Connected Cars Transmit Sensitive Data to Ad and Tracking Firms, Study Finds
A new study reveals that both modern vehicles and their companion apps transmit sensitive data, including VINs and location, to third-party advertising and tracking companies.

Modern vehicles are increasingly connected, offering a suite of conveniences from remote control to advanced navigation. However, a recent study highlights a significant privacy trade-off: these connected cars and their associated mobile applications are transmitting sensitive user data to advertising and tracking firms.
The research, conducted by Northeastern University in collaboration with Consumer Reports, tested 21 vehicles from 19 different brands and their 30 companion apps. The findings indicate a widespread practice of data sharing, with 19 out of 21 tested vehicles contacting third-party domains over Wi-Fi, many of which are linked to advertising and tracking operations. Furthermore, seven of the 30 tested apps were found to transmit sensitive identifiers to these third parties.
While it's understood that connected vehicles require network access for essential functions like safety alerts, navigation, and account management, the study's concern lies in the potential for combining various identifiers. A Vehicle Identification Number (VIN), for instance, can directly link a specific car to its owner. When combined with precise location data, this information can reveal highly sensitive patterns about an individual's life, including where they live, work, worship, seek medical attention, or socialize.
Adding personal information such as an email address or name to this data pool can significantly simplify the creation of detailed consumer profiles by advertisers and data brokers. This practice raises substantial privacy concerns for drivers, who may be unaware of the extent to which their driving habits and personal movements are being monitored and monetized.
The study also points to the inadequacy of current consent mechanisms. Many manufacturers require users to accept extensive terms and conditions to access advertised vehicle functionalities. In some cases, declining these agreements can lead to reduced functionality or even inoperability, as noted with a Tesla warning. This situation presents a weak safeguard, as drivers may feel compelled to consent to data collection to fully utilize their vehicle's features, undermining the concept of informed consent.
There was a glimmer of positive change noted: following the researchers' presentation of their findings, Honda reportedly directed its vendor, Amplitude, to delete location data it had received and ceased further transmission. However, the researchers emphasize that consumers should not have to rely on academic studies to understand how their data is being shared.
Compounding the issue, major tech companies such as Amazon, Google, Meta, and Microsoft were identified as significant recipients of this driver data. These companies already possess vast amounts of personal information, and the addition of vehicle-derived data further enriches their profiles.
Until automakers implement more robust data minimization practices, provide clear and accessible privacy settings, offer meaningful opt-out controls, and enable deletion capabilities, drivers are advised to treat their connected cars and companion apps with the same caution as other privacy-sensitive devices. Reviewing app permissions, disabling optional data-sharing settings, and limiting account linking are recommended steps for mitigating these risks.