Modern car interior dashboard with digital display and steering wheel

TL;DR: The California Privacy Protection Agency's connected-car enforcement sweep is now producing fines. American Honda Motor Co. settled on March 12, 2025 for $632,500 after a CPPA Board decision found the company required excessive personal information to exercise opt-out rights, ran an asymmetric privacy management tool, made authorized-agent submissions hard, and shared consumer data with ad-tech vendors without compliant contracts [1]. Ford Motor Company settled on March 5, 2026 for $375,703 after a CPPA Board decision found the company required email verification before processing opt-out requests from its connected-vehicle services, an obstacle the agency called "unnecessary friction" [2]. Both cases arose from the same review: the CPPA Enforcement Division's ongoing audit of data privacy practices by connected vehicle manufacturers and related technologies [1][2]. The Honda and Ford settlements are the second and third actions in a wave that produced the $12.75 million GM record penalty in May 2026 for actually selling OnStar driving data to LexisNexis and Verisk [3]. California is now enforcing the connected-car privacy bar on three fronts: the data, the opt-out, and the friction.

The Sweep That Started the Wave

On July 31, 2023, the California Privacy Protection Agency's Enforcement Division opened a review of data privacy practices by connected vehicle manufacturers and related technologies [1]. That single sentence is the legal trigger for everything that has happened since. The CPPA did not announce a list of targets. It did not publish a list of named companies. It just opened the file, and the automakers started hearing from the agency.

Honda was the first to settle. Ford was second. GM was third, and the largest by an order of magnitude. The pattern across the three cases is what makes the sweep a sweep, not three unrelated incidents. The CPPA is treating the connected car as a covered device under the California Consumer Privacy Act, the same way it would treat a website, a mobile app, or a streaming service. The agency's theory is straightforward: if a company collects personal information through a connected product, the CCPA's opt-out, deletion, and limitation rights apply to that product, and the company has to make those rights actually exercisable.

The cases differ on what the company did wrong. Honda was the opt-out minefield. Ford was the single extra step. GM was the data sale. The fines track the harm: the opt-out friction got the automakers fined, and the actual data sales got GM fined at a level the previous CCPA record could not have predicted. Read together, the three decisions draw a clear line. If you make the privacy rights on a connected car hard to use, you will be fined. If you sell the data the connected car collects, you will be fined harder.

Honda: $632,500 for the Opt-Out Minefield

On March 12, 2025, the CPPA Board issued a decision requiring American Honda Motor Co. to change its business practices and pay a $632,500 fine to resolve claims that the company violated the CCPA [1]. The fine was the first action in the connected-car sweep, and the violations alleged by the Enforcement Division were four distinct kinds of friction, each of them mapped to a specific CCPA right.

First, Honda required Californians to verify themselves and provide excessive personal information to exercise the right to opt out of sale or sharing and the right to limit use of sensitive personal information. The CCPA establishes a "right to opt-out" with a statutory cap on the friction a business can impose; Honda's verification flow, the agency alleged, exceeded that cap. Second, Honda's online privacy management tool did not offer privacy choices in a symmetrical or equal way. The opt-out was harder to find than the opt-in, and the right to limit sensitive data was structured to discourage use. Third, Honda made it difficult for consumers to authorize "authorized agents" (other individuals or organizations) to exercise their privacy rights on their behalf, which is a statutorily protected channel. Fourth, Honda shared consumer personal information with ad-tech companies without producing contracts that contain the necessary terms to protect privacy [1].

To resolve the allegations, Honda agreed to implement a new and simpler process for Californians to assert their privacy rights. The company is required to certify its compliance, train its employees, and consult a user experience (UX) designer to evaluate its methods for submitting privacy requests [1]. The UX-designer requirement is notable: the CPPA did not just fine Honda, it required a usability expert to be part of the fix, which is a step beyond what a typical CCPA settlement has imposed. Honda also had to change its contracting process to ensure appropriate mechanisms are in place to protect personal information shared with ad-tech vendors [1].

The CCPA authorizes the agency to impose an administrative fine of up to $2,500 for each violation ($7,500 for each intentional violation), plus an increase for inflation, in addition to ordering businesses to cease engaging in violative business practices. The Honda order spells out the number of consumers whose rights were implicated by some of Honda's practices, underscoring that fines apply on a per-violation basis. The $632,500 figure is the aggregate [1].

