On May 8, 2026, California Attorney General Rob Bonta announced a $12.75 million settlement with General Motors and its OnStar subsidiary to resolve alleged violations of the California Consumer Privacy Act (CCPA). The settlement is the largest CCPA penalty to date and marks a clear escalation in California's privacy enforcement posture. Businesses that collect, use, or share personal information of California consumers should treat this resolution as a strong indicator of where regulatory scrutiny is heading.

According to the Attorney General's office, between 2020 and 2024, GM and OnStar sold the names, contact information, geolocation data, and driving behavior data of hundreds of thousands of Californians to data brokers without providing the notice and choice mechanisms required under the CCPA. The investigation focused heavily on connected-vehicle and telematics data, signaling that regulators view information generated by modern vehicles as squarely within the scope of California's privacy framework. Companies operating in the automotive, mobility, insurance, and broader Internet of Things sectors should anticipate continued attention to how telematics and behavioral data are collected, monetized, and disclosed.

Significantly, this action represents California's first data minimization enforcement action under the CCPA. The Attorney General's reliance on the data minimization principle indicates that regulators are prepared to take action when businesses collect or retain personal information beyond what is reasonably necessary to achieve the purposes disclosed to consumers, even where notice and opt-out mechanisms may be present. In other words, compliance is no longer measured solely by disclosures and consumer rights workflows; the underlying volume and purpose of data collection are themselves enforcement targets.

For businesses subject to the CCPA, the practical implications are substantial. Organizations should re-examine data inventories, vendor and data broker relationships, retention schedules, and the alignment between stated purposes and actual data uses. Privacy notices, consent flows, and opt-out mechanisms should be reviewed in light of heightened expectations, particularly where sensitive categories such as geolocation or behavioral data are involved. Documentation supporting necessity and proportionality of data practices should be strengthened in anticipation of regulatory inquiry.

This article is provided for general informational purposes only and does not constitute legal advice. Clients are encouraged to seek tailored counsel regarding their specific circumstances and compliance obligations.