In short: Today's connected cars collect GPS tracks, driving behaviour, data from your paired phone and, in some models, cabin audio — and according to a Mozilla Foundation study, 19 out of 25 car brands reserve the right to sell that data. A VPN on your phone will not stop your car's telematics unit: it sends data to the manufacturer over its own SIM card, independently of your phone's internet traffic. What a VPN does help with: the brand's companion app when you're on a public network, dealer or charging-station Wi-Fi, and devices tethered to the car's hotspot. The most effective controls are in-car privacy settings and an opt-out request through your brand's app.
What Data a Connected Car Actually Collects
Data generated by the car itself
Any vehicle with a built-in telematics module logs your position continuously, building a trip-by-trip GPS track. Alongside location, the system records speed, hard braking and rapid acceleration events (used to derive a driving style score), odometer readings, engine start and stop times, and live diagnostics from the vehicle's systems. The VIN ties all of this data to a specific vehicle and, indirectly, to its registered owner.
Newer models add interior presence sensors, external and internal cameras (driver monitoring systems for fatigue and distraction), and microphones. Microphones serve more than just voice assistants: vehicles sold in the EU since 2018 are required to carry an eCall emergency module, which includes a GSM modem, GNSS receiver and a built-in microphone for two-way voice contact with emergency services in the event of a crash.
None of this data just sits locally. A connected car has a built-in SIM card in its telematics module, and data flows to the manufacturer's servers in real time or in batches. How long that data is retained and who can access it are details that most manufacturers do not disclose clearly — and that opacity is precisely the problem Mozilla's study put on record.
- GPS track of every trip: route, timing, speed profile
- Driving behaviour: hard braking, rapid acceleration, speed violations
- Odometer and live diagnostics (OBD-II / CAN bus)
- VIN, IMEI of the telematics unit, device identifiers
- Interior and exterior camera data, presence sensor readings
- Voice queries to the infotainment assistant
Data pulled from your paired phone
When you pair a smartphone over Bluetooth or connect via Apple CarPlay or Android Auto, the infotainment system requests access to contacts and call logs — the standard Bluetooth HFP (Hands-Free Profile). Many systems also pull recent navigation destinations. Some of this data persists in the car's memory even after you disconnect the phone.
The brand's companion app (MyToyota, BMW Connected, Mercedes me and their equivalents) also collects data directly from your phone: device model, IP address, advertising identifier and in-app behaviour. The scope depends on the permissions you granted at install time — and companion apps routinely request background location access, meaning they can record your position even when the app is closed.
Where the Data Goes and Who Profits
In Mozilla Foundation's Privacy Not Included review of privacy policies across 25 car brands, 19 out of 25 companies state they can sell drivers' personal data. Not a single brand in the study met Mozilla's minimum privacy standards. That does not mean all 19 brands actively sell data at this moment — but the right is written into their terms of service.
One of the most thoroughly documented routes is the data-broker pipeline: manufacturers share telematics data with brokers, who aggregate it into driving profiles and sell those profiles to insurance companies. Insurers can then adjust rates based on driving scores — often without an explicit notification to the vehicle owner. This exact mechanism was at the centre of the FTC action against GM: telematics data ended up with insurers and influenced risk assessments of policyholders.
In January 2026, the US Federal Trade Commission (FTC) finalised an order against General Motors and its OnStar service. The investigation found that GM collected customers' location and driving data and shared it with credit reporting agencies without proper informed consent. Under the order, GM must stop sharing that data with credit bureaus for five years and must provide all owners with a working option to turn off location collection — a genuine, functional opt-out.
The Record (Recorded Future News) described the GM/OnStar action as a shot across the bow to the auto industry. Regulatory scrutiny of connected-car privacy is intensifying in 2026, with proposed requirements in both the US and EU for explicit consent and data minimisation in automotive telematics.
eCall and Emergency Systems: the Honest Picture
EU-mandated eCall has been required in all new passenger cars sold in Europe since April 2018. It is an in-vehicle emergency device: a SIM card, GSM modem, GNSS receiver, microphone and speaker for voice contact with emergency operators. Each unit has its own IMEI.
A critical distinction that often gets lost: eCall does not stream your location continuously. It transmits a Minimum Set of Data — including your position and VIN — only when triggered: either manually via the SOS button or automatically when crash sensors fire. This is an emergency function, not persistent surveillance.
The continuous data collection you should be concerned about comes from the manufacturer's proprietary telematics system and companion app — entirely separate from eCall. That is the channel that logs every trip and routes data to the brand's servers, and potentially onwards to brokers and insurers. The US equivalent, Automatic Crash Notification (ACN), follows the same pattern: the emergency trigger is narrowly scoped, while the surrounding telematics platform is broader in scope and less regulated.
Where a VPN Helps — and Where It Doesn't
Your car's telematics module connects to the manufacturer's servers via its own SIM card over a GSM channel that is completely independent of your smartphone and its internet traffic. A VPN on your phone operates on your phone's traffic — it has no reach over the car-to-manufacturer channel.
| Data channel / type | Does a VPN protect it? | What actually helps |
|---|---|---|
| Car telematics to manufacturer (location, driving data) | No | In-car privacy settings, opt-out |
| Companion app on phone (network, IP, ad trackers) | Partially (network / IP) | VPN + permission limits + advertising ID reset |
| Public Wi-Fi at a dealer or charging station | Yes | VPN |
| eCall / emergency module (crash / SOS trigger) | No (and you don't want it to) | Nothing — it's a safety function |
| Data sold to brokers / insurers | No | Opt-out with brand + data broker removal requests |
Three scenarios where a VPN makes a real difference. First: you open the brand's companion app (Toyota, BMW, Mercedes) on a public network. Without a VPN, your phone's IP address and traffic to advertising SDKs inside the app are visible to the network operator. A VPN encrypts that traffic and hides your real IP from third-party trackers embedded in the app — especially relevant when using the app on hotel, airport or cafe Wi-Fi. Second: dealer Wi-Fi or a free charging-station hotspot is a classic interception point — LiMP VPN on Android encrypts traffic from all apps simultaneously. Third: any device tethered to the car's Wi-Fi hotspot benefits from the same protection if that device runs a VPN. For a wider look at phone-level threats, see how to stop phone tracking.
