Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Data Privacy

Location Data Enforcement in 2026: Kochava, GM/OnStar, and Allstate/Arity

Separate the 2026 Kochava and GM orders, California's GM settlement, Texas's Allstate/Arity suit, and private location-data litigation.

By Rebecca Leung · August 8, 2026 ·
Table of Contents

TL;DR

  • The 2026 record includes different proceedings with different legal effects: an FTC final GM order, an FTC Kochava settlement/stipulated order, a California GM stipulated judgment, a Texas AG Allstate/Arity action, and separate private federal litigation.
  • A motion-to-dismiss decision means specified allegations may proceed; it does not establish that the allegations are true.
  • Consent must be traceable through SDKs, data brokers, connected products, consumer reporting agencies, and end users.
  • Financial institutions that buy location or telematics data should test provenance, purpose, minimization, FCRA roles, and downstream use—not rely on a vendor’s generic privacy representation.

Location data can reveal home and work patterns, health or religious visits, driving behavior, and relationships. The 2025–2026 enforcement record shows regulators following that data across the supply chain: from embedded software and connected vehicles, through aggregators and brokers, to underwriting and other downstream uses.

The compliance lesson is strong. The procedural lesson is equally important: these matters are not interchangeable.

Keep the Proceedings Separate

MatterForum / enforcerStatus at the research cutoffWhat the status means
FTC v. KochavaFederal court / FTCFTC announced settlement and Commission-approved stipulated final order on May 4, 2026Settlement obligations; use the order for exact terms
In re General Motors / OnStarFTC administrative proceedingFinal FTC order announced January 14, 2026Binding administrative order
California v. General MotorsCalifornia state enforcement$12.75 million stipulated judgment announced May 2026Settlement and injunctive terms, not a litigated merits opinion
Texas v. Allstate / ArityTexas state enforcementFiled January 2025; certain later jurisdictional dismissals were proceduralAllegations and live-docket posture; no blanket merits ruling
Private Allstate / Arity litigationN.D. Ill., No. 1:25-cv-00407Motion to dismiss granted in part and denied in part March 3, 2026Specified claims survived pleading; others were dismissed; no final liability finding

A single sentence saying “the Allstate case survived” erases the distinction between Texas enforcement and private federal claims. Board papers, alerts, and control assessments should name the case, forum, date, and procedural posture.

Kochava: Controls at the Broker Layer

The FTC’s Kochava case page records the agency’s May 2026 settlement with Kochava and subsidiary Collective Data Solutions. The stipulated order addresses sensitive precise-location data and imposes obligations that include consent, deletion, consumer requests, and supplier assessment.

For due diligence, the supplier-assessment concept is especially important. A broker cannot create reliable permission merely by accepting a contractual promise that an upstream app “complies with law.” Evidence should connect the consumer-facing collection to the data later offered for sale or sharing.

A provenance file should show:

  • the app, device, SDK, or other source;
  • the notice and consent flow used at collection;
  • the purpose disclosed to the consumer;
  • precise-location and sensitive-location handling;
  • transformations, identifiers, and aggregation;
  • each downstream disclosure and permitted use;
  • retention and deletion controls; and
  • the method for honoring access or deletion requests across the chain.

GM/OnStar: Connected-Product Data and Consumer Reporting

The FTC finalized its GM/OnStar order on January 14, 2026. The order includes a five-year restriction on disclosure of geolocation and driver-behavior data to consumer reporting agencies, along with longer-running consent and privacy-program obligations. The final order is the source for definitions and exceptions.

California then announced a $12.75 million GM stipulated settlement in May 2026. California emphasized collection and use limits, transparency, consumer choice, and downstream disclosures under the CCPA and related law.

Together, the matters make three control questions unavoidable:

  1. Was the collection and downstream use within the consumer’s informed choice?
  2. Was the amount and sensitivity of data proportionate to the stated purpose?
  3. Did use in eligibility, pricing, or insurance introduce consumer-reporting duties?

An opt-in to a vehicle feature or app function is not automatically consent to every downstream underwriting or brokerage use.

Allstate/Arity: One Fact Pattern, Different Cases

The Texas Attorney General’s January 2025 petition alleges that embedded software gathered location and driving data through mobile apps and that the data was used or sold for insurance-related purposes without adequate notice or consent. The AG announcement describes claims under Texas privacy and consumer-protection law.

Those remain government allegations unless resolved by an order or judgment. Reported dismissals of certain Texas defendants for lack of personal jurisdiction are not findings that the challenged collection was lawful. Personal jurisdiction asks whether a particular court may exercise authority over a defendant; it does not adjudicate the underlying privacy claim.

Separately, private plaintiffs brought consolidated claims in the Northern District of Illinois. In Sims v. The Allstate Corporation, No. 1:25-cv-00407, Document 74, the court granted in part and denied in part defendants’ motion to dismiss on March 3, 2026. Some claims continued and others did not. That opinion can inform issue spotting around alleged interception, consumer reporting, and privacy claims, but it is not the Texas case and does not establish final liability.

The Control Pattern Across the Chain

These proceedings involve different statutes, but they expose a common governance failure: data moves farther than the collection experience would lead a consumer to expect.

Collection and SDK governance

Maintain an inventory of every mobile and web SDK, the data it can access, remote configuration, destination domains, and release owner. Test the compiled application—not only the SDK vendor’s questionnaire. A vendor update can change collection without a new contract.

