Privacy is not about what someone _might_ do with your data, it’s what they _can_ do with your data.
It’s also that they have your data, which means it can be exposed to staff or the world as the result of a breach.
On the second point, sure, but so we have knowledge of what, how, and for how long, the carmakers are storing?
What they do with the data changes based on leadership (should we sell to 3rd party data brokers to increase our revenue or not?)
It’s also out of their hands once a subpoena for that data comes from law enforcement.
It's important to know what they do with that data today.
It's also important to know what they could do with that data tomorrow.
Even if a company provides assurances and pledges never to mishandle your data or use it for nefarious purposes, there remains a risk that your data could still end up in the wrong hands.