As autonomous and connected vehicle technologies move from pilot programs toward broader commercial deployment, more companies throughout the automotive ecosystem are leveraging location information of vehicles.
A recent Supreme Court decision addressing geofence warrants and cell phone location history highlights the growing legal significance of precise location data and offers an early indication of how courts may approach the implication of holding similar information, as generated by connected and autonomous vehicles, and whether law enforcement may access it.
Although the decision arose outside the automotive context, its reasoning has implications for manufacturers, suppliers, fleet operators, and technology providers that develop or rely on location-enabled services.
Potential New Route for Autonomous and Connected Vehicle Location Data
On June 29, the Supreme Court held in Chatrie v. United States that law enforcement's acquisition of Google "Location History" through a geofence warrant constitutes a Fourth Amendment search. Location History is a service provided by Google that regularly collects data over time about a cell phone's location. Relying on Carpenter v. United States, the Court concluded that Google's Location History is subject to constitutional privacy protections, rejecting the government's arguments that the limited two-hour time frame and Chatrie's voluntary opt-in to the Google account setting eliminated any reasonable expectation of privacy.
Although Chatrie addressed location data collected via cell phones, the Court's reasoning offers an early indication of the extent to which law enforcement may obtain location data collected by vehicles. Modern connected vehicles generate location information through a wide range of features and services, including embedded telematics systems, mobile applications, cellular vehicle-to-everything communications, roadside infrastructure, and cloud-based fleet platforms.
Notably, applying Carpenter, the Court concluded that the location data at issue implicated a reasonable expectation of privacy because it was generated by a personal device carried on Chatrie's person "all the time" and provided "an intimate window into a person's life." Then, whether that reasoning extends to vehicle-generated location data is less clear and may depend on how the technology is deployed. For example, personally owned connected vehicles, which often accompany the same driver or household over extended periods, may more closely resemble the personal-device context considered in Carpenter.
Similar arguments could potentially apply to connected or autonomous commercial motor vehicles where a safety driver or other operator regularly occupies the same vehicle for extended periods. By contrast, fleet-operated robotaxis and other autonomous commercial vehicles typically generate location data that is collected and controlled by the businesses that own or operate them, raising different questions regarding the existence of a reasonable expectation of privacy and the continued applicability of the third-party doctrine.
Keeping Privacy and Data Compliance in the Driver's Seat
Companies that develop, offer, or operate autonomous and/or connected vehicles should consider whether their existing procedures adequately address law enforcement requests, whether accompanied by a warrant or not. The same is true for suppliers providing mapping, connectivity, cloud infrastructure, analytics, or over-the-air software updates, many of which also collect or process vehicle location data. Here are some tips on how companies may do so:
- Revisit data maps and retention practices to understand where precise location information is generated and how it moves through the organization
- Review policies for responding to law enforcement and third-party requests for location data. Those procedures should establish a clear process for receiving and preserving requests, escalating them for legal review, documenting the basis for any disclosure, and providing notice to customers or users when appropriate
- Incorporate privacy considerations into connected-vehicle and autonomous-vehicle systems throughout the development process. That may mean, where feasible, restricting internal access to those data, implementing appropriate security controls, and relying on aggregation or other privacy-enhancing techniques when developing analytics
- Reflect operational controls in commercial agreements. Contracts can help define which party is responsible for responding to law enforcement requests, identify the permitted uses of location information, establish retention and deletion expectations, and address whether service providers must notify customers when they receive requests involving vehicle or user data
The Road Ahead for Privacy in Autonomous and Connected Vehicles
The legal landscape around the privacy implications of location data is also evolving beyond the Fourth Amendment. Regulators, state legislatures, and private litigants continue to scrutinize how companies collect, use, and share vehicle-generated location information, while also examining the transparency of data flows throughout the automotive supply chain.
Although Chatrie does not answer every question about vehicle-generated location data, and courts may treat different technologies and deployment models differently, this recent decision reinforces a practical point for the connected-vehicle and autonomous-vehicle ecosystem: precise location data is likely to remain a scrutinized data element.
If you have questions about how this or other legal developments may impact your business in mobility and privacy matters, please reach out to Venable's Autonomous and Connected Mobility Group or Privacy and Data Security Group for assistance.