Feature Data Privacy
California Just Fined GM $12.75 Million for Selling Driver Data Without Consent. Your Financial Data Practices Face the Same Scrutiny.
The $12.75M GM/OnStar CCPA settlement makes data minimization and purpose limitation enforcement reality. Here's what fintech and financial services compliance teams need to do about consumer behavioral data sales and sharing.
Table of Contents
TL;DR
- On May 8, 2026, California AG Rob Bonta and the California Privacy Protection Agency announced a $12.75 million CCPA settlement with General Motors and OnStar — the largest CCPA penalty on record.
- GM allegedly sold precise geolocation, driving behavior, braking, seatbelt, and speed data to LexisNexis and Verisk without consumer consent, earning approximately $20 million between 2020 and 2024.
- The core violations: data minimization and purpose limitation — GM collected data for vehicle safety, then repurposed it for insurance underwriting without new consent.
- LexisNexis and Verisk aren’t automotive companies. They’re financial services infrastructure. If your behavioral data flows reach those vendors — or others like them — the enforcement framework just expanded to cover you.
There’s a moment when an enforcement case stops being about the defendant and starts being about every organization doing something structurally similar. The $12.75 million California settlement with General Motors and OnStar is that moment — except it isn’t really an automotive case. It’s a data monetization case, and the vendors at the center of it are the same ones used in financial services underwriting every day.
What GM Actually Did
General Motors equipped its connected vehicles with OnStar, marketed as a safety and concierge service. When consumers activated OnStar, vehicles collected granular telemetry: precise GPS coordinates at regular intervals, hard braking events, rapid acceleration, seatbelt status, late-night driving patterns, speed threshold crossings, and trip timing and duration.
From 2020 through 2024, GM sold this data to LexisNexis Risk Solutions and Verisk Analytics. Those companies incorporated the driving scores into consumer risk profiles that insurers used to set premium rates — without drivers knowing their vehicle data had been collected, packaged, and sold.
GM made approximately $20 million from these sales. Numerous drivers saw insurance rates increase with no explanation. Many discovered only through media reporting that their behavioral data had become an insurance underwriting product.
California AG Rob Bonta’s May 8, 2026 announcement set the standard bluntly: “When it comes to data privacy, consumers must be in the driver’s seat.”
The $12.75 million settlement is the largest CCPA fine on record, eclipsing Disney’s $2.75 million from February 2026. GM must stop selling driving data to consumer reporting agencies for five years, delete retained data within 180 days absent express consent, ask LexisNexis and Verisk to delete purchased data, and maintain a formal privacy program subject to regulatory review.
The Two CCPA Principles That Got GM Fined
Data Minimization
The CCPA/CPRA requires that personal information collected be adequate, relevant, and limited to what is necessary for the stated purpose. GM collected trip-level precision telemetry — hard braking timestamps, late-night driving patterns, precise coordinates — and regulators took the position that this level of granularity exceeded what vehicle safety and concierge services required.
For financial institutions, data minimization applies directly. If you collect transaction metadata, GPS coordinates from mobile transactions, or device behavior for fraud detection, the minimization question is whether you’re retaining and sharing more granular data than your stated purpose requires. Keeping 36 months of location pings when your fraud model needs only 90 days creates exposure. Sharing full behavioral datasets when a summary score would suffice creates exposure.
Purpose Limitation
This is the sharper issue. Purpose limitation means data collected under one disclosed purpose cannot be repurposed for a materially different use without fresh consent.
GM disclosed OnStar as a safety and concierge service. Selling behavioral scoring data to insurance underwriting platforms is a materially different purpose. Consumers didn’t agree to become insurance actuarial products.
Financial services organizations face the identical risk pattern when:
- Transaction data collected for fraud detection gets shared with marketing analytics firms
- Mobile banking location signals collected for account security get incorporated into credit risk models
- Spending behavior aggregated for product recommendations gets sold to or shared with data brokers
- Account-level activity data gathered for regulatory compliance gets used in unrelated commercial analytics
The California AG’s office was explicit that purpose limitation enforcement in the GM case establishes a framework, not a one-time action.
LexisNexis and Verisk Aren’t Just GM’s Problem
This is the critical connection for financial services compliance teams.
LexisNexis Risk Solutions and Verisk Analytics are not auto industry companies. They are core infrastructure in financial services — used for insurance underwriting, mortgage origination, credit risk scoring, identity verification, and fraud analytics across the industry. If your organization hasn’t recently audited which third-party analytics vendors receive consumer behavioral data and under what consent framework, there is a real possibility your data flows resemble what just cost GM $12.75 million.
The settlement doesn’t impose liability on the buyers of the data. But it defines the enforcement framework governing how data reaches those buyers in the first place. Every financial institution that shares consumer behavioral data — spending patterns, payment behavior, cash flow signals, geolocation — must now be able to demonstrate that the consumer’s consent specifically covers that sharing.
California’s CPPA has active rulemaking underway on automated decision-making technology and additional sensitive data categories. The FTC separately sent PADFAA warning letters to 13 data brokers in February 2026 about selling consumer data to foreign adversaries. Multiple states are closing the entity-level GLBA exemption. The enforcement environment for consumer data monetization has shifted substantially in the last 12 months — GM is the high-profile headline, not the endpoint.
The GLBA Exemption Is Narrower Than You Think
Financial institutions often lean on GLBA compliance as a backstop for consumer data practices. That posture is increasingly risky.
