Your next new car could know where you went last night, how quickly you accelerated, how hard you braked, which phone you paired with it and whether your eyes were actually on the road
Here is something rather important that is probably buried three menus deep in your next car. Actually, scrub that: it may already be buried three menus deep in your current car, somewhere between the ambient-lighting colour selector and the setting that makes the dashboard bong furiously because you dared to glance at the heater controls it forced onto a touchscreen in the first place.
Your car may know where you went last night, how fast you drove, how sharply you accelerated, how hard you braked, whether your seat belt was fastened, which phone was paired to it, which routes you use most often and, increasingly, whether your eyes were on the road, whether you appeared tired and perhaps, before very long, whether you were stressed, distracted, anxious or generally wondering why the driver behind has attached himself to your rear bumper like an emotionally needy limpet.
No, you do not need to buy a self-driving robotaxi, a mysterious high-tech import or an obscure prototype from a motor show in 2037. Much of the necessary hardware is already fitted to perfectly ordinary family cars, because the British government confirmed in July 2026 that it intends to proceed with a package of mandatory safety technologies for mass-produced vehicles, including advanced distraction warning, drowsiness and attention warning, intelligent speed assistance and event data recorders. These are safety systems, absolutely; potentially life-saving systems, without question; but they also establish the sensors, processing and connectivity required for a car that watches, measures and interprets its driver.
So when I say your car is spying on you, I do not mean there is necessarily a chap at headquarters wearing headphones and taking notes every time you sing Gold but something subtler and, in many respects, considerably more powerful: observation, inference, connection and the possibility of information travelling beyond the car. The new divide in motoring is no longer simply petrol versus electric, manual versus automatic or human versus autonomous. It is you versus your car. Is it merely transporting you, or is it also building a picture of you and quietly logging that picture somewhere else?
The black box is not the real villain
Let us begin with the so-called black box, because this is where a great deal of the confusion starts. An automotive event data recorder is not the equivalent of an aircraft cockpit recorder, endlessly storing conversations, video and a complete diary of every journey. America’s National Highway Traffic Safety Administration defines it as a device or function that records technical vehicle and occupant information for a brief period — seconds rather than minutes — before, during and after a crash. Depending on the vehicle, that can include speed, braking, throttle, steering inputs, seat-belt use, airbag deployment and the forces involved in the collision; it does not, within that definition, include an audio or video recording of the cabin.
European rules go further in setting privacy boundaries. The event data recorder cannot be disabled, but it must operate as a closed-loop system, its data must be anonymised and it must not store information capable of identifying the individual car, owner or keeper. Access by national authorities is restricted under law to accident research and analysis. The black box can therefore become an extremely important witness after a collision, but it is not, by itself, the all-seeing surveillance machine many people imagine. The same is broadly true of the regulated 112 eCall system, which is supposed to remain dormant during normal driving and sends a limited set of information when a serious collision triggers it or somebody presses the SOS button. It is designed to summon help, not to follow you to Tesco and report that you bought the expensive biscuits again.
The car has developed a data exhaust
The more interesting — and much broader — issue begins when you open the privacy notice for a connected car and watch the cosy idea of a simple mechanical possession dissolve before your eyes. Ford’s current UK connected-car policy makes a useful example precisely because Ford is not an obscure technology start-up making wild claims about reinventing mobility. It is Ford, the company that gave Britain Escorts, Fiestas, Mondeos and generations of cars into which entire families climbed without once wondering whether the seat-position setting counted as personal information.
The policy describes connected vehicle information associated with the vehicle identification number, which can in turn be linked to an owner or lessee. It lists driving characteristics such as speed and the use of the accelerator, brakes, steering and seat belts; real-time latitude and longitude, from which direction and speed can be determined; navigation and infotainment use; phone and Bluetooth pairings; climate settings; seat position; and changes to the connectivity settings. Once connected, the vehicle sends periodic alerts to Ford containing identifiers for the vehicle’s SIM, VIN and modem. None of that is automatically sinister. Remote diagnostics can warn you before a breakdown, live traffic requires location, an app cannot show you where the car is parked without knowing where it is parked, and an over-the-air update rather obviously needs the car to communicate with something beyond the end of your driveway.
