Lessons from the CCPA “Connected Vehicle” Enforcement Initiative

Editor’s Note: California privacy regulators signaled in 2023 that they would take a hard look at the auto industry, and the results are now in. In this article, Phil Favro examines the enforcement actions that grew out of the state’s connected vehicle initiative, including settlements with Honda, Ford, and General Motors (GM). The GM case stands out: a $12.75 million penalty, a five-year ban on selling driver data to consumer reporting agencies, and the first enforcement of the California Privacy Protection Agency’s data minimization provision. Each automaker had a privacy program on paper, yet all three still sold consumer data against customers’ wishes. That gap between written policy and actual practice is the story here, and counsel and privacy teams should take note. Favro closes by asking the question every privacy team should be weighing: would your opt-out process hold up if regulators came knocking?


Lessons from the CCPA “Connected Vehicle” Enforcement Initiative

By Phil Favro, Contributing Author for HaystackID

Regulators tasked with enforcing provisions from the California Consumer Privacy Act (CCPA) adopted a time-honored strategy a few years ago to step up their enforcement efforts. That strategy—targeting a specific industry whose practices could run afoul of a legal regime—focused on the automobile industry and whether “connected vehicle” technologies may violate the CCPA. To date, the investigation the California Privacy Protection Agency Board (Agency) and California Attorney General (AG) initiated has led to settlements with three automakers.

The Agency has finalized enforcement actions against American Honda Motor Co. (Honda) and Ford Motor Company (Ford). Those actions, which targeted allegedly excessive “friction” in data opt-out workflows for consumers, have resulted in modest penalties. They include a $632,500 fine for Honda and a $375,703 fine for Ford. However, Honda and Ford have also agreed to some Agency oversight of the organizations, including aspects of their privacy compliance efforts.

More significant than the Honda and Ford settlements is the stipulated judgment that the AG reached with General Motors (GM). The investigation of GM targeted its monetization of driver telemetry, alleging that the automaker tracked and sold precise geolocation and driving behavior data, including speed, braking habits, and acceleration metrics. As a result of the enforcement action, GM stipulated to a $12,750,000 fine, along with continuing oversight by the Agency regarding GM’s privacy compliance efforts for several years.

For corporate counsel, together with information governance and privacy professionals, the Agency’s connected vehicle initiative highlights the importance of reviewing enterprise privacy compliance programs to better ensure proactive conformity with CCPA provisions. It’s not enough for enterprises to implement a privacy program. The active CCPA enforcement climate demonstrates that regulated companies should regularly evaluate compliance efforts to ensure conformity with the CCPA, along with other privacy and data protection regimes.

The Agency’s “Connected Vehicles” Initiative

The Agency first announced the “connected vehicles” initiative on July 31, 2023. In so doing, the Agency highlighted that contemporary vehicles have advanced digital features, such as “location sharing, web-based entertainment, smartphone integration, and cameras.” According to the Agency, these features allow vehicle manufacturers to collect massive amounts of consumer data, including precise geographic telemetry, driver and passenger preferences, and other consumer activities and details. As the Agency’s then executive director, Ashkan Soltani, observed, today’s cars are “connected computers on wheels,” capable of harvesting “a wealth of information via built-in apps, sensors, and cameras, which can monitor people both inside and near the vehicle.”

The Agency framed its investigation as an issue of widespread public importance, affecting nearly every resident who drives or rides in a car. According to the Agency’s press release, even pedestrians and others who, through mere happenstance, find themselves close to vehicles could be impacted by these technologies.

The Honda and Ford Enforcement Actions

Honda

The Agency obtained its first enforcement milestone in March 2025 when it finalized a settlement with Honda to address CCPA violations. In its investigation, the Agency discovered that the carmaker required consumers to submit excessive and unnecessary personal information to verify their identity for basic opt-out requests. While the CCPA allows regulated entities to require verification for certain consumer demands, such as requests to delete or correct personal information, the Agency reasoned that the CCPA does not require verified responses for opt-out or data limitation requests.

In addition, the Agency found (among other things) that Honda’s opt-out feature for managing cookies was not sufficiently symmetrical, i.e., it did not provide consumers with a simple “Accept All” or “Decline All” choice. Nor was the carmaker able to provide the Agency with copies of its contracts with the “advertising technology companies” that purchased the consumers’ personal information.

