Modern cars can record far more than mileage and fuel use. Connected vehicles may collect precise location histories, speed, braking patterns, acceleration, seatbelt use, phone connections and information entered into navigation or entertainment systems.
Privacy researchers have warned that many automakers can share or sell at least some of this information to data brokers, advertisers, service providers or other third parties. Oregon has now responded with a state law designed specifically to give vehicle owners stronger control over data collected by their cars.
The Oregon measure requires covered automakers to let consumers access their vehicle data, request its deletion and stop certain sales of personal information for targeted advertising. It represents one of the first state laws to address connected-car privacy directly rather than relying entirely on broader consumer-data rules.
Modern Cars Have Become Data-Collection Platforms
A connected vehicle is effectively a network of computers, cameras, sensors and wireless communication systems. These technologies support useful functions such as emergency assistance, navigation, remote starting, predictive maintenance and collision warnings.
The same technology can also create a detailed record of how and where the vehicle is used.
Location data may reveal where someone lives, works, attends religious services, receives medical treatment or takes children to school. Driving-behavior data can show how quickly the vehicle accelerates, how hard it brakes and whether it travels late at night.
Information can come from the vehicle itself, a manufacturer’s mobile app, an infotainment system or a phone paired through Bluetooth, Apple CarPlay or Android Auto. Some systems continue communicating with the manufacturer even when the driver is not actively using a connected service.
An academic review of Android Automotive systems found that vehicles could collect large numbers of vehicle properties, including speed, climate settings and seat-related data. Researchers also found gaps between some data observed in the system and what manufacturers disclosed in their privacy policies.
Most Major Car Brands Have Broad Data-Sharing Policies
A widely cited Mozilla Foundation investigation examined the privacy policies of 25 major automotive brands. None met the organization’s minimum privacy standards.
Nineteen of the 25 manufacturers stated that they could sell personal information, while many reserved the right to share data with service providers, business partners, governments or law-enforcement agencies. Only two brands in the review offered drivers a clear right to request deletion of their information, and those brands were not sold in North America.
The research did not prove that every manufacturer sells every piece of information it collects. Privacy policies generally describe what a company is legally permitted to do, which may be broader than its day-to-day practices.
Still, the findings showed that consumers had limited visibility into where vehicle data went after collection. Automakers frequently used general terms such as affiliates, partners, service providers or marketing companies without identifying every recipient.
The full Mozilla findings are available through its Privacy Not Included vehicle research, which explains how individual brands describe their collection and sharing practices.
Driving Data Has Already Reached Insurance Systems
Concern about connected-car data became more urgent after investigations revealed that some driving information had been supplied to consumer-reporting companies.
The Federal Trade Commission alleged that General Motors and its OnStar subsidiary collected precise location and driving-behavior information through a misleading enrollment process. According to the agency, the data included instances of speeding, hard braking and late-night driving and was provided to consumer-reporting agencies that supplied information to insurance companies.
GM later discontinued its Smart Driver program and ended relationships with the data brokers LexisNexis Risk Solutions and Verisk Analytics. A finalized federal order prohibits the companies from sharing certain location and driving-behavior data with consumer-reporting agencies for five years and requires stronger consent and deletion options.
California separately reached a proposed $12.75 million settlement with GM over allegations that the company sold detailed information about hundreds of thousands of drivers without proper knowledge or consent. The data reportedly included names, addresses, phone numbers, GPS locations, speeds and rapid-acceleration events.
These cases do not establish that every automaker operates the same way. They demonstrate, however, that connected-car information can travel far beyond the dashboard and potentially affect financial decisions such as insurance pricing.
What Oregon’s New Vehicle Privacy Law Does
Oregon’s law expands the state’s consumer-privacy protections to ensure that automakers cannot avoid important requirements merely because vehicle data is collected through a car rather than a website or conventional mobile application.
Covered manufacturers must provide consumers with access to qualifying personal information associated with their vehicles. Drivers can also request deletion, subject to legal exceptions that may allow companies to retain information required for warranties, safety investigations, security or compliance obligations.
The measure also allows consumers to direct manufacturers to stop selling certain personal information or using it for targeted advertising. Automakers operating in Oregon must establish a process through which drivers can submit these requests.
