{"id":33257,"date":"2024-05-16T10:59:42","date_gmt":"2024-05-16T08:59:42","guid":{"rendered":"https:\/\/www.kaspersky.co.za\/blog\/?p=33257"},"modified":"2024-05-16T11:00:01","modified_gmt":"2024-05-16T09:00:01","slug":"car-manufacturers-silently-sell-user-telematics-data","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.za\/blog\/car-manufacturers-silently-sell-user-telematics-data\/33257\/","title":{"rendered":"I know how you drove last summer"},"content":{"rendered":"<p>Early in the movie \u201cThe Fifth Element\u201d, there is a sequence that shows the dystopian nature of the future world: Korben Dallas\u2019s smart taxi fines him for a traffic violation and revokes his license. Back in 1997, this seemed like science fiction \u2013 and it was. Today it\u2019s turning into reality. But first things first.<\/p>\n<p>Not so long ago, we looked at the potential <a href=\"https:\/\/www.kaspersky.com\/blog\/spies-on-wheels-how-carmakers-sell-your-intimate-data\/49341\/\" target=\"_blank\" rel=\"noopener nofollow\">dangers<\/a> associated with the amount of data modern vehicles collect about their owners. Then, even more recently, an <a href=\"https:\/\/www.nytimes.com\/2024\/03\/11\/technology\/carmakers-driver-tracking-insurance.html\" target=\"_blank\" rel=\"nofollow noopener\">investigation<\/a> revealed what this might mean in practice for drivers.<\/p>\n<p>It turns out that carmakers, through specialized data brokers, are already selling telematics data to insurance companies, who are using it to raise the cost of insurance for careless drivers. Most alarming of all, however, is that car owners are often kept in the dark about all of this. Let\u2019s investigate further.<\/p>\n<h2>Gamification of safe driving with far-reaching consequences<\/h2>\n<p>It all started in the US when owners of General Motors vehicles (parent company of the Chevrolet, Cadillac, GMC, and Buick brands) noticed a sharp rise in their auto insurance premiums compared to the previous period. The reason, it transpired, was the practice of risk profiling by data broker LexisNexis. LexisNexis works with auto insurers to supply them with driver information, usually about accidents and traffic fines. But vehicle owners hit by the premium hike had no history of accidents or dangerous driving!<\/p>\n<p>The profiles compiled by LexisNexis were found to contain detailed data on all trips made in the insured vehicle, including start and end times, duration, distance and, crucially, all instances of hard acceleration and braking. And it was this data that insurers were using to increase insurance premiums for less-than-perfect drivers. Where did the data broker get such detailed information?<\/p>\n<p>From General Motors\u2019 OnStar Smart Driver. That is the name of the \u201csafe driving gamification\u201d feature built into General Motors vehicles and the myChevrolet, myCadillac, myGMC, and myBuick mobile apps. The feature tracks hard acceleration and braking, speeding, and other dangerous events, and rewards \u201cgood\u201d driving with virtual awards.<\/p>\n<div id=\"attachment_51249\" style=\"width: 2058px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/103\/2024\/05\/16103951\/car-manufacturers-silently-sell-user-telematics-data-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51249\" class=\"size-full wp-image-51249\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/103\/2024\/05\/16103951\/car-manufacturers-silently-sell-user-telematics-data-1.jpg\" alt=\"OnStar Smart Driver in General Motors mobile apps\" width=\"2048\" height=\"1764\"><\/a><p id=\"caption-attachment-51249\" class=\"wp-caption-text\">The OnStar Smart Driver safe driving gamification feature is built into myChevrolet, myCadillac, myGMC, and myBuick mobile apps by General Motors. <a href=\"https:\/\/www.onstar.com\/services\/smart-driver\" target=\"_blank\" rel=\"nofollow noopener\">Source<\/a><\/p><\/div>\n<p>What\u2019s more, according to some car owners, they didn\u2019t enable the feature themselves \u2013 the car dealer did it for them. Crucially, neither General Motors\u2019 apps nor the terms of use explicitly warned users that OnStar Smart Driver data would be shared with insurance-related data brokers.