General Motors agreed to a $12.75 million settlement with California to resolve allegations that it illegally sold OnStar subscribers' location and driving data to third-party brokers.
The settlement concludes an investigation into GM's practice of monetizing personal vehicle data without proper consumer consent. OnStar, GM's connected vehicle service, collected location and driving information from millions of subscribers.
California authorities found that GM sold this data to insurance companies, financial institutions, and other brokers—activities not adequately disclosed to customers. The automaker's terms of service allowed data sharing for "business purposes," but regulators determined this language was insufficient for such sales.
The $12.75 million penalty reflects growing regulatory scrutiny of automakers' data practices. Regulators across multiple states have examined how car manufacturers handle vehicle and driver information as connected cars become more prevalent.
GM did not admit wrongdoing in the settlement. The agreement includes restrictions on future data sales and requires enhanced transparency for OnStar subscribers about how their information is used and shared.
The case underscores ongoing tensions between automakers' revenue opportunities and consumer privacy expectations in the connected vehicle era.
A limited-permission Kubernetes user can potentially gain full control of a Google Cloud organization by exploiting the Google Kubernetes Config Connector. The vulnerability represents a classic confused deputy problem in cloud infrastructure.
Enterprise infrastructure management systems are under sustained attack, with critical vulnerabilities being exploited before or immediately after vendor patches become available, according to a new InfraTrust report.
Comma's hands-off driving technology is being investigated following at least two fatal crashes. The inquiry involves instances where drivers were operating modified versions of Comma's software.
Sweden's data privacy regulator IMY has fined IT systems provider Miljödata $183,000 for inadequate security measures that led to a data breach in August 2025. The incident exposed personal information of 2.2 million individuals.