Feature Data Privacy
Location Data Enforcement in 2026: Kochava, GM/OnStar, and Allstate/Arity
Separate the 2026 Kochava and GM orders, California's GM settlement, Texas's Allstate/Arity suit, and private location-data litigation.
Table of Contents
TL;DR
- The 2026 record includes different proceedings with different legal effects: an FTC final GM order, an FTC Kochava settlement/stipulated order, a California GM stipulated judgment, a Texas AG Allstate/Arity action, and separate private federal litigation.
- A motion-to-dismiss decision means specified allegations may proceed; it does not establish that the allegations are true.
- Consent must be traceable through SDKs, data brokers, connected products, consumer reporting agencies, and end users.
- Financial institutions that buy location or telematics data should test provenance, purpose, minimization, FCRA roles, and downstream use—not rely on a vendor’s generic privacy representation.
Location data can reveal home and work patterns, health or religious visits, driving behavior, and relationships. The 2025–2026 enforcement record shows regulators following that data across the supply chain: from embedded software and connected vehicles, through aggregators and brokers, to underwriting and other downstream uses.
The compliance lesson is strong. The procedural lesson is equally important: these matters are not interchangeable.
Keep the Proceedings Separate
| Matter | Forum / enforcer | Status at the research cutoff | What the status means |
|---|---|---|---|
| FTC v. Kochava | Federal court / FTC | FTC announced settlement and Commission-approved stipulated final order on May 4, 2026 | Settlement obligations; use the order for exact terms |
| In re General Motors / OnStar | FTC administrative proceeding | Final FTC order announced January 14, 2026 | Binding administrative order |
| California v. General Motors | California state enforcement | $12.75 million stipulated judgment announced May 2026 | Settlement and injunctive terms, not a litigated merits opinion |
| Texas v. Allstate / Arity | Texas state enforcement | Filed January 2025; certain later jurisdictional dismissals were procedural | Allegations and live-docket posture; no blanket merits ruling |
| Private Allstate / Arity litigation | N.D. Ill., No. 1:25-cv-00407 | Motion to dismiss granted in part and denied in part March 3, 2026 | Specified claims survived pleading; others were dismissed; no final liability finding |
A single sentence saying “the Allstate case survived” erases the distinction between Texas enforcement and private federal claims. Board papers, alerts, and control assessments should name the case, forum, date, and procedural posture.
Kochava: Controls at the Broker Layer
The FTC’s Kochava case page records the agency’s May 2026 settlement with Kochava and subsidiary Collective Data Solutions. The stipulated order addresses sensitive precise-location data and imposes obligations that include consent, deletion, consumer requests, and supplier assessment.
For due diligence, the supplier-assessment concept is especially important. A broker cannot create reliable permission merely by accepting a contractual promise that an upstream app “complies with law.” Evidence should connect the consumer-facing collection to the data later offered for sale or sharing.
A provenance file should show:
- the app, device, SDK, or other source;
- the notice and consent flow used at collection;
- the purpose disclosed to the consumer;
- precise-location and sensitive-location handling;
- transformations, identifiers, and aggregation;
- each downstream disclosure and permitted use;
- retention and deletion controls; and
- the method for honoring access or deletion requests across the chain.
GM/OnStar: Connected-Product Data and Consumer Reporting
The FTC finalized its GM/OnStar order on January 14, 2026. The order includes a five-year restriction on disclosure of geolocation and driver-behavior data to consumer reporting agencies, along with longer-running consent and privacy-program obligations. The final order is the source for definitions and exceptions.
California then announced a $12.75 million GM stipulated settlement in May 2026. California emphasized collection and use limits, transparency, consumer choice, and downstream disclosures under the CCPA and related law.
Together, the matters make three control questions unavoidable:
- Was the collection and downstream use within the consumer’s informed choice?
- Was the amount and sensitivity of data proportionate to the stated purpose?
- Did use in eligibility, pricing, or insurance introduce consumer-reporting duties?
An opt-in to a vehicle feature or app function is not automatically consent to every downstream underwriting or brokerage use.
Allstate/Arity: One Fact Pattern, Different Cases
The Texas Attorney General’s January 2025 petition alleges that embedded software gathered location and driving data through mobile apps and that the data was used or sold for insurance-related purposes without adequate notice or consent. The AG announcement describes claims under Texas privacy and consumer-protection law.
Those remain government allegations unless resolved by an order or judgment. Reported dismissals of certain Texas defendants for lack of personal jurisdiction are not findings that the challenged collection was lawful. Personal jurisdiction asks whether a particular court may exercise authority over a defendant; it does not adjudicate the underlying privacy claim.
Separately, private plaintiffs brought consolidated claims in the Northern District of Illinois. In Sims v. The Allstate Corporation, No. 1:25-cv-00407, Document 74, the court granted in part and denied in part defendants’ motion to dismiss on March 3, 2026. Some claims continued and others did not. That opinion can inform issue spotting around alleged interception, consumer reporting, and privacy claims, but it is not the Texas case and does not establish final liability.
