Skip to content
RiskTemplates · The Daily Brief Sunday, September 27, 2026
Wire OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program. SEP 26

Feature Data Privacy

California Just Fined GM $12.75 Million for Selling Driver Data Without Consent. Your Financial Data Practices Face the Same Scrutiny.

The $12.75M GM/OnStar CCPA settlement makes data minimization and purpose limitation enforcement reality. Here's what fintech and financial services compliance teams need to do about consumer behavioral data sales and sharing.

By Rebecca Leung · September 22, 2026 ·
Table of Contents

TL;DR

  • On May 8, 2026, California AG Rob Bonta and the California Privacy Protection Agency announced a $12.75 million CCPA settlement with General Motors and OnStar — the largest CCPA penalty on record.
  • GM allegedly sold precise geolocation, driving behavior, braking, seatbelt, and speed data to LexisNexis and Verisk without consumer consent, earning approximately $20 million between 2020 and 2024.
  • The core violations: data minimization and purpose limitation — GM collected data for vehicle safety, then repurposed it for insurance underwriting without new consent.
  • LexisNexis and Verisk aren’t automotive companies. They’re financial services infrastructure. If your behavioral data flows reach those vendors — or others like them — the enforcement framework just expanded to cover you.

There’s a moment when an enforcement case stops being about the defendant and starts being about every organization doing something structurally similar. The $12.75 million California settlement with General Motors and OnStar is that moment — except it isn’t really an automotive case. It’s a data monetization case, and the vendors at the center of it are the same ones used in financial services underwriting every day.

What GM Actually Did

General Motors equipped its connected vehicles with OnStar, marketed as a safety and concierge service. When consumers activated OnStar, vehicles collected granular telemetry: precise GPS coordinates at regular intervals, hard braking events, rapid acceleration, seatbelt status, late-night driving patterns, speed threshold crossings, and trip timing and duration.

From 2020 through 2024, GM sold this data to LexisNexis Risk Solutions and Verisk Analytics. Those companies incorporated the driving scores into consumer risk profiles that insurers used to set premium rates — without drivers knowing their vehicle data had been collected, packaged, and sold.

GM made approximately $20 million from these sales. Numerous drivers saw insurance rates increase with no explanation. Many discovered only through media reporting that their behavioral data had become an insurance underwriting product.

California AG Rob Bonta’s May 8, 2026 announcement set the standard bluntly: “When it comes to data privacy, consumers must be in the driver’s seat.”

The $12.75 million settlement is the largest CCPA fine on record, eclipsing Disney’s $2.75 million from February 2026. GM must stop selling driving data to consumer reporting agencies for five years, delete retained data within 180 days absent express consent, ask LexisNexis and Verisk to delete purchased data, and maintain a formal privacy program subject to regulatory review.

The Two CCPA Principles That Got GM Fined

Data Minimization

The CCPA/CPRA requires that personal information collected be adequate, relevant, and limited to what is necessary for the stated purpose. GM collected trip-level precision telemetry — hard braking timestamps, late-night driving patterns, precise coordinates — and regulators took the position that this level of granularity exceeded what vehicle safety and concierge services required.

For financial institutions, data minimization applies directly. If you collect transaction metadata, GPS coordinates from mobile transactions, or device behavior for fraud detection, the minimization question is whether you’re retaining and sharing more granular data than your stated purpose requires. Keeping 36 months of location pings when your fraud model needs only 90 days creates exposure. Sharing full behavioral datasets when a summary score would suffice creates exposure.

Purpose Limitation

This is the sharper issue. Purpose limitation means data collected under one disclosed purpose cannot be repurposed for a materially different use without fresh consent.

GM disclosed OnStar as a safety and concierge service. Selling behavioral scoring data to insurance underwriting platforms is a materially different purpose. Consumers didn’t agree to become insurance actuarial products.