Nonetheless, consider what has changed. In an older car, pressing the accelerator opened a throttle. In a connected car, the same action can also become a data point: how often, how hard, where and under whose account. The physical act is identical, but it now leaves a digital shadow.
Then there is the cabin camera. Tesla says its camera can determine driver inattentiveness, but its current UK guidance also makes an important distinction: by default, images and video from the camera do not leave the vehicle and are not transmitted to Tesla unless data sharing is enabled. If the owner enables cabin-camera analytics and a safety-critical event occurs, the car can share short video clips, while data may also be shared if diagnostics are required on the camera’s functionality. That is not the same as saying Tesla continuously uploads footage of everybody inside the car, because it says it does not; it does mean an owner who enables the relevant setting should understand what it permits and, since the camera may see more than the driver, should probably tell passengers too. Yes, even the ones in the back who suddenly appear unusually interested in whether the lens has a privacy cover.
Do not forget the phone either. Pair it, synchronise it and grant access to contacts, messages, calendars, voice services and media, and the car becomes the meeting point between vehicle data and the most intimate computer most people own. We spend a great deal of time worrying about whether the car is a smartphone on wheels while voluntarily introducing it to the actual smartphone containing our conversations, appointments, relationships, photographs and the precise location of that takeaway we insist we only visit occasionally.
When a driving tip became an insurance file
The case that turns an abstract concern into something painfully real arrived in America. In January 2026, the Federal Trade Commission finalised a consent order settling allegations against General Motors and OnStar. The FTC alleged that the companies collected, used and sold precise geolocation and driving-behaviour data from millions of vehicles without adequately notifying consumers or obtaining affirmative consent. The information included hard braking, speeding and late-night driving; for some users, precise location was allegedly collected as frequently as every three seconds. According to the regulator, consumer-reporting companies compiled reports from the information which insurers then used to set rates and, in some cases, deny insurance.
The final order imposed a five-year ban on GM disclosing covered geolocation and driving-behaviour data to consumer-reporting agencies, while the broader order runs for 20 years and requires clearer consent, access and deletion mechanisms, together with ways for US consumers to opt out of certain collection or disable precise-location collection where the vehicle supports it. GM and OnStar neither admitted nor denied the substantive allegations. That qualification matters, as does the fact that this was an American case and does not establish that every manufacturer is secretly selling British drivers’ data to insurers. What it does establish is that the chain is technically and commercially possible, and that a regulator concluded the notice and consent in this case were not good enough.
Ford’s UK policy, meanwhile, says driving-characteristics data may be used to provide services such as insurance-discount offerings sponsored by an insurance company, where available. There is nothing inherently sinister about that when the bargain is clearly explained, genuinely optional and knowingly chosen by the customer; many drivers have willingly fitted telematics boxes or cameras in return for a lower premium. The danger begins when a cheerful feature carrying a name such as “Smart Driver” quietly becomes a financial judgement made somewhere else, using information the motorist did not realise had moved beyond the dashboard.
Mozilla’s privacy nightmare on wheels
In 2023, the Mozilla Foundation’s Privacy Not Included project reviewed 25 major car brands and reported that all 25 received failing marks for consumer privacy. Mozilla said 84 per cent of the brands’ policies allowed personal data to be shared, 76 per cent said it could be sold and 92 per cent gave drivers “little to no control” over it; according to the project, only Renault and Dacia stated that every driver had the right to have personal data deleted. Policies examined by the researchers even reserved the ability to collect sensitive categories including medical conditions, genetic information and, get this, sexual activity. Blimey. You thought the suspension was intrusive because it transmitted every pothole into your spine.
This finding needs to be described accurately. Mozilla assessed publicly available privacy policies and associated consumer information; it did not conduct a regulatory investigation, physically inspect every car or prove that every company carried out every practice its policy permitted. The review was also heavily centred on North American material, and privacy policies are often written broadly to preserve options a company may never exercise. Yet that does not make their language meaningless. It shows how much information companies believe they may be entitled to collect, combine, use or share, and how little of that possibility is visible when somebody is standing in a showroom choosing between metallic paint and the winter pack.