The Control Pattern Across the Chain
These proceedings involve different statutes, but they expose a common governance failure: data moves farther than the collection experience would lead a consumer to expect.
Collection and SDK governance
Maintain an inventory of every mobile and web SDK, the data it can access, remote configuration, destination domains, and release owner. Test the compiled application—not only the SDK vendor’s questionnaire. A vendor update can change collection without a new contract.
Consent evidence
Store versioned notices, interface screenshots, timestamps, jurisdiction, device context, consent action, and later withdrawals. Generic acceptance of terms is weak evidence for an unexpected sensitive-data use.
Purpose and minimization
Map each field to a specific purpose and retention period. If precise location is collected for navigation or rewards, a separate underwriting or sale use needs its own legal and consumer-expectation analysis.
Use a privacy impact assessment for mixed GLBA and non-GLBA data to document that analysis at the field-and-purpose level. The same evidence can feed the broader state privacy enforcement readiness review without treating every state law as identical.
Broker and fourth-party diligence
Identify who collected the data and every material intermediary. Confirm registrations where required, restrictions on sensitive locations, onward-transfer controls, and deletion propagation. Contract language should create audit and incident rights, but testing should verify performance.
Test one lineage end to end
Select a real data event and reconstruct its path from the consumer interface through each processor, broker, model, and downstream recipient. Preserve the notice and consent version, device or account identifier, event timestamp, transformations, purpose code, recipient, retention rule, and deletion status.
Then compare the reconstructed flow with the data map, vendor inventory, contract, and customer-facing policy. A mismatch may reveal an undocumented SDK destination, a stale purpose, an identifier that prevents deletion propagation, or a downstream use that was never assessed. Assign each exception an owner, legal and technical disposition, correction date, and retest.
Repeat the test after a material app release, SDK change, vendor acquisition, new model feature, or expansion into another use. These trigger-based tests are implementation recommendations, but they make the article’s core consent-and-provenance lesson measurable.
Retain each test result with the corresponding product-release and remediation records.
FCRA and eligibility use
If data contributes to insurance, credit, employment, housing, or another eligibility decision, determine whether any participant is acting as a consumer reporting agency, furnisher, or user of a consumer report. Document permissible purpose, accuracy, dispute, and adverse-action analysis rather than assuming “alternative data” sits outside the FCRA.
A 30-Day Remediation Plan
Week 1: Inventory. List location, telematics, device, and movement data received or generated. Include SDKs, connected products, fraud vendors, data brokers, and model features.
Week 2: Trace. For each flow, link collection notice and consent evidence to purpose, recipient, retention, and deletion. Flag broken lineage.
Week 3: Classify. Assess sensitive-location restrictions, state privacy applicability, broker registration, FCRA roles, and contract gaps. Record unsettled legal questions rather than forcing a green rating.
Week 4: Remediate. Disable unnecessary collection, segregate or delete unsupported data, revise notices and choices, impose use restrictions, and establish monitoring. Escalate material legacy data and model impacts.
So What?
Location-data governance is now a chain-of-custody exercise. Each participant needs evidence that collection, consent, purpose, minimization, retention, and downstream use remain aligned.
It is also a legal-status exercise. Cite agency allegations as allegations, settlements as settlements, jurisdictional dismissals as procedural, and pleading-stage decisions as pleading-stage decisions. Accuracy about the case is part of accuracy about the control risk.
The Data Privacy Compliance Kit provides data-mapping, vendor, and consumer-rights structures. Adapt them to the applicable order, statute, and live product flow.
Authoritative sources: FTC Kochava case and order record | FTC GM/OnStar final-order announcement | California GM stipulated settlement | Texas AG Allstate/Arity petition | N.D. Ill. March 3, 2026 opinion
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the FTC's Kochava settlement require?
What did the FTC's final GM/OnStar order do?
What was California's General Motors settlement?
Did the Texas Allstate/Arity court decide the privacy claims on the merits?
Did Allstate/Arity privacy claims survive in a different case?
What should a financial institution ask a location-data vendor?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Global Privacy Control for Financial Services: A State-by-State Scope Test
A practical Global Privacy Control guide for financial services: state scope, GLBA exemptions, signal handling, testing, and evidence.
Aug 17, 2026
Data Privacy
California Just Fined a Data Broker $116K for Making Opt-Out Too Hard. Your Fintech's Data Practices Are Next.
CalPrivacy ordered LocateSmarter to pay $116,490 over registration and opt-out violations, then fined Cybba $52,400 two days later.
Aug 14, 2026
Data Privacy
Washington MHMDA for Fintech: The GLBA Data Exemption and CPA Enforcement
Washington's My Health My Data Act has a data-level GLBA exemption and uses the Consumer Protection Act for public and private enforcement.
Aug 12, 2026