Michael Macko, the head of the CPPA's Enforcement Division, framed the settlement the way a regulator frames a teachable moment: "The remedy should fit the problem behavior. We won't hesitate to use our cease-and-desist authority to change business practices, and we'll tally fines based on the number of violations. Today's resolution reflects Honda's early cooperation and commitment to make things right" [1].

Ford: $375,703 for the Email Verification Step

Almost exactly a year later, on March 5, 2026, the CPPA Board issued a second decision in the same sweep, this time against Ford Motor Company, requiring the automaker to pay a $375,703 fine and change its practices following a settlement reached by CalPrivacy's Enforcement Division [2]. The Ford case is narrower than Honda. The specific allegation is that Ford required consumers to verify their email address as part of the opt-out process, and would not process opt-out requests unless the verification step was completed. The decision emphasizes that unnecessary friction in the opt-out process violates the CCPA [2].

Ford vehicles are commonly found on roadways across California. The state's privacy law, the CCPA, gives consumers the right to stop Ford and other businesses from selling and sharing their personal information by opting out. According to the Board's decision, Ford required consumers to verify their identity before they could opt out. Ford did so by requiring consumers to verify their email address as part of the opt-out process, resulting in unnecessary friction for consumers seeking to exercise their rights [2]. The company required consumers to complete an email verification step before they could opt out of the sale and sharing of personal information collected through its digital properties and connected vehicle services. As a result, Ford did not process opt-out requests unless consumers completed this step. In response to the agency's investigation, Ford has since processed the opt-out requests that lacked verification [2].

Macko, the same enforcement head who handled Honda, framed the Ford case as a follow-through on the same principle: "Opting out is supposed to be easy. Just as unnecessary steps in the checkout process can discourage consumers from completing a purchase, unnecessary steps in the opt-out process can discourage consumers from exercising their privacy rights. We will continue to scrutinize practices that create these kinds of barriers for Californians" [2]. Tom Kemp, CalPrivacy's Executive Director, added: "The agency has made it a priority to remove obstacles that prevent Californians from exercising their privacy rights. This case shows that the Enforcement Division will take all appropriate action when practices fall short of the law's requirements" [2].

In addition to paying the fine, Ford must change its business practices by providing consumers with easy methods to submit opt-out requests with minimal steps. Ford must also conduct an audit of the tracking technologies on its website and ensure compliance with opt-out preference signals, including the Global Privacy Control [2]. The GPC requirement is the part of the settlement that matters most for the future: the Global Privacy Control is a browser-level signal that lets a consumer express an opt-out once, and the CCPA requires businesses to honor it. The audit is going to tell us whether Ford's data flows into ad networks are GPC-compliant at the network level, or only at the consumer-facing preference center.

The case was handled by Enforcement Division Attorneys Alex Berger and Michael Meyer, with investigative assistance from Research Technologist Nikita Samarin. The matter arose from the Enforcement Division's review of data privacy practices by connected vehicle manufacturers, similar to the enforcement action last year against American Honda Motor Co. [2]. That sentence in CalPrivacy's own press release is what links the two cases into a wave, rather than two isolated decisions.

What the Pattern Tells You

Three connected-car cases in 14 months. Three different kinds of violation, three different fine sizes, and a common thread. The thread is that the CPPA is testing every link in the connected-car privacy chain:

  • Honda (March 2025): The opt-out minefield. Excessive personal information required to opt out, asymmetric privacy choices, blocked authorized agents, ad-tech sharing without compliant contracts. Fine: $632,500 [1].
  • Ford (March 2026): The single extra step. Email verification before opt-out is processed, even on requests from connected-vehicle services. Fine: $375,703 [2].
  • GM (May 2026): The data sale. Geolocation and driving behavior from hundreds of thousands of California drivers sold to LexisNexis and Verisk, packaged into driver-rating products for insurers. Fine: $12.75 million, the largest CCPA penalty ever [3].

Read left to right, the fines look like a sliding scale tied to the severity of the underlying conduct. Honda and Ford were fined for making privacy rights hard to use. GM was fined for monetizing the data the connected car collected. The CCPA's $2,500-per-violation cap meant Honda's $632,500 was the result of a per-violation tally; the GM penalty was negotiated up to a record level in part because the volume of drivers and the duration of the conduct (four years) put the conduct on the high end of the agency's penalty matrix.

What the three cases do not tell you, yet, is what happens when a connected-car maker builds the privacy right into the product, then ignores it anyway. That is the Toyota scenario, in a separate class action: a driver uses the in-app opt-out, the company confirms the opt-out, and the data keeps flowing. The Toyota case is a private lawsuit, not a CPPA enforcement action, but it is the natural next thing the CPPA is likely to test, especially since the same Macko-led Enforcement Division has now shown it is willing to look at opt-out mechanics in granular detail.

