“The worst offender was Nissan, Mozilla said. The carmaker’s privacy policy suggests the manufacturer collects information including sexual activity, health diagnosis data, and genetic data, though there’s no details about how exactly that data is gathered. Nissan reserves the right to share and sell “preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes” to data brokers, law enforcement, and other third parties.”

https://gizmodo.com/mozilla-new-cars-data-privacy-report-1850805416

If You’ve Got a New Car, It’s a Data Privacy Nightmare

Bad news: your car is a spy. Every major car brand's new internet-connected models flunked privacy and security tests conducted by Mozilla.

Gizmodo
@nazgul surely, legally, most, if not all, of that needs consent. So how the hell does that work for passengers, or other people driving than the owner (who may have agreed)?
@revk @nazgul This is mentioned in one of the articles. Nissan puts the task of informing passengers and borrowers about privacy issues on the owner, making them complicit in their abuses.
@reinderdijkhuis @nazgul But if the owner does not, then Nissan would be in breach of GDPR. What do they do - sue the owner for breach of contract when they get charged/fined? Is it a reasonable consumer contract term? And if the owner sells the car, how does the new owner come in to such a deal?

@revk @reinderdijkhuis @nazgul Given that the car has probably already been purchased by the time the owner is asked to accept the privacy policy (and no doubt they reserve the right to revise the privacy policy at any point in the future), I'd venture that it isn't a valid contract since it was never "freely entered into". That's assuming you can even prove the owner was the one to agree.

But then, these are the same problems as smart TVs, smart speakers, etc.