To address these violations, the Agency negotiated a stipulation with Honda. Under the stipulation, the Agency issued the above-referenced fine ($632,500), along with a requirement that Honda update its user interface to provide legally compliant mechanisms that offer consumers a straightforward process to exercise an opt-out request. The Agency also directed Honda to engage a user experience designer to assist with this process. Among other things, the designer should issue recommendations to Honda regarding how to “ensure that methods for submitting CCPA Requests are easy to use and avoid language and interactive elements that are confusing to a reasonable Consumer.” The Agency also ordered Honda to better manage its contracts with the companies to which it sold consumers’ personal information.

Ford

The Agency finalized its next settlement in March 2026, announcing that it had reached a stipulation with Ford that addressed its CCPA infractions. Similar to Honda, the Agency determined that Ford improperly required consumers to verify their identity for opt-out requests. Ford did so by layering in an email and identity verification page for consumers to finalize after they completed a standard opt-out form. By including this additional step, the Agency found that Ford’s process “created unnecessary friction for consumers to exercise their opt-out rights.” The result was that “dozens” of opt-out requests were not timely processed and Ford—contrary to consumers’ wishes—sold their personal information to third parties.

To resolve the violations, Ford agreed to pay a nominal fine ($375,703) and offer consumers an “easy” opt-out process that would not burden consumers with a verification request. In addition, the Agency directed Ford to “conduct an audit” of its cookies and other tracking technologies to ensure they are “properly configured” to comply with consumers’ opt-out requests.

The Proposed Judgment and Permanent Injunction Against GM

Two months later, on May 8, 2026, the AG announced a far more significant and extensive settlement with GM. Along with a coalition of California district attorneys and with operational support from the Agency, the AG filed a complaint against GM, along with a proposed “Final Judgment and Permanent Injunction,” for allegedly tracking and selling data belonging to hundreds of thousands of California drivers. The complaint memorializes the AG’s allegations against GM, while the proposed judgment and injunction reflect the remedies that the AG and GM appear to have negotiated.

GM’s Alleged Violations of the CCPA

In the complaint, the AG alleged that GM monetized driver telemetry—including precise GPS location coordinates, vehicle speed, and hard braking metrics—that it collected through its OnStar connectivity service. From 2020 through 2024, GM allegedly sold this detailed information to LexisNexis Risk Solutions (Lexis) and Verisk Analytics (Verisk) to help auto insurers build driver-rating profiles and, in some states, set premium rates.

Central to the AG’s CCPA and related claims was the inconsistency between GM’s representations to its consumers regarding the handling of their personal information and its actual practices. GM’s privacy policy expressly indicated that it would not sell driving or location data, and that any disclosure to insurers would occur only at the consumer’s express direction. On the contrary, GM provided this very data directly to data brokers. Moreover, while GM offered a generic online opt-out mechanism, the AG alleged that it did not stem the flow of telemetry data.

In addition, the AG asserted that GM violated the CCPA’s purpose limitation principle by using sensitive telemetry data—originally collected for legitimate consumer safety and emergency roadside assistance services—for an entirely unrelated, undisclosed commercial monetization scheme. The complaint further alleges that GM violated CCPA data minimization standards when it sold geolocation data to Lexis reflecting parking data, offering insights into drivers’ personal habits. According to the AG, this is the first action pursued to enforce violations of the CCPA’s data minimization provision.

All of this occurred despite GM’s information governance measures. GM apparently maintained an “internal privacy program” designed to protect consumers’ personal information. Under that program, the company “required clear descriptions of privacy practices to consumers, mandated purpose limitation and data minimization requirements, and required written privacy risk assessments for activities like selling data.” Nevertheless, GM allegedly failed to follow its own governance regime. Moreover, GM sidestepped express contractual provisions that forbade certain data transmissions, including the transfer of precise geolocation data to Verisk.

Stipulated Remedies

The proposed judgment and injunction imposed a greater financial penalty ($12,750,000) on GM than either Honda or Ford incurred. For a company with annual revenue approaching $200 billion, though, such a fine represents little in the way of incentive to correct its ways. However, the proposed remedies include strict mandates that prevent GM from monetizing vehicle-generated telematics.