Financial services organizations face the identical risk pattern when:

  • Transaction data collected for fraud detection gets shared with marketing analytics firms
  • Mobile banking location signals collected for account security get incorporated into credit risk models
  • Spending behavior aggregated for product recommendations gets sold to or shared with data brokers
  • Account-level activity data gathered for regulatory compliance gets used in unrelated commercial analytics

The California AG’s office was explicit that purpose limitation enforcement in the GM case establishes a framework, not a one-time action.

LexisNexis and Verisk Aren’t Just GM’s Problem

This is the critical connection for financial services compliance teams.

LexisNexis Risk Solutions and Verisk Analytics are not auto industry companies. They are core infrastructure in financial services — used for insurance underwriting, mortgage origination, credit risk scoring, identity verification, and fraud analytics across the industry. If your organization hasn’t recently audited which third-party analytics vendors receive consumer behavioral data and under what consent framework, there is a real possibility your data flows resemble what just cost GM $12.75 million.

The settlement doesn’t impose liability on the buyers of the data. But it defines the enforcement framework governing how data reaches those buyers in the first place. Every financial institution that shares consumer behavioral data — spending patterns, payment behavior, cash flow signals, geolocation — must now be able to demonstrate that the consumer’s consent specifically covers that sharing.

California’s CPPA has active rulemaking underway on automated decision-making technology and additional sensitive data categories. The FTC separately sent PADFAA warning letters to 13 data brokers in February 2026 about selling consumer data to foreign adversaries. Multiple states are closing the entity-level GLBA exemption. The enforcement environment for consumer data monetization has shifted substantially in the last 12 months — GM is the high-profile headline, not the endpoint.

The GLBA Exemption Is Narrower Than You Think

Financial institutions often lean on GLBA compliance as a backstop for consumer data practices. That posture is increasingly risky.

The CCPA’s GLBA exemption operates at the individual-record level, not the entity level. GLBA protects non-public personal financial information under Regulation P. It does not blanket-cover every category of data a financial institution collects. Behavioral metadata — location signals from mobile transactions, device identifiers, usage patterns, spending category trends — may sit outside Reg P’s definition of NPPI and fall directly into California privacy law.

Montana’s and Connecticut’s recent amendments have made this narrowing explicit: both states moved from an entity-level GLBA carve-out to a data-level exemption, meaning nonbank fintechs and financial services companies that relied on GLBA for blanket CCPA coverage now have direct state privacy law obligations for data outside GLBA’s scope. The question is no longer “are we a financial institution?” — it’s “does GLBA actually cover this specific data category?”

Building the Data Flow Audit

The core remediation for GM-type risk is a data flow audit. Here’s what it needs to document:

Collection sources and categories: What behavioral, metadata, and contextual data do you collect, and from which touchpoints? Mobile app activity logs, transaction metadata, geolocation from card usage, device fingerprinting, spending category data.

Consent scope at collection: What did consumers actually consent to? Pull the full disclosure language — not the summary — from each enrollment flow, app permissions request, and privacy notice in effect at the time data was collected. List the purposes stated.

Data destinations: For each data category, where does it go after initial collection? Internal analytics systems, downstream vendor APIs, batch exports, data licensing arrangements, consumer reporting agency pipelines.

Vendor contracts: For each third-party data recipient, what does the contract say about permitted use? Does it prohibit repurposing? Can the vendor create derivative products or share data further downstream?

Consumer reporting agency exposure: The GM settlement specifically flagged sales to consumer reporting agencies. LexisNexis and Verisk operate CRA-regulated products alongside their analytics services. If your data flows reach a CRA — including through intermediary vendors — FCRA requirements layer on top of CCPA exposure.

The AI and Consumer Data Rights framework is directly applicable here for fintechs using behavioral data in automated decisioning — the same data-use questions arise when an AI model is the downstream consumer of the shared data.

One consistent failure pattern in enforcement is a gap between the sophistication of the data monetization program and the specificity of consumer consent. GM’s enrollment flow included language about vehicle diagnostics and safety features. It did not specifically disclose that driving behavior scores would be sold to insurance underwriting platforms for premium calculations.

For financial services, the consent architecture question is: does your current privacy notice describe what you’re actually doing with data at the specificity CCPA requires?