Now the cameras are turning around
Cars used to direct most of their senses outwards. Is there a wall behind you, a vehicle in the blind spot, a pedestrian in the road or a lane marking beneath the wheels? Now the sensors are turning around. In the European Union, advanced driver-distraction warning applied to new vehicle types from July 2024 and to newly registered vehicles within scope from 7 July 2026. The system must determine when the driver’s visual attention is not directed towards the driving task and issue a warning.
There is an important privacy safeguard that should not be skipped merely because it weakens a more dramatic headline. The EU rules require drowsiness, attention and distraction systems to retain only the data necessary for their function inside a closed loop, prevent that data being made available to third parties and delete it after processing; the advanced-distraction specification also forbids identifying the person through biometric processing. The European safety rule is therefore not a licence for manufacturers to upload your face. It is evidence of something more fundamental: driver-facing sensing is rapidly becoming ordinary equipment, which means the capability exists and could potentially support other functions later, subject to law, consent and the way each manufacturer designs its system.
The industry is already looking beyond whether you glanced at your phone. Harman’s Ready Care technology is marketed as capable of detecting visual and mental distraction, drowsiness, stress, posture, heart rate and breathing through an infrared camera or in-cabin radar, then responding by altering temperature, lighting, audio or even seat massage. It can also monitor occupants, seat-belt routing and the presence of a child. The UK Information Commissioner’s Office has mapped a possible future in which connected cars identify occupants, authorise payments, link fatigue patterns to wellness apps and perhaps tailor advertising according to passengers’ previous reactions. That does not mean your next supermini will diagnose an existential crisis and prescribe a soothing playlist on Tuesday morning; some of these are supplier capabilities, some are safety-rating ambitions and some are regulatory foresight. Put them together, however, and the direction is difficult to miss: the car is evolving from a machine that responds to commands into a system that interprets and predicts the human beings inside it. In other words, you.
Why would we accept any of this?
Most people will accept it for entirely reasonable reasons. A camera that notices closed eyes could prevent a motorway crash. Radar that detects a child left in a hot car could save a life. An event recorder can help establish what happened. Location can guide an ambulance. Vehicle data can expose a failing battery, brake system or tyre before it leaves somebody stranded at night in horizontal rain on the hard shoulder, which is precisely when all mechanical components are contractually obliged to fail.
The European Commission estimates that its mandatory assistance systems could save more than 25,000 lives and prevent at least 140,000 serious injuries by 2038. The British government’s impact analysis suggests the proposed safety technologies have the potential to prevent more than 758,000 collisions and 65,000 casualties over 15 years. These are projections rather than guarantees, but they explain why governments and safety organisations are pushing the technology so hard.
There is also an economic contest beneath the safety argument. Vehicle-generated information can support insurance, repairs, charging, traffic management, subscriptions, marketing and personalised services. The EU Data Act, which began applying in September 2025, gives users of connected products greater rights to access, use and share the data generated by them, including with independent repair and after-sales providers. That matters because, as I explored in my feature on digitally locked car parts, the software-defined vehicle is not merely changing how a car operates; it is changing who controls the relationship between the machine, its information and the person who supposedly bought it.
This is the dividing line. The betrayal is not a camera preventing a tired driver from drifting across a lane, an emergency service receiving the location of a wrecked car or a diagnostic system identifying a dying battery. It is collecting more than is necessary, disguising consent, retaining information for too long, repurposing safety data for profit or making customers pay for consequences they were never clearly told about. Safety may justify watching. It does not justify secrecy.
Seven things to do before your car knows too much
What can you actually do without trading your new car straight back in for a battered Ford Escort, fitting a choke, buying a road atlas and rediscovering the character-building joy of wondering whether it will start?
- Ask for the connected-car privacy notice before buying. Not the glossy brochure, not the salesperson’s assurance that “everybody accepts it” and not a hurried explanation delivered while pointing at the signature box. Ask what is collected, what leaves the vehicle, who receives it, how long it is retained and which functions stop working if you refuse.
