Most articles about car data privacy make the same mistake. They treat “your car is spying on you” as one story, when it is actually four separate systems doing four different things, governed by different rules, with different people able to reach them.
That distinction matters, because three of the four are things you can control this afternoon, and one of them is not. Knowing which is which is the entire practical value of understanding this topic.
We diagnose European cars for a living, which means we plug into these systems every day. So this is written from the inside — what is actually stored in a modern BMW, Mercedes, Audi, Volvo or Porsche, what leaves the vehicle, what we can see when your car is on our lift, and what we cannot.
The four systems, and why they get confused
| System | What it holds | Who can reach it |
| Event Data Recorder (EDR) | ~5 seconds before a crash: speed, throttle, braking, seatbelt status, airbag deployment | Owner; others only by consent, court order or discovery |
| Diagnostic memory (control modules) | Fault codes, freeze-frame data, adaptation values, overrev counters, service history, true mileage | Anyone with a scan tool and physical access to the car |
| Telematics / connected services | Location, trip logs, mileage, driving behaviour, remote commands — transmitted over a built-in cellular modem | The manufacturer, continuously, plus whoever they share it with |
| Infotainment & phone pairing | Contacts, call logs, text messages, navigation history, home address, garage door codes | Anyone who sits in the driver’s seat |
Notice which one is the outlier. The EDR — the “black box” everyone worries about — is the most tightly regulated and the least revealing. It is a crash recorder. It holds a few seconds of data and nothing else, and it does not transmit anywhere.
The telematics modem is the one that runs constantly, knows where you are, and reports to somebody in another state. That is the system worth your attention.
The black box: less than you fear, and legally yours
Event data recorders are not federally mandated, but virtually every new car sold in the United States has one, and any manufacturer that fits one has to follow federal rule 49 CFR Part 563. That rule specifies fifteen data elements the recorder must capture, and it defines the window: roughly five seconds before the crash event.
Five seconds. Speed, engine RPM, throttle position, whether you were braking, steering input, seatbelt status, and the airbag deployment sequence. Then it stops. It is not a driving log, it does not run continuously, and it has no idea where you were.
NHTSA proposed in 2022 to extend that recording window from 5 seconds to 20 seconds of pre-crash data. Worth knowing, but even at 20 seconds it remains a crash recorder rather than a tracker.
Here is the part most Washington drivers do not know.
Washington already decided who owns this data — and it is you
Chapter 46.35 RCW is Washington’s recording-device statute, and it is more protective than most states.
The law says data recorded by a device in your vehicle belongs to the vehicle’s owner — and “owner” is defined broadly enough to include the registered title holder, someone buying under a security agreement, and anyone leasing the car for more than three months. If a collision occurs, the person who owned the car at the time keeps those rights.
Nobody else may retrieve that data except in a short list of circumstances:
- Under a court order or through discovery — and anything obtained that way is explicitly private and confidential, not subject to public disclosure
- With the owner’s consent, given for a specific instance of access
- For motor vehicle safety research, provided the vehicle, owner and driver are not identified
- For emergency medical response after a collision, used solely for medical purposes
- For subscription services
Violating that is a misdemeanor, and it also counts as an unfair or deceptive practice under Washington’s Consumer Protection Act — which opens the door to civil damages, not just a criminal charge.
Read that exception list again, though, and look at the last item. “For subscription services.” That is not a loophole somebody snuck in; it is the whole connected-car business model sitting inside a consumer protection statute. When you activated BMW ConnectedDrive, Mercedes me connect, Audi connect, VW Car-Net or Volvo’s connected services, you consented. The strong ownership rule in RCW 46.35 protects the crash recorder beautifully. It does very little about the modem.
What actually leaves your car, and where it goes
This is where the picture gets less comfortable.
In September 2023, Mozilla’s Privacy Not Included researchers reviewed 25 major car brands. All 25 failed. It was the first time in the project’s history that every product in a category flunked, and not one brand met the minimum security standard — the researchers could not even confirm that personal data was encrypted on the vehicle.
