Home/ Insights/ Why Texas, Not Washington, Actually Killed GM's Data-Sellin…
Why Texas, Not Washington, Actually Killed GM's Data-Selling Business
Automotive & Mobility · Marqstats Research

Why Texas, Not Washington, Actually Killed GM's Data-Selling Business

Federal policy gets the headlines. State regulators got the result. Marqstats explains how Texas and California actually stopped GM's data sales.

7 min read 1,204 words Automotive & Mobility

Why Texas, Not Washington, Actually Killed GM's Data-Selling Business

Everyone watching US connected-car regulation has been tracking a federal rule with a genuinely dramatic name: the Department of Commerce's ban on Chinese and Russian connected-vehicle hardware and software. It's real, it's significant, and its hardware deadline doesn't bind until model year 2030. Meanwhile, a state attorney general's lawsuit and a state privacy agency's consent order did something the federal rule hasn't done yet: they forced General Motors to shut down an entire data-monetization business within months.

What Actually Happened

General Motors' OnStar Smart Driver program collected driving-behavior data — hard braking, rapid acceleration, speeding, trip duration — from enrolled vehicles and sold it to commercial data brokers LexisNexis Risk Solutions and Verisk Analytics. Insurance underwriters then used that data to adjust premiums across more than 14 million registered vehicle files nationwide. In August 2024, the Texas Attorney General sued GM and OnStar under the state's Deceptive Trade Practices Act, alleging drivers were enrolled through dealership onboarding flows without clear disclosure. By then, GM had already terminated the program entirely, back in April 2024.

14,000,000+
Registered vehicle files affected by GM's OnStar Smart Driver data-broker program before its April 2024 termination
Source: Texas Attorney General filing, cited in Marqstats analysis

Why California's Smaller Case Matters Just as Much

California's Privacy Protection Agency ran a parallel, separate action against Honda, culminating in a March 2025 consent order and a $632,500 penalty — a modest sum next to GM's much larger exposure, but the finding itself is arguably more instructive. The CPPA didn't object to Honda collecting telemetry data; it objected to Honda making it easy to opt in (single-click enrollment) and hard to opt out (requiring a VIN and government ID). That asymmetry — not the data collection itself — was the violation.

State enforcement actions moved from investigation to consequence faster than the federal supply-chain rule's own compliance deadlines. Source: Marqstats Intelligence | Texas AG, CPPA.
State enforcement actions moved from investigation to consequence faster than the federal supply-chain rule's own compliance deadlines. Source: Marqstats Intelligence | Texas AG, CPPA.

The Counter-Case: Isn't the Federal Rule Still More Consequential Long-Term?

It's a fair point — the BIS supply-chain rule will eventually force a complete hardware redesign across the entire industry, a structurally larger undertaking than any single state privacy case. But "eventually" is doing real work in that sentence: the hardware deadline is model year 2030, years away, while GM's data-broker business was dismantled in a matter of months following media disclosure and before either state action reached final judgment. For anyone assessing near-term regulatory risk specifically, the state privacy cases have already delivered their consequence; the federal rule's biggest impact is still ahead.

Why the Federal-State Split Is Likely Permanent, Not Temporary

There's little indication this state-led pattern will consolidate into a single federal framework anytime soon, given how differently Texas's and California's own regulatory philosophies already treat consumer data — expect connected-vehicle privacy compliance to remain a genuinely state-by-state exercise for automakers operating nationally, rather than a single national standard any company could design once and apply everywhere.

The CPPA's Honda finding is worth reading closely for what it implies about future enforcement beyond just this one case: the agency explicitly objected to single-click opt-in paired with VIN-and-ID-required opt-out, a specific, replicable design pattern many connected-car consent flows across the industry plausibly share in some form. Any automaker running a similarly asymmetric consent interface, regardless of whether they've sold data to a broker at all, now has a clear, tested enforcement template sitting on the record for California regulators to apply again.

A Named Comparison: How This Differs From the BIS Supply-Chain Rule's Own Timeline

It's worth being specific about why these two regulatory tracks move at such different speeds. The BIS supply-chain rule requires an entire industry to redesign physical hardware and software supply chains before a fixed compliance date — a genuinely large engineering and procurement undertaking that structurally cannot happen overnight, regardless of regulatory intent. State privacy enforcement, by contrast, targets a company's own internal data-handling and contractual decisions, which a company can reverse unilaterally the moment it decides the legal and reputational exposure outweighs the revenue — exactly what GM did with OnStar Smart Driver, months before either state case reached a final ruling.

What This Means for Anyone Building a Data-Monetization Strategy

The practical lesson: treat state privacy enforcement, not federal policy, as the nearer-term commercial risk for any connected-vehicle data-monetization plan, and audit consent-flow symmetry specifically — how easy opt-in is relative to opt-out — as the single clearest variable regulators have shown they scrutinize.

That precedent-setting effect, more than the specific penalty amount in any single case, is likely why the response from the rest of the industry has been so immediate — the risk isn't the $632,500 Honda paid; it's what a similar finding against any other automaker's own consent design would now plausibly trigger.

Texas's DTPA lawsuit and California's CPPA consent order against GM/OnStar and Honda respectively forced GM to terminate its entire OnStar Smart Driver data-broker program in April 2024, months before either case reached final judgment — demonstrating that state privacy enforcement, not the federal BIS supply-chain rule, has been the more immediate commercial constraint on US connected-vehicle data monetization.

What Congress Hasn't Done That States Have

It's worth noting the federal legislative branch has largely stayed out of this specific fight — congressional inquiries followed the initial media disclosures, but no federal consumer-privacy statute specifically targeting connected-vehicle telemetry has passed. That legislative gap is precisely what has let individual states move first and fastest, each applying their own existing consumer-protection or privacy statute (Texas's DTPA, California's CCPA/CPRA) to a genuinely new category of data collection those laws were never written with cars specifically in mind.

Why Texas, Not Washington, Actually Killed GM's Data-Selling Business — exhibit 2

Why Other Automakers Are Watching This Case Closely

GM was far from the only automaker running secondary data-monetization arrangements with insurance-focused data brokers — the underlying research documents that LexisNexis Risk Solutions and Verisk Analytics served as commercial data pipelines that could plausibly have involved other OEM relationships as well. GM's specific case became the visible test of how aggressively state regulators would pursue this exact pattern, and the speed and severity of the response — an entire program terminated within months of disclosure — has reportedly prompted other automakers to review their own data-sharing arrangements proactively rather than wait for a similar enforcement action of their own.

The Number Worth Watching Going Forward

If you only track one leading indicator for this specific regulatory risk, track the number of new state-level connected-vehicle privacy investigations opened per year, not the number concluded. Investigations, not final judgments, appear to be what actually moves automaker behavior in this market — GM shut its program down while its own case was still pending, which means the deterrent effect happens well before any formal enforcement outcome is even known.

What This Means for a Sizing or Sourcing Model

Anyone modeling US connected-vehicle revenue should track state privacy-enforcement actions as a distinct, faster-moving risk variable separate from federal supply-chain compliance timelines. The full market sizing this piece draws on is set out in the Marqstats analysis linked below.

Related reportUnited States Connected Car Market Size, Share & Forecast 2026 – 2030The full sizing, segmentation and forecast this piece draws its reconciliation from.
Marqstats
Marqstats Research
Market Intelligence & Advisory · marqstats.com
Automotive & Mobility Market Research Marqstats Intelligence
Back to insights