TL;DR
Get bike and ride gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A study by Northeastern University and Consumer Reports tested 21 vehicles and 30 companion apps, finding widespread sharing of location, timing, and VIN data with advertising and tracking companies — sometimes reaching dozens of third parties. Most automakers deflected responsibility to vendors; only Honda changed its practices after being contacted.
A study by Northeastern University in partnership with Consumer Reports found that modern connected vehicles and their companion mobile apps share sensitive driver data — including vehicle identification numbers (VINs), location, and timing information — with far more third-party advertising and tracking companies than most owners realize, in some cases reaching more than 50 distinct tracking domains through a single app.
The research, an 18-page paper, examined 21 vehicles from 19 brands — including models from Tesla, GM, Ford, Honda, Mercedes-Benz, Rivian, and Toyota — along with 30 companion mobile apps that handle user data. The findings show that opting out of this data collection is nearly impossible for owners who want to use their vehicles’ modern convenience features.
According to the study, 70% of companion apps contacted more than five unique advertising, tracking, and analytics (ATA) domains, typically sharing location and timing data. The myCadillac app contacted 51 ATA domains. The Nissan Ariya and Buick Envista, which on their own sent almost no data, each reached 20 or more ATA companies once the companion app was included. Over Wi-Fi, vehicles averaged about nine integrated third parties, with the Tesla Model 3 contacting 34 ATA domains and the Cybertruck 23, while the Mercedes EQS and Buick Envista contacted none.
Perhaps the study’s most pointed finding: seven apps covering 19 of the 21 test cars transmitted personal information — most commonly the VIN — to third parties, including recipients such as Google, Microsoft, and Meta. All four GM apps, HondaLink, Lincoln, and MyNissan were identified. The study notes that a VIN combined with an email, phone number, or location could allow an advertiser to link a specific person to their browsing and purchase history — and unlike a phone’s advertising ID, a VIN cannot be reset.
Why Your VIN Is the Problem
The VIN sharing finding matters because it goes beyond what smartphones can expose. As the study highlights, a VIN is a persistent identifier that cannot be reset the way a phone’s advertising ID can. Combined with an email address, phone number, or location, it gives advertising companies a durable way to tie a specific person to their vehicle and, potentially, their broader browsing and purchasing activity.
The scale also matters for everyday owners. Thirteen of the 21 vehicles contacted Google ATA domains, including domains like doubleclick.net that the researchers noted are not needed for core vehicle services. Vehicles running Android Automotive and Google services contacted many more trackers than others — meaning a buyer’s choice of infotainment platform may have privacy consequences they never see disclosed.
How Automakers Responded
Of 17 manufacturers contacted for the study, 14 responded. All said their vendor contracts covered the data flows. Five blamed embedded browsers in their apps, and seven said reading third-party terms of service was the consumer’s responsibility. Privacy policies generally disclosed that data may go to third parties, but not which companies or why.
The researchers also flagged an opt-out trap: Tesla warned that declining data sharing could cause reduced functionality or inoperability, while Rivian warned of disabled navigation and over-the-air updates. Only Honda changed its practices — it had analytics vendor Amplitude delete the location data it had received and stopped the app from sending it.
Data collection was difficult to measure because some pre-installed apps connect to the driver’s phone and open its browser, at which point data flows follow the phone’s browser settings rather than the car’s, introducing cookies and browsing data the owner did not expect.
“The only way you’ll be surprised by what you’re about to read is if you’ve been in a coma for the last decade or two.”
— The Drive, reporting on the study
What the Study Didn’t Test
The study covered only 21 vehicles and 30 apps, a fraction of the connected-car market, so findings for sibling brands — such as the Buick Envista, Cadillac Lyriq, and Chevrolet Blazer behaving differently — may not generalize. It is not clear whether the third parties receiving VINs and location data combined them into user profiles, or what those companies did with the data. The study also could not fully trace what happens once an in-car app hands off to a phone’s browser, since those flows follow phone settings outside the researchers’ vehicle-based measurements. Whether other automakers will follow Honda’s example of deleting collected data remains unknown.
Pressure on Drivers and Regulators
The Northeastern and Consumer Report findings add to existing regulatory scrutiny of automotive data practices in the United States, where the Federal Trade Commission and state privacy laws have increasingly targeted automakers. Owners concerned about their own exposure can review their vehicle’s privacy settings and companion app permissions, though as the study shows, opting out often disables core features like navigation and over-the-air updates. Further research and potential regulatory action may follow publication of the 18-page paper, and consumer advocates are likely to press other manufacturers to match Honda’s deletion of collected location data.
Key Questions
Do all connected cars share data with third parties?
No. The study found wide variation: the Mercedes EQS and Buick Envista contacted no third parties over Wi-Fi, while the Tesla Model 3 contacted 34 ATA domains. Companion apps, however, sharply increased third-party exposure for most vehicles.
Why is sharing my VIN a privacy concern?
According to the study, a VIN combined with an email, phone number, or location can let an advertising company link you to your browsing and purchase history. Unlike a phone’s advertising ID, a VIN cannot be reset.
Can I stop my car from sharing my data?
Only partially. Opting out or avoiding connected features often disables functionality — Tesla warned of reduced or lost features, and Rivian of disabled navigation and over-the-air updates. Companion app permissions can be reviewed on your phone, but some flows follow browser settings rather than vehicle settings.
Which automaker changed its practices after the study?
Honda. The company had analytics vendor Amplitude delete the location data it had received and stopped its app from sending that data. The other responding manufacturers said their vendor contracts covered the data flows.
Which cars were included in the study?
21 vehicles from 19 brands, including the 2024 Tesla Model 3 and Cybertruck, 2024 Ford Mustang GT, 2023 Ford F-150 Lightning, 2024 Honda Prologue, 2023 Toyota Corolla Cross, 2023 Nissan Ariya, 2023 Mercedes-Benz EQS450, 2022 Rivian R1S, and 2024 Volvo C40, among others.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
