FTC’s Actions Against Automakers: A Necessary Step for Consumer Data Privacy

The Federal Trade Commission’s stance this month against the automobile industry’s data collection practices aligns with established legal precedent and addresses crucial consumer protection concerns.

Analysts predict that, by 2025, over 400 million cars will become connected through infotainment platforms—a significant jump from 2021’s 237 million. This figure is projected to surge to 95% of passenger cars being internet-enabled by 2030. However, as vehicles increasingly integrate digital technology, concerns over data privacy are intensifying.

In 2022, the Mozilla Foundation examined the data practices of 25 leading car manufacturers and found that all of them collect more personal data than is necessary and use it for reasons beyond operating the vehicle. The FTC has been aware of such issues for years, first highlighting them in a 2013 workshop and releasing a related report two years later. A subsequent 2017 workshop addressed the types of data automakers collect, as well as their privacy and security practices.

Recent developments have brought the issue to the forefront. For instance, automakers started removing AM radio from cars, a move seen as an effort to “digitize” dashboards and subsequently collect more consumer data. This led to the introduction of the AM Radio for Every Vehicle Act in Congress. Additionally, a New York Times report revealed that some automakers share driving behavior data with the insurance industry without drivers’ consent, and a coalition of lawmakers discovered this data is sometimes handed over to law enforcement without a warrant.

On May 14, the FTC announced it would take action to protect consumers from the illegal collection, use, and disclosure of their personal data. Critics argue that no legal issue is at play here, but the commission has a clear mandate to curb such data collection practices.

The FTC’s regulatory authority is well-established. Under Section 5 of the Federal Trade Commission Act, it can regulate unfair practices, defined as those likely causing substantial consumer injury that consumers cannot avoid themselves. It also covers deceptive acts likely to mislead reasonable consumers. As shown in the recent revelations about General Motors, if a company falsely claims not to share data with third parties, this could be seen as a deceptive practice under Section 5.

The courts have consistently upheld the FTC’s authority. In FTC v. Wyndham Worldwide Corp., the Third Circuit affirmed that the FTC could regulate cybersecurity practices under the unfairness prong of Section 5. This case involved Wyndham’s failure to protect consumer data from hackers, resulting in significant consumer harm and fraudulent charges.

The court’s decision in Wyndham underscores the FTC’s mandate to enforce data security and privacy standards across industries, including automotive, ensuring consumers have control over their personal information. With decades of legal precedents backing its authority, the FTC’s actions to curb illegal data collection align with its statutory responsibilities and long-standing consumer protection principles.

Protecting drivers’ data remains essential, and the FTC should continue its efforts despite opposition, leveraging its legal authority and historical precedents to ensure consumer privacy remains safeguarded.

This article does not necessarily reflect the opinion of Bloomberg Industry Group, Inc., the publisher of Bloomberg Law and Bloomberg Tax, or its owners.

David Balto is a former policy director of the FTC and has practiced antitrust law for over 30 years.