Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes use and disclosure of de-identified data for purposes not described in the privacy statement, states that reasonable re-identification prevention measures are applied and required of third parties, but does not specify what technical standards constitute adequate de-identification.
This analysis describes what General Motors's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that de-identified data falls outside the policy's stated use and disclosure limitations, and may be shared with third parties for unstated purposes, subject to a reasonable safeguard standard whose specific technical parameters are not defined in the document.
Interpretive note: The specific technical standard applied to de-identification is not defined in the document, making it difficult to assess whether the stated 'reasonable steps' standard satisfies the specific requirements of CCPA, CPRA, or other applicable state frameworks.
The updated statement narrowed its definition of personal information from 'identifies, relates to, or could reasonably be linked to you' to 'describes, relates to, or could reasonably be linked to you.' This language change affects which information GM must treat as personal information under the policy. The revised de-identification section reorganizes prior language, now stating GM 'may use technical measures to remove information that could reasonably identify you or your vehicle' and requires 'the same safeguards from any third parties we share it with.' The policy clarifies that its protections apply to personal information dealers disclose to GM, but do not cover dealers' independent data practices. Cruise is no longer listed as a GM affiliate exempt from this privacy statement, though the scope of privacy protections for Cruise users depends on whether Cruise now operates under this statement or maintains separate privacy terms.
View change record →The agreement establishes that data from which identifying information has been removed using technical measures is classified as de-identified, is not subject to the policy's personal information use restrictions, and may be used and disclosed for purposes not described in the privacy statement, with a stated but unspecified reasonable re-identification prevention standard.
Cross-platform context
See how other platforms handle De-identified Data Use and Third-Party Sharing and similar clauses.
Compare across platforms →Monitoring
General Motors has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may use technical measures to remove information that could reasonably identify you or your vehicle. We take reasonable steps to prevent this de-identified data from being re associated with you and require the same safeguards from any third parties we share it with. De-identified data is not Personal Information and may be used and disclosed for purposes not described in this Privacy Statement.Excerpt from General Motors's GM Privacy Statement
(1) REGULATORY LANDSCAPE: The de-identification framework engages CCPA and CPRA, which establish specific technical and administrative standards for de-identification, including a requirement that the business implement processes to prevent re-identification and publicly commit to not re-identify the information. The FTC has issued guidance on de-identification standards in its privacy framework. The policy's 'reasonable steps' standard should be assessed against these specific regulatory benchmarks. (2) GOVERNANCE EXPOSURE: Medium. The authorization to use and disclose de-identified data for purposes not described in the privacy statement creates an operational flexibility that depends entirely on the robustness of the de-identification process. If re-identification is technically feasible from the de-identified data shared with third parties, the data may be reclassified as personal information under applicable law, potentially retroactively affecting the legality of third-party disclosures. (3) JURISDICTION FLAGS: California CPRA's de-identification standard requires businesses to implement technical safeguards and publicly commit to not attempt re-identification. The adequacy of GM's stated 'reasonable steps' standard against this specific requirement should be assessed. Illinois BIPA and Washington My Health MY Data Act may impose additional standards if de-identified data is derived from biometric or health-adjacent information. (4) CONTRACT AND VENDOR IMPLICATIONS: Third-party recipients of de-identified data are required by the policy to maintain the same re-identification safeguards, which should be confirmed in contractual data sharing terms. The scope of permitted use by third parties of de-identified data is stated to be unconstrained by the privacy statement, which means third-party data agreements should define permitted purposes to prevent unintended use. (5) COMPLIANCE CONSIDERATIONS: Legal teams should assess whether GM's de-identification technical standard meets the specific requirements of CCPA, CPRA, and other applicable state frameworks. Internal de-identification processes should be documented and auditable. Third-party data sharing agreements for de-identified data should specify the re-identification prohibition commitment and the technical safeguards required.
This provision establishes that de-identified data falls outside the policy's stated use and disclosure limitations, and may be shared with third parties for unstated purposes, subject to a reasonable safeguard standard whose specific technical parameters are not defined in the document.
The agreement establishes that data from which identifying information has been removed using technical measures is classified as de-identified, is not subject to the policy's personal information use restrictions, and may be used and disclosed for purposes not described in the privacy statement, with a stated but unspecified reasonable re-identification prevention standard.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by General Motors.