Feature Data Privacy
GM Paid $12.75M for Selling Driver Data Without Consent. Your Fintech May Have the Same Problem.
California's record $12.75M CCPA settlement with General Motors over unconsented data sales to LexisNexis and Verisk exposes a pattern that runs through fintech: sharing consumer data with analytics firms, credit bureaus, and third parties without adequate notice or consent. Here's what the enforcement signal means for financial services compliance teams.
Table of Contents
TL;DR
- California settled with GM for $12.75M — the largest CCPA fine ever — over unconsented sale of driver data to LexisNexis and Verisk. GM made $20M from the data. The violation was purpose limitation and data minimization failure, not a breach.
- The same pattern runs through fintech: transaction data shared with analytics firms, behavioral signals sold to underwriting platforms, financial profiles packaged for third-party use — often without consent that meets 2026 CCPA standards
- California’s Data Broker Enforcement Strike Force (launched November 2025) is actively investigating financial services firms; CCPA penalties scale to $7,988 per intentional violation per consumer
- The Section 1033 open banking rule is enjoined — but state law still applies to every data flow your fintech runs today
The news about General Motors landed in May like a reminder that went straight to your inbox whether you opened it or not.
On May 8, 2026, the California Attorney General announced a $12.75 million settlement with General Motors and its connected vehicle subsidiary OnStar — the largest CCPA fine ever imposed. The allegation wasn’t a data breach. There was no ransomware, no unauthorized access, no hacker. The allegation was that GM collected detailed data on how its customers drove — location, speed, braking patterns, trip behavior — and sold that data to LexisNexis Risk Solutions and Verisk Analytics. Without telling customers clearly. Without getting consent that met California’s standard. For approximately four years, from 2020 to 2024, GM made about $20 million doing it.
If you work in fintech compliance and read that story as an automotive problem, read it again. Because the underlying conduct — sharing consumer financial behavior data with analytics and scoring firms without adequate notice or consent — is not a niche GM practice. It’s a standard feature of how many fintechs operate.
What GM Actually Did
The OnStar service is straightforward: drivers pay for navigation, emergency roadside assistance, and vehicle diagnostics. In exchange, their vehicles continuously transmit telematics data to GM. What consumers understood they were consenting to was getting help when their airbags deployed. What GM was actually doing with that data was selling a granular behavioral profile — how hard you brake, how often you speed, where you drive, how you drive at night — to firms that use it to price insurance.
LexisNexis Risk Solutions and Verisk Analytics are not general-interest companies. They’re data analytics firms that specialize in risk scoring for insurers. When they received GM’s data, it went into insurance risk models. Drivers who didn’t know their OnStar subscription was also a behavioral data subscription started getting higher insurance quotes without knowing why.
California’s settlement required GM to stop selling driving data to consumer reporting agencies for five years, delete retained data within 180 days absent affirmative express consent, request deletion by LexisNexis and Verisk, and implement a comprehensive privacy program subject to regulatory reporting.
The legal theory wasn’t complex. California’s CCPA prohibits collecting or selling personal information for purposes beyond what was disclosed at collection (purpose limitation) and collecting more data than necessary for the disclosed purpose (data minimization). GM disclosed a vehicle service. It ran a data monetization business.
The Fintech Version of This Problem
The fintech industry runs on data sharing. That’s not a critique — data sharing enables the products consumers actually want: instant credit decisions, automatic savings transfers, real-time fraud alerts, open banking aggregation. But the consent and disclosure infrastructure underneath those data flows has often lagged the commercial reality.
Walk through a typical fintech’s data ecosystem:
Transaction data to underwriting platforms. Many lending fintechs share transaction history with underwriting analytics firms to power alternative credit scoring. What did the consumer consent to at application? “We may share your information with third parties to evaluate your application” covers a lot of ground, but may not adequately disclose that their transaction history is being sent to a firm building behavioral risk models that will be used by other lenders.
Behavioral data to marketing analytics. Fintech apps that share usage behavior — which features you use, how often, what you look at before applying for a product — with marketing analytics platforms are sharing personal information. Whether this constitutes a “sale” under CCPA (which includes data sharing for cross-context behavioral advertising) depends on the specific arrangements. Many firms have assumed it doesn’t. The CPPA’s 2025 enforcement actions suggest that assumption warrants scrutiny.
Financial data to aggregators and API partners. Open banking integrations frequently involve sharing consumer financial data with third-party applications. The consumer connects the integration, but the consent scope disclosed — “allow [App] to access your account” — often doesn’t clearly explain how that data will be used, stored, or shared downstream by the aggregator.
