General Motors · GM Privacy Statement · View original document ↗

De-identified Data Use and Third-Party Sharing

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time General Motors changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for General Motors Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy authorizes use and disclosure of de-identified data for purposes not described in the privacy statement, states that reasonable re-identification prevention measures are applied and required of third parties, but does not specify what technical standards constitute adequate de-identification.

This analysis describes what General Motors's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that de-identified data falls outside the policy's stated use and disclosure limitations, and may be shared with third parties for unstated purposes, subject to a reasonable safeguard standard whose specific technical parameters are not defined in the document.

Interpretive note: The specific technical standard applied to de-identification is not defined in the document, making it difficult to assess whether the stated 'reasonable steps' standard satisfies the specific requirements of CCPA, CPRA, or other applicable state frameworks.

Recent Activity

This document changed recently

Medium Jun 18, 2026

The updated statement narrowed its definition of personal information from 'identifies, relates to, or could reasonably be linked to you' to 'describes, relates to, or could reasonably be linked to you.' This language change affects which information GM must treat as personal information under the policy. The revised de-identification section reorganizes prior language, now stating GM 'may use technical measures to remove information that could reasonably identify you or your vehicle' and requires 'the same safeguards from any third parties we share it with.' The policy clarifies that its protections apply to personal information dealers disclose to GM, but do not cover dealers' independent data practices. Cruise is no longer listed as a GM affiliate exempt from this privacy statement, though the scope of privacy protections for Cruise users depends on whether Cruise now operates under this statement or maintains separate privacy terms.

View change record →

Consumer impact (what this means for users)

The agreement establishes that data from which identifying information has been removed using technical measures is classified as de-identified, is not subject to the policy's personal information use restrictions, and may be used and disclosed for purposes not described in the privacy statement, with a stated but unspecified reasonable re-identification prevention standard.

Cross-platform context

See how other platforms handle De-identified Data Use and Third-Party Sharing and similar clauses.

Compare across platforms →

Monitoring

General Motors has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We may use technical measures to remove information that could reasonably identify you or your vehicle. We take reasonable steps to prevent this de-identified data from being re associated with you and require the same safeguards from any third parties we share it with. De-identified data is not Personal Information and may be used and disclosed for purposes not described in this Privacy Statement.

Excerpt from General Motors's GM Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The de-identification framework engages CCPA and CPRA, which establish specific technical and administrative standards for de-identification, including a requirement that the business implement processes to prevent re-identification and publicly commit to not re-identify the information. The FTC has issued guidance on de-identification standards in its privacy framework. The policy's 'reasonable steps' standard should be assessed against these specific regulatory benchmarks. (2) GOVERNANCE EXPOSURE: Medium. The authorization to use and disclose de-identified data for purposes not described in the privacy statement creates an operational flexibility that depends entirely on the robustness of the de-identification process. If re-identification is technically feasible from the de-identified data shared with third parties, the data may be reclassified as personal information under applicable law, potentially retroactively affecting the legality of third-party disclosures. (3) JURISDICTION FLAGS: California CPRA's de-identification standard requires businesses to implement technical safeguards and publicly commit to not attempt re-identification. The adequacy of GM's stated 'reasonable steps' standard against this specific requirement should be assessed. Illinois BIPA and Washington My Health MY Data Act may impose additional standards if de-identified data is derived from biometric or health-adjacent information. (4) CONTRACT AND VENDOR IMPLICATIONS: Third-party recipients of de-identified data are required by the policy to maintain the same re-identification safeguards, which should be confirmed in contractual data sharing terms. The scope of permitted use by third parties of de-identified data is stated to be unconstrained by the privacy statement, which means third-party data agreements should define permitted purposes to prevent unintended use. (5) COMPLIANCE CONSIDERATIONS: Legal teams should assess whether GM's de-identification technical standard meets the specific requirements of CCPA, CPRA, and other applicable state frameworks. Internal de-identification processes should be documented and auditable. Third-party data sharing agreements for de-identified data should specify the re-identification prohibition commitment and the technical safeguards required.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has issued guidance on de-identification standards and has authority over unfair or deceptive practices where de-identification claims do not meet applicable technical standards.
    File a complaint →
  • State AG
    State attorneys general in California and other states with specific de-identification standards under comprehensive privacy laws have enforcement authority over de-identification practices.
    File a complaint →

Provision details

Document information
Document
GM Privacy Statement
Entity
General Motors
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016056
Document ID
CA-D-00615
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
1aadaf983854ba12c04ee6971f292dd73de91df0db3ac8d30fd0ad5fcc9309da
Analysis generated
July 9, 2026 09:29 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: General Motors
Document: GM Privacy Statement
Record ID: CA-P-016056
Captured: 2026-07-09 09:29:04 UTC
SHA-256: 1aadaf983854ba12…
URL: https://conductatlas.com/platform/general-motors/gm-privacy-statement/provision/CA-P-016056/de-identified-data-use-and-third-party-sharing/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does General Motors's De-identified Data Use and Third-Party Sharing clause do?

This provision establishes that de-identified data falls outside the policy's stated use and disclosure limitations, and may be shared with third parties for unstated purposes, subject to a reasonable safeguard standard whose specific technical parameters are not defined in the document.

How does this clause affect you?

The agreement establishes that data from which identifying information has been removed using technical measures is classified as de-identified, is not subject to the policy's personal information use restrictions, and may be used and disclosed for purposes not described in the privacy statement, with a stated but unspecified reasonable re-identification prevention standard.

Is ConductAtlas affiliated with General Motors?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by General Motors.