Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that personal information stored in a vehicle, including contacts, address searches, and preferences, may remain accessible to future vehicle users if not deleted prior to sale or transfer, and encourages but does not require the owner to delete this data before transfer.
This analysis describes what General Motors's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that data deletion before vehicle sale or transfer is the responsibility of the current owner rather than a system-enforced process, and that failure to delete may result in personal information being accessible to subsequent vehicle users.
The updated statement narrowed its definition of personal information from 'identifies, relates to, or could reasonably be linked to you' to 'describes, relates to, or could reasonably be linked to you.' This language change affects which information GM must treat as personal information under the policy. The revised de-identification section reorganizes prior language, now stating GM 'may use technical measures to remove information that could reasonably identify you or your vehicle' and requires 'the same safeguards from any third parties we share it with.' The policy clarifies that its protections apply to personal information dealers disclose to GM, but do not cover dealers' independent data practices. Cruise is no longer listed as a GM affiliate exempt from this privacy statement, though the scope of privacy protections for Cruise users depends on whether Cruise now operates under this statement or maintains separate privacy terms.
View change record →The agreement discloses that personal information stored in the vehicle may remain accessible to future users after sale or transfer if the current owner does not delete it; the policy encourages deletion and account transfer or cancellation but does not describe an automated deletion mechanism.
Cross-platform context
See how other platforms handle Vehicle Sale and Transfer Data Persistence and similar clauses.
Compare across platforms →Monitoring
General Motors has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If you sell or otherwise transfer your vehicle, we strongly encourage you to delete all Personal Information (such as contacts, address searches, saved map addresses, or preferences) from the vehicle and contact us to transfer or cancel your account. If you do not delete this Personal Information, it may remain in the vehicle and may be accessible to future users of the vehicle.Excerpt from General Motors's GM Privacy Statement
(1) REGULATORY LANDSCAPE: The absence of an automated data deletion process upon vehicle transfer may engage state privacy law requirements regarding data security and consumer notification. The FTC Act applies to unfair or deceptive practices where consumer data is left accessible without adequate warning or protective mechanisms. California CPRA's data security obligations may apply to the accessibility of personal information on transferred vehicles. (2) GOVERNANCE EXPOSURE: Medium. The policy's reliance on consumer-initiated deletion rather than system-enforced processes creates a documented gap in data lifecycle management that may expose prior owners' personal information to unauthorized access by subsequent vehicle users. The policy's disclosure of this risk may satisfy transparency obligations but does not eliminate the underlying data security consideration. (3) JURISDICTION FLAGS: California's CPRA requires reasonable security measures for personal information, which may include consideration of data accessibility on resold or transferred devices. Other states with general data security statutes may impose similar obligations. The practical risk of personal information exposure varies by vehicle model and the technical ease of accessing stored data. (4) CONTRACT AND VENDOR IMPLICATIONS: GM dealers facilitating vehicle resale should be assessed to determine whether they provide guidance to consumers on data deletion prior to trade-in, and whether dealer agreements address liability for personal information accessible on traded-in vehicles. (5) COMPLIANCE CONSIDERATIONS: Legal teams should assess whether the policy's reliance on consumer-initiated deletion is an adequate data security practice under applicable state laws, or whether additional technical controls (such as factory reset prompts or remote data wipe capabilities) are warranted. The instructions for deleting personal information from the vehicle, referenced as available in the owner's manual, should be reviewed for accessibility and clarity.
This provision establishes that data deletion before vehicle sale or transfer is the responsibility of the current owner rather than a system-enforced process, and that failure to delete may result in personal information being accessible to subsequent vehicle users.
The agreement discloses that personal information stored in the vehicle may remain accessible to future users after sale or transfer if the current owner does not delete it; the policy encourages deletion and account transfer or cancellation but does not describe an automated deletion mechanism.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by General Motors.