Somewhere in Canberra, government lawyers are trying to work out exactly what a Toyota RAV4 knows about the person driving it, who else has seen that information, and whether anyone actually agreed to any of it. Strip away the regulatory language, and that is what a new investigation into Toyota and Hyundai actually amounts to. American readers should recognize the shape of this story immediately, because U.S. regulators already asked General Motors the same question. The answer was ugly enough to end in a five-year federal ban.
Australia’s Office of the Australian Information Commissioner has opened a formal investigation into how Toyota and Hyundai collect, use, and obtain consent for the personal data generated by their connected-car systems, according to Choice, the Australian consumer group that first reported it. Privacy Commissioner Carly Kind is leading the probe, after telling Parliament earlier this year that her office was reviewing two brands headquartered in Asia without naming them at the time. Toyota has been Australia’s best-selling brand for more than two decades. Hyundai, marking 40 years in the market this month, finished fifth in 2025. Neither is a boutique player, and that’s exactly why this case matters outside Australia. The connected-car platforms under review are largely the same ones sold in the United States, the United Kingdom, and everywhere else the two brands do business.
Three Questions, Eighteen Months
The investigation is expected to run as long as 18 months and will center on three specific questions: whether the automakers are collecting more personal information than their vehicles and connected services actually require, whether that data is being shared with third parties such as marketing partners without an owner’s consent, and whether either company is properly deleting or de-identifying data once it’s no longer needed. Toyota declined to comment directly on the investigation, instead pointing to its Connected Services Privacy Policy’s promises about transparency and responsible data governance. Hyundai’s statement was even shorter, saying only that the company takes privacy seriously. Read either statement twice. Neither one is a denial.
The Hardware Is Older Than the Law Policing It
Here’s the detail that should stop any car enthusiast mid-scroll: none of this technology is new. GM’s OnStar debuted in a Cadillac in 1996. Toyota didn’t bring a comparable system to Australia until the Yaris Cross arrived in 2020, and Hyundai’s Bluelink didn’t land there until 2022. The idea of a car that phones home has been around since the first Clinton administration. What changed isn’t the hardware sitting behind the dashboard. It’s that regulators are only now applying real scrutiny to it, using privacy law that in Australia’s case dates to 1988, years before the commercial internet existed, let alone a transmission control unit with a modem soldered into it. The Australian Electric Vehicle Association has already put a number on how quickly that gap is closing, warning that “consumer protection and national security risks will likely escalate without intervention” as internet-enabled vehicles approach total market saturation. The law is trying to catch up to a fleet that’s already three decades into the experiment.
Detroit Already Paid This Fine
The clearest preview of where this goes sits in an FTC case file, not an Australian one. For years, GM’s OnStar Smart Driver feature collected precise geolocation and driving-behavior data, in some cases every three seconds, and passed it to consumer reporting agencies that packaged it into reports insurers used to raise premiums or deny coverage, often without the driver ever knowingly agreeing to it. GM had already paid $12.75 million to settle a related California lawsuit over the same OnStar practices. Then came the FTC’s first-ever connected-vehicle privacy case, which banned GM and OnStar from disclosing that kind of data to consumer reporting agencies for five years and ordered the company to start collecting genuine, affirmative consent going forward.
That pattern, a feature marketed as a convenience quietly turning into a data product sold to somebody else, has already reshaped how ordinary drivers get priced for insurance. The Auto Wire covered exactly how that plays out for owners back when it was still a novelty. It isn’t a novelty anymore. It’s a business model, and Toyota and Hyundai are the latest brands being asked to explain theirs.
This Stopped Being Just a Marketing Story
Toyota and Hyundai’s Australian case is narrowly about commercial data handling. But the same underlying concern, a modem and a sensor suite quietly recording things nobody explicitly agreed to share, has already escalated into a national security question elsewhere. The U.S. barred Chinese connected-vehicle software and hardware under its Connected Vehicle Rule this year, a decision that forced Polestar to halt U.S. sales. Israel barred Chinese-made vehicles from its military bases in 2025 over concerns about onboard cameras and sensors, and Poland followed with a similar ban at its own military facilities in February 2026. Data privacy and national security are turning out to be the same conversation, just conducted at different volumes.
None of this means Toyota or Hyundai did anything uniquely reckless. That’s the uncomfortable part. They didn’t have to. Every connected car sold today, regardless of badge, runs on the same basic exchange: the owner gets live traffic, remote climate control, and a stolen-vehicle locator, and the manufacturer gets a rolling record of that owner’s behavior, a record that turns out to carry real cash value for somebody who isn’t the owner. GM found out what happens once a regulator finally asks where that value was flowing. Toyota and Hyundai are about to find out too, and they will not be the last familiar name to get the question.
If every statistic in this piece is forgotten by tomorrow, remember this instead: the cars didn’t get more dangerous. What the cars know about you did.