Credit bureau reporting. Fintechs that report to credit bureaus are operating under different consent frameworks (adverse action notice, furnisher obligations under FCRA). But that framework doesn’t extend to sharing derived insights, behavioral scores, or data beyond what FCRA covers.
None of these are hypothetical. The CPPA is investigating them.
The Data Broker Strike Force Is Looking at Financial Services
In November 2025, the California Privacy Protection Agency formally launched the Data Broker Enforcement Strike Force within its Enforcement Division. The mission statement was explicit: investigate CCPA violations by companies that collect and sell personal information without a direct consumer relationship.
The enforcement focus quickly expanded beyond the obvious data broker category. ArentFox Schiff’s analysis of 2025 enforcement patterns notes that “later actions expanded to businesses dealing in inferred data and custom audiences, signaling that California interprets the term ‘data broker’ broadly.”
A fintech that doesn’t sell consumer data as a primary business model can still be a “data broker” under California law if it receives compensation for sharing personal information with a third party that doesn’t have a direct relationship with the consumer. The analytical question the CPPA is applying isn’t “Is data sharing your business?” It’s “Are you sharing personal information for consideration — money, services, or in kind — outside the direct consumer relationship?”
If your fintech receives a lower API rate, preferred partner status, or revenue share from a data aggregator in exchange for consumer data access, that arrangement warrants review. The CPPA’s current enforcement posture suggests it’s looking at exactly these structures.
The 2026 Penalty Math
CCPA penalties are inflation-adjusted annually. The 2026 numbers: $2,663 per unintentional violation and $7,988 per intentional violation.
Those numbers look manageable until you apply them per consumer. A fintech with 500,000 users that has been improperly sharing behavioral data for two years — characterizing that as “unintentional” — faces theoretical exposure of over $1.3 billion before settlement negotiations begin. Regulators don’t collect full theoretical liability, but the per-violation scale is what creates the leverage for a $12.75M settlement with a company that made $20M from the conduct.
For violations involving children’s data, the intentional fine amount triples to nearly $24,000 per violation. If your app doesn’t age-gate and has any users under 16, this is a separate risk category.
Recent California settlements for context: General Motors ($12.75M, May 2026), Disney ($2.75M, February 2026), Healthline ($1.55M, July 2025), Jam City ($1.4M, November 2025), Tractor Supply ($1.35M, September 2025). The direction is up. The frequency is increasing. The IAPP’s reporting on the GM settlement notes that “the record settlement signals that California is willing to pursue major enforcement actions against large companies.”
What GLBA Preemption Doesn’t Cover
The natural response from a fintech legal team is to reach for GLBA. The Gramm-Leach-Bliley Act’s Financial Privacy Rule governs how financial institutions share nonpublic personal information. GLBA preempts state laws that are inconsistent — which has historically provided some protection from CCPA’s application to financial data.
But GLBA preemption has gaps that California has been explicit about exploiting:
It doesn’t cover all data types. GLBA’s financial privacy provisions apply to “nonpublic personal information” in the context of a financial product or service. Behavioral analytics data — usage patterns, app engagement, derived behavioral scores — may not fit cleanly within GLBA’s NPI definition.
It doesn’t preempt state laws that provide greater protection. California’s position is that CCPA’s data minimization and purpose limitation requirements go beyond GLBA’s notice-and-opt-out framework in ways that are not inconsistent. Federal courts have not fully resolved this.
The GLBA preemption bill hasn’t passed. The House bill that would have broadly preempted state privacy laws for financial institutions died in the Senate. State law enforcement remains active and pending further federal legislative action.
For context on where this is heading, the March 2026 GLBA fight and the California AG’s position are covered in the earlier post: Congress Wants to Kill State Privacy Laws for Banks. Here’s What the GLBA Overhaul Means for Your Compliance Program.
The Section 1033 Complication
One argument that’s circulated in fintech privacy discussions: Section 1033 of Dodd-Frank — the CFPB’s open banking rule — will establish a federal framework for consumer data sharing that preempts state law. If the rule passes, the argument goes, California’s authority over financial data sharing narrows.
The problem: as of September 2026, the Section 1033 rule is enjoined. A federal district court in the Eastern District of Kentucky issued a preliminary injunction preventing enforcement. The CFPB issued an ANPR in August 2025 inviting reconsideration. Whether the rule emerges in recognizable form, gets substantially revised, or is withdrawn remains genuinely uncertain.