In particular, the proposed judgment and injunction impose a five-year restriction that bans GM from selling driving data to “consumer reporting agencies,” which includes data brokers such as Lexis and Verisk. In addition, GM must delete or destroy all historically retained driving data within 180 days—unless consumers expressly authorize otherwise—and requires that GM request that Lexis and Verisk delete all previously transferred data. Finally, GM must develop a “robust privacy program” that assesses and memorializes the risks of data collection, with a strict mandate to submit privacy risk assessments to privacy regulators. These and other remedies memorialized in the proposed judgment and injunction are designed to enhance privacy safeguards for consumers and their personal information.

Lessons for Enterprises from the Connected Vehicle Enforcement Initiative

For lawyers and privacy professionals, the connected vehicle enforcement initiative highlights the importance of reviewing corporate privacy programs to ensure they satisfy CCPA strictures, together with the requirements of other privacy and data protection regimes. The Honda, Ford, and GM settlements demonstrate that these companies previously implemented privacy policies and corresponding practices to ensure compliance with the CCPA. Nevertheless, the enforcement actions demonstrate that privacy workflows and practices can descend or drift into noncompliance. The result was that the automakers sold personal information against consumers’ wishes and in violation of the CCPA.

To start, enterprises undertaking an audit of their privacy programs may consider evaluating the effectiveness of their opt-out forms and whether they are CCPA compliant. With the Honda, Ford, and GM settlements in mind—all of which spotlighted issues with the opt-out process—consider the following:

  • Is the opt-out process operational? Does it really work?
  • Do enterprises provide consumers with a symmetrical choice to opt-out from tracking technologies such as cookies?
  • Does the opt-out process impose barriers that regulators could perceive as creating an impermissible verified request?
  • Does the opt-out process actually stop companies from selling consumers’ personal information?

Enterprises may also wish to audit their contracts with consumer reporting agencies and data brokers to ensure they comply with the CCPA’s purpose limitation principle. If companies have collected consumer personal information for one stated purpose, contracts that provide for the sale of that information generally should not allow data brokers to use it for an entirely unrelated purpose. Reviewing those contracts to ensure they meet CCPA requirements may help entities avoid violations that resulted in compliance issues for GM.

There are other lessons from the connected vehicle initiative, particularly the need to ensure compliance with data minimization standards. The AG’s emphasis that its action against GM was the first enforcement proceeding regarding the CCPA data minimization provision suggests increased regulatory emphasis on this requirement.

Finally, these recommended assessments and others should not be a “one-and-done” corporate initiative. Instead, companies should consider handling them both periodically and on a regularly established schedule. Doing so has the potential to better ensure that enterprises remain compliant with the CCPA.


About Phil Favro

Phil Favro is the founder of Favro Law PLLC, where he counsels clients on ESI, AI, and discovery issues and serves as a special master, mediator, and expert witness. Phil is nationally recognized for his expertise on ESI, discovery, and information governance, with courts acknowledging his credentials. See, e.g., Oakley v. MSG Networks, Inc., No. 17-CV-6903 (RJS), 2025 WL 2061665 (S.D.N.Y. July 23, 2025). This background makes Phil particularly well-suited to counsel clients and advise courts on information-related issues. As a special master, Phil is acclaimed for his collaborative approach, working with parties to find stipulated solutions to complex issues. For disputes that require adjudication, he is renowned for the clarity and vigor of his written dispositions, which are available on legal search engines.

HaystackID® solves complex data challenges related to legal, compliance, regulatory, and cyber requirements. Core offerings include Global Advisory, Cybersecurity, Core Intelligence AI™, and ReviewRight® Global Managed Review, supported by its unified CoreFlex™ service interface and eDiscovery AI™ technology. Recognized globally by industry leaders, including Chambers, Gartner, IDC, and Legaltech News, HaystackID helps corporations and legal practices manage data gravity, where information demands action, and workflow gravity, where critical requirements demand coordinated expertise, delivering innovative solutions with a continual focus on security, privacy, and integrity. Learn more at HaystackID.com.

Assisted by GAI and LLM technologies.

SOURCE: HaystackID