Share

May 5, 2025 — A new peer-reviewed study from Northeastern University, conducted with Consumer Reports, gives one of the clearest pictures yet of where connected cars and their companion apps send driver data. Testing 21 late-model vehicles and 30 branded mobile apps inside a radio-shielded tent in Connecticut, the researchers found that nearly every automaker transmitted data to outside companies — including Amazon, Google, Meta and Microsoft — and that 28 of 30 apps contacted advertising or analytics firms. Seven apps went further, sending personally identifiable information such as a VIN paired with an email address or location.
The study, titled "Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem," is peer-reviewed and is being published this week. It covers 21 vehicles from model years 2022 through 2025, most of them electric, because running combustion engines inside a sealed Faraday tent — a metal-lined enclosure engineered to block radio signals — would have posed a carbon monoxide hazard.
Each car was connected to a custom Wi-Fi access point that recorded all outbound traffic. Researchers logged data with the vehicles parked, driven at moderate speeds, and pushed through hard acceleration, sudden braking and swerving meant to mimic reckless driving. For the 30 companion apps, they signed in and used every function available, from locating the car to remotely opening the trunk. They accepted every terms-and-conditions prompt they encountered, on the theory that a driver who wants the car to work fully would do the same.
One qualifier applies. Because much of the traffic is encrypted, the methodology identifies where data is going more confidently than it reveals the full contents of each transmission. The study is strongest as a map of destinations. That map is crowded.
Nearly every vehicle in the test sent driver-related data to outside companies. Some recipients were the usual data-broker suspects; many were household names in advertising and technology, including Amazon, Google, Meta, Microsoft, Pinterest, Snap and Yahoo. Analytics and marketing firms such as Adobe and ContentSquare also appeared among the destinations, TechCrunch reported.
Consumer Reports points to the double role these companies play: they supply the software, such as the Android Automotive operating system, that runs infotainment systems in a growing number of cars, and they also operate the ad auctions marketers use to target specific kinds of customers. The company collecting the data, in other words, is the first stop in a much larger personal-data supply chain.
The most externally chatty vehicles were the Cadillac Lyriq, the Chevrolet Blazer, the Lucid Air and Tesla's Model 3 and Cybertruck. A different group — the Mercedes-Benz EQS, Land Rover Range Rover and Buick Envista — generated no advertising or tracking traffic at all, though they still contacted some outside domains. That contrast is the study's quiet headline: automakers can build a connected car without feeding the ad economy. The variation is a design choice, not a technological inevitability.
The apps proved far more problematic than the vehicles themselves. Consumer Reports' count showed 28 of the 30 apps transmitting data to at least one outside advertising or analytics company, and seven passed along at least one piece of personally identifiable information, whether an owner's name, a vehicle identification number or a precise location. Pairing an app with its vehicle roughly doubled the number of advertising and tracking companies exposed to the data, according to TechCrunch.
The apps sharing VINs alongside either an email address or location data were General Motors' four-brand suite — myCadillac, myChevrolet, myBuick and myGMC — plus HondaLink, MyNissan and the Lincoln app. Apps from BMW, GM's brands and Toyota contacted the largest number of outside companies overall.
Co-authors Nicole Zagson, a cybersecurity doctoral candidate at Northeastern, and her colleague Sarah Elizabeth Gillespie drew a blunt conclusion from the data: large technology companies are structurally embedded in the vehicles Americans drive, and Gillespie said she sees no way for a shopper to buy a new car that does not track its owner.
A VIN alone is a machine identifier. Add an email address or an owner's name, and it becomes a merge key. The researchers described this pairing as their most worrisome finding, because it lets a major advertising or technology company connect a specific car and driver to one of the commercial consumer profiles that already exist — profiles built from browsing history, shopping behavior and estimated income.
Such profiles are routinely sold to banks, insurers, drug companies, lenders and retailers, who may use them to tailor loan terms and filter financial offers, as a Consumer Reports and CalMatters investigation found. To a data broker, the VIN-plus-identifier combination is a key to a locked file.
Automakers have a standard response: most data flows are opt-in. Several told Consumer Reports that drivers agree to the data sharing when they register and sign in. The researchers reject that framing for a practical reason: popular features often refuse to work unless the driver accepts the terms, and in some cases the car cannot be driven at all. Tesla's agreement, for example, warns owners who decline that the vehicle could suffer reduced functionality, serious damage or inoperability. Repeated surveys have found that most people accept terms and conditions without reading them.
Several automakers also pointed out that some links inside their apps open external web pages, where third parties can embed tracking pixels and cookies. The researchers noted that this happens without any warning to the driver. GM, Honda, Nissan and Stellantis added that some data recipients are contractually barred from using or selling what they receive. The Northeastern team responded that such contractual limits offer little guarantee.
Perhaps the most telling episode happened after the researchers briefed the automakers on what they had found. All but one of the companies deflected responsibility, usually steering it back to the driver. Honda instead told its analytics vendor, Amplitude, to wipe the location data it had collected and updated HondaLink so the app would no longer send that information. The correction was quick and uncomplicated, which raises a fair question about how long that data flowed before anyone outside the company asked.
The study lands against a crowded regulatory backdrop. In January, the Federal Trade Commission finalized an order barring General Motors and its OnStar subsidiary from disclosing driver behavior and location data to consumer reporting agencies without consent for five years. In May, California announced a record $12.75 million civil penalty against GM under the California Consumer Privacy Act, alleging that GM sold the driving data of hundreds of thousands of Californians to data brokers LexisNexis Risk Solutions and Verisk Analytics without their knowledge. Court filings put GM's earnings from those arrangements at roughly $20 million. California has also reached privacy settlements with Honda and Ford, and Texas has sued GM over its handling of driver data.
The Northeastern study stands apart because of where it trains the spotlight. Most enforcement to date has aimed at the downstream buyers — data brokers and insurers. This research redirects attention to the major technology and advertising platforms receiving data from cars and their apps, where the flows are far harder for owners to detect, let alone stop.
The study covers model years through 2025 and a sample of 21 vehicles rather than the whole market, so it does not capture the newest generation of cars and interfaces. But the breadth of the findings, across brands, price points and powertrains, argues against treating them as outliers.
For current owners, Consumer Reports has published guidance on opting out of driver-behavior data sharing and on requesting deletion, though following it may cost some convenience features. For shoppers, four questions are worth raising before signing on the dashboard: Does the privacy policy state which data categories leave the vehicle? Are those data linked to a VIN, a name or an account? Will the app's core functions still work if third-party ad trackers are blocked? And is location data deleted by default, or merely stored? If the answers are vague, the safest assumption is that the data flows. The technology that makes a car smart, this study suggests, also makes it the newest endpoint in the advertising economy.









