorney General fined General Motors $12.75 million after discovering that its OnStar telematics platform collected and sold precise driver location data to data brokers without consumer consent, breaching CCPA. The settlement mandates a five‑year sales ban, data deletion, and enhanced privacy controls, underscoring third‑party risk for firms that ingest vehicle‑derived data.

LiveThreat™ Intelligence · 📅 May 12, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

GM Settles $12.75 M for Illegal Sale of California Drivers’ Location Data

What Happened – California regulators fined General Motors $12.75 million after uncovering that its OnStar “Smart Driver” system collected precise driving and location data from California residents and sold it to data‑brokers Verisk Analytics and LexisNexis Risk Solutions between 2020‑2024, in violation of the California Consumer Privacy Act (CCPA).

Why It Matters for TPRM

  • Demonstrates that vehicle‑telemetry platforms can become vectors for unlawful data commercialization.
  • Highlights regulatory risk for third‑party data‑sharing arrangements, especially when consent and data‑minimization controls are weak.
  • Sets a precedent for hefty civil penalties and mandatory remediation actions that can affect supply‑chain contracts.

Who Is Affected – Automotive manufacturers, telematics service providers, data‑broker intermediaries, insurers that rely on driver‑scoring data, and any downstream vendors that ingest GM‑derived datasets.

Recommended Actions

  • Review contracts with automotive OEMs and telematics vendors for CCPA‑compliant data‑handling clauses.
  • Verify that any third‑party data you receive from vehicle‑derived sources includes documented consumer consent and retention limits.
  • Conduct a privacy‑impact assessment (PIA) on any driver‑behavior analytics you ingest or store.

Technical Notes – The violation stemmed from systematic collection of GPS‑level location and driving‑behavior metrics via OnStar, followed by bulk transfer to external brokers without explicit consumer consent. No technical exploit was involved; the risk was procedural and governance‑related. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/legal/gm-agrees-to-1275m-california-settlement-over-sale-of-drivers-data/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.