Researchers find totaled Teslas contain unencrypted and personally revealing data about owners, including locations visited, phone contacts, and dash cam video
- Crashed Tesla vehicles, sold at junk yards and auctions, contain deeply personal and unencrypted data including info …
Context & Ripple Effects
This finding slots into a long-running pattern around how Tesla handles the data its cars generate. Back in 2017, the company was already selectively releasing driver data logs to media after accidents — logs that even the drivers themselves couldn't access. By 2022, reporting showed the scale of collection had grown to breadcrumb GPS trails and gateway logs across roughly 3 million vehicles, feeding Autopilot development.
What's new here is the disposal end of that pipeline: when a Tesla is totaled and resold through junk yards and auctions, everything the car recorded — locations visited, phone contacts, dash cam video — leaves with it, unencrypted. That makes the car itself, not just Tesla's servers, an unguarded archive of owner behavior.
First-order effects
- Owners whose Teslas end up totaled have their locations, contacts, and camera footage exposed to whoever buys the vehicle at auction or salvage — a direct privacy breach they never consented to and likely don't know about.
- Tesla faces renewed questions about why vehicle-stored data isn't encrypted or wiped before resale, especially given its history of controlling who sees driver data.
Second-order effects
- Salvage yards and auction houses become de facto brokers of personal data whether they intend to or not, forcing them to consider wiping procedures or liability policies for connected vehicles they handle.
- The finding compounds pressure from prior disclosures — staff sharing customer camera footage internally and the 100GB whistleblower leak of FSD complaint data — giving regulators and plaintiffs a multi-year record of Tesla data-handling gaps to cite.
Third-order effects
- If totaled connected cars routinely leak their data histories, vehicle data ownership and end-of-life data destruction become regulatory questions — who owns the archive a car accumulates, and who must erase it before resale.
- The pattern points toward connected-vehicle privacy becoming a distinct compliance category, separate from phone or computer privacy, as automakers' fleets turn into continuously recording sensor networks.
The trend: Connected cars are evolving into rolling personal-data archives whose collection, internal handling, and disposal are all outpacing the privacy controls around them.