Automotive
A connected car sends location, speed and the way you drive off the vehicle by default, and your driving can be scored for insurers. One car means several files: the maker, the dealer, the finance arm and the app each hold their own, and selling the car clears none of them.
The read at a glance
The car reports to its maker whether or not you use their app.
A leak exposes everywhere you drive, how you drive, and often the cabin microphone and camera data.
Connected-car and finance data is kept for years; "anonymised" telematics has no end date.
Purchase or finance requires identity and a credit check; the car itself collects the rest.
Industry profile reviewed 23 August 2026. Also machine-readable via the free API.
If it leaks
A connected car logs where you went and how you drove, and makers have left exactly that exposed on the open internet for months at a time. Where the file is finance instead, it is your income and your credit history.
What repeats in the policies
One car, several companies, several files
The maker, the dealer, the finance arm and the app each hold their own file under their own policy, so a request to one does not reach the rest. If this company financed or leased the car, its file is a credit application: identity, affordability and the payment record, not a driving trail.
The car reports as you go
Connected features send location, speed and the way you drive off the vehicle by default, and the only opt-out on offer is switching the feature off. Cameras and microphones now point into the cabin, and voice requests leave the car too.
Your driving is scored for insurance
How you accelerate, brake and corner becomes a score aimed at insurers, and some makers run their own insurance arm. A US regulator ordered one maker to stop selling location and driver behaviour to the reporting firms insurers use.
Selling the car does not clear it
Wiping the head unit and unlinking the account is left to you, and one maker warns a factory reset does not switch the connected service off. When a retention period ends, policies commonly keep the data by de-identifying it instead of deleting it.
What a company here typically holds
Worked out from the industry, not from any one company. What you actually handed over is yours to record.
The list understates it for a connected car: the vehicle reports where you went and how you drove, by default and without asking each time.
What this can reveal about you
Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.
Where you go Highly likely
The car logs every journey you take.
Your face and voice Possible
In-cabin cameras and driver profiles capture your face.
What lawfully stays after you leave
Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.
Anonymised, aggregated, or AI-trained data They set it often kept indefinitely
They treat it as no longer being about you, though such data can sometimes be re-identified.
Identity / anti-money-laundering records Law sets it about 5 years
Money-laundering rules require ID and transaction records after an account closes.
Financial regulatory records Law sets it around 5 to 7 years
Financial regulators require advice, suitability, and transaction records.
Tax and accounting records Law sets it about 6 years
Tax and company law makes them keep billing and payment records.
Records tied to a live or potential dispute They set it the limitation period of the claim
They can keep records to defend a live or possible legal claim.
Who wants this data
Driving data is a market. A US regulator ordered one maker to stop selling precise location and driver behaviour to the reporting firms insurers use, taken as often as every three seconds. It leaks too: one group left terabytes from around 800,000 cars open on the internet for months, and another exposed the location data of about 2.15 million customers.
Sold or shared Likely
Telematics and location data has an active resale market.
AI training Moderate
Driving and sensor data trains autonomy and risk models.
Even anonymised, this can still be you
Connected-car journeys are mobility data, where four time-and-place points single out 95% of people (de Montjoye et al., 2013).
Name, date of birth, postcode Typical
Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).
Location traces Sometimes
Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).
Payment patterns Typical
Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).
Face and voice Sometimes
A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.
Browsing fingerprint Sometimes
Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).
The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)
Before writing to a company like this
Worth asking here even with no account. A connected car and the maker's app already carry your details, and the driving file built from them can reach the reporting firms insurers use before you ever see it. The request is how you find out whether a file exists at all, and what is in it.
The wording that does the work
Clauses that recur across this industry, and what each one actually permits.
“to provide and improve our services”
The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.
The move An objection tells them to use your data to run the service and nothing more.
“we do not sell your personal information”
Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.
The move Use the do-not-sell switch where there is one, and put an objection in writing as well.
“service providers, partners, and affiliates”
This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.
The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.
“aggregated or de-identified information”
Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.
The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.
“retained as long as necessary, or as required by law”
They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.
The move Which reasons apply to you, and how long each runs, is a request of its own.
“you grant us a licence to use your content”
This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.
The move Their terms say whether the licence ends when the account does. Close the account and log the date here.
“we disclose your data to insurance companies, leasing companies, financial service providers, fleet companies, and data aggregators”
Driving and location data can move to insurers, to lenders and leasing firms, and to companies whose business is aggregating it, all named up front. The list is the set of routes the policy keeps open.
The move Which of those named recipients holds a copy of your data is theirs to answer.
“de-identified data is not personal information and may be used and disclosed for purposes not described in this notice”
Once data is labelled de-identified, the company treats it as outside these rules: free to use and pass on for anything, and outside the retention limits. Location trails re-identify easily, so the label is wording, not proof the trail is anonymous.
The move Whether any of your data now travels under that label is theirs to answer.
“some of these disclosures may qualify as "sales" under some state laws”
The data still goes to third parties. The policy concedes only that this might count as a sale, and only in certain places, keeping the plain word sale out of the operative promise.
The move Whether your data was sold under that definition is theirs to answer.
Their own policy is the one that binds them. Pin it down with a request, and keep the reply.