11 Ways Your Car Spies on You and How to Stop It

C. da Costa Avatar
C. da Costa Avatar

By

Image: Gadget Review

Key Takeaways

The U.S. Department of Transportation proposed requiring Event Data Recorders in light passenger vehicles, a rule that took effect in 2012. That was just the start. Modern cars collect everything from speed to location data, creating detailed profiles of driving behavior. Most drivers have no idea their vehicles transmit telemetry to manufacturers, insurers, and data brokers. This goes beyond convenience features—it’s surveillance infrastructure built into the machine you own. Understanding what data your car collects, who receives it, and how to disable collection is no longer optional privacy housekeeping.

11. Event Data Recorder (EDR) / “Black Box”

Image: Wikipedia

Federal rules standardize crash data recording, but don’t mandate EDRs in every vehicle.

By the mid-2010s, roughly 90% of new cars already included an Event Data Recorder, the automotive equivalent of an aircraft black box. This passive device captures technical data—speed, braking, throttle position, seatbelt status, steering angle—for about 5 seconds before a crash and 1–2 seconds after. The recording window is brief and local; EDRs store data onboard without transmitting anything to external servers.

Under the Driver Privacy Act of 2015, any information an EDR retains legally belongs to the vehicle’s owner or lessee. Law enforcement, insurers, or other parties generally need owner consent or a court order to access it, with limited exceptions for emergency medical response or traffic safety research. Federal regulation (49 CFR Part 563) standardizes what crash data must be recorded if a vehicle is equipped with an EDR, covering light passenger vehicles under 8,500 lbs GVWR. The rule took effect September 1, 2012, setting data format and access requirements—not mandating installation in every car.

EDR data can provide objective evidence after an accident, clarifying fault when witness accounts conflict. Since the device operates passively and stores information locally, it presents minimal ongoing privacy risk compared to connected systems that stream telemetry continuously.

10. Telematics Control Unit (TCU) / Built-in Vehicle Connectivity Modules

Image: Wikipedia

Embedded cellular modems stream location, speed, and diagnostics to manufacturer servers.

A Telematics Control Unit is an embedded hardware module combining a cellular modem, GPS receiver, and interface to the vehicle’s internal network. It gathers telemetry—location, speed, engine diagnostics, driver behavior—and transmits selected data over LTE/4G/5G to manufacturer back-end systems. The TCU supports two-way communication, enabling over-the-air software updates, remote start/lock commands, stolen-vehicle tracking, and emergency call services.

In software-defined vehicles, the TCU functions as an edge-computing node orchestrating remote diagnostics, OTA updates, and in some architectures, vehicle-to-everything (V2X) communication. Connectivity operates continuously when the vehicle is running, creating a persistent data stream to cloud servers.

Physically disconnecting the TCU typically disables connected services while leaving core mechanical operation—engine, brakes, steering—unaffected. Many TCUs are standalone modules connected by a wiring harness; unplugging the connector severs network access. Integrated designs can be more complex, and exact procedure varies by make and model. Consult vehicle-specific forums or service manuals before attempting disconnection, as some systems may trigger dashboard warnings or disable features beyond connectivity.

9. GM OnStar & Smart Driver Program / Data Broker Partnerships

Image: Wikipedia

GM transmitted driving behavior to LexisNexis and Verisk without clear consent, triggering regulatory action.

From roughly 2015 to early 2024, GM’s OnStar Smart Driver program logged granular driving data: hard braking, rapid acceleration, speeds over 80 mph, trip times, distances, and precise location with timestamps. This telemetry flowed to data brokers LexisNexis Risk Solutions and Verisk Analytics, which converted it into driver risk scores sold to auto insurers.

A 2024 New York Times investigation revealed drivers discovering hundreds of trips logged in LexisNexis files, including speed and braking events transmitted from GM vehicles—often without clear informed consent. Individual drivers faced unexpected premium increases after insurers purchased their risk profiles from brokers. Facing public backlash, GM announced in March 2024 it would stop sharing Smart Driver customer data with LexisNexis and Verisk, terminating these partnerships. The company discontinued the Smart Driver program entirely in April 2024.

In 2026, the California Attorney General announced a $12.75 million settlement with GM under the California Consumer Privacy Act. The settlement found GM sold precise driving and location data from OnStar-equipped vehicles to LexisNexis and Verisk between about 2020 and 2024 without valid CCPA-compliant consent. Under settlement terms, GM must obtain explicit opt-in consent before sharing driving data with third parties and delete previously collected telematics data per customer request.

8. Insurance Telematics: Progressive Snapshot, State Farm Drive Safe & Save, Allstate Drivewise

Image: Wikipedia

OBD-II dongles and mobile apps monitor driving behavior for potential premium discounts—and ongoing risk assessment.

Usage-based insurance programs from Progressive, State Farm, and Allstate monitor driving behavior in exchange for potential discounts. Progressive’s Snapshot uses a plug-in OBD-II device or smartphone app to capture hard braking, time of day, mileage, and sometimes GPS location. State Farm’s Drive Safe & Save employs a Bluetooth beacon device, connected car integration, or OnStar; the beacon pairs with a mobile app to track speed, braking, acceleration, cornering, mileage, and time of day. Allstate’s Drivewise uses a mobile app or connected-car systems to record speed, braking patterns, and trip duration.