Store versioned notices, interface screenshots, timestamps, jurisdiction, device context, consent action, and later withdrawals. Generic acceptance of terms is weak evidence for an unexpected sensitive-data use.

Purpose and minimization

Map each field to a specific purpose and retention period. If precise location is collected for navigation or rewards, a separate underwriting or sale use needs its own legal and consumer-expectation analysis.

Use a privacy impact assessment for mixed GLBA and non-GLBA data to document that analysis at the field-and-purpose level. The same evidence can feed the broader state privacy enforcement readiness review without treating every state law as identical.

Broker and fourth-party diligence

Identify who collected the data and every material intermediary. Confirm registrations where required, restrictions on sensitive locations, onward-transfer controls, and deletion propagation. Contract language should create audit and incident rights, but testing should verify performance.

Test one lineage end to end

Select a real data event and reconstruct its path from the consumer interface through each processor, broker, model, and downstream recipient. Preserve the notice and consent version, device or account identifier, event timestamp, transformations, purpose code, recipient, retention rule, and deletion status.

Then compare the reconstructed flow with the data map, vendor inventory, contract, and customer-facing policy. A mismatch may reveal an undocumented SDK destination, a stale purpose, an identifier that prevents deletion propagation, or a downstream use that was never assessed. Assign each exception an owner, legal and technical disposition, correction date, and retest.

Repeat the test after a material app release, SDK change, vendor acquisition, new model feature, or expansion into another use. These trigger-based tests are implementation recommendations, but they make the article’s core consent-and-provenance lesson measurable.

Retain each test result with the corresponding product-release and remediation records.

FCRA and eligibility use

If data contributes to insurance, credit, employment, housing, or another eligibility decision, determine whether any participant is acting as a consumer reporting agency, furnisher, or user of a consumer report. Document permissible purpose, accuracy, dispute, and adverse-action analysis rather than assuming “alternative data” sits outside the FCRA.

A 30-Day Remediation Plan

Week 1: Inventory. List location, telematics, device, and movement data received or generated. Include SDKs, connected products, fraud vendors, data brokers, and model features.

Week 2: Trace. For each flow, link collection notice and consent evidence to purpose, recipient, retention, and deletion. Flag broken lineage.

Week 3: Classify. Assess sensitive-location restrictions, state privacy applicability, broker registration, FCRA roles, and contract gaps. Record unsettled legal questions rather than forcing a green rating.

Week 4: Remediate. Disable unnecessary collection, segregate or delete unsupported data, revise notices and choices, impose use restrictions, and establish monitoring. Escalate material legacy data and model impacts.

So What?

Location-data governance is now a chain-of-custody exercise. Each participant needs evidence that collection, consent, purpose, minimization, retention, and downstream use remain aligned.

It is also a legal-status exercise. Cite agency allegations as allegations, settlements as settlements, jurisdictional dismissals as procedural, and pleading-stage decisions as pleading-stage decisions. Accuracy about the case is part of accuracy about the control risk.

The Data Privacy Compliance Kit provides data-mapping, vendor, and consumer-rights structures. Adapt them to the applicable order, statute, and live product flow.


Authoritative sources: FTC Kochava case and order record | FTC GM/OnStar final-order announcement | California GM stipulated settlement | Texas AG Allstate/Arity petition | N.D. Ill. March 3, 2026 opinion

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the FTC's Kochava settlement require?
On May 4, 2026, the FTC announced a settlement and Commission-approved stipulated final order with Kochava and Collective Data Solutions. The order restricts sale, sharing, or disclosure of sensitive precise-location data without affirmative express consent and imposes deletion, consumer-access, supplier-assessment, and compliance duties. Describe it as the FTC settlement and stipulated-order record; do not invent a separate damages award.
What did the FTC's final GM/OnStar order do?
The FTC finalized its administrative order on January 14, 2026. It imposes long-term privacy and consent duties and a five-year prohibition on disclosing geolocation and driver-behavior data to consumer reporting agencies. The order and its exceptions—not a summary headline—control the exact obligations.
What was California's General Motors settlement?
California's Attorney General and Privacy Protection Agency announced a $12.75 million stipulated judgment in May 2026 concerning connected-vehicle data. The settlement included injunctive terms addressing notice, consent, data minimization, consumer rights, and disclosure to data brokers and insurers.
Did the Texas Allstate/Arity court decide the privacy claims on the merits?
No broad merits conclusion is supported. Texas sued over alleged SDK-based collection and use of driving data. Later personal-jurisdiction dismissals of certain defendants were procedural and did not decide whether the alleged conduct violated the TDPSA or other law. The remaining Texas posture must be checked in the live docket.
Did Allstate/Arity privacy claims survive in a different case?
Yes, in separate private consolidated litigation in the Northern District of Illinois, the court granted in part and denied in part a motion to dismiss on March 3, 2026. That pleading-stage opinion allowed specified claims to continue and dismissed others. It is not an order in the Texas Attorney General case and is not a final merits judgment.
What should a financial institution ask a location-data vendor?
Ask for data lineage, collection notices, consent evidence, SDK and subcontractor inventory, purpose and retention limits, sensitive-location filters, broker registrations, consumer-rights handling, FCRA role analysis where data affects eligibility or pricing, and proof that downstream use matches what consumers were told.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.