They also should be looking at other brands who did this - like Subaru, Hyundai/Kia, Mitsubishi, etc. I recall that Subaru in particular did not revise their location sharing policy when articles came out earlier this year about how these companies resell data to brokers like Lexis Nexis or Verisk. If you get a new Subaru with a Sirius XM radio for example, something that gets forced onto many or all configuration of cars (not sure), by default there is an option selected for sharing your location data with them. That might be true for any brand that shoves satellite radio into your vehicle. But you also are giving them authorization to do whatever they want with such data when you sign up for convenience services like the ability to lock/unlock/remote start the car from your phone. The fine print for those digital services includes giving your consent from what I read.
There's really no way to allow companies to have your data when they need it, and also not lose it. Even if they don't sell our data, they can just get hacked, our info gets leaked, and now everybody has it anyway. Data security should come first, then data privacy, then data autonomy.
HIPAA was basically created to do this (require your consent to receive your information, then require your consent to transmit or share it, within reason) but lack of data security means our private medical data still gets leaked. So I agree we absolutely need all personal data to be treated like HIPAA (at minimum) but it's kind of pointless without improved security requirements.