The categories of data listed in manufacturer privacy policies went well past driving: location and driving patterns, braking and seatbelt habits, facial expressions, demographic data, biometric information, and in the worst cases health and genetic information. Volkswagen’s policy covered collecting demographic and driving-behaviour data for targeted marketing. Audi’s policy was flagged as long, vague and difficult to interpret. Mercedes-Benz, to be fair, was the only manufacturer that responded to the researchers’ questions about encryption at all. Renault came out best, essentially because Europe’s GDPR forced it to.
Then it stopped being theoretical. In January 2026, the FTC finalised a settlement with General Motors and OnStar over sharing drivers’ geolocation and behaviour data with consumer reporting agencies — companies that then packaged it for insurers. The settlement bars that sharing for five years, requires affirmative consent for collection, and requires that drivers be able to turn geolocation off and opt out. The FTC’s position was blunt: companies cannot monetise people’s information beyond what is needed to deliver the service the customer actually asked for.
GM is not a European brand. But the mechanism — modem collects behaviour data, manufacturer shares it with a data broker, broker sells to insurers, driver never knowingly agreed — is not a GM invention. It is the architecture. What differs between manufacturers is policy, not capability.
What we see when your car is on our lift
Since we are asking you to be sceptical of data collection generally, it is only fair to tell you what an independent repair shop can see.
When we connect a factory-level scan tool to your car, we get the diagnostic memory — the second row of that table. That means:
- Every stored and pending fault code, active or historic
- Freeze-frame data — a snapshot of engine load, coolant temperature, road speed and RPM at the exact moment a fault was recorded
- Adaptation values — the long-term corrections the engine and transmission have learned, which tell us how the car has been running for months
- Overrev counters on many performance engines, logging how many times the engine exceeded its redline and by how much, in bands, permanently
- Service history stored in the vehicle, and the true mileage recorded by multiple modules
What we do not get: your location, your trips, your phone contacts, your navigation history, or anything the telematics modem has sent to Munich or Stuttgart. Those live on the manufacturer’s servers, and an independent shop has no access to them.
That distinction is worth understanding, because the diagnostic memory is genuinely useful to you. It is the reason a proper pre-purchase inspection catches a car that was thrashed by its previous owner even when the paint is perfect and the service book looks tidy. Overrev counters and adaptation values do not lie, and a seller cannot talk their way past a permanently logged 8,000 rpm event.
The practical part: what to actually do
Four things, in order of how much they matter.
1. Audit your connected services account. Open the manufacturer app — My BMW, Mercedes me, myAudi, VW, Volvo Cars — and find the privacy or data-sharing section. Look specifically for anything described as driving-behaviour scoring, usage-based insurance, safe-driving programmes or improvement programmes. Those are the settings that feed the pipeline the FTC just spent five years litigating. Turn them off if you did not deliberately want them on.
2. Understand that “off” often means “reduced”. Disabling data sharing usually stops behavioural and marketing data. It rarely disables the modem, because the modem also handles emergency call functions, stolen-vehicle tracking and over-the-air updates. That is a reasonable trade — but it is not the same as being offline, and no manufacturer will pretend otherwise if you read the fine print.
3. Wipe the infotainment before the car leaves your hands. This is the one people skip, and it is the one with real-world consequences. Before you sell, trade in or hand back a lease, the car should have:
- All paired phones deleted, individually
- Contacts and call logs cleared from the head unit
- Navigation history and saved destinations wiped — including “Home”
- HomeLink garage door codes erased
- The connected services account unlinked from the vehicle, from your side, in the app
- A factory reset of the infotainment system as the final step, not the first
The garage door one is not hypothetical. A used car sold with an intact HomeLink code and a saved home address in the navigation system is a working key to a house, sitting on a dealer lot.
4. Do the reverse when you get into a car you do not own. Rental cars, loaners and courtesy vehicles accumulate the pairing data of everyone who has driven them. If you pair your phone with a rental, delete it before you return the car — and if you are collecting a used car, check what the last owner left behind. It is frequently a lot.
