Your Car Is Sharing More Private Data Than Your Smartphone. Who’s Getting It?

When researchers contacted automakers for answers, most passed the buck and hid behind their vendor contracts. Only one took action and changed its location-data policy.
Toyota

Modern vehicles, like every other technology device we own, from smartphones to fridges and even dog collars, are connected to the internet 24/7. They learn from us, know things about us, and most of the time use that information to make our lives easier. Cars, specifically, collect vital driving and behavior data that is borderline impossible to opt out of if you want to use your vehicle’s modern convenience features. And a new study recently found that your sensitive information (some of which isn’t even car-related) is being shared with far more parties than you realize.

The only way you’ll be surprised by what you’re about to read is if you’ve been in a coma for the last decade or two. But even for those of us who are mildly aware of how the technology we rely on every day interacts with us and the data we generate, this recent study by Boston’s Northeastern University in partnership with Consumer Reports will make you raise an eyebrow—several times.

The study covered 21 vehicles of 19 different brands (listed below) and 30 companion mobile apps that process and handle user data.

You can peruse the 18-page paper here, but you can also see the main takeaways below:

  • Companion Apps Share Data That Goes Beyond Car Stuff: 70% of companion apps contacted more than five unique ATA (advertising, tracking, analytics) domains, typically sharing location, timing, and other data packets. For most test vehicles, adding the automaker or third-party (usually pre-installed) app at least doubles the number of ATA companies exposed to the owner’s data. The Envista and Nissan Ariya, which were nearly silent on their own, each reach 20+ ATA companies once the app is counted. myCadillac contacted 51 ATA domains.
  • How Many Third-Party Apps Your Car Contacts Wildly Varies: Over Wi-Fi, vehicles contacted at most four first-party domains but averaged about 9 integrated third parties. The Tesla Model 3 contacted 34 ATA domains and the Cybertruck 23, while the Mercedes EQS and Buick Envista contacted no third parties. Thirteen of the 21 vehicles contacted Google ATA domains, including ones like doubleclick.net that aren’t needed for core services. Vehicles with Android Automotive and Google services contacted many more trackers, and even sibling brands differed; oddly enough, the Envista, Lyriq, and Blazer did not behave in the same manner.
  • Some Apps Share Your VIN With Vendors, Something Not Even Your Smartphone Can Do: Seven apps (19 of 21 cars) transmitted personal information to ATA third parties: all four GM apps, HondaLink, Lincoln, and MyNissan. VINs were the most common, sent to recipients including Google, Microsoft, and Meta. The worry is that a VIN plus an email, phone number, or location lets an ad company link a specific person to their browsing and purchase history. The study also highlights that a VIN can’t be reset the way a phone’s advertising ID can. Also, I just published a blog this week about how I enjoyed Honda’s infotainment with Google Built-in, and cracked a joke about the price I am willing to pay for convenience.
  • OEMs Mostly Pass the Buck to Their Partners and Vendors: Of 17 manufacturers contacted for the study, 14 responded. All said their vendor contracts covered data flows. Five blamed embedded browsers in their apps, and seven said reading third-party terms is the consumer’s responsibility. Of course, if you opt out or simply don’t use the features, then you wouldn’t be utilizing your car to its full potential. Tesla warned about reduced functionality or inoperability, while Rivian warned about disabled navigation and over-the-air updates. The privacy policies disclosed that data may go to third parties but not which ones or why. Only Honda changed course. It had Amplitude delete the location data it received and stopped the app from sending it. Go Honda.
  • Gathering This Data Wasn’t Easy: Even if you only use the official apps pre-installed in your car, some of these may connect to your phone and ultimately open your browser. Once it does, the whole flow of data changes because it follows your phone’s browser settings, not your car’s. This means your car is now receiving cookies and browsing data and sharing them in ways you weren’t aware of or expected.

These are the cars involved in the study:

  • 2024 Buick Envista
  • 2024 Cadillac Lyriq
  • 2024 Chevrolet Blazer
  • 2023 Dodge Hornet
  • 2024 Fiat 500e
  • 2025 RAM 1500 Bighorn
  • 2023 Fisker Ocean
  • 2022 Ford F-150 Lightning
  • 2024 Ford Mustang GT Fastback
  • 2024 Honda Prologue Touring AWD
  • 2023 Land Rover Range Rover Sport
  • 2024 Lexus NX450h+ PHEV
  • 2023 Toyota Corolla Cross
  • 2023 Subaru Solterra
  • 2023 Lucid Air Touring
  • 2023 Mercedes-Benz EQS450 4Matic
  • 2023 Nissan Ariya Platinum
  • 2022 Rivian R1S
  • 2024 Tesla Cybertruck
  • 2024 Tesla Model 3
  • 2024 Volvo C40

Got a tip? Email us at tips@thedrive.com

Add The Drive as a preferred source on Google to see more of our reporting.

Jerry Perez Avatar

Jerry Perez

Deputy Editor

As deputy editor, Jerry draws on a decade of industry experience and a lifelong passion for motorsports to guide The Drive’s short- and long-term coverage.


Loading comments…