All stories
Big Tech

Modern Cars Revealed as 'Data Probes,' Relentlessly Sharing Sensitive User Information

A groundbreaking study by Northeastern University and Consumer Reports reveals nearly all modern vehicles and their apps relentlessly transmit sensitive user data to a vast network of third-party tech and advertising companies, turning driving habits into monetizable assets and raising critical privacy concerns.

By TECH NEWS Editorial·Source:TechCrunch·4 min read·1h ago

✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Modern Cars Revealed as 'Data Probes,' Relentlessly Sharing Sensitive User Information

The modern automobile, once a bastion of personal freedom, has quietly evolved into a sophisticated data probe, relentlessly transmitting sensitive user information to a vast network of tech companies. A groundbreaking study, jointly conducted by Northeastern University and Consumer Reports and published on September 29, 2026, reveals that nearly all late-model vehicles and their companion mobile applications are engaged in extensive, often opaque, data sharing practices. Researchers, who examined 21 vehicles from 19 different brands and 30 associated apps between October 2024 and August 2025, discovered that 19 of the 21 tested vehicles transmitted data to third-party entities, with every single vehicle connecting to at least one external domain via Wi-Fi. More alarmingly, over half of these vehicles were found to be communicating with advertising and analytics networks.

The investigation pinpointed seven specific companion apps—HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick, and myGMC—as actively dispatching sensitive personal data, including Vehicle Identification Numbers (VINs), phone numbers, and precise geolocation, directly to advertising networks. Vehicles equipped with Google's Android Automotive OS and Google Automotive Services exhibited the highest volume of third-party domain contacts, reaching Google's own ad servers like doubleclick.net and googlesyndication.com, alongside mapping providers such as HERE, TomTom, and Mapbox. Tesla's Model 3, for instance, proved exceptionally communicative, contacting 34 advertising, tracking, and analytics domains, in addition to 37 domains linked to integrated infotainment apps. While the encrypted nature of much of this traffic prevented researchers from decrypting exact data payloads, the sheer volume and destination of these transmissions paint a clear picture of pervasive data outflow.

This extensive data collection carries profound implications for consumers, transforming driving habits into monetizable assets. The granular details of braking patterns, acceleration, and routes are not merely benign telemetry; they are valuable data points that can directly influence insurance premiums, potentially leading to increased costs for drivers largely unaware of how their daily commute is being financially assessed. The study underscores a critical transparency deficit, highlighting a significant gap between what automakers publicly disclose in their privacy policies and the actual scope of data sharing. This personal information, once collected, can be aggregated and utilized by a broad spectrum of third parties, including banks, insurers, pharmaceutical companies, lenders, and retailers, to construct detailed profiles of drivers, often without their explicit knowledge or consent. The dilemma for users is further compounded by the reality that attempting to opt out of data collection frequently results in a loss of essential vehicle functionalities, such as remote locking or roadside assistance, forcing a difficult trade-off between privacy and convenience. As David Choffnes, the project lead at Northeastern University, aptly summarized, cars are rapidly becoming "the global smartphones" of our tracking ecosystem, extending the digital surveillance landscape from our pockets to our driveways.

For the automotive industry, these findings represent a critical juncture. The push towards "software-defined vehicles" is heavily predicated on the recurring revenue potential derived from connected services and, implicitly, from the data they generate. However, the revelations of this study, coupled with growing consumer privacy concerns, threaten to erode trust and invite stricter regulatory scrutiny. The industry's historical reliance on broad consent clauses buried deep within user agreements is proving insufficient. Automakers' common defense—that data collection is covered by terms of service or results from user error in accepting cookies—increasingly rings hollow in the face of findings that reveal widespread, often hidden, data transfers to advertising networks. Honda's proactive response, being the sole automaker to halt HondaLink's geolocation transmissions and request the deletion of previously collected location data from an analytics provider, stands as an outlier and a potential benchmark for responsible industry conduct, although the actual deletion of data remains unconfirmed.

This current landscape is not without precedent. An earlier Consumer Reports investigation in March 2025 had already highlighted widespread collection of driving behavior data, scrutinizing the privacy policies of 15 automakers. Furthermore, the Federal Trade Commission (FTC) finalized a significant order against General Motors and OnStar in early 2026, mandating affirmative express consent before these entities can collect, use, or share connected-vehicle data. This regulatory action signals a clear shift towards requiring active, explicit consent from consumers, rather than relying on passive opt-out mechanisms or vague terms of service. The widespread adoption of large infotainment screens and other connected features over the past decade has fundamentally transformed vehicles from mere transportation devices into complex data-gathering platforms.

Looking ahead, the implications are clear: the era of unchecked automotive data harvesting is drawing to a close. The FTC's order against GM and OnStar serves as a powerful harbinger, indicating that regulatory bodies are prepared to intervene to protect consumer privacy. For consumers, the immediate imperative is greater vigilance; simply deleting a companion app from a phone does not erase data already held by the automaker or its vendors, necessitating direct engagement with privacy settings and deletion requests. The critical distinction between opt-in and opt-out consent will define the battleground for future automotive data privacy. For the industry, the path forward demands radical transparency, robust data governance, and a re-evaluation of business models that prioritize user trust over unbridled data monetization. Failure to adapt will not only invite further regulatory penalties but also alienate an increasingly privacy-conscious consumer base, fundamentally altering the competitive landscape of the connected car market.

Sources