Where the data genuinely works in your favour
None of this means connected cars are a bad deal. The same systems produce real benefits:
- Automatic collision notification that calls for help when you cannot
- Remote diagnostics that read a fault before you have driven to the shop
- Condition-based service intervals that count actual engine load, fuel used and cold starts rather than assuming every 10,000 miles is identical — genuinely better for the car than a fixed schedule
- Over-the-air updates that fix software faults without a service visit
- Stolen vehicle tracking, which works exactly as advertised
The reasonable position is not to reject the technology. It is to know which settings you chose deliberately and which ones were chosen for you.
The part that affects where you can get your car fixed
There is a second-order consequence to all of this that rarely makes the privacy articles.
As more vehicle information moves off the diagnostic port and onto the manufacturer’s servers, the question of who may access it stops being about privacy and starts being about competition. If diagnostic and repair data flows only to the manufacturer, independent shops need explicit permission to see what they need to fix your car — and the manufacturer’s own dealer network does not. That is the substance of the right-to-repair legislation currently in front of Congress, and it is the reason shops like ours pay for factory-level diagnostic subscriptions rather than relying on generic tools.
Your data privacy and your ability to choose your own mechanic turn out to be the same argument, viewed from two ends.
Frequently asked questions
Does my car track my location all the time?
If it has an active connected-services subscription — BMW ConnectedDrive, Mercedes me connect, Audi connect and their equivalents — the built-in cellular modem can transmit location data. The crash recorder does not; it stores about five seconds of crash data and does not transmit at all. To see what your specific car does, check the privacy settings in the manufacturer’s app rather than assuming either extreme.
Who legally owns the data in my car in Washington?
Under Chapter 46.35 RCW, data recorded by a device in your vehicle belongs to the vehicle’s owner, including lessees on leases longer than three months. Others may retrieve it only with your consent for a specific instance, under a court order or discovery, for anonymised safety research, for emergency medical response, or for subscription services. Violations are a misdemeanor and count as an unfair practice under the Consumer Protection Act.
Can my insurance company get my driving data without asking me?
That is precisely what the FTC’s January 2026 settlement with General Motors and OnStar addressed — the sharing of geolocation and driver behaviour data with consumer reporting agencies that supply insurers. The settlement bars it for five years and requires affirmative consent. Across the industry, the safest assumption is that if you enrolled in a driving-score or safe-driver programme in the manufacturer’s app, that data is being shared. Check the app.
What can a repair shop see when it plugs into my car?
The diagnostic memory: stored and pending fault codes, freeze-frame snapshots of the conditions when each fault occurred, learned adaptation values, overrev counters on many performance engines, and mileage recorded across multiple modules. Not your location, trips, contacts or navigation history — those sit on the manufacturer’s servers, and independent shops have no access to them.
What should I delete before selling my European car?
Delete every paired phone individually, clear contacts and call logs, wipe navigation history and saved destinations including Home, erase HomeLink garage door codes, unlink the vehicle from your connected-services account inside the app, and only then run a factory reset of the infotainment system. Doing the factory reset first sometimes leaves the account link intact on the manufacturer’s side.
Does turning off data sharing break anything?
Generally no. Disabling behavioural and marketing data collection does not disable emergency calling, stolen-vehicle tracking or over-the-air updates, because those run on the same modem but a different permission. You may lose personalised recommendations and some app conveniences. Read what each toggle says before switching it, as the wording varies considerably between manufacturers.
Ask us what your car is storing
Next time your car is in with us, ask. We will show you what the diagnostic memory actually holds — the codes, the freeze frames, the adaptation values, the mileage records — and walk you through where the privacy settings live in your specific model’s system.
Eastside European Auto Service and Repair has been the Eastside’s dealer alternative since 2010, working on Mercedes-Benz, BMW, Audi, Volkswagen, Volvo, Porsche, Jaguar, Land Rover, MINI and Smart. ASE-certified technicians, over 75 years of combined experience, factory-level diagnostic equipment, and loaner cars available.
Call 425-823-8200 or book online. 12415 NE 124th St, Kirkland, WA 98034. Serving Kirkland, Bellevue, Bothell, Redmond, Issaquah, Mercer Island and Woodinville.