<\/p>\n<p>This lack of transparency extended to the <a href=\"https:\/\/www.onstar.com\/legal\/privacy-statement\" target=\"_blank\" rel=\"nofollow noopener\">privacy statement<\/a> on the OnStar website. While the statement mentions the possibility of sharing collected data with third parties, insurers are not specifically listed, and the text generally aims for maximum vagueness.<\/p>\n<p>Along the way, LexisNexis was discovered to be working with three other automakers besides General Motors \u2013 Kia, Mitsubishi, and Subaru \u2013 all of which have similar safe driving gamification programs under names like \u201cDriving Score\u201d or \u201cDriver Feedback\u201d.<\/p>\n<div id=\"attachment_51248\" style=\"width: 2114px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/103\/2024\/05\/16104005\/car-manufacturers-silently-sell-user-telematics-data-2.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51248\" class=\"size-full wp-image-51248\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/103\/2024\/05\/16104005\/car-manufacturers-silently-sell-user-telematics-data-2.jpg\" alt=\"Description of the telematics data sale service on the LexisNexis website \" width=\"2104\" height=\"1738\"><\/a><p id=\"caption-attachment-51248\" class=\"wp-caption-text\">According to the LexisNexis website, the companies that work with the data broker include General Motors, Kia, Mitsubishi, and Subaru. <a href=\"https:\/\/risk.lexisnexis.com\/products\/telematics-ondemand\" target=\"_blank\" rel=\"nofollow noopener\">Source<\/a><\/p><\/div>\n<p>At the same time, another data broker \u2013 Verisk \u2013 was found to be providing telematics data to car insurers. Its automotive clients include General Motors, Honda, Hyundai, and Ford.<\/p>\n<div id=\"attachment_51247\" style=\"width: 2114px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/103\/2024\/05\/16104024\/car-manufacturers-silently-sell-user-telematics-data-3.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-51247\" class=\"size-full wp-image-51247\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/103\/2024\/05\/16104024\/car-manufacturers-silently-sell-user-telematics-data-3.jpg\" alt=\"Description of the telematics data sale service on the Verisk website\" width=\"2104\" height=\"1738\"><\/a><p id=\"caption-attachment-51247\" class=\"wp-caption-text\">Another broker, Verisk, lists General Motors, Honda, Hyundai, and Ford in its telematics sales service description. <a href=\"https:\/\/www.verisk.com\/insurance\/products\/drivingdna-data\/\" target=\"_blank\" rel=\"nofollow noopener\">Source<\/a><\/p><\/div>\n<p>As a result, many drivers found themselves, in effect, locked into a car insurance policy with costs based on driving habits. It\u2019s just that <a href=\"https:\/\/www.kaspersky.com\/blog\/progressive-snapshot-car-hacking\/7284\/\" target=\"_blank\" rel=\"noopener nofollow\">such programs<\/a> used to be voluntary, offering a basic discount for participation \u2013 and even then, most drivers opted out. Now it appears that carmakers are enrolling customers not only without their consent, but without their knowledge.<\/p>\n<p>According to available information, this is currently only happening to drivers in the US. But what starts in the States usually migrates, so similar practices may soon appear in other regions.<\/p>\n<h2>How to protect yourself from data-hungry cars<\/h2>\n<p>Unfortunately, there is no silver bullet to stop your automobile from harvesting data. Most new vehicles already come with built-in telematics collection as standard. And the number is only <a href=\"https:\/\/www.globenewswire.com\/news-release\/2021\/11\/15\/2333887\/28124\/en\/Global-Automotive-OEM-Telematics-Market-Report-2021-Nearly-62-of-All-Cars-Sold-in-2020-were-Equipped-with-OEM-Embedded-Telematics-Market-Analysis-Forecast-to-2026.html\" target=\"_blank\" rel=\"noopener nofollow\">going to grow<\/a> so that in a year or two these cars will make up more than 90% of the market. Naturally, the maker of your car won\u2019t make it easy or even possible to turn off telematics.<\/p>\n<p>If you\u2019re ready to consider the factor of your car collecting data on you for third parties (or, in simple words, spying), then read our post with detailed tips on <a href=\"https:\/\/www.kaspersky.com\/blog\/spies-on-wheels-how-carmakers-sell-your-intimate-data\/49341\/\" target=\"_blank\" rel=\"noopener nofollow\">how you can try to get rid of surveillance by carmakers<\/a>. Spoiler alert: it\u2019s not easy and requires careful study of the documentation, as well as sacrificing some of the benefits of connected cars, so these tips won\u2019t work for everyone.