The Partially entry in the table for the companion app deserves more detail. A VPN hides your real IP from the app's trackers and encrypts the network-layer traffic between your phone and the VPN exit node. What it does not stop: the app continuing to read your advertising identifier, collect in-app analytics, or access sensors it has permission to access. That's why a VPN is one layer, not a complete solution — it combines best with permission management and an advertising ID reset.
How to Limit Data Collection: Settings and Opt-Out
Start with the car's infotainment system. Most modern systems have a Privacy, Data and Diagnostics or Connected Services section in their settings. BMW lets owners disable analytics data transmission all the way through to a full Connected Drive opt-out; other brands offer more limited controls. Look for this option not inside the navigation menu but in the main system or account settings — that is where connectivity and data-sharing controls typically live.
Next, use the brand's companion app. Consumer Reports identifies these specific paths: Toyota and Lexus — open the app, tap the profile icon then Account then Data Privacy Portal; Ford — the privacy section inside FordPass or the brand's website dashboard; GM — the FTC order requires a working opt-out for all owners. If your brand's app does not have a clearly labelled privacy section, check your account settings on the brand's website or contact support — following the FTC action, most major manufacturers have added opt-out mechanisms.
Honest trade-off: disabling data collection may disable some connected features along with it. Remote start, crash detection with automatic emergency calls (in brands that implement this separately from eCall), and real-time diagnostic alerts may stop working or work in a reduced mode. An unconditional guarantee of zero outgoing data is rare, and language like 'data necessary to provide the service' leaves manufacturers significant latitude.
At the phone level: grant the companion app only the permissions it genuinely needs — restrict location to while using and turn off background refresh. To get your data removed from broker databases, follow the steps in how to remove your data from the internet. Also reset your advertising identifier — this reduces cross-app data linkability and limits the usefulness of any data the telematics pipeline already has about you.
Checklist: What to Do Today
- Open your brand's companion app and find the Data Privacy Portal (or equivalent) — submit an opt-out request for driving data and location collection.
- Go to infotainment settings and find Privacy / Connected Services — turn off analytics and diagnostics sharing with the manufacturer's servers where the option exists.
- Check what phone data was imported into the car's memory (contacts, call history) — remove paired devices from any car that isn't yours.
- In your phone's settings, limit the companion app's location access to While Using and disable background refresh.
- Reset your advertising identifier (Android: Settings then Privacy; iOS: Settings then Privacy then Tracking).
- Submit removal requests to two or three major data brokers — see the full guide to removing your data from the internet.
- Before selling your car: sign out of your brand account in the companion app, delete all paired phones from the infotainment system, and perform a factory reset of the multimedia system.
- Install a VPN on your phone for use on dealer Wi-Fi, charging-station networks and the car's hotspot — see also how to stop phone tracking.
Frequently Asked Questions
Can a VPN hide my location from the car manufacturer?
No. The telematics module connects to the manufacturer's servers via its own SIM card over a GSM channel that is entirely separate from your phone's internet traffic. A VPN on your phone has no access to that channel. To limit the location data your manufacturer receives, you need to opt out through the brand's app or infotainment settings — it's worth knowing this clearly before assuming VPN coverage extends to the car itself.
Does an older car without smart features collect data?
It depends on whether the car has a built-in telematics module and internet connectivity. A vehicle without a factory SIM card stores data locally and does not transmit it over the network. The older and simpler the car, the fewer external data-sharing capabilities it has. Aftermarket OBD dongles — installed by insurers or leasing companies — create a separate collection channel that is not factory-default and operates independently of any manufacturer app.
What should I do about data when selling a used car?
Three steps before handing over the keys: sign out of your brand account in the companion app (so the new owner cannot access your trip history under your login), delete all paired phones from the infotainment system's Bluetooth and CarPlay/Android Auto memory, and perform a full factory reset of the multimedia system — usually found under a Reset or Factory Settings menu option. On some models you may need to confirm the reset through the brand's website or at a dealership.
Can insurers raise my premiums based on driving data?
Yes, and the pipeline is documented. The FTC's GM/OnStar investigation found that driving data was passed to brokers and could affect a driver's insurance risk score. An opt-out through your brand's app or infotainment settings is the primary control available to you at the source. A separate opt-out with data brokers removes data that has already been collected — both steps together give the most complete coverage.
What features will I lose if I turn off data collection?
Some connected features may stop working or work in a reduced mode: remote start and lock via the app, crash detection with automatic assistance (where implemented separately from eCall), and real-time diagnostic alerts. The eCall emergency system itself operates on its own independent circuit and will continue to function. The exact impact depends on your brand and model — it is worth checking with the manufacturer's support what specific features are tied to data-sharing consent.
Does data collection happen even if I don't use the brand's app?
Yes. The telematics module runs autonomously — in the background, without user action and without the app installed. The companion app is just one interface for accessing vehicle data and controlling connected features; the actual data transmission from car to manufacturer's servers happens regardless of whether you have the app on your phone.
