GM’s Record $12.75 Million CCPA Fine: The OnStar Data Lesson
As if Disney’s $2.75 million CCPA settlement wasn’t big enough, General Motors has eclipsed the record for data sharing violations in the state of California with a monster $12.75 million payout.
The reason? From 2016 to 2024, GM collected and retained the names, contact details, geolocation data, and driving behavior of hundreds of thousands of Californians through its OnStar service. Then, beginning in 2020, it sold that information to two data brokers, Verisk Analytics and LexisNexis Risk Solutions. It did all of this without its customers’ knowledge or consent, violating the California Consumer Privacy Act (CCPA) and California’s Unfair Competition Law.
It’s the largest CCPA penalty in California history, and also the state’s first enforcement action built on the CCPA’s data minimization and purpose limitation requirements.
More Than Just a Fine
While the $12.75 million figure is a headline grabber, it’s not the end of the story. Under the settlement (which is subject to court approval), GM must:
- Stop selling driving data to consumer reporting agencies (including data brokers like LexisNexis and Verisk) for five years
- Delete retained driving data within 180 days, except for limited internal uses, unless consumers give affirmative, express consent
- Request that LexisNexis and Verisk delete the driving data they purchased
- Build and maintain a privacy program that assesses, mitigates, and documents the risks of collecting data through OnStar
- Report its privacy assessments to the DOJ, the participating district attorneys, and the California Privacy Protection Agency (CalPrivacy)
As with Disney, compliance doesn’t end with the hefty one-time payment. There’s an ongoing operational obligation that will cost the company time and money.
What Actually Went Wrong?
San Francisco DA Brooke Jenkins — one of the four county district attorneys who joined the action — called modern connected cars “rolling data collection machines.” They allowed GM to collect precise location and driving behavior data through OnStar, the telematics service drivers use for navigation and emergency assistance. Both brokers bought this data to build driver-rating products they could market to auto insurers for setting rates. GM reportedly earned around $20 million nationwide from these sales.
The problem wasn’t just the sale itself, though. It was the gap between what GM told consumers it would do, and what it actually did:
- No notice, no consent. Consumers were never told their data was being sold to LexisNexis and Verisk.
- Misleading disclosures. GM’s privacy policy stated it did not sell driving or location data, and that any disclosure for insurance purposes would happen only at the consumer’s express direction.
- Ignored internal controls. GM had an internal privacy compliance program that required it to tell consumers how their information would be used and which third parties would receive it. The sales went ahead anyway.
- Unlawful retention. GM held on to driving and location data long after it was needed to operate OnStar, then sold it.
It’s interesting to note that even though California drivers weren’t penalized with higher insurance premiums (because California insurance law prohibits insurers from using driving data to set rates), enforcers still held GM accountable for data collection, retention, and sale violations.
Data Minimization Enters the Enforcement Era
As noted, there’s a shift here. Earlier CCPA actions (against Sephora, DoorDash, Healthline, and Disney) largely focused on whether companies were honest with consumers, and if their opt-out controls worked.
With the GM case, the CCPA is focusing on purpose limitation and data minimization principles. Added in 2023, they say that companies can only collect what data they need, can only use it for the disclosed purposes, and can’t warehouse it indefinitely for some future, undisclosed use — exactly what happened here, with data gathered from 2016 and only repurposed for sale in 2020. That’s a fundamentally higher compliance bar.
The Coordinated Enforcement Problem
Another step change with this action was the fact that multiple regulators worked together: the California DOJ, four county district attorneys (San Francisco, Los Angeles, Napa, and Sonoma), and CalPrivacy’s Enforcement Division. The investigation began with CalPrivacy’s 2023 sweep of connected vehicle privacy practices and accelerated after 2024 press reporting revealed automakers were sharing driving data with insurers.
The lesson for businesses is that privacy enforcement in California is now a networked effort. A regulatory inquiry in one office can pull in others, and public reporting can trigger investigations that were already simmering. So, if your data practices attract scrutiny from one direction, expect others.
What This Means for You
To avoid a $12.75 million penalty plus extra reporting and scrutiny, ask the same questions regulators do:
- Do you collect only what you need?
- Do you delete data when its disclosed purpose is fulfilled?
- Do your actual third-party data flows match what your privacy policy says?
- Would your internal compliance program have caught this, and would anyone have listened if it did?