<\/p>\n<p>As for the scenario described in this post of selling driver data to insurers, our advice is to search the in-vehicle menu and mobile app for a safe driving gamification feature and disable it. It may be called \u201cSmart Driver\u201d, \u201cDriving Score\u201d, \u201cDriver Feedback\u201d, or something similar. US-based drivers are also advised to request their data from <a href=\"https:\/\/consumer.risk.lexisnexis.com\/consumer\" target=\"_blank\" rel=\"nofollow noopener\">LexisNexis<\/a> and <a href=\"https:\/\/fcra.verisk.com\/%23\/\" target=\"_blank\" rel=\"nofollow noopener\">Verisk<\/a> to be prepared for nasty surprises, and to see if it\u2019s possible to delete information that has already been collected.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-gamer\">\n","protected":false},"excerpt":{"rendered":"<p>Vehicle makers sell the data collected by connected cars about their users&#8217; driving habits to data brokers \u2013 who resell it to insurance companies.<\/p>\n","protected":false},"author":2726,"featured_media":33259,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1788,1789,2670],"tags":[109,651,730,423,43,768,422],"class_list":{"0":"post-33257","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-privacy","8":"category-technology","9":"category-threats","10":"tag-apps","11":"tag-cars","12":"tag-connected-cars","13":"tag-mobile-devices","14":"tag-privacy","15":"tag-surveillance","16":"tag-threats"},"hreflang":[{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/car-manufacturers-silently-sell-user-telematics-data\/33257\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/car-manufacturers-silently-sell-user-telematics-data\/27445\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/car-manufacturers-silently-sell-user-telematics-data\/22764\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/car-manufacturers-silently-sell-user-telematics-data\/11663\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/car-manufacturers-silently-sell-user-telematics-data\/30126\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/car-manufacturers-silently-sell-user-telematics-data\/27596\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/car-manufacturers-silently-sell-user-telematics-data\/27384\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/car-manufacturers-silently-sell-user-telematics-data\/30037\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/car-manufacturers-silently-sell-user-telematics-data\/28849\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/car-manufacturers-silently-sell-user-telematics-data\/37436\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/car-manufacturers-silently-sell-user-telematics-data\/12388\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/car-manufacturers-silently-sell-user-telematics-data\/51245\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/car-manufacturers-silently-sell-user-telematics-data\/21891\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/car-manufacturers-silently-sell-user-telematics-data\/22626\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/car-manufacturers-silently-sell-user-telematics-data\/31280\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/car-manufacturers-silently-sell-user-telematics-data\/36410\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/car-manufacturers-silently-sell-user-telematics-data\/27742\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/car-manufacturers-silently-sell-user-telematics-data\/33594\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.za\/blog\/tag\/cars\/","name":"Cars"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/posts\/33257","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/comments?post=33257"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/posts\/33257\/revisions"}],"predecessor-version":[{"id":33262,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/posts\/33257\/revisions\/33262"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/media\/33259"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/media?parent=33257"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/categories?post=33257"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/tags?post=33257"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}