Criterica Intelligence — production models trained on real court records, not synthetic data
Data Breach — MDL No. 3115

Consumer Vehicle Driving Data Tracking

U.S. District Court for the Northern District of Georgia

The Consumer Vehicle Driving Data Tracking litigation was centralized before Judge Thomas W. Thrash, Jr. in the Northern District of Georgia in June 2024, consolidating claims that automakers and connected-vehicle technology providers collected detailed driving-behavior data — including speed, braking patterns, and location — from consumer vehicles and shared that data with third parties, including insurance-scoring companies and data brokers, without adequate disclosure or consumer consent. With 21 pending actions, this is a smaller, still-developing docket relative to the largest data-breach MDLs, but it represents a distinct and growing category of automotive data-privacy litigation.

Unlike a traditional data-breach MDL centered on unauthorized third-party intrusion, this docket's core liability theory concerns lawful-seeming but allegedly inadequately disclosed data-collection and data-sharing practices built into normal vehicle operation and connected-services programs. That distinction shapes duration and resolution risk differently: rather than establishing that a security failure occurred, plaintiffs must establish what disclosures were provided, whether those disclosures satisfied applicable consumer-protection and privacy-statute standards, and whether consumers had meaningful ability to opt out of the data collection.

As connected-vehicle technology becomes standard across the automotive industry, litigation addressing driving-behavior data collection and third-party sharing is likely to remain an active and growing category, with resolution outcomes shaped heavily by jurisdiction-specific privacy statutes and each manufacturer's specific disclosure practices. Criterica Intelligence's platform tracks this emerging automotive-data-privacy category separately from traditional breach litigation, since the underlying liability theory, evidence, and typical resolution path differ meaningfully between the two. A companion capital brief on this docket is available through Criterica Capital.

Frequently Asked Questions
What conduct is alleged in this MDL?

That automakers and connected-vehicle technology providers collected detailed driving-behavior data from consumer vehicles and shared it with third parties, including insurance-scoring companies and data brokers, without adequate disclosure or consent.

Why is this not framed as a traditional data breach?

Because the data collection was an ongoing, built-in business practice rather than the result of unauthorized third-party intrusion, so the claims center on disclosure and consent rather than a security failure.

What will drive resolution risk in this docket?

Whether each manufacturer's disclosures — in purchase agreements, mobile apps, or connected-services terms — satisfied applicable state consumer-protection and privacy-statute standards, and whether consumers had a meaningful ability to opt out.

Is this a growing litigation category?

Likely, as connected-vehicle technology becomes standard across the industry — Criterica Intelligence tracks this automotive-data-privacy category separately from traditional breach litigation given its distinct liability theory and evidence.

Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.

← All Pending MDLsFunding brief on Criterica Capital →