Connected car apps share driver data with third parties

Connected car apps share driver data with third parties

Most major car manufacturers pass personal data gathered by connected vehicles and their companion apps to advertisers, analytics firms, large tech companies and data brokers, according to new research from Northeastern University and the nonprofit Consumer Reports.

The study covered 21 major automakers. Researchers found that 19 of them collect customers' private data and share it widely.

Connected cars have been known to be privacy invasive for some time. The US Federal Trade Commission (FTC), the federal consumer protection regulator, cautioned automakers about their data practices in 2024. The new research adds detail on the path the data takes. It starts in the vehicle, moves to the apps drivers download when they buy the car, and from there reaches outside companies.

Apps as the main channel

The researchers examined 30 connected car apps. Of those, 28 sent data to at least one third-party advertising or analytics company.

Seven of the 30 apps went further and transmitted at least one piece of personally identifiable information to at least one outside firm. According to an online post by Consumer Reports, this included owners' names, email addresses and precise geolocation.

Some apps also paired vehicle identification numbers (VINs) with other personal details. This applied to four General Motors (GM) companion apps, myCadillac, myChevrolet, myBuick and myGMC, as well as apps from Honda, Nissan and Lincoln. They shared VINs together with either location data or email addresses. The researchers said this makes it easy for data brokers to link driving patterns to specific people and sell that information.

GM has already faced penalties over driver data. In May, California Attorney General Rob Bonta and the California Privacy Protection Agency (CPPA), the state's dedicated privacy regulator, together with four local prosecutors, fined the company more than $12 million. GM was also ordered to stop sharing driver data with credit reporting agencies and data brokers for five years.

Big tech on the receiving end

The list of recipients is long. Besides advertisers and analytics firms, the automakers shared data with dozens of tech companies, including Google's Alphabet, Amazon, Microsoft, Meta, Reddit and Pinterest.

Consumer Reports pointed out that many of these firms play a double role. They supply software to the automakers, and they also run advertising "auction" platforms that marketers use to reach specific groups of customers.

"As such, the companies that collect driver data are often the first node in a vast personal data ecosystem," the press release said.

None of the automakers named in the report immediately responded to a request for comment.

Honda deletes location data

One manufacturer did act after learning of the findings. According to the press release, Honda instructed a digital data analytics and tracking vendor it uses to delete all location data it had received and to stop sharing it with third parties.

Other automakers explained part of the data flow to Consumer Reports. Several said links inside their connected apps open external web pages. Those pages allow third-party firms to set cookies and pixels, which means they can collect consumer data, usually without the driver being aware of it.

Many manufacturers also said that some of the third parties receiving the data are not allowed to use or sell it "independently."

The opt-in argument

Car companies defended their practices by pointing out that data sharing requires the driver to opt in. Consumer Reports disputes that this offers real protection. It argues that drivers often do not understand what they are agreeing to, and that some automakers warn customers their vehicles may not work properly if they decline.

"The findings underscore the immense personal data ecosystem that American consumers are unwittingly drawn into when they purchase and use everyday consumer products, including autos," the press release said.

Why It Matters

The report suggests that the main privacy risk in a modern car is often not the vehicle itself but the smartphone app that comes with it. Those apps rely on the same advertising and analytics code as ordinary mobile software. This fits a wider pattern seen in research on mobile and desktop platforms, where everyday software quietly exposes information about what users do.

The pairing of VINs with location data or email addresses deserves particular attention. A VIN is tied to a registered owner, so combining it with location history turns individual trips into a profile of a specific person. Once that data sits with brokers, drivers have little insight into where it ends up. That makes the traditional opt-in model hard to rely on, especially if declining can affect how the car works.

The GM settlement in California shows that regulators are willing to act, and state privacy agencies such as the CPPA appear to be the most active enforcers for now. It is worth watching whether this research prompts similar action against the other automakers named in the report, and whether the FTC follows up on the warning it issued in 2024. Honda's decision to have its vendor delete location data suggests that public scrutiny can also change practices without a regulator stepping in.

For drivers, the practical advice is to review the privacy settings in any car companion app and to think carefully before granting location access or linking personal accounts. Security and privacy teams whose staff use company vehicles should also treat these apps as part of the wider data exposure picture.