Modern vehicles have become rolling data-collection hubs, and a new report from the Mozilla Foundation suggests that drivers have little say over what happens to the information their cars gather. The nonprofit, known for its Firefox browser, reviewed the privacy policies of 25 popular car brands in Europe and North America and found that none met its minimum privacy standards.
In its latest Privacy Not Included survey, Mozilla found that 19 of the 25 automakers say they may sell drivers' personal data, and half say they could share it with governments or law enforcement upon request, without requiring a court order. Only two brands—Renault and Dacia, which are not sold in North America—offer drivers the option to have their data deleted.
Jen Caltrider, the study's lead researcher, described cars as having "flown under the privacy radar" and called the situation "truly awful." She noted that cars are equipped with microphones and cameras, both inward- and outward-facing, making them uniquely intrusive. "Cars have microphones and people have all kinds of sensitive conversations in them," she said.
The findings come as European regulators push for stricter data protection under the General Data Protection Regulation (GDPR), and as the EU develops its digital ID wallet, which aims to give citizens more control over their personal data. Yet the automotive sector appears to lag behind other industries in privacy practices.
A 'wiretap on wheels'
Albert Fox Cahn, a technology and human rights fellow at Harvard's Carr Center for Human Rights Policy, called most cars "wiretaps on wheels." He stressed the unique invasiveness of turning a private space like a car into a corporate surveillance zone. "There is something uniquely invasive about transforming the privacy of one's car into a corporate surveillance space," he said.
The study also highlighted the vague security standards in the industry, a concern given automakers' history of cybersecurity vulnerabilities. With the rise of autonomous vehicles across Europe, the amount of data collected is only set to increase.
Mozilla's researchers found that most car brands ignored their emailed questions about data practices, and those that responded gave partial, unsatisfactory answers. However, Japan's Nissan stood out for its unusually detailed privacy notice, which lists sensitive data such as driver's license numbers, immigration status, race, sexual orientation, and health diagnoses. Nissan also says it can collect "genetic information" and data on "sexual activity," though it doesn't explain how.
Tesla, the all-electric carmaker, scored high on Mozilla's "creepiness" index. Its privacy notice warns that if owners opt out of data collection, the company may not be able to notify them in real time of issues that could cause "reduced functionality, serious damage, or inoperability."
The Alliance for Automotive Innovation, a trade group representing major carmakers in the US, pushed back against the "wiretap" characterization. In a letter to US congressional leaders, it said it shares the goal of protecting consumer privacy and called for a federal privacy law, arguing that a "patchwork of state privacy laws creates confusion among consumers." The group expressed concerns about allowing customers to completely opt out of data collection for safety reasons, but endorsed giving drivers more control over how their data is used in marketing.
For European drivers, the report underscores a growing tension between the convenience of connected vehicles and the right to privacy. As the EU considers new rules on artificial intelligence and data governance, the automotive industry may face increased scrutiny. The Mozilla study serves as a reminder that, in the digital age, the car is no longer just a means of transport—it's a data-generating device that demands careful oversight.