- Open every connectivity menu on delivery day. Look separately for vehicle data, driving data, location, analytics, voice-recognition feedback and cabin-camera analytics. Do not assume one master switch controls everything, because it may not, and remember that a setting labelled “improve our products” can cover something rather broader than correcting the spelling on the navigation system.
- Audit every app account linked to the car. Multiple linked users may be able to see the vehicle’s location or use remote start, locking and unlocking functions. Make sure every account belongs there, particularly after a relationship, change of employee, change of driver or used-car purchase.
- Treat used and rental cars like borrowed phones. Delete paired devices, call history, messages, navigation favourites and home addresses, and perform a proper factory or master reset when selling. The UK’s National Protective Security Authority specifically warns that hiring a connected vehicle can leave contacts or journey information behind. Your holiday rental does not need a permanent souvenir of where you live.
- Do not confuse mandatory safety with optional analytics. Covering a driver-monitoring lens may disable an assistance feature and create a genuine safety problem. Use the official privacy settings, understand which functions are optional and accept that emergency or legally required systems may remain active.
- Use your data rights. In Britain, you can ask an organisation for a copy of the personal information it holds about you through a subject access request. Depending on the circumstances, you may also have rights to correct it, erase it, restrict its use, move it or object to processing. These rights are real, although they are not absolute.
- Check everything again after major software updates. Connected cars change during their lives. Features, interfaces, account permissions and data practices can be altered, expanded or reset, so the privacy decision you made on delivery day may not remain the decision the car is following three years later.
You bought the car, but what did the car buy?
Your next new car will probably be safer, cleverer and more capable than anything most of us grew up driving. It may protect you from a collision, summon help, find itself in a car park, diagnose its own faults and notice danger before you do. It may also know where you travel, how you behave, who connects to it, what you pay attention to and, eventually, how you feel.
That does not make the car evil. It makes the car powerful and, as Uncle Ben told a certain young superhero, with great power comes great responsibility. Power needs visibility, limits and consent. We used to judge a car by what it did when we operated its controls; now it is judging us by how we operate the controls.
So here is my question. Should every new car offer one genuine privacy mode: a single control that keeps essential safety and emergency systems working while preventing every optional piece of personal information from leaving the vehicle? Or are you comfortable with the bargain because the convenience and protection are worth it and, as the familiar argument goes, if you have done nothing wrong, what is there to hide?
And what about classics? Will we always be allowed to keep driving cars that cannot monitor us, update themselves or send a report about the manner in which we approached a roundabout? Who, exactly, would object — and who exactly is “they” anyway?
Tell me what you think in the comments below. More importantly, tell me what you discovered when you opened the privacy and connectivity menus in your own car, because I suspect many of us are going to find rather more in there than we expected.
Reporting note
This article distinguishes between mandatory safety processing, published manufacturer policies, supplier capabilities, projected future uses and regulatory allegations. The GM and OnStar section reports allegations settled through an FTC consent order; the companies neither admitted nor denied the substantive allegations. Mozilla’s findings were assessments of published privacy information rather than proof that every permitted practice was carried out in every market.
Support independent car journalism 🙏🏽☺️
If you found this useful, interesting or entertaining, please watch and share the video, take up BrownCarGuy channel membership, buy me a coffee on Ko-Fi, join me on Patreon, or check out my books, including Silent Ruin, How to Be an Automotive Content Creator, Quantum Races and The ULEZ Files. Every bit helps me continue producing independent motoring content.
👉🏽 Channel membership: https://www.youtube.com/browncarguy/join
👉🏽 Buy me a Coffee! https://ko-fi.com/browncarguy
👉🏽 Patreon – https://www.patreon.com/BrownCarGuy
MY BOOKS ON AMAZON!
https://browncarguy.com/2026/04/15/browncarguy-books/
📖 Silent Ruin – A Jamshed Khan Thriller. This international espionage novel is an action-packed page-turner!
📖 Want to become an automotive journalist, content creator, or car influencer? Check out my book: How to be an Automotive Content Creator
📖 Quantum Races – A collection of my best automotive sci-fi short stories!
📖 The ULEZ Files – Debut novel – all-action thriller!
Discover more from Brown Car Guy
Subscribe to get the latest posts sent to your email.