Which means: the federal preemption that some compliance teams were counting on to simplify their California exposure doesn’t exist yet, and may not in the form originally hoped. In the meantime, every data flow your fintech runs today is subject to the current law — CCPA, GLBA, state equivalents, and the CPPA’s active enforcement program.
So What? The Data Flow Audit
The GM case gives compliance teams a clear framework for self-assessment. California’s theory was: you collected data for purpose A, shared it for purpose B, made money doing it, and didn’t tell consumers clearly.
Apply the same analysis to your own data flows:
Step 1: Map every data-out relationship. For every third party that receives consumer data from your systems — directly, via API, via data feed, via analytics integration — list what data elements flow, how often, and what the commercial arrangement looks like.
Step 2: Check the disclosed purpose. Go back to the consumer-facing disclosures at the moment of data collection — the app’s privacy notice, the account agreement, the authorization screens. Does the disclosed purpose cover how this third party actually uses the data? If a customer agreed to “sharing for purposes of evaluating credit applications” and you’re also sharing with a marketing analytics firm, the marketing use isn’t covered.
Step 3: Assess the consent basis. For each third-party data sharing arrangement, identify your CCPA legal basis: consumer consent, service provider relationship (with appropriate contractual limits), legitimate business purpose, or GLBA NPI exemption. Arrangements that don’t fit cleanly into one of these categories are exposures.
Step 4: Review your data sharing agreements. CCPA requires that service providers (firms receiving your data for internal business purposes) are contractually restricted from selling or using the data for their own commercial purposes. If your data sharing agreement with an analytics firm doesn’t include these restrictions — or if the firm’s actual use goes beyond what the agreement says — you may not be able to claim the service provider exemption.
The FTC Safeguards Rule enforcement context from August 2026 is a useful parallel: non-bank financial institutions face multiple, overlapping regulatory frameworks on data. California is one layer. FTC is another. The firms that get caught are the ones treating these as separate compliance programs with separate accountability — rather than a unified data governance framework that applies across all of them.
The RiskTemplate Third-Party Risk Management (TPRM) Kit includes data sharing due diligence questionnaires, vendor contract review checklists, and ongoing monitoring frameworks that surface exactly the third-party data use gaps that California is now enforcing. The firms building that infrastructure now are ahead of the enforcement wave. The ones that aren’t will be catching up after the supervisory letter arrives.
Related reading:
- CCPA and CPRA Enforcement in 2025: What the California Privacy Protection Agency Is Actually Going After
- Congress Wants to Kill State Privacy Laws for Banks. Here’s What the GLBA Overhaul Means for Your Compliance Program.
- The FTC’s 30-Day Breach Notification Requirement: What Non-Bank Fintechs Keep Getting Wrong
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did General Motors actually do to get a $12.75M CCPA fine?
Why does this matter to fintechs that aren't in the automotive business?
What is California's Data Broker Enforcement Strike Force?
What are the current CCPA/CPRA fine levels for 2026?
Does GLBA preemption protect fintechs from CCPA/CPRA liability?
What should my fintech do right now to assess CPRA exposure?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Data Privacy
FTC Chairman Ferguson Says a Privacy Enforcement Surge Is Coming in H2 2026. Here's What Financial Services Companies Need in Place.
FTC Chairman Andrew Ferguson publicly warned that reporters covering the FTC will 'have a hard time keeping up' with the number of privacy enforcement cases coming in the second half of 2026. The Kochava settlement and new Section 5 standalone data-security cases telegraph exactly what's in the crosshairs. Here's what financial services companies need to have documented before the cases start landing.
Sep 9, 2026
Data Privacy
CalPrivacy Has Issued Eight Data Broker Fines and Is Still Going. What the September 2026 Enforcement Advisory Means for Your Fintech.
California's Privacy Protection Agency issued Enforcement Advisory 2026-01 on September 3, making clear that inaccurate data broker registration is a live $200-per-day penalty risk. Two August 2026 settlements and eight prior enforcement actions signal that CalPrivacy is done with warnings. Here's what fintech compliance teams need to know.
Sep 7, 2026
Data Privacy
PADFAA Is Real Enforcement Now: What Fintech Data Companies Need to Know Before the FTC Files Its First Case
The Protecting Americans' Data from Foreign Adversaries Act prohibits data brokers from selling sensitive consumer data — including financial records — to entities in China, Russia, Iran, North Korea, Cuba, and Venezuela. The FTC sent 13 warning letters in February 2026. Here's what counts as a data broker, what data is covered, and what your compliance program needs before enforcement begins.
Sep 5, 2026