Back to the hub

General Motors CCPA settlement: what did the $12.75 million judgment require?

California's Attorney General announced the General Motors settlement on May 8, 2026: $12.75 million in civil penalties, the largest CCPA penalty in California history to date and the first case brought on data minimization. GM sold OnStar driving and location data to two data brokers without telling drivers.

Applies to: Businesses covered by the CCPA that collect personal information through a connected product or service, and any business that keeps personal information after the purpose it was collected for has ended.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

The General Motors settlement is the largest CCPA penalty California has imposed, and it is the first one where keeping data too long was itself the offense. That second point is the one that changes how an ordinary business should read the case.

What happened

Between 2020 and 2024, GM sold the names, contact information, geolocation data, and driving behavior data of hundreds of thousands of Californians to two data brokers, Verisk Analytics and LexisNexis Risk Solutions. The data was collected through consumers' use of OnStar. Both brokers intended to build a driver-rating product marketed to auto insurers for setting rates. The Attorney General's office reported that GM made approximately $20 million nationwide from these data sales.

Californians were spared the downstream harm, because California insurers are prohibited from using driving data to set rates, so the investigation determined that California drivers were not directly impacted the way drivers in other states were. The privacy violation stood regardless.

GM gave no notice of the sales. It implied the data would only be used to provide OnStar services. Its privacy policy stated that it did not sell driving or location data, and that any disclosure for insurance purposes would happen at the consumer's express direction. That gap between the policy and the practice is what brought California's Unfair Competition Law into the case alongside the CCPA.

The data minimization count

Separately from the sales, GM retained driving and location data long after that data had served its OnStar operational use, and then sold the retained data. The Attorney General treated this as a violation of the CCPA's purpose limitation and data minimization requirements, added to the law in 2023, and described the action as the first time the Department of Justice had enforced data minimization.

That is the part worth generalizing. Until this case, CCPA enforcement read as a disclosure and opt-out story: tell people, and let them say no. Data minimization is a different kind of duty. It asks whether you should still be holding the record at all, and no consumer request is needed to trigger it. A retention schedule stops being documentation hygiene and starts being a defense.

What the settlement required

GM agreed to pay $12.75 million in civil penalties. It must stop selling driving data to any consumer reporting agencies for five years, including to brokers such as LexisNexis and Verisk. It must delete any driving data it retained within 180 days, except for certain limited internal uses, unless it has affirmative express consumer consent. It must request that LexisNexis and Verisk delete the driving data. It must develop and maintain a privacy program that assesses, mitigates, and documents the risks of OnStar collection and ensures CCPA compliance. And it must report its privacy assessments to the Department of Justice, the participating District Attorneys, and CalPrivacy.

Who brought it

This was not the Attorney General alone. Attorney General Bonta filed with the District Attorneys of San Francisco, Los Angeles County, Napa County, and Sonoma County, with support from the California Privacy Protection Agency, which now operates as CalPrivacy. Its Enforcement Division supported the investigation.

The coalition matters for planning purposes. California privacy exposure is no longer a single regulator with a single queue, and the agency that runs its own administrative enforcement track can also feed a civil action brought by prosecutors.

What this means for a smaller business

You are not selling telematics to insurers. The transferable questions are narrower and cheaper to answer. Does your privacy policy contain a denial that is no longer true. Do you still hold records whose original purpose ended years ago. Could you name, today, every third party that receives personal information from your product.

For the wider pattern across California's settlements, see CCPA enforcement actions. The retention question is covered in CCPA data retention disclosure, and precise location sits inside the sensitive category described in sensitive personal information.

Next step

If your product collects location or behavioral data and you are unsure how long you are allowed to keep it, the free 2-minute Obligation Scan checks whether the CCPA applies to your business and lists the retention, disclosure, and opt-out duties that follow.

Compliance checklist

  • Write down the purpose each data set was collected for, and delete or stop processing it once that purpose ends, because retention alone can now be the violation.
  • Check that your privacy policy does not deny doing something the business actually does, which was the Unfair Competition Law count here.
  • Treat precise location and behavioral telemetry from a connected product as high-exposure data, not as ordinary product analytics.
  • Name every data broker or analytics partner you transfer personal information to, and confirm consumers were told before the transfer, not after.
  • Keep documented privacy risk assessments for the collection your product does, since reporting assessments to regulators was part of the remedy here.

Sources

Last verified: 2026-09-08

Informational, not legal advice.