You lock your car when you leave it.
You probably do not leave your phone sitting on the dashboard. You may be careful about who knows where you live, where your children go to school, where you worship or which doctor you visit.
Yet the car itself may know all of those things.
Modern vehicles are increasingly filled with cameras, microphones, GPS systems, mobile applications, driver-assistance technology, biometric features and internet-connected services. They can know where we go, when we go there, how quickly we drive, how hard we brake, what we listen to and, depending on the vehicle and services being used, potentially what we say.
The car has changed.
But our understanding of what we are buying has not.
In September 2023, researchers at the Mozilla Foundation examined the privacy practices of 25 major automobile brands. Every one received Mozilla’s Privacy Not Included warning label.
Mozilla called cars the worst product category it had ever reviewed for privacy. Researchers spent more than 600 hours studying vehicle privacy policies, apps and connected services and concluded that cars presented extraordinarily broad opportunities to collect information — in Mozilla’s assessment, even more than smart-home devices or the mobile phones we carry everywhere.
For a Caribbean region rapidly embracing newer, smarter and increasingly connected vehicles, there is a question we have barely begun asking:
When exactly did buying a car become an agreement to be monitored?
Your vehicle knows more than you think
Some collection is entirely understandable.
A modern vehicle needs information to operate safety systems, diagnose faults, navigate, provide roadside assistance and increasingly deliver software updates. Connected technology can make vehicles safer, easier to maintain and far more convenient.
The problem begins when data collection extends beyond what the average driver would reasonably expect.
Mozilla found privacy policies allowing manufacturers to collect information ranging from precise location and driving behaviour to demographic and health-related information. Six manufacturers’ policies referred to genetic information or genetic characteristics. Nissan’s policy reviewed at the time included categories such as sexual activity and genetic information, while Kia’s referred to information about a person’s sex life.
That requires an important qualification. It does not mean a Nissan parked in Half-Way Tree is secretly sequencing its driver’s DNA.
Privacy policies often describe information that a company may obtain from several sources — the vehicle, an associated app, a dealership interaction, connected services or third parties. Indeed, Mozilla itself questioned exactly how some of the more extraordinary categories would be collected.
But that does not make the issue unimportant.
It may make it more troubling.
A vehicle is no longer one product. It can be part of an ecosystem linking the manufacturer, dealership, mobile application, navigation provider, entertainment services, telecommunications networks, insurers, roadside-assistance providers and other third parties.
Consider Kia’s current connected-services privacy notice. It describes processing GPS location, trips, maximum and average speed, acceleration and deceleration, driving patterns, points of interest, multimedia usage, vehicle-status information and voice data from online voice recognition, among numerous other categories.
That is an extraordinary portrait of a person’s life to emerge from something most of us still think of primarily as transportation.
Location is not just a dot on a map
There is a tendency to dismiss location data because many of us already share it with our phones.
But a history of where someone travels is capable of revealing far more than coordinates.
Repeated journeys can suggest where someone lives and works. They may reveal a child’s school, a partner’s home, a church, mosque or temple, a medical clinic, political meeting, nightclub, rehabilitation facility or another location from which sensitive conclusions can be drawn.
The European Data Protection Board warned this year that connected-vehicle location information can expose drivers’ life habits and potentially reveal characteristics such as religion, sexual orientation and lifestyle. Its guidance says continuous location collection should not simply be enabled by default and users should be able to deactivate tracking.
This is the distinction privacy discussions sometimes miss.
A company does not necessarily need to ask your religion to learn something about your religion.
Data can speak through patterns.
This is no longer a theoretical concern
In January 2026, the United States Federal Trade Commission finalised an order against General Motors and OnStar after alleging that they collected and sold precise geolocation and driving-behaviour information from millions of vehicles without adequately informing consumers or obtaining affirmative consent.
According to the FTC’s complaint, location information from some vehicles was collected as frequently as every three seconds. Driving information, including hard braking, speeding and late-night driving, was shared with consumer-reporting agencies and could ultimately affect insurance decisions and premiums.
Think about that for a moment.
A technology presented to a customer as a useful connected-car service could help create a behavioural record capable of influencing what that customer pays for another service altogether.
The problem is therefore not merely that data exists.
It is function creep — information collected in one context gradually acquiring another purpose.
Convenience becomes monitoring.
Monitoring becomes profiling.
Profiling becomes a commercial decision about you.
And somewhere between those stages, the consumer may have stopped paying attention.
So when did you consent?
This may be the most important question of all.
Imagine buying a new car in Jamaica.
You visit the showroom. You negotiate the price. Financing is discussed. Insurance is arranged. Forms are signed. Perhaps someone helps pair your phone, download the manufacturer’s app and activate the vehicle’s connected services.
At what point does somebody sit across the desk and say:
“Before you drive away, let us explain what information this vehicle may collect about you, where that information may be sent, who may receive it and which parts you can decline?”
For most purchasers, privacy is unlikely to feature alongside horsepower, warranty coverage and monthly payments.
Instead, important choices may appear during account registration, app installation, infotainment setup or activation of connected services. They may exist inside privacy notices containing thousands of words.
Legally, an opportunity to click “accept” may sometimes constitute part of a consent process.
Practically, we should ask whether that is how meaningful human choice works.
This is exactly how privacy drifts.
Rarely does someone knock on our door and announce that a right is being removed. More often, another feature arrives, another permission is requested, another policy changes and another button is pressed.
We explored this problem previously in The Privacy Drift: the uncomfortable reality that privacy is frequently not stolen from us at all. It disappears gradually through complexity, convenience and agreements few people realistically interrogate.
Connected cars may be one of the clearest examples yet.
And now the Caribbean automobile market is changing rapidly
This question matters particularly now.
