Automotive Fleet
MenuMENU
SearchSEARCH

Reduce Your Risk of Vehicle Data Breaches: Tips to Keep Your Information Safe

Personal information is harder than ever to protect, and much of it is stored in vehicles themselves. So, how can you protect your company and fleet users’ data?

June 13, 2022
Reduce Your Risk of Vehicle Data Breaches: Tips to Keep Your Information Safe

Not-so-fun fact: Four out of every five remarketed cars sold last year contained personal information, according to Privacy4Cars.

Photo: belozersky/depositphotos.com

5 min to read


Andrea Amico, founder and CEO at Privacy4Cars, is passionate about privacy and security, and is chock full of stats and facts on how far-reaching data sharing has become and how many companies have access to personal information. Vehicles themselves collect and store more information than most of us would ever realize, and there is growing history of breaches, warnings, lawsuits, and even settlements. Amico presented all of this in a session at March’s 2022 NAFA Institute & Expo, startling attendees with more than just his blue hair.

Amico first engaged the crowd by handing out USB filters that allow a cell phone to charge without its data being retrieved. The point was to warn attendees to never use other USB sticks, especially given by vendors, “because it’s how bad guys do things.”

Ad Loading...

Then, Amico provided some basic definitions: Security in this case is defined as preventing unauthorized people or companies from having access to personal data, and privacy is the right to have data in the first place.

Chances are you don’t really know how your car works, he said. Car collect data locally (and that data is not stored in a  database that has traditional security and privacy) and increasingly they send data out. Consequently, just like with laptops, securing vehicle data must start from protecting the data that is on them... but the more connected they are, the more complex the issue becomes.

Andrea Amico of Privacy4Cars shares some scary and surprising information about just how much data retrived from cell phones connected to vehicles is shared. Here, Amico presents at the 2022 Government Fleet Expo. He delivered a similar presentation to NAFA I&E attendees in March.

Photo: Ross Stewart Photography

When you plug your phone into a car, whether to pair it or charge it via a USB, lots of information from that phone is collected. This can include:

  • Biometric IDs.

  • Passwords.

  • Contacts.

  • Call logs.

  • Text messages.

  • Calendar events.

  • Downloaded files.

  • Medical providers.

  • Navigation history.

  • Home address.

  • Garage codes.

  • Health and credit information.

  • Third-party apps.

Companies and individuals can buy this data for a steal, too. Amico said the current market price is somewhere between $10 and $60 per person per year.

Ad Loading...

While most drivers only see directions on their GPS navigation in the car, that geolocation goes much further than the vehicle's infotainment or the manufacturer. It is also shared with firmware providers, component manufacturers, telecom providers, other connected devices, traffic services, weather services, insurance companies, Google, Apple, and more.

Don’t believe it? Check out these headlines.

In this case, sharing is not caring.

State & Federal Laws

“There's a lot of things in which America leads in, but privacy is not one of those things,” Amico said, referencing Europe’s General Data Protection Regulation (GDPR), known as the toughest privacy and security law in the world.

Ad Loading...

In the U.S., without a federal privacy law, data regulation is left up to states. And all 50 states do regulate the personal information collected by vehicles, but not all laws are equal. California, Colorado, Virginia, and Utah, have privacy laws modeled after Europe’s GDPR; while California adds on IoT security laws; and Illinois, Florida, California, Washington, as well as some cities, have biometrics laws. New Jersey was the first state to pass a bill about vehicle telematics and driver monitoring, where companies must tell employees they’re being tracked. If they don't, the company is actually liable.

Biometrics laws, in particular, are under scrutiny, and several companies are facing several lawsuits for violations. In an example, Amico offers this: “You drive a Tesla, it has a camera facing you, it is actually recognizing you, but plaintiff attorneys increasingly are arguing that it is not asking for your consent. In Illinois, for instance, the statutory damages for biometrics violations are $500 a person, so a smart attorney has run the tab and they figure out it's probably worthwhile suing Tesla.”

To help understand the statutes that apply to your state, Privacy4Cars offers a free online resource.

Don't be a stat: know your rights, delete your data, & keep your privacy safe.
Spotify: https://open.spotify.com/show/75xGpTgYNZomBLLAdZ0AOn?utm_source=twitter&utm_medium=referral&utm_campaign=facts_not_feelings_evergreen&utm_content=spotify
Apple: https://podcasts.apple.com/us/podcast/facts-not-feelings-with-brooke-c-furniss/id1609639468?utm_source=twitter&utm_medium=referral&utm_campaign=facts_not_feelings_evergreen&utm_content=apple_podcast
Youtube: https://youtu.be/ZX5m28Gi5Uk?utm_source=twitter&utm_medium=referral&utm_campaign=facts_not_feelings_episode22&utm_content=andrea_episode#BZConsultants#FactsNotFeelings#AndreaAmico#Privacy4Cars#Privacy#Automotive@Privacy4Carspic.twitter.com/cG9u4mMDZ9

— BZConsultants (@BzConsultants) April 13, 2022

While many companies will issue statements about their ethics, anonymization of data, compliance with GDPR or CCPA, Amico advises digging deeper.

Ad Loading...

What to Read or Ask OEM & Telematics Providers

  • Privacy policies and terms of service.

  • Contract and clauses on consent, use, sharing and retention of data.

  • If they claim geolocation data is anonymized (if so, it’s a red flag as that is hardly possible).

  • Documentation of compliance with California’s IoT law (even if you’re not in California).

  • Take the Privacy4Cars fleet risk assessment (below).

Privacy4Cars Fleet Risk Assessment

To take this fleet risk assessment, score each row and total the sum of all rows to find your risk level.

