In the age of digital transformation, our cars have long been more than just a means of transportation.
They have evolved into data hubs on wheels, equipped with sensors, computer systems, and connectivity features. This technological evolution has undoubtedly improved the driving experience, but it also raises serious data protection questions.
In this blog post, we take a closer look at the privacy issues surrounding modern vehicles and show you what types of information your car may be collecting about you.
What Your Car Knows About You
Cars can collect an enormous amount of data about us, including our location, driving behavior, voice interactions, and even biometric characteristics. They are essentially evolving into powerful surveillance machines that we interact with every day. This data is extremely valuable to car manufacturers, as it can be used to improve products and services, but at the same time it raises significant privacy concerns.
By 2025, over 80% of all newly produced vehicles will be considered "connected cars," equipped with constant connectivity. These systems often work together with mobile devices and cloud services that capture driving habits, preferences, and even emotional states, for example through cabin-facing cameras and AI specialized in emotion recognition.
| Location data | Your car can track your whereabouts, which may include information about where you go, how often you go there, and how long you stay. |
| Voice recordings | Some cars have voice recognition systems that can record your voice when you use voice commands or interact with in-car systems. |
| Financial data | Your car can collect information about your financial status, such as your income and spending habits. |
| Personal data | Car manufacturers can collect personal information about you, including your immigration status, race, genetic information, and even information about your sexual activity. |
| Personal photos and images | If you use in-car infotainment systems or connect your phone, your car may have access to your personal photos. Your car can also capture images, although the exact details of which images are collected are often unclear. |
| Calendar and activities | Some cars can access and store your calendar events and to-do lists. |
| Route history | Your car can record information about the routes you take to build a picture of your travel habits. |
| Employment information | Information about your workplace and commuting habits can be collected. |
Learn more: Personal Data and the GDPR
How Your Car Collects Your Information
At the center of this relentless data collection are the onboard systems of modern vehicles.
A recent 2025 report by the Mozilla Foundation confirms: Not a single major car manufacturer meets today's data protection standards. Brands like Kia, Nissan, and Tesla continue to collect highly sensitive information, including data on sexual activity or genetic characteristics, often without explicit consent or effective user control.
According to an original McKinsey forecast from 2023, around 95% of all new vehicles were expected to be connected by 2030. More recent figures show the industry is rapidly approaching this goal: By 2025, over 80% of new cars produced worldwide are expected to have connected features. The highest adoption rates are expected in North America, the EU, and parts of Asia.
A key aspect of this development is connectivity. Internet-enabled vehicles collect real-time data on your location, traffic volume, and even how you use the infotainment system. And that's often just the beginning: Telematics devices used in many vehicles transmit additional data, frequently straight to insurers. They monitor your driving behavior, such as speed, braking, and acceleration patterns.
If you sync your car with the manufacturer's app, you can expect another intrusion into your privacy. These seemingly harmless applications quietly collect data about nearly every move you make, your usage habits, your exact location, and your individual preferences. All of this information is systematically captured and sent directly to the car manufacturer.
Car companies often go even further and obtain additional information from so-called data brokers. These specialize in collecting and selling personal data from a wide variety of sources, from your social media profiles to government databases.
But even a simple test drive is not safe from data collection. Dealerships can discreetly gather information during test drives, such as your contact details, driving behavior, and personal preferences. Government agencies also play their part: Vehicle registration and driver's license data occasionally feed into this data stream as well.
Beyond manufacturer apps, new vehicle systems such as Android Automotive OS or Apple CarPlay 2.0 promote the sharing of third-party data. Apps integrated directly into the infotainment system have access to location information, vehicle diagnostics, and even microphone input, making it even harder to protect your privacy.
Data Destination: Where Does Your Information Go?
Car manufacturers frequently share and sell the data they collect to third-party companies. These third parties can be a wide range of actors: service providers, data brokers, or other companies. Manufacturers' privacy policies are often vague about who the data is actually shared with, so it remains unclear exactly who gets access. In addition, many manufacturers combine the data collected in the vehicle with personal information from external sources to create comprehensive user profiles, usually for marketing or other commercial purposes.
By 2025, vehicle manufacturers are intensifying their collaboration with telecommunications companies, cloud providers, and app developers to fully exploit the potential of user data. This is giving rise to so-called "data enrichment platforms," where vehicle data is merged with social media activity and publicly available data (e.g., from government sources) with the goal of creating targeted marketing profiles.
Many car manufacturers explicitly reserve the right to share or sell personal data in their privacy policies. This includes information such as your driving behavior, your preferences, or other personal data. Some of this data may be aggregated and anonymized before being shared, but in many countries no data protection laws apply to such data, making traceability and control nearly impossible.
According to a Mozilla report evaluating car brands' privacy practices, Subaru states in its policy: Even as a passenger, you are considered a user, and as a user you automatically consent to the privacy policy.
Volkswagen, Ford, and Stellantis follow a similar practice: Their privacy policies classify even passengers as users, extending the consent requirement to all occupants. This trend, known as "Passenger Profiling," raises serious legal questions, particularly in light of new privacy laws such as the California Privacy Rights Act (CPRA) in the US or Canada's consumer privacy law, the CPPA.
Car manufacturers often work with data brokers or so-called automotive data hubs.
These act as intermediaries that collect, bundle, and redistribute vehicle data. The collected information is then sold to various companies, including insurers, advertising firms, and research institutions.
These partnerships create a complex data ecosystem in which your vehicle becomes not just a means of transportation but also a data source for commercial purposes.