Jamaican consumers have substantially more vehicle choice than they did only a few years ago, including a growing number of technologically sophisticated Chinese brands.
ATL Automotive has added brands including BYD, Omoda and Jaecoo to a portfolio that already includes several connected-car manufacturers. GAC entered Jamaica in late 2025 as part of a Caribbean expansion that also includes Barbados, St Lucia, Grenada and St Vincent and the Grenadines. In May 2026, Jetour Jamaica officially launched with six models.
This is not an argument against Chinese vehicles.
Nor is the privacy problem uniquely Chinese. Mozilla’s 2023 findings covered major American, European, Japanese and Korean manufacturers and concluded that problems were industry-wide.
That is precisely the point.
As competition gives Caribbean consumers better technology, more features and potentially better value, privacy needs to become part of what we mean by vehicle quality.
We examine crash-test ratings.
We compare warranties.
We ask about parts.
We check fuel economy and battery range.
Perhaps it is time we also ask what happens to the data.
Does Jamaica’s Data Protection Act protect us?
Potentially, yes — and more significantly than many consumers or manufacturers may realise.
Jamaica’s Data Protection Act does not apply only to companies headquartered here. Section 3 extends its application in certain circumstances to organisations outside Jamaica where they process the personal data of someone in Jamaica in connection with offering products or services here or monitoring behaviour taking place here. Such controllers are also required to appoint a representative established in Jamaica.
That provision becomes particularly interesting when the product doing the monitoring has four wheels and sits in a Kingston driveway.
The Act’s core principles are also highly relevant.
The Office of the Information Commissioner states that personal data must be processed fairly and lawfully; people must receive sufficient information to make informed decisions; collection should be limited to what is reasonably required; data should be used for specified purposes; and transfers outside Jamaica are subject to protection requirements.
Most importantly for the issue of consent, the OIC explains that consent must be informed, freely given, specific and unequivocal. It also notes that consent is not considered freely given where access to goods or services is conditional upon agreeing to data collection or use beyond what is reasonably necessary to provide them.
That principle creates a fascinating question for connected cars.
If I spend millions of dollars purchasing a vehicle, should I have to accept unnecessary behavioural surveillance in order to use functionality built into the product?
And if refusing data collection materially diminishes the vehicle I have already purchased, how meaningful was my choice?
Those questions deserve closer attention from manufacturers, distributors, dealers, consumers and regulators.
The dealership may be the missing link
There is another party in this ecosystem that receives relatively little attention: the local dealer.
Manufacturers write the software and privacy policies. But the dealership frequently controls the consumer’s first meaningful interaction with the connected vehicle.
That creates an opportunity.
A responsible dealership should be able to tell a purchaser, in plain English:
what connected services are active;
what categories of personal information they collect;
whether location or voice information leaves the vehicle;
which company controls that information;
where it is processed;
whether it is shared with third parties;
which features are optional; and
how the owner can later withdraw consent or disable unnecessary collection.
This should not require turning a salesperson into a data-protection lawyer.
It requires transparency.
We already expect a salesperson to explain a warranty. Privacy should eventually become just as ordinary a part of the handover.
Passengers present an even stranger problem
Then there is everybody who did not buy the car.
Your spouse.
Your children.
A colleague.
A client.
The friend sitting beside you discussing something deeply personal.
A passenger may enter a connected vehicle without ever seeing the manufacturer’s privacy notice, downloading its app or knowing that microphones, cameras or other sensors are present.
Mozilla highlighted precisely this issue in its research: the privacy implications of modern cars extend beyond the registered owner to passengers and potentially others around the vehicle.
It raises an uncomfortable question.
Can the driver meaningfully consent on behalf of everyone who gets into the car?
Technology has moved faster than our social understanding of the space.
For generations, the interior of a car has felt private. It is where families argue, executives take calls, teenagers confide in friends and people speak freely precisely because they believe the doors are closed.
The connected vehicle challenges that assumption.
We do not need less technology. We need better governance.
None of this is an argument for returning to cars without GPS, emergency assistance or modern safety technology.
Connected vehicles can make driving safer. Predictive maintenance can prevent breakdowns. Crash detection can save lives. Navigation reduces wasted time. Remote diagnostics can improve servicing. Vehicle data may help manage fleets, improve roads and support new mobility services.
The appropriate response is not technological fear.
It is privacy by design.
Manufacturers should collect what they genuinely need rather than everything technology makes possible. Optional processing should genuinely be optional. High-risk data should have stronger safeguards. Consumers should be able to understand their choices without reading a small library of legal documents.
Dealerships and distributors should understand the privacy architecture of the products they sell.
Regulators should recognise connected vehicles as part of the modern data ecosystem.
Businesses purchasing fleets should assess vehicle-data practices just as they would assess another technology vendor.
And consumers should start asking a new question before accepting the keys:
What does this car know about me?
The next privacy frontier may already be parked outside
The transformation of the automobile is remarkable.
We wanted vehicles that could navigate for us, recognise our voices, remember our preferences, anticipate hazards, call for help after an accident and increasingly drive themselves.
To do many of those things, cars need data.
But somewhere along the road from mechanical machine to intelligent platform, an important conversation was skipped.
We discussed what these vehicles could do.
We did not discuss nearly enough about what they could know.
That conversation now matters for Jamaica and the Caribbean, particularly as a new generation of highly connected vehicles enters our markets.
Privacy rarely disappears in one dramatic moment.
It leaves centimetre by centimetre: through the app we activate, the setting we never change, the policy we never read and the feature we are told is simply part of owning the product.
We may discover that one of the most sophisticated surveillance devices in our lives was never hidden from us at all.
We bought it, insured it, parked it outside our homes — and never thought to ask what it was watching.