These devices contain cellular radios and GPS, continuously streaming driving data to insurer servers while the vehicle operates. The data feeds risk-scoring algorithms that can influence premiums at renewal—either discounts for smooth driving or increases for behaviors flagged as risky. Discount ranges often reach 30% for optimal performance, creating strong financial incentive.

Enrollment terms specify customers consent to data collection and sharing for underwriting and analytics. Data is retained beyond initial monitoring periods and may affect premiums after promotional phases end. The OBD-II port, standard on most U.S. vehicles since model year 1996, provides direct access to vehicle telemetry; insurance dongles remain powered whenever the ignition is on, logging every trip.

To avoid this surveillance, decline enrollment in usage-based programs. If already enrolled, contact the insurer to cancel and request data deletion. Remove any plug-in device from the OBD-II port and uninstall monitoring apps.

7. Mozilla Foundation “Privacy Not Included” 2023 Report

Image: Unsplash

All 25 major car brands reviewed failed minimum privacy standards.

In September 2023, the Mozilla Foundation published a Privacy Not Included study reviewing 25 major car brands. The verdict: every brand failed Mozilla’s minimum privacy standards, making cars “the worst product category” the organization had ever reviewed. All 25 brands collected more personal data than necessary and used it for purposes beyond operating the vehicle or maintaining customer relationships—ranging from driving behavior and routes to, in some cases, health data or sexual activity, depending on brand policy language.

Mozilla found 84% of brands said they can share user data with service providers, data brokers, or other businesses. About 76% said they can sell personal data. More than half indicated they may share information with government or law enforcement on request, often without requiring a court order. Only two brands—Renault and Dacia, both Europe-only—clearly offered all drivers the right to delete their personal data.

Data sources included vehicle sensors, built-in telematics, in-car apps, connected services, dealer systems, and mobile apps tied to the car. Toyota presented a complex web of overlapping privacy documents; Volkswagen used driving behaviors and demographics for targeted marketing; Nissan and Kia explicitly allowed collection of “sexual activity” or “sex life” information in their policies. The report emphasized drivers have little meaningful control: 92% of brands offered minimal ability to manage personal information.

6. FordPass Connect Modem & Connected Vehicle Data

Image: Unsplash

Embedded modems transmit location and driving data independently of mobile apps.

Many Ford vehicles from 2017 onward include a FordPass Connect modem, an embedded connectivity device linking the vehicle to Ford servers independently of the driver’s phone. When activated and the vehicle is linked to a Ford account, the car transmits Connected Vehicle Information—precise GPS location, travel direction, speed, environmental data—and Driving Data, including use of accelerator, brakes, steering, and seat belts.

The modem sends periodic messages via cellular network, containing identifiers such as the vehicle’s VIN, modem serial numbers, and SIM identifier, allowing Ford to associate telemetry with specific vehicles. Ford’s connected-vehicle policies describe sharing information with service providers and partners for connectivity, roadside assistance, and mapping. Vehicle location data may be shared in pseudonymous form with third-party traffic services like HERE Global BV.

Simply uninstalling the FordPass mobile app does not stop data transmission from a vehicle with an activated modem. To reduce collection, disable connectivity through in-vehicle settings (usually in SYNC’s Privacy or Connectivity menus) and revoke permissions in your Ford account online. This two-step process severs the data pipeline; otherwise, the modem continues transmitting telemetry regardless of app installation.

5. Toyota Connected Services & 2023 Data Leak

Image: Unsplash

Misconfigured cloud database exposed location data for 2.15 million customers over a decade.

Toyota Connected Services (T-Connect, G-Link, and related platforms) provide cloud-based navigation, remote services, and vehicle health reporting for connected Toyota and Lexus vehicles. The services use onboard data communication modules and mobile apps to collect location data, driving data (speed, acceleration, braking, journey logs), and vehicle health reports. Toyota’s privacy notices state location data can be stored up to 7 years, driving data up to 15 years in some versions.

In 2023, Toyota disclosed a decade-long data leak affecting about 2.15 million customers in Japan, caused by a misconfigured cloud database for Connected services. The leak exposed vehicle location and timestamp data, chassis numbers, navigation terminal IDs, and in some cases videos from drive recorders. The misconfiguration left parts of the infrastructure accessible on the public internet from roughly November 2013 to April 2023, potentially allowing unauthorized parties to track vehicles via VIN and location logs. Toyota stated it had no evidence of malicious use.

Toyota’s regional policies clarify that when Connected Services are active, the vehicle collects and transmits data including location, driving behavior, fuel levels, and personal contact information. Data may be shared with third parties such as debt collectors or insurers. Disconnection often requires disabling the data communication module’s SIM card via a dealer service appointment. Adjust privacy settings through the vehicle’s infotainment menus and online account to limit what telemetry Toyota collects and retains.

