CIC panels discuss personal data found on vehicles

Published on August 13, 2026

Ninety percent of vehicles that go to a salvage auction still have private personal information (PPI) accessible, said Andrea Amico, Privacy4Cars founder and CEO, during a Collision Industry Conference (CIC) meeting in Chicago held late last month. 

The average cell phone has about 40 sensors, Amico said. Yet, the average car in the past 10 years has about 250 sensors. 

“Cars have become the third personal computing device that consumers use every day,” he added. 

However, vehicles typically lack encryption or hidden controls compared to phones or computers, he said. 

Vehicles can collect personal data through cameras, microphones, GPS, and synced phones, he said. Data collected by vehicles includes call logs, garage codes, biometrics, contacts, and passwords. 

Amico pointed to multiple court cases in recent years involving automakers and insurers. Most recently, California reached a settlement agreement with General Motors regarding the sale of residents’ vehicle data. 

In January, the Federal Trade Commission (FTC) finalized a 20-year order with GM and OnStar to settle allegations that they collected, used, and sold geolocation and driving behavior data from millions of vehicles without notifying consumers or obtaining consent. 

The collision industry has been pondering who should be responsible for removing data from vehicles, Amico said. 

Amico says that repair shops would be liable if they offer removing data as a service.

“Once you do that [offer a service], there are things you want to think about very hard,” Amico said. 

He added that if you promise to do something for a customer but you don’t do it correctly, that’s when customers can sue. 

Amico said shops could offer data removal as a courtesy rather than a service. 

During a separate CIC presentation, Tracy Dombrowski of Collision Advice provided an example of a woman who sold her vehicle to a dealer without disconnecting it from her app. 

“She was able to follow that vehicle from the sale of the vehicle to Florida to Texas,” Dombrowski said. “She is still able to remote start that vehicle; she is still able to access that vehicle at any given time.” 

The job of removal of data typically falls on the consumer, she said. But shops can help consumers as a courtesy. 

There are four steps to removal of PPI from vehicles, she said. 

“Those steps really vary on the make, model, and year of vehicle,” Dombrowski said. “The OEs have been very good at providing that information in your owner’s manual and support material.” 

Dombrowski said the key is for the shop not to take on data removal liability. She said to make sure the customer authorizes the removal of the data before taking any action. 

Best practice is to provide customers the information they need to clear the data on their own. 

There are three different scenarios a vehicle could be in when it comes time to remove data, she said. The vehicle could be powered on, powered off, or towed off-site and not accessible by the owner. 

She offered steps for each scenario. 

“The order of operations in this becomes very critical,” Dombrowski said. “A lot of those [steps] can only be done when they are still paired to the app.” 

Dombrowski provided OEM webpages that offer resources for removing PPI. 

She also provided key terms for searching for information. These included factory reset, master reset, delete profile, remove vehicle, and ownership transfer.

Amico noted during his presentation that PPI could be found on vehicles you might not suspect. 

Any vehicle with bluetooth has the ability to “spy” Amico said.

For example, a 2025 Dodge Ram 2500 Truck SLT doesn’t have self-driving, telematics, carplay or navigation but it does have a bluetooth, enabling its ability to “spy.”

Images

Andrea Amico, Privacy4Cars founder and CEO, speaks during a Collision Industry Conference (CIC) meeting in Chicago on July 22, 2026/Teresa Moss