Source: Privacy4Cars

There are steps you can take to protect your data. In 2018, the FTC actually advised fleets to dump the data stored in cars in a message called “Be discreet when you delete your fleet.”

Amico recommends connecting with fleet management companies (FMCs), many of which offer in-vehicle data deletion at the time of sale — Element, Wheels Donlen, and Holman all do, he said.

Actions to Take to Reduce Risk

  • Read all privacy and service policies.

  • Ask your FMC what solutions they have in place to help.

  • Engage legal.

  • Perform CISO/compliance checks.

  • Delete all in-vehicle data at handoffs and sale.

  • Perform a data privacy assessment.

  • Get vehicles under the same policy policies as other devices (laptops, phones).

  • Prune! What data do you really need?

  • Implement robust consent management.

  • Demand a telematics “kill switch” for off-work hours.

To the last point in the list above, Amico elaborates that in Europe, employees — and any family members — who use a work vehicle for personal use after hours cannot be tracked. California has plans to adopt this rule starting in January, and more states will likely follow suit. Until then, Amico recommends asking your telematics provider how to turn off tracking between shifts.

Ad Loading...

Additionally, consider adding to your fleet policy a clause about shared vehicles and rentals that requires data deletion at handoff.

“As a business, to protect your employees, you need to start protecting yourself,” Amico said.

Subscribe to Our Newsletter

More Operations

SponsoredMay 15, 2026

Hybrids: Electrification Without the Challenges

For fleet managers, fuel is one of the biggest line items in the budget — and it's one hybrids can shrink without changing how your people work. Download the eBook to see the numbers, understand the technology, and get a step-by-step guide to making the switch.

Read More →
Man speaking during an Automotive Fleet interview beside text reading “The 60% Driver Improvement Nobody Expected!” with blue motion graphics background.
Operationsby Chris BrownMay 14, 2026

How NOV Uses Telematics to Improve Fleet Safety Across 160 Locations

James Victory of NOV discusses how the company manages fleet safety, maintenance, and telematics across more than 150 locations supporting oilfield operations throughout the U.S.

Read More →
A graphic with Ford Pro's Steven Sanstostasi's headshot on it representing the Fleet Meets series.
Operationsby Faith HowellMay 14, 2026

Fleet Meets: Steven Santostasi

This edition of the Fleet Meets series features Steven Santostasi, the current TSP channel manager for Ford Pro.

Read More →
Ad Loading...
Cover of a whitepaper titled “The Hidden Costs of Departmentally Assigned Vehicles on Your Fleet” featuring a black fleet vehicle driving on a road at sunset. Subheadline reads: “Discover how your fleet can reduce costs and minimize risk by implementing vehicle sharing.” The document focuses on fleet optimization, vehicle sharing, cost reduction, utilization tracking, and risk management for fleet operations.
SponsoredMay 13, 2026

Why Fleet Managers Are Replacing Departmental Vehicles with Shared Motor Pools

Departmentally assigned vehicles often create hidden costs through underutilization, poor visibility, and increased administrative burden. This white paper explores how shared motor pool strategies help fleets reduce costs, improve accountability, and optimize vehicle utilization.

Read More →
Three team members in shop with Chris
Operationsby Chris BrownMay 12, 2026

Soap Box Derby Challenge: Assembling the Crew

Meet Gabriel, Matthew, and Angel — the team helping bring this soap box derby build to life.

Read More →
Handshake graphic featuring BBL Fleet and Velcor Leasing Corporation logos announcing BBL Fleet’s acquisition of Velcor to expand fleet management services nationwide.
Operationsby News/Media ReleaseMay 8, 2026

BBL Fleet Acquires Velcor Leasing Corporation

BBL Fleet expanded its footprint in the fleet management industry with the acquisition of Velcor Leasing Corporation of Madison through a stock purchase agreement finalized Feb. 27, 2026.

Read More →
Ad Loading...
Graphic reading “What’s New From Lytx at Protect 2026?” over a blue digital network background highlighting Lytx fleet technology and AI-powered safety solutions.
Operationsby News/Media ReleaseMay 6, 2026

Lytx Introduces New AI Fleet Technologies at Protect 2026

The company introduced new AI-driven fleet safety and operations technologies during its annual user conference.

Read More →
Cover image for the “5th Annual Market Pulse Report” by Element titled “Navigating fleet management in 2026: Data and insights shaping the future of fleet and mobility.” The design features an aerial view of a cable-stayed bridge with vehicles traveling on a highway beside a dense green forest. A teal graphic panel overlays the lower portion of the image, with the Element logo and tagline “Intelligence in motion” at the bottom.
SponsoredMay 6, 2026

Fleet Costs Are Rising: Here’s How Leaders Are Responding

Fleet leaders are under pressure to reduce costs, adapt to economic uncertainty, and make smarter decisions. See how peers across North America are responding with real data, proven strategies, and forward-looking insights. Download the 2026 Market Pulse Report to benchmark your strategy and uncover where you can gain an edge.

Read More →
A blue Automotive Fleet graphic representing the weekly AF News Recap series.
Operationsby Faith HowellMay 4, 2026

From Waffle House to AI: Fleet Trends You Need to Know

In this AF news recap, host Faith Howell covers how Waffle House stepped up during disaster response and new AI tech on the market.

Read More →
Ad Loading...
OperationsApril 30, 2026

Fleet Operations in the Age of AI: Navigating Ethical and Legal Challenges

AI is no longer a future concept for fleets—it’s already embedded in the tools, data, and decisions that operators rely on every day. In this episode of the Fleet Forward Podcast, recorded live at Fleet Forward, industry leaders take the conversation beyond hype to examine what responsible AI adoption really looks like in fleet operations.

Read More →