The CCPA’s GLBA exemption operates at the individual-record level, not the entity level. GLBA protects non-public personal financial information under Regulation P. It does not blanket-cover every category of data a financial institution collects. Behavioral metadata — location signals from mobile transactions, device identifiers, usage patterns, spending category trends — may sit outside Reg P’s definition of NPPI and fall directly into California privacy law.
Montana’s and Connecticut’s recent amendments have made this narrowing explicit: both states moved from an entity-level GLBA carve-out to a data-level exemption, meaning nonbank fintechs and financial services companies that relied on GLBA for blanket CCPA coverage now have direct state privacy law obligations for data outside GLBA’s scope. The question is no longer “are we a financial institution?” — it’s “does GLBA actually cover this specific data category?”
Building the Data Flow Audit
The core remediation for GM-type risk is a data flow audit. Here’s what it needs to document:
Collection sources and categories: What behavioral, metadata, and contextual data do you collect, and from which touchpoints? Mobile app activity logs, transaction metadata, geolocation from card usage, device fingerprinting, spending category data.
Consent scope at collection: What did consumers actually consent to? Pull the full disclosure language — not the summary — from each enrollment flow, app permissions request, and privacy notice in effect at the time data was collected. List the purposes stated.
Data destinations: For each data category, where does it go after initial collection? Internal analytics systems, downstream vendor APIs, batch exports, data licensing arrangements, consumer reporting agency pipelines.
Vendor contracts: For each third-party data recipient, what does the contract say about permitted use? Does it prohibit repurposing? Can the vendor create derivative products or share data further downstream?
Consumer reporting agency exposure: The GM settlement specifically flagged sales to consumer reporting agencies. LexisNexis and Verisk operate CRA-regulated products alongside their analytics services. If your data flows reach a CRA — including through intermediary vendors — FCRA requirements layer on top of CCPA exposure.
The AI and Consumer Data Rights framework is directly applicable here for fintechs using behavioral data in automated decisioning — the same data-use questions arise when an AI model is the downstream consumer of the shared data.
The Consent Architecture Problem
One consistent failure pattern in enforcement is a gap between the sophistication of the data monetization program and the specificity of consumer consent. GM’s enrollment flow included language about vehicle diagnostics and safety features. It did not specifically disclose that driving behavior scores would be sold to insurance underwriting platforms for premium calculations.
For financial services, the consent architecture question is: does your current privacy notice describe what you’re actually doing with data at the specificity CCPA requires?
The CPRA demands that privacy notices describe the categories of data collected, the purposes for collection and use, and whether data is sold or “shared” — with sharing defined broadly to include transfers for cross-context behavioral advertising. If you’re sharing behavioral data with analytics firms and the sharing purposes differ from the stated collection purposes, updating the consent architecture isn’t optional, it’s the remediation.
The Paylogix vendor breach case showed what happens when TPRM contracts don’t govern notification requirements. GM shows what happens when they don’t govern repurposing restrictions. Both failures start in the same place: inadequate control over what third parties do with your consumers’ data.
”So What?” — The 60-Day Priority List
This settlement will be cited in CPPA enforcement documents for the next several years. For compliance teams, the near-term work is:
Days 1–30:
- Run a data flow audit across every behavioral and metadata category you collect
- Pull the exact consent language from current privacy notices, app permissions, and enrollment flows
- Identify all third-party data recipients and confirm their permitted use categories
- Flag any relationships with consumer reporting agencies, data brokers, or analytics vendors receiving behavioral data
Days 31–60:
- Review vendor contracts for restrictions on data repurposing and sublicensing
- Update privacy notices where stated purposes don’t match actual data practices
- Confirm GLBA exemption scope for each data category — particularly behavioral metadata and mobile signals
- Determine whether any data-sharing practices require opt-in consent rather than opt-out
The Data Privacy Compliance Kit includes multi-state consent mapping, a data inventory template, and vendor data sharing agreement review checklist designed for exactly this kind of audit. The GM settlement is the enforcement signal — whether your practices survive the same scrutiny is a question your data flow documentation answers.
Sources
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did California allege against GM and OnStar?
What is the significance of the $12.75M settlement for CCPA enforcement?
What is 'purpose limitation' and why does it matter for financial services?
Do California privacy laws apply to fintechs and financial services companies?
What does the GM/OnStar settlement require the company to do?
What should compliance teams do first after this settlement?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Your Analytics Stack Is a GLBA Time Bomb. The Class Action Wave Targeting Financial Institutions That Use Meta Pixel Has Arrived.
TaxAct just paid Connecticut $275K for sharing taxpayer data via Meta Pixel. Class actions against banks and fintechs using third-party tracking scripts are surging. Here's what the GLBA exposure actually looks like — and what your tag governance program needs.
Sep 25, 2026
Data Privacy
Montana and Connecticut Just Narrowed the GLBA Exemption. Every Nonbank Financial Institution Has New Privacy Obligations.
Montana's privacy law amendments took effect October 1, 2025. Connecticut's took effect July 1, 2026. Both states moved from a broad entity-level GLBA exemption to a narrower data-level exemption — meaning fintechs, nonbank mortgage companies, and other non-depository financial institutions that relied on GLBA for blanket coverage are now subject to state privacy law for data outside GLBA's scope.
Sep 18, 2026
Data Privacy
NYDFS Just Published a 'How-To' for Cyber Risk Assessments. Most of Yours Still Won't Pass.
On September 10, 2026, NYDFS issued comprehensive guidance on how to conduct risk assessments under Part 500. It identifies common failures and what 'based on' actually means. Here's what every covered entity needs to review.
Sep 16, 2026