The law does not prohibit all vehicle-data collection. Manufacturers can still process information needed to deliver requested services, diagnose mechanical problems, provide emergency assistance, comply with recalls and protect against fraud or cybersecurity threats.
The practical change is that collecting vehicle data no longer gives an automaker unlimited freedom to use it for unrelated commercial purposes without offering the consumer meaningful control.
The Law Is Not a Complete Ban on Data Sales
Calling the measure a total ban would overstate what it does.
Oregon drivers receive stronger rights to access, delete and restrict the sale of personal information, but the law contains exceptions. Data may still be used for necessary business operations, legal compliance, safety, research or services specifically requested by the owner.
Aggregated or de-identified information may also fall outside some protections when it cannot reasonably be connected to a particular person or household.
The law is therefore better understood as a control-and-consent framework. It limits certain sales and uses while requiring automakers to respond when consumers exercise their privacy rights.
Whether it produces major changes will depend on enforcement, the design of automaker request systems and how broadly manufacturers interpret the law’s exceptions.
Drivers Outside Oregon May Also Have Privacy Rights
Oregon is not the only state with a comprehensive consumer-privacy law. California, Colorado, Connecticut, Texas, Virginia and several other states give residents rights involving access, deletion and opt-outs from certain data sales.
Some automakers accept privacy requests from drivers nationwide, while others restrict their request portals to people living in states with applicable laws.
Drivers can begin by locating the manufacturer’s privacy portal or privacy policy. Searching the automaker’s website for “privacy request,” “do not sell,” “delete my data” or “connected services privacy” may lead to the appropriate form.
Consumer Reports provides a detailed guide to stopping car data collection and sharing. The guide explains how drivers can review manufacturer portals and connected-service settings.
Privacy4Cars also offers tools that direct owners to relevant request systems. Drivers should confirm that any third-party service is legitimate before entering a vehicle identification number, address or identity document.
Turning Off Data Collection Can Affect Vehicle Features
Drivers may be able to reduce data sharing through the vehicle’s display, a mobile application or the manufacturer’s account portal.
Possible controls include disabling personalized advertising, restricting location history, turning off driver-scoring programs and declining to share information with insurance partners.
However, some settings are bundled with useful services. Disabling connected data may interfere with navigation, emergency calling, stolen-vehicle recovery, remote unlocking, software updates or maintenance alerts. Automakers should clearly disclose these consequences before requiring drivers to choose.
The goal is not necessarily to disconnect every system. It is to prevent unnecessary collection and make informed decisions about which services justify sharing information.
Drivers should also factory-reset the infotainment system before selling, trading or returning a vehicle. Stored contacts, navigation destinations, garage-door codes and account credentials may otherwise remain available to the next owner. The Associated Press recommends resetting the vehicle and notifying the manufacturer when ownership changes.
Passengers Can Be Collected in the Data Too
Vehicle privacy is not limited to the registered owner.
Passengers may connect their phones, appear on interior cameras, speak near microphones or enter destinations into navigation systems. They may have no direct relationship with the manufacturer and may never see the vehicle’s privacy notice.
Rental cars and employer-owned vehicles create additional complications. A rental customer may sign into an infotainment system without realizing that personal information remains stored. Employees driving fleet vehicles may be monitored through systems selected by the company rather than the individual driver.
These situations demonstrate why vehicle privacy cannot depend entirely on a long policy accepted during purchase. Clear dashboard controls and visible notices are also needed.
Oregon’s Law Could Influence Other States
The auto industry has called for a national privacy framework, arguing that different state rules create confusion and complicated compliance obligations. Privacy advocates respond that state action is necessary because Congress has not passed a comprehensive federal consumer-data law.
Oregon’s measure may become a model for lawmakers who believe ordinary privacy statutes do not adequately address the unusual amount of information generated by connected vehicles.
Future legislation could require opt-in consent before driving data is shared with insurers, clearer in-car notices, limits on data retention and separate permission for precise location tracking.
For now, protections still depend heavily on where a driver lives and which manufacturer produced the vehicle.
A modern car can provide extraordinary convenience while quietly generating a revealing record of daily life. Oregon’s new law does not end connected-car data collection, but it gives drivers a stronger ability to see what is being held, request deletion and restrict certain commercial uses.
That shift places an important principle into state law: purchasing a vehicle should not automatically require surrendering control over every destination, driving habit and personal detail the vehicle can record.