That last point stings in the GM case: the company had a privacy compliance program on paper, but that’s where it stayed. A policy that isn’t enforced and respected is worse than useless: it becomes evidence of what you knew you should have done.
Generating the right answers takes visibility on two fronts, and it’s worth being clear about which is which. Continuous client-side monitoring of the trackers, pixels, tags, and third-party scripts running on your sites and apps can tell you which vendors are collecting what, where that data is being sent, and whether anything keeps firing after a user opts out. That’s the exact failure mode behind the Disney settlement, and it’s the kind of contradiction between policy and reality that a tool like Reflectiz is built to catch in real time, before a regulator does.
But the GM case is a reminder that the web layer isn’t the whole picture. The violations here lived on the backend: data collected through an embedded telematics service, retained longer than its stated purpose allowed, and sold to brokers. No client-side monitor can see that; it takes data-governance controls, retention policies, and honest internal audits of where data goes after it’s collected. Data minimization is a governance discipline, not a browser problem.
The takeaway for compliance teams is to close both gaps. Ensure opt-out actually works, and that your tag ecosystem matches your disclosures. Then, separately, map your backend data lifecycle: what you retain, for how long, for what purpose, and who you share it with.
Start with what you can see today. Reflectiz continuously monitors every tracker, pixel, and third-party script on your site — flagging the exact policy-vs-reality gaps that triggered the Disney settlement, in real time, before a regulator does. Request a scan →
FAQs
Does this case affect industries beyond automotive?
Yes. Any business that collects location data, behavioral data, or telemetry — connected devices, apps, IoT products, streaming platforms — faces the same data minimization and purpose limitation requirements.
Is this the largest CCPA penalty ever?
Yes. At $12.75 million, it’s the largest CCPA penalty in California history, far exceeding the previous record of $2.75 million set by the Disney settlement in February 2026.
Were California drivers charged higher insurance rates because of GM’s data sales?
No. California insurance law prohibits insurers from using driving data to set rates, so Californians avoided the premium increases reported in other states. Enforcers pursued the case anyway, targeting the undisclosed collection, retention, and sale of the data itself.
What did GM actually do wrong?
GM collected and retained the names, contact information, geolocation data, and driving behavior of hundreds of thousands of Californians through its OnStar service from 2016 to 2024, and began selling that data to Verisk Analytics and LexisNexis Risk Solutions in 2020, all without notifying consumers or obtaining consent. Its privacy policy even stated that it did not sell such data. GM also retained data longer than needed to operate OnStar, violating the CCPA’s data minimization requirements.
What is the GM CCPA settlement and when was it announced?
On May 8, 2026, California Attorney General Rob Bonta, four county district attorneys, and the California Privacy Protection Agency announced that General Motors agreed to a $12.75 million settlement for violating the CCPA and California’s Unfair Competition Law by selling consumers’ location and driving data to data brokers without notice or consent. The settlement is subject to court approval.
What must GM do beyond paying the penalty?
GM must stop selling driving data to consumer reporting agencies for five years, delete retained driving data within 180 days absent express consumer consent, ask LexisNexis and Verisk to delete the data they bought, maintain a robust privacy program covering OnStar data collection, and report its privacy assessments to state and local regulators.
What’s the key compliance lesson for other companies?
Your actual data lifecycle must match your disclosures. Having a privacy policy, or even an internal compliance program, as GM did, means nothing if data flows to third parties contradict it. Companies should map what they collect and why, how long they keep it, and who receives it, and verify that reality matches their promises before a regulator does.
Why is the data minimization angle significant?
This is the California DOJ’s first enforcement action based on the CCPA’s data minimization and purpose limitation requirements, added in 2023. It signals that regulators will now scrutinize not just disclosures and opt-outs, but whether companies collect only what they need, retain it only as long as necessary, and use it only for disclosed purposes.
Subscribe to our newsletter
Stay updated with the latest news, articles, and insights from Reflectiz.
Related Articles
AI Has Changed The Web.
Are You Ready for What’s Next?
Third-party code shifts by the hour. Supply-chain compromises strike without warning. AI-driven web attacks now evolve faster than traditional security can ever keep up.
Reflectiz delivers the continuous, real-time visibility needed to expose the risks traditional tools miss entirely.
Zero code changes. Zero access to your data. Ultimate peace of mind.