The CPRA demands that privacy notices describe the categories of data collected, the purposes for collection and use, and whether data is sold or “shared” — with sharing defined broadly to include transfers for cross-context behavioral advertising. If you’re sharing behavioral data with analytics firms and the sharing purposes differ from the stated collection purposes, updating the consent architecture isn’t optional, it’s the remediation.

The Paylogix vendor breach case showed what happens when TPRM contracts don’t govern notification requirements. GM shows what happens when they don’t govern repurposing restrictions. Both failures start in the same place: inadequate control over what third parties do with your consumers’ data.

”So What?” — The 60-Day Priority List

This settlement will be cited in CPPA enforcement documents for the next several years. For compliance teams, the near-term work is:

Days 1–30:

  • Run a data flow audit across every behavioral and metadata category you collect
  • Pull the exact consent language from current privacy notices, app permissions, and enrollment flows
  • Identify all third-party data recipients and confirm their permitted use categories
  • Flag any relationships with consumer reporting agencies, data brokers, or analytics vendors receiving behavioral data

Days 31–60:

  • Review vendor contracts for restrictions on data repurposing and sublicensing
  • Update privacy notices where stated purposes don’t match actual data practices
  • Confirm GLBA exemption scope for each data category — particularly behavioral metadata and mobile signals
  • Determine whether any data-sharing practices require opt-in consent rather than opt-out

The Data Privacy Compliance Kit includes multi-state consent mapping, a data inventory template, and vendor data sharing agreement review checklist designed for exactly this kind of audit. The GM settlement is the enforcement signal — whether your practices survive the same scrutiny is a question your data flow documentation answers.


Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did California allege against GM and OnStar?
California AG Rob Bonta and the California Privacy Protection Agency alleged that GM and OnStar collected precise geolocation, driving behavior (hard braking, acceleration, speed thresholds), seatbelt usage, late-night driving patterns, and trip timing from connected vehicles, then sold that data to LexisNexis Risk Solutions and Verisk Analytics — without consumer consent — for use in insurance underwriting. GM allegedly earned approximately $20 million from these data sales between 2020 and 2024.
What is the significance of the $12.75M settlement for CCPA enforcement?
The May 8, 2026 settlement is the largest CCPA penalty imposed to date, surpassing Disney's $2.75 million settlement from February 2026. It marks the first major enforcement action specifically targeting data minimization and purpose limitation — principles embedded in CCPA since 2020 but largely unenforced until now. The California AG's office described it as a landmark and signaled more enforcement in the same space.
What is 'purpose limitation' and why does it matter for financial services?
Purpose limitation is the principle that data collected for one stated purpose cannot be repurposed for a materially different use without new consent. GM collected OnStar data for vehicle safety and concierge services, then sold it to insurance underwriting platforms. Financial institutions face the same risk when transaction data gathered for fraud detection gets shared with marketing analytics firms, or mobile location signals collected for account security get incorporated into credit risk models without consumer disclosure.
Do California privacy laws apply to fintechs and financial services companies?
Yes. The CCPA/CPRA applies to for-profit businesses that collect personal data from California residents and meet the revenue, data volume, or data selling thresholds. While GLBA-covered data has a specific CCPA exemption, that exemption operates at the individual-record level — not the entity level. Data outside GLBA's scope, including behavioral metadata, geolocation, and data shared with non-bank analytics vendors, may be subject to CCPA requirements.
What does the GM/OnStar settlement require the company to do?
GM must stop selling driving data to consumer reporting agencies for five years, delete retained driving data within 180 days absent express consumer consent, ask LexisNexis and Verisk to delete the data they purchased, and maintain a robust privacy program governing OnStar data collection. GM must also report its privacy assessments to California state and local regulators.
What should compliance teams do first after this settlement?
Start with a data flow audit: identify every category of consumer behavioral data you collect, map where it goes after initial collection, and flag any transfers to third-party analytics firms, data brokers, or consumer reporting agencies. Compare actual data flows against the consent language in your privacy notices. Any gap between what you told consumers and what you're actually doing is a CCPA exposure.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.