There is also a question the CPPA has not yet answered in writing, and that the connected-car industry is watching closely: does the Global Privacy Control apply to the connected car's data flows in the same way it applies to a website? The Ford settlement imposes an audit to test exactly that, and the result of the audit, when it is finalized, will be the first written agency view of GPC coverage for connected vehicles. If the audit finds that GPC works at the preference-center layer but not at the in-vehicle telematics layer, the next settlement is going to be a large one.

What This Means If You Drive a Honda or a Ford

The Honda and Ford settlements do two things that matter for drivers right now, and one thing that matters for drivers later. The thing that matters now is the practical fix: if you tried to opt out of Honda or Ford data sharing before the settlement and the company made you jump through hoops you could not clear, the company was supposed to honor your opt-out anyway. Honda's remedy requires a UX review, which is the agency telling the company to redesign the flow so a real person can actually use it. Ford has already processed the opt-out requests that lacked verification [2], which means the opt-out is now in effect for those consumers, not still pending.

The thing that matters later is the contract and ad-tech layer. Honda had to change its contracting process to ensure that contracts with ad-tech vendors contain the necessary terms to protect personal information [1]. That is a quiet change with a loud effect. The next time Honda shares consumer data with an ad-tech vendor, the contract has to specify what the vendor can and cannot do with the data, and the contract has to be on file with the agency. If the ad-tech vendor does something Honda did not authorize, Honda is on the hook. That is the contractual version of data minimization: the privacy standard has to be enforceable against the next party in the chain, not just against the first party that collected the data.

The thing that matters for drivers is the same opt-out pattern the GM record penalty produced: the privacy right has to be exercisable on the device, and the device-maker has to honor it. The simplest way to verify you are not in the friction bucket is to submit a CCPA opt-out through Honda's or Ford's privacy portal today, watch for the confirmation, and treat any email-verification or identity-verification step beyond what the law permits as a fixable violation you can report. The CPPA complaint process is online, and the agency has shown it is willing to act on what comes in.

For California residents in particular, the Global Privacy Control is the lever. If you have the GPC signal enabled in your browser, a CCPA-covered business is supposed to honor it as a universal opt-out. The Ford settlement specifically requires Ford to audit its tracking technologies for GPC compliance [2]. If you have the GPC signal on and you still see Ford or Honda data flowing to a third party, that is the kind of evidence the CPPA Enforcement Division is now willing to use. The agency has demonstrated, three times in 14 months, that it treats opt-out friction as the kind of violation it is willing to spend enforcement resources on.

The Bigger Picture: A Connected-Car Privacy Floor

The CPPA's connected-car sweep is now the single most concentrated privacy enforcement effort in the United States. Three cases, three automakers, three different theories of harm, and a clear signal to the rest of the industry that the agency is not going to treat connected cars as a special carve-out. The next manufacturer that runs an opt-out flow with a friction step the agency has already called "unnecessary" is going to be the next settlement, and the fine is going to be larger than Ford's because the agency has now published the standard.

The other thing the sweep is doing is creating a written record. A year ago, the legal consensus on connected-car privacy was: state privacy laws apply, but the enforcement is theoretical. The CPPA has now produced three written decisions in 14 months, each of them citing the CCPA, each of them tied to the same review, and each of them published with the dollar figure, the violations, the remedy, and the named individuals. The legal record now exists, and any plaintiff, regulator, or journalist who needs to argue that a connected-car maker is on notice about the privacy standard can cite the CPPA record directly.

For drivers, the practical takeaway is that the privacy rights they have on a website now extend to their car, and the agency that enforces those rights is willing to spend the resources to make the extension real. The Honda and Ford settlements are not the end of the connected-car enforcement story. They are the first two chapters of a story the CPPA is now writing in public.

Sources

  1. CPPA: Honda Settles With CPPA Over Privacy Violations (March 12, 2025)
  2. CalPrivacy: Ford to Change Practices, Pay Fine for Adding Unnecessary Friction to Opt-Out Process (March 5, 2026)
  3. ComplianceHub: California's CPPA Is Fining Real Companies Now: Lessons from Disney, Ford, Honda, and Tractor Supply (May 2, 2026)
  4. CPPA: Enforcement Division Sweep of Connected Vehicle Manufacturer Privacy Practices (July 31, 2023)