HomeSecurityCalifornia imposes record fine on General Motors

California imposes record fine on General Motors

California Attorney General Rob Bontaand a coalition of state and local law enforcement agencies have announced a $12.75 million settlement with General Motors (GM). The settlement covers allegations that GM collected and illegally sold personal driver data without proper consent, in violation of the California Consumer Privacy Act (CCPA).

 California General Motors

This settlement is the largest CCPA in California history to date and represents the first enforcement action focused on data minimization requirements under the law.

The case centers on allegations that General Motors shared sensitive driver information, including geolocation and driving behavior data, with data brokers Verisk Analytics and LexisNexis Risk Solutions (between 2020 and 2024).

General Motors (GM): Illegal Sales of Driver Data

According to the complaint, GM collected data through its OnStar, which offers emergency, navigation and accident response services. Investigators alleged that the company sold the names, contact information, precise location information and driving behavior data of hundreds of thousands of Californians to the two data brokers.

See also: ZARA: Data breach affects 197,000 customers

Authorities said the data was intended to create products risk assessment driver that could be used by insurance companies when setting premiums.

The investigation was conducted jointly by the California Department of Justice, the California Privacy Protection Agency (CalPrivacy), and prosecutors from San Francisco, Los Angeles, Napa and Sonoma counties.

Attorney General Rob Bonta said the settlement sends a clear message about consumers' control over their personal data.

“General Motors sold the data of California drivers without their knowledge or consent,” Bonta said, adding that the data could reveal sensitive details about consumers’ daily routines and movements.

California imposes record fine on General Motors

CCPA Violations and Data Minimization Concerns

A significant portion of the case focused on alleged violations of the CCPA's data minimization requirements, which were added to California law in 2023.

See also: Polish security service reports ICS violations at water facilities

Under these provisions, companies are required to collect and retain only the data necessary for a stated purpose. The investigators alleged that GM retained driving and location data for much longer than needed to operate OnStar services and later sold that data to third parties.

Authorities also alleged that GM failed to inform consumers about how their information would be used. The complaint said GM's privacy policies indicated that driver data would only be used to provide requested OnStar services and further claimed that the company did not sell driving or location data.

The investigators said the company's practices contradicted these statements.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

San Francisco County District Attorney Brooke Jenkinsdescribed modern vehicles as “machines data collection” and said consumers deserve transparency about what information is collected and how it is shared.

Los Angeles County District Attorney Nathan J. Hochmansaid companies that handle consumer data will be held accountable under California privacy laws, regardless of their size.

California imposes record fine on General Motors

General Motors Settlement Terms

Under the proposed settlement, General Motors must implement several privacy-related. Specifically, the company will be required to:

– Pay $12.75 million in civil penalties.

– Stop selling driving data to consumer reporting organizations for five years.

– Delete driving data within 180 days, unless consumers provide explicit consent for limited uses.

– Request the deletion of driver data already shared with LexisNexis and Verisk.

– Establish and maintain a comprehensive privacy compliance program.

– Submits privacy assessments and compliance reports to California regulators and prosecutors.

The settlement also strengthens California's broader effort to strengthen consumers' control over their personal information, under the CCPA.

See also: RansomHouse claims to have stolen Trellix source code

Along with announcing the settlement, regulators also highlighted the state's "Delete Request and Opt-out Platform" (DROP), which allows Californians to submit requests to delete personal information held by hundreds of registered data brokers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS