Yes, consumer driving reports were shared improperly. General Motors and its OnStar subsidiary sold detailed driving behavior data to LexisNexis Risk Solutions and Verisk Analytics without meaningful consent from vehicle owners, then these data brokers packaged the information into driver behavior reports and sold them to insurance companies. One GM driver discovered that insurers possessed 331 separate reports documenting his driving habits—including hard braking events, rapid acceleration, high-speed driving, distance traveled, and vehicle identification numbers—collected between 2020 and 2024 without his knowledge or permission. The scope of this data sharing was massive.
GM generated approximately $20 million selling driver information to insurance companies, according to California officials. A federal judge in Georgia ruled in April 2026 that the automaker must face claims under the federal Wiretap Act, Stored Communications Act, Computer Fraud and Abuse Act, and Fair Credit Reporting Act. Meanwhile, California’s Attorney General secured a record $12.75 million settlement on May 8, 2026, marking the first cash penalty any U.S. authority has imposed on an automaker for selling driving data without consent—and the nationwide federal class action covers an estimated 16 million GM drivers affected by the practice.
Table of Contents
- How Did GM and OnStar Share Detailed Driving Behavior Data?
- What Made This Data Sharing a Legal Violation?
- Who Were the Affected Drivers and What Time Period Did This Cover?
- What Are the Main Legal Claims and Theories of Liability?
- What Does the California Settlement Require GM to Do?
- Federal Class Action Status and Estimated Recoveries
- What Does This Mean for Consumer Privacy and Automotive Data?
- Conclusion
How Did GM and OnStar Share Detailed Driving Behavior Data?
GM and OnStar collected granular data about how drivers actually operated their vehicles, capturing information that went far beyond basic location or mileage. The data included acceleration patterns, hard braking events, instances of high-speed driving, total distance traveled, and vehicle identification numbers tied to specific drivers. This information was collected continuously from 2020 through 2024 without explicit notification to vehicle owners that their driving behavior was being monetized.
Once collected, GM transferred this data to LexisNexis Risk Solutions and Verisk Analytics, two major data brokers in the insurance industry. These companies then packaged the raw driving information into driver behavior reports designed specifically for sale to insurance companies. The reports were formatted to be instantly usable by insurers for underwriting decisions—meaning an insurance company could access your driving patterns when you applied for a policy or renewal. In one plaintiff’s case documented in court filings, seven unnamed insurance companies rejected his application or raised his rates based on the shared driving reports, even though he had never authorized GM to provide that information to them.

What Made This Data Sharing a Legal Violation?
The core legal problem was consent. Drivers did not explicitly agree that GM could sell their real-time driving behavior to insurance companies and other third parties. Many GM customers believed OnStar was a safety and navigation service, not a data monetization operation. The privacy violation was magnified by the sensitive nature of the information: driving behavior data can reveal patterns about your life, your commute, your risk profile, and your habits in ways that feel intensely personal.
A critical limitation of earlier privacy frameworks was that they often did not clearly address the sale of driving data to consumer reporting agencies. The Fair Credit Reporting Act governed how credit bureaus operate, but the application to driving behavior reports was murkier. However, both the Federal Wiretap Act (which restricts interception of electronic communications) and the Stored Communications Act (which governs how stored data is accessed and used) apply more directly to the unauthorized collection and sharing of continuous driving data. California’s Consumer Privacy Act (CCPA) also violated data minimization and purpose limitation principles—GM collected and sold data for a purpose (insurance profiling) that consumers had not authorized.
Who Were the Affected Drivers and What Time Period Did This Cover?
The data collection and sharing spanned four years, from 2020 through 2024, meaning millions of drivers who owned or leased GM vehicles during this window could have been affected without their knowledge. The federal class action is estimated to include 16 million GM drivers, making it one of the largest privacy breaches tied to automotive data. This covers not just the most recent model years but a full generation of vehicles, from compact cars to trucks and SUVs.
One documented plaintiff had 331 individual driving reports generated about him. That single driver’s data footprint illustrates the systematic nature of the collection—if one person’s behavior was being tracked and reported on 331 separate occasions, imagine the cumulative volume across millions of drivers. The reports were not generated once and forgotten; they were created continuously, tracking each trip or driving session, then sold repeatedly to different insurance companies and potentially other underwriting entities. For many drivers, this data was shared without any notification that it was happening, let alone an opportunity to opt out.

