I'm not sure what Caraid does, but I continue to be surprised by the complete lack of security awareness from car makers. Why do they even need this data? If it's a safety feature, then sure, ping a remote endpoint every 60 second with your current location, but don't store it anything but the last ten minutes and delete everything after a week.
The automotive industry has such a shitty track record with software that it baffles the mind that they haven't improved or simply decided that it's not worth the risk. One quote stands out to me as particularly egregious: "Cariad responded to Spiegel saying that no sensitive data was exposed, adding that customers don’t need to take any action, as no sensitive information like passwords or payment data is affected."[2] That tells me that Cariad doesn't understand security or privacy AT ALL. Having someone know you location can be much more damaging/dangerous that losing your payment information. The difference is that passwords and credit cards is financial damage, which companies apparently understand, but location is people getting stalked or killed, once the first companies have been held financially reliable for providing location info to a killer, then perhaps something will improve. As long as losing your ability to accept a VISA card is more important than your customers physical safety nothing will change.
1) https://www.techspot.com/news/106155-volkswagen-data-leak-ex...
2) https://electrek.co/2024/12/30/massive-data-leak-at-volkswag...
They sell it of course.
The stated reasoning is that the want to track battery performance to optimize it, thus they need to see in what environment (weather and terrain) the vehicle is used to make sense of the data.
The second reason is that they offer "fleet management" for company cars, so that a dispatcher for some company can see which car is where and which to send to a customer.
Of course location data is valuable in many other ways as well ...