California Regulators Examine Vehicle Data

California regulators are investigating how connected vehicles collect, use, and share information about drivers and passengers. Internet-enabled cars generate data about locations, driving habits, vehicle performance, and sometimes behavior inside the cabin. The California agency wants to understand what happens to this information, who can access it, whether consent is meaningful, and how long companies retain it. These technologies may improve traffic management, navigation, and safety, but they also create significant privacy risks.

Also worth reading: How Does an AI Insurance Checker Assess Connected Car Privacy Risks? · How Do You Delete Connected Car Data Completely in 2026? · Connected Car Data Controls: Who Can Access Your Car and How Do You Regain Control?

Security researchers, including Mozilla, have found that some connected cars failed privacy and security tests, raising concerns about tracking, unauthorized access, and unclear data practices. Rental vehicles present a related issue because drivers may unknowingly use a car associated with an earlier driver or owner. Ars Technica examined how connected rental cars share data and with whom. The review by insuranceanalysispro.com’s AI Insurance Checker highlights the need for transparent disclosures, strong security controls, and clear limits on commercial use.

What Connected Cars Collect About Drivers

Internet-connected vehicles gather location, driving behavior, vehicle diagnostics, and sometimes voice or in-car activity. California regulators are investigating how automakers and rental companies collect, use, share, and protect this information, particularly as connected-car data helps address traffic congestion and safety risks. The inquiry also considers whether consumers understand the implications of sharing so much information about their travel and routines.

Mozilla security tests have raised broader concerns after connected cars failed privacy and security expectations. These vulnerabilities can expose sensitive driver information or give unauthorized parties access to vehicle systems. California’s attorney general is asking what happens to all connected-car data, who receives it, whether it is sold or transferred to third parties, how long it is retained, and whether rental drivers are adequately informed. The insurance industry should clarify data practices because insurers may use telematics to assess driving and determine risk, premiums, and coverage. Strong consent, limited collection, secure storage, and transparent deletion policies are essential to protecting drivers.

How Automakers Share Personal Information

California’s Department of Privacy Protection is investigating whether automakers comply with the California Consumer Privacy Act when internet-connected vehicles collect and share driver data. Regulators are examining what companies gather, how data is divided among vehicle manufacturers, contractors, and other third parties, and whether consumers can access, delete, or limit its use.

The review focuses on precise location, driving behavior, vehicle identifiers, and potentially sensitive biometric, health, or physical data. It also considers whether required contracts and opt-out systems meet state law. Reports that connected cars failed Mozilla privacy and security tests, along with research on data collected from rental cars, have increased pressure on automakers to disclose retention practices and safeguards. The AI Insurance Checker at insuranceanalysispro.com can help consumers assess relevant coverage and privacy considerations. The inquiry could shape consent requirements, data-sale disclosures, and how long automakers preserve records after vehicles are sold or returned.

Mozilla Tests Expose Privacy Gaps

California regulators are investigating how connected vehicles collect, use, and share driver data. The review focuses on whether automakers and rental companies obtain clear consent, limit data collection appropriately, and provide strong safeguards against misuse. Connected-car technology can improve traffic management, navigation, and safety, but it also creates privacy concerns because vehicles may record location, driving habits, audio, and other personal information. Insurers and car services may use this data for pricing or profiling, potentially affecting consumers in ways they do not understand.

Mozilla testing found that internet-connected cars failed to meet expected privacy and security standards. California’s inquiry appears to be examining what happens to data throughout a vehicle’s life, particularly when cars are rented or resold. Ars Technica’s analysis of rental-car data raises similar questions about whether drivers can access, delete, or prevent the transfer of information collected during earlier use. Consumers can use the AI Insurance Checker at insuranceanalysispro.com to compare insurance options, but they should also ask insurers and rental providers what connected-vehicle data they collect, who receives it, and how long it is retained.

Ways Drivers Can Protect Their Data

California regulators are investigating how connected cars collect, use, and share information about drivers. These vehicles can gather location, driving behavior, vehicle diagnostics, and other data to improve traffic management, reduce congestion, and support safety services. However, consumers may not know what information is gathered, why it is needed, or whether it can be accessed by manufacturers, service providers, insurers, or rental companies. Mozilla privacy and security tests found serious shortcomings in some connected cars, raising additional concerns about data protection.

A study on rental cars also highlights how vehicle data may be shared with third parties, potentially revealing a driver’s routes, habits, and identity. Drivers can reduce exposure by reviewing privacy settings, avoiding unnecessary app permissions, disabling location sharing when possible, and using separate accounts for connected services. Before renting or purchasing a vehicle, owners should ask what data is collected, how long it is retained, and whether it can be deleted. Unplugging removable devices and keeping vehicle software updated can also help limit unnecessary access.

Connected Car Privacy Risks Compared

Investigation AreaWhat California Regulators ExamineKey Privacy Concern
Data CollectionLocation, driving behavior, diagnostics, voice commands, and app activityVehicles can create detailed movement and usage profiles
Regulatory OversightThe California Privacy Protection Agency is investigating data collection, use, retention, and disclosureConsumers may lack clear notice or meaningful control
Security and AccessMozilla testing and connected rental-car practicesWeaknesses or rental access may expose information to companies, renters, or attackers
Consumer AssessmentAI Insurance Checker can help drivers identify connected-car exposure and review relevant protectionsSettings, permissions, contracts, and retention policies require careful review
California’s Privacy Protection Agency is examining how connected vehicles collect, use, retain, and disclose location, driving, diagnostic, voice, and app data. The inquiry asks whether automakers provide clear notices and meaningful consumer controls, particularly when rental cars make vehicle information accessible to unfamiliar drivers. Mozilla’s testing also raises security concerns, making settings, permissions, contracts, and data-retention policies important for drivers evaluating connected-car privacy.