4. Stellantis Uconnect / Mopar Connected Services (RAM, Jeep, Chrysler, Dodge)

Image: Unsplash

European privacy policy details extensive “over the air” data collection and partner sharing.

Uconnect is Stellantis’ infotainment and connected-services platform for brands including Jeep, RAM, Chrysler, and Dodge. Newer versions (Uconnect 5 and related services) rely on embedded telematics hardware and cloud back-ends. Stellantis’ European Connected Vehicles Privacy Policy states that when connected services are active, it can collect vehicle data including advanced driving data and usage information “over the air,” associated with vehicle identifiers and customer accounts.

Drivers can adjust privacy settings in the infotainment system—modes such as “Data & Location,” “Data only,” or “Plane Mode”—which control whether geolocation and other telemetry is transmitted. Stellantis Europe or PSA Automobiles serve as independent data controllers for Connected Vehicle Services. If a driver opts into receiving offers, vehicle and personal data can be shared with group companies and selected partners in automotive, finance, insurance, and telecom sectors. Data may be transferred outside the European Economic Area under standard contractual clauses.

Stellantis maintains a centralized privacy portal where users can exercise data rights (access, deletion, objection) and identifies a dedicated Data Protection Officer for Connected Vehicles. Navigate your vehicle’s Uconnect privacy settings to disable location sharing and reduce telemetry transmission. Access the Mopar owner portal online to manage account-level permissions and submit data deletion requests if desired.

3. Hyundai Blue Link Connected Services

Image: Unsplash

Remote diagnostics and OTA updates depend on continuous collection of location and performance data.

Hyundai Bluelink integrates in-vehicle systems, sensors, software, and mobile apps to provide remote controls (lock/unlock, start), diagnostics, live traffic, OTA updates, and safety features. Hyundai’s Vehicle Technologies and Services Privacy Notice states Bluelink collects identifiable information linked to the vehicle and owner, including performance and location data about operation and use of the services.

Regional Bluelink privacy notices (Australia, Europe) specify purposes such as remote diagnostics, OTA updates, connectivity services, troubleshooting, research and product development, and direct marketing where legally permitted. All rely on personal and vehicle data. When Bluelink data is linked to a vehicle’s VIN and associated with a person, it is treated as personal information under applicable privacy laws.

Drivers can cancel Bluelink subscriptions by calling Bluelink Customer Care or using in-vehicle settings to remove the vehicle owner from the account. Adjust privacy settings through the infotainment system’s Bluelink privacy menus to activate or deactivate service categories. Disabling Bluelink will terminate remote features and reduce data transmission, though local vehicle systems continue operating normally.

2. Cached Phone Data in Infotainment Systems

Image: Unsplash

Contact lists, call logs, and text previews remain stored after disconnecting your phone.

Modern infotainment systems automatically sync personal data when phones connect via Bluetooth or USB: contact lists, call histories, recent text message previews. This information is cached locally in the vehicle’s memory and persists after the phone disconnects. When bringing a vehicle for service, loaning it to others, or selling it, anyone with access can potentially retrieve stored personal details.

Deleting paired devices from Bluetooth settings is insufficient. Navigate the infotainment system’s settings to manually clear contacts, call logs, and messages. Perform a full factory reset before returning a rental or selling your vehicle. This ensures your digital footprint is wiped. Consult your owner’s manual for model-specific reset procedures; the option is usually located in System Settings or Privacy menus.

Some systems require a security code to factory reset; keep this code accessible. After reset, all saved preferences, paired devices, and cached data are erased. The infotainment returns to factory state, removing any trace of your personal information.

1. Over-the-Air (OTA) Software Update History

Image: Wikipedia

Manufacturers log every remote software package pushed to your vehicle.

Connected vehicles receive over-the-air software updates, allowing manufacturers to modify features, adjust performance parameters, and patch vulnerabilities remotely. Automakers like Tesla, GM, and Ford routinely push OTA updates while vehicles are parked. These updates arrive without explicit user action beyond initial consent in terms of service agreements.

Many connected vehicles log every software update received: when it was applied, what version was installed, and what specific changes occurred. This detailed update history is stored in the vehicle’s system logs, creating a comprehensive record of modifications made by the manufacturer. Updates can enable new features, disable existing ones, or change driving characteristics—often without explicit notifications.

Manufacturers use OTA capability to address safety recalls, improve performance, and introduce new services. The Vehicle Identification Number and telematics modem serial number link update logs to specific vehicles. Review your vehicle’s software version in the infotainment settings (usually in System or About menus). Some manufacturers provide update history through owner portals; check your account online for a log of applied updates.

Blocking OTA updates typically requires disabling the telematics modem or disconnecting cellular service, which also disables other connected features. Weigh the trade-off between preventing remote modifications and losing legitimate safety updates or convenience features. If concerned about specific updates, contact the manufacturer to inquire about update content and whether installation can be deferred.

Share this Article



About Gadget Review’s Editorial Process

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →

Why Trust Gadget Review

Years of Experience

Reviews Analyzed

Products Tested

Experts We’ve Tested