Automotive Companies With Data Privacy Breaches
Toyota disclosed a significant data breach in which the data of more than 2.15 million customers was exposed between November 2013 and April 2023, caused by a misconfigured cloud storage solution.
The incident affected sensitive information from Toyota's cloud-based Connected Services, which was accessible without authorization during this period. Although the breach only affected customers in Japan, Toyota emphasized that no individual customer identities were compromised and that no cases of third-party misuse of the exposed data have been reported so far. Surprisingly, this incident occurred shortly after a separate security issue earlier in the year, in which a hacker exploited a vulnerability in Toyota's customer relationship management software.
Volkswagen and its subsidiary brand Audi also suffered a data breach affecting 3.3 million customers, primarily in the US and Canada. The period stretched from August 2019 to May 2021. Customer data used for sales and marketing purposes was exposed, including names, addresses, email addresses, phone numbers, and details about vehicles purchased or inquired about. While most records contained only basic contact information, around 90,000 Audi customers in the US were affected by a more sensitive data leak in which driver's license numbers and social security numbers were compromised. The breach was traced back to an unnamed partner service provider.
Other data privacy incidents in the automotive industry:
- BYD (2024): A cloud misconfiguration led to the exposure of vehicle locations and profile information of 1.3 million users.
- Rivian (2025): The company admitted unauthorized access to vehicle cameras and voice recordings during software testing.
- Hyundai-Kia (2024): Faced public criticism and class-action lawsuits in the US after behavioral data was shared with third parties for advertising purposes.
These incidents illustrate how interconnected vehicle data systems have become and how vulnerable they remain to security gaps and data privacy breaches.
Learn more: Understanding and Implementing Data Protection Basics — Get Informed With heyData
Data Privacy Best Practices for Cars
It is important to be aware of the risks associated with in-car data collection and to take active steps to protect your privacy. Always review your vehicle's privacy policy to understand what data is collected and how it is used. You may also have the option to object to certain types of data collection.
Recent research by the Mozilla Foundation has uncovered concerning practices in the automotive industry: Some manufacturers collect data without explicitly asking for your consent first. Objecting to certain data collection is often not possible at all, leaving you with only limited control over your personal data.
Mozilla's 2025 findings showed that none of the 25 major manufacturers examined meets basic criteria such as data transparency, user control, or security. Some companies even claim the right to sell sensitive data without anonymization.
As a company committed to data protection, we strongly advise consumers to carefully review their vehicle's privacy policies. Here are some tips for protecting your privacy when using connected cars:
Understand your car's privacy policy
- The policy describes what data is collected and what it is used for. It is important to know this information thoroughly before using connected features.
- Pay particular attention to details about data storage, data sharing with third parties, and the purpose of data collection.
Limit data collection
- Many manufacturers such as BMW, GM, and Tesla tie key features, such as remote locking, navigation, or software updates, to data collection. Opting out may result in these features being deactivated, effectively limiting user autonomy. So always consider carefully which functionalities matter to you in relation to the privacy risks.
With some manufacturers, the responsibility for "better decisions" lies entirely with consumers. Tesla, for example, notes in its privacy policy that declining data collection may impair certain vehicle features, such as over-the-air updates, remote services, or other vehicle systems. That's why it is important to weigh the pros and cons and make informed decisions. The option to opt out should be transparent and should never be used to manipulate consumers.
Be careful with third-party apps
Particular caution is required when using Android Automotive or CarPlay 2.0. These platforms often grant apps more extensive access rights than traditional smartphone syncing. Even weather or calendar apps may request access to vehicle movements, speed, and location by default.
Protect your personal data
Be mindful of what personal information you share through your vehicle's communication systems, for example during phone calls or text messages.
Conclusion
As our vehicles become increasingly connected and intelligent, it is crucial to understand what data they collect and how it is used. The automotive industry is evolving faster than data protection laws can keep up. Nevertheless, new regulations such as the EU Digital Services Act, California's CPRA, and Canada's CPPA are increasingly creating more consumer rights. It is important to stay informed regularly, review your privacy settings, and advocate for laws that create more data transparency.
Don't forget to subscribe to our email newsletter for more updates on data protection and compliance, and to get the latest blogs delivered straight to your inbox.
FAQ
What personal data do modern connected cars collect?
What personal data do modern connected cars collect?
Modern vehicles collect a wide range of sensitive information. This includes:
- Location and movement profiles: GPS data, routes driven, breaks, and destinations.
- Driving behavior: Acceleration, braking maneuvers, speed, and use of assistance systems.
- In-car entertainment & communication: Contact details, call logs, and text messages through paired smartphones.
- Biometric & sensor data: Seat occupancy, camera images from the interior, or drowsiness detection.
Does vehicle data legally qualify as personal data under the GDPR?
Does vehicle data legally qualify as personal data under the GDPR?
Yes. As soon as vehicle data can be attributed to a specific natural person via a vehicle identification number (VIN), a license plate, or a link to a user account, it falls under the GDPR. Vehicle manufacturers and fleet managers are therefore obligated to comply with all data protection requirements.
Are car manufacturers allowed to simply pass on vehicle data to third parties?
Are car manufacturers allowed to simply pass on vehicle data to third parties?
No. Passing data on to third-party providers (such as insurers, advertising partners, or data brokers) is not permitted without the driver's explicit consent or a clear legal basis. Exceptions exist only for legally required safety functions such as the automatic emergency call system eCall.







