A Northeastern University study, conducted with Consumer Reports, watched 21 late-model vehicles and 30 companion apps to see who was receiving driver data. The answer includes some of the largest advertising companies in the world.
At Consumer Reports’ auto test center in Connecticut, researchers built something unusual for a car-testing facility: a Faraday tent, a shielded enclosure designed to block radio signals. Inside it, one vehicle at a time, they parked cars from Tesla, Cadillac, Ford, Toyota, Rivian, Lucid and a dozen other brands, then quietly recorded every digital conversation the vehicles tried to have with the outside world. The goal was simple and long overdue: to document, in a controlled and repeatable way, exactly where the data from a modern connected car goes.
The findings, released this week by a team from Northeastern University’s Khoury College of Computer Sciences, are unlikely to reassure anyone who has ever tapped “accept” on a car’s terms and conditions. Nearly every automaker in the test sent driver-related data to outside companies. Many of the recipients were not obscure data brokers but household names in advertising and technology, including Amazon, Google, Meta, Microsoft, Pinterest, Snap and Yahoo.
Inside the Tent
The study, titled Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem, is peer-reviewed and is being published this week. It covers 21 vehicles from model years 2022 through 2025, a mix of mass-market and luxury models, many of them electric because running combustion engines inside an enclosed tent would have posed an obvious hazard. Alongside the cars, the researchers examined 30 companion mobile apps, the kind owners download to unlock doors, start climate control, locate a parked vehicle or check service history.
The method was designed to capture what neither drivers nor regulators can normally see. Each car was connected to a custom Wi-Fi access point that logged all outgoing traffic. Testers collected data with the vehicles parked, driven at moderate speeds, and put through bursts of hard acceleration, sudden braking and swerving meant to mimic reckless driving. For the apps, they logged in and used every function available, from geolocating the car to, where possible, opening the trunk. Crucially, the researchers accepted every terms-and-conditions prompt they encountered, on the theory that a driver who wanted the car to work fully would do the same.
One caution applies. According to one summary of the work, the technique identifies where data is going more confidently than it reveals the full contents of each transmission, since much of that traffic is encrypted. The study is strongest as a map of destinations and patterns, and it should be read that way.
Who Is on the Receiving End
The recipients list reads like a directory of the modern advertising economy. Beyond the biggest technology platforms, TechCrunch reported that analytics and marketing firms such as Adobe and ContentSquare also appeared among the destinations. Consumer Reports observed that many of these companies play a double role in the driver-data ecosystem: they supply software, such as the Android Automotive operating system that runs the infotainment systems in a growing number of cars, and they also operate the advertising auctions marketers use to target particular kinds of customers. In practice, that makes the company collecting the data the first stop in a much larger personal-data supply chain.
The vehicles that reached out to the most outside advertising and analytics companies were the Cadillac Lyriq, the Chevrolet Blazer, the Lucid Air and Tesla’s Model 3 and Cybertruck. Others in the test showed a very different profile. Consumer Reports’ breakdown shows the Mercedes-Benz EQS, Land Rover Range Rover and Buick Envista generating no advertising or tracking traffic at all, though they still contacted other outside domains. The difference suggests that this behavior is a design choice, not an inevitability of connected-car technology.
The Apps Are the Bigger Problem
If the vehicles were leaky, the apps were worse. Consumer Reports found that 28 of the 30 apps sent data to at least one outside advertising or analytics company, and seven of them transmitted at least one piece of personally identifiable information, such as an owner’s name, a vehicle identification number, or precise location. TechCrunch’s account adds that pairing an app with its vehicle roughly doubled the number of advertising and tracking companies exposed to the data.
Four General Motors apps, myCadillac, myChevrolet, myBuick and myGMC, as well as the HondaLink, MyNissan and Lincoln apps, were found sharing VINs paired with either an email address or location data. Apps from BMW, GM’s brands and Toyota contacted the largest number of outside companies overall.
Why a VIN Plus an Email Matters
To a casual reader, a string of letters and numbers identifying a car may not sound alarming. To a data broker, it is a key. The researchers described the combination of a VIN with a second identifier such as an email address or an owner’s name as the most worrisome finding, because it lets a major advertising or technology company match a specific car and driver to one of the commercially available consumer profiles that already exist. Those profiles often contain online behavior and shopping history, and, as a Consumer Reports and CalMatters investigation found, they are routinely sold to banks, insurers, drug companies, lenders and retailers, who may use them to tailor loan terms and filter financial and insurance offers.
Nicole Zagson, a doctoral candidate in cybersecurity at Northeastern and a co-author of the study, said big technology companies are deeply embedded in the vehicles Americans drive, whether or not consumers realize it. Co-author Sarah Elizabeth Gillespie went further, saying she saw no way for a shopper to buy a new car that does not track its owner.
The Consent Problem
Automakers have a standard reply to concerns like these: most of the data flows are opt-in. Several told Consumer Reports that drivers agree to data sharing when they register and sign in, which puts the responsibility on the customer. The researchers push back on that framing for a practical reason. Popular features often will not work unless the driver accepts the terms, and in some cases the car cannot be driven at all. Tesla’s agreement, for example, warns owners who decline that the vehicle could suffer reduced functionality, serious damage or inoperability. Surveys have repeatedly shown that most people accept terms and conditions without reading them.
Several manufacturers also told Consumer Reports that some links inside their apps open outside webpages, where third parties can embed tracking pixels and cookies. The researchers responded that this happened without any warning to the driver. GM, Honda, Nissan and Stellantis added that certain data recipients are contractually barred from using or selling what they receive on their own. The Northeastern team found that such restrictions are not necessarily effective.
One Automaker Moved
The study’s most telling moment came after the researchers shared their findings with the companies. According to the researchers, every manufacturer except Honda deflected responsibility, often toward consumers. Honda, by contrast, instructed its analytics vendor, Amplitude, to delete all of the location data it had received, and it updated its HondaLink app to stop transmitting that information. A fix that simple, delivered that quickly, raises an obvious question about how long the data flowed before anyone outside the company looked.
A Regulatory Backdrop That Is Already Crowded
None of this arrives in a vacuum. Regulators and courts have spent the past two years scrutinizing connected-car data, and the results have been costly for the companies involved. In January, the Federal Trade Commission finalized an order against General Motors and its OnStar subsidiary that bars them from disclosing driver behavior and location data to consumer reporting agencies without consent for five years. In May, California announced a record $12.75 million civil penalty against GM under the California Consumer Privacy Act, alleging the company sold driving data on hundreds of thousands of Californians to the data brokers LexisNexis Risk Solutions and Verisk Analytics without their knowledge. Court filings put GM’s earnings from those sales at roughly $20 million. California has also reached privacy settlements with Honda and Ford, and Texas has sued GM over its handling of driver data.
What distinguishes the Northeastern study is where it points the spotlight. Most enforcement to date has centered on data brokers and insurers. The new research suggests that a wider circle, the major technology and advertising platforms, is also receiving data from cars and their apps, and that the flows are far harder for owners to detect or stop.
What Comes Next
For an industry racing to turn vehicles into software platforms, the study lands as an uncomfortable reminder that software brings an advertising economy along with it. The research covers model years through 2025, so it does not capture the newest generation of cars and interfaces, and it examines a sample of 21 vehicles rather than the whole market. But the breadth of the findings, across brands, price points and powertrains, argues against treating them as outliers, and the contrast between the cars that stayed quiet and those that did not shows that automakers have real choices.
For drivers, the practical advice is unsatisfying but real. Consumer Reports has published a guide to opting out of driver-behavior data sharing and requesting deletion, though opting out may cost some convenience features.