A government ethics panel in Quebec just spent the better part of a year producing a 64-page indictment of your dashboard, and the case it built about consent, insurance, and cloud storage reads almost like a legal brief the FTC already filed against General Motors. Only this time, the target isn’t one automaker’s fine print. It’s the entire idea that “I agree” still means anything once you’re driving a computer with seats.
The report comes from Quebec’s Commission de l’ethique en science et en technologie, a provincial body that usually spends its time on subjects like artificial intelligence and biotechnology, not bumper-to-bumper traffic. Its president, Luc Begin, working with a committee of outside experts, spent months mapping what happens to the data a modern car generates every time it moves. They identified twelve distinct problems, and none of them are hypothetical.
The Consent Model Was Built for Websites, Not 4,000-Pound Objects
Start with the finding that should worry car enthusiasts more than the others: the report concludes that the classic model of individual consent is fundamentally broken for connected vehicles. That isn’t a vague complaint about long terms and conditions, though the commission notes that only about seven percent of people ever read them. It’s a structural problem. A privacy policy assumes the person who clicked accept is the same person using the product for its entire life. Phones mostly work that way. Cars don’t.
A car gets driven by a spouse who never opened the app, a teenager who borrowed the keys, a valet, a rental customer, and eventually a used-car buyer who has no idea what account is still synced to the infotainment system. Nobody re-consents at any of those handoffs. The data keeps flowing regardless of who’s actually behind the wheel, which means the person described in the terms and conditions and the person actually being tracked are frequently not the same human being.
Detroit Already Ran This Exact Experiment
Quebec’s insurance findings will sound familiar to anyone who followed Toyota and Hyundai’s Australian privacy investigation this year, because the United States already litigated almost this exact scenario. The Federal Trade Commission’s first connected-vehicle privacy case found that GM’s OnStar Smart Driver feature collected precise location and driving-behavior data, in some cases every few seconds, and fed it to consumer reporting agencies that packaged it into scores insurers used to raise premiums, often without drivers knowingly agreeing to any of it. The result was a five-year ban on GM sharing that kind of data and an order to start collecting real consent going forward, on top of a separate $12.75 million settlement in California.
The CEST report describes the mechanics of that same business model in more clinical terms: algorithms score drivers without disclosing how, which means there’s no way to dispute a bad score, and the variables those algorithms weigh, like driving at night or through certain neighborhoods, quietly penalize shift workers and lower-income drivers who have the least flexibility to change their routes or hours. It isn’t scoring bad driving. It’s scoring a work schedule.

The Cybersecurity Problem the Industry Hasn’t Solved
All of that driving data has to live somewhere, usually a third-party cloud server the driver never sees, and the commission points to a real-world failure as proof of how thin that protection can be. In December 2024, an unsecured Amazon Web Services database run by Volkswagen’s software unit, Cariad, left the precise GPS location history of roughly 800,000 Volkswagen Group electric vehicles exposed to anyone who found it, for months, before it was locked down. Begin’s committee frames that kind of exposure as more than a customer-service headache. Treat enough vehicles as a single data set, and a breach becomes a question of digital sovereignty and national security.

A Feature That Doesn’t Know a Relationship Ended
The report’s most uncomfortable finding has nothing to do with hackers or insurers. Location-sharing features built for convenience, the kind that let a family see where everyone’s car is, don’t know when a marriage ends or a restraining order gets filed. The commission specifically flags coercive control and domestic violence, noting that an abuser with access to the right app can track a partner’s car continuously without them ever knowing. The Auto Wire has already covered how easily that kind of location tracking gets misused, and the CEST report treats it as a design flaw baked into the product, not a rare edge case. Nobody built a way to revoke that access the moment a relationship turns dangerous, and that gap doesn’t show up on a spec sheet.
What This Means the Next Time You Buy or Sell a Car
There’s a practical lesson buried in all twelve findings that most owners never think about until it’s too late: the data relationship a car creates rarely gets cleanly severed at the point of sale. Unless someone specifically walks through the automaker’s account-transfer or factory-reset process, a previous owner’s phone can, in some systems, retain remote-start access, location history, or paired contacts long after the title changes hands. Before selling a connected car, or buying one used, check the automaker’s app for a remove-previous-owner or erase-personal-data option, and don’t assume the dealer already did it.
The Rulebook Is Already Being Written, Just Not in Quebec
None of this stays a Canadian policy story for long. U.S. Senators Ron Wyden and Ed Markey pushed the FTC in 2024 to investigate automakers selling driving data to brokers, Australia’s privacy regulator opened its own formal investigation into Toyota and Hyundai this year, and Congress has debated treating vehicle data as a national-security question, not just a consumer one. Quebec’s commission is recommending more government oversight and better data-handling standards. That recommendation lands in a policy environment where regulators on three continents have already reached similar conclusions, independently of each other.
The real story here was never that a government commission thinks cars have gotten too smart. It’s that the industry built its entire data pipeline around a legal fiction: the idea that one signature can speak for everyone who will ever sit in that car, for as long as it runs. A phone’s privacy policy governs one person for a couple of years. A car’s privacy policy is supposed to govern a spouse, a teenager, a valet, a stranger’s rideshare passenger, and whoever buys it six years from now, all under a consent nobody but the original owner ever gave. That isn’t a loophole. That’s the whole design, and Quebec just put a number on how badly it’s failing: twelve ways, and counting.

