A Northeastern University study, conducted with Consumer Reports, tested 21 cars from 19 brands and 30 companion apps across model years 2022–2025, observing network activity while vehicles were stationary, driven, and via their apps. The researchers found that both vehicles and their apps connected to third-party domains linked to advertising and tracking, with 19 of the 21 vehicles contacting at least one third party over Wi‑Fi and seven of the 30 apps transmitting sensitive identifiers to such third parties.
The key concern is not the car talking to its manufacturer—essential for safety, navigation, and maintenance—but the potential to link multiple identifiers (for example, vehicle identification numbers with precise location, plus an email or name) to build detailed consumer profiles held by data brokers and advertisers. The report also notes privacy risks around cameras that monitor drivers for distraction or impairment.
The article argues that consent is weak when drivers must accept extensive terms to use advertised features, and that opting out can still reduce functionality. There were some corrective actions: Honda told Consumer Reports it had directed a vendor to delete location data and stopped sending it after the study’s findings. The piece highlights that large tech firms such as Amazon, Google, Meta, and Microsoft were among the leading recipients of driver data.
Practical responses include reviewing app permissions, disabling optional data sharing, avoiding unnecessary account links, and asking manufacturers what data is retained, shared, and deleted. The article urges meaningful opt-outs and deletion controls as car data practices evolve.