What Are the Main Legal Claims and Theories of Liability?
The federal class action alleges violations under multiple statutes. The Federal Wiretap Act prohibits the intentional interception, use, and disclosure of wire and electronic communications without consent. By continuously collecting and transmitting real-time driving data without explicit authorization, the defendants’ conduct falls within the statute’s scope. The Stored Communications Act similarly restricts unauthorized access to stored electronic communications and data. Once the driving information was collected and stored, sharing it with third parties without legal authority or user consent violates this statute.
The Computer Fraud and Abuse Act (CFAA) claims rest on the theory that unauthorized collection of driving data from vehicle computer systems without permission constitutes unauthorized access to a computer system. The Fair Credit Reporting Act (FCRA) applies because the driving reports were used to make underwriting decisions about credit and insurance—the exact scenario FCRA was designed to regulate. Additionally, state privacy laws provided additional theories of liability. The distinction between these claims matters because they carry different statutory damages, attorney fee provisions, and remedial options. A Wiretap Act violation, for example, can result in statutory damages of $100 to $1,000 per violation, while FCRA violations allow actual damages plus statutory damages up to $1,000 per violation.
What Does the California Settlement Require GM to Do?
California’s $12.75 million settlement with GM includes several binding restrictions on future conduct. Most importantly, GM must stop selling or sharing driving data with consumer reporting agencies for five years, effectively eliminating the revenue stream that motivated the entire data monetization scheme. Within 180 days of the settlement’s final approval, GM must delete all retained driving data it has collected. This deletion requirement extends to the data already transferred to third parties: GM must require LexisNexis Risk Solutions and Verisk Analytics to delete the collected records and confirm deletion in writing. The settlement also requires GM to implement a stricter privacy compliance program to prevent similar violations in the future.
This includes enhanced notice to customers about what data is collected, how it is used, and whether it will be sold. However, a significant limitation of the California settlement is that it is state-specific and requires court approval before it becomes final. The settlement only applies to GM; it does not impose liability on LexisNexis or Verisk, the data brokers who packaged and resold the information to insurers. Those companies face potential liability in separate proceedings. Additionally, the five-year restriction means that after 2031, GM would technically be permitted to resume data sales unless separate legislation or other legal action extends the prohibition.

Federal Class Action Status and Estimated Recoveries
The federal class action proceeding in the U.S. District Court for the Northern District of Georgia covers an estimated 16 million GM drivers affected by the practice. In April 2026, the federal judge ruled that the defendants must face claims under the Wiretap Act, Stored Communications Act, Computer Fraud and Abuse Act, Fair Credit Reporting Act, and state privacy laws—denying motions to dismiss on most counts. This represents a significant legal victory for class members because it means the case will proceed to discovery and trial rather than being dismissed on procedural grounds.
The federal class action has the potential to result in far larger monetary recoveries than the California settlement alone, depending on how a jury or settlement negotiation values the claims. Statutory damages under the Wiretap Act could accumulate quickly across 16 million drivers. However, federal class actions also take longer to resolve and face ongoing legal battles over damages calculations and settlement approval. No final settlement has been announced in the federal case yet; the current status is that the court has permitted claims to proceed, and the case is moving toward discovery.
What Does This Mean for Consumer Privacy and Automotive Data?
The GM and OnStar case has signaled a shift in how regulators and courts view driving behavior data. The California Attorney General’s $12.75 million penalty was explicitly called a “record settlement for CCPA data minimization and purpose limitation violations,” suggesting that selling data for purposes beyond what consumers reasonably authorized is now a serious enforcement priority. The Federal Trade Commission also issued a separate order banning GM and OnStar from providing customer driving information to consumer reporting agencies for five years, bringing federal regulatory weight to the same restrictions.
This case will likely influence how other automakers handle telematics and connected vehicle data going forward. Companies that collect detailed driving information will face pressure to either obtain explicit consent, implement strict purpose limitations, or delete the data after specific periods. The wider implication is that data brokers like LexisNexis and Verisk may face increased scrutiny about where they source driving information and how they use it in underwriting decisions. For consumers, it reinforces the importance of understanding what data your vehicle is collecting, who has access to it, and whether you can opt out.
Conclusion
Yes, the LexisNexis driver data class action establishes that consumer driving reports were shared improperly—without meaningful consent, for purposes beyond what drivers authorized, and through a profit-driven system that enriched GM, data brokers, and insurers at the expense of 16 million vehicle owners. The $12.75 million California settlement and the ongoing federal class action represent two significant enforcement responses, but they come years after the unauthorized sharing began and only after individual drivers discovered their data had been sold.
If you are a GM driver who owned or leased a vehicle between 2020 and 2024, you may be eligible to participate in the federal class action or to claim against the California settlement once it receives final court approval. Watch for settlement notices from the court or your insurance company, and consider documenting any evidence that your insurance rates were affected by the shared driving reports. The case is ongoing, and final settlements have not yet been finalized in the federal proceeding, so timing for compensation remains uncertain.
You Might Also Like
- Rivian Range Class Action Claims EV Buyers Were Misled About Driving Distance
- Progressive Snapshot Privacy Class Action Claims Driver Data Was Collected Without Proper Consent
- Allstate Arity Data Class Action Claims Driving Behavior Data Was Sold Without Consent
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase: