
Study: connected cars still leak driver data to dozens of ad and tracking firms
Researchers at Northeastern University and Consumer Reports measured the traffic of 21 cars and 30 companion apps. Tesla's Model 3 contacted the most ad and tracking domains, and Honda changed its data practices after seeing the findings.
Researchers at Northeastern University and Consumer Reports measured traffic from 21 vehicles (19 brands, 2022-2025 model years) and 30 automaker apps at Consumer Reports' center. Their paper, “Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem,” will be presented at the ACM Internet Measurement Conference in October.
What the study did
A 2023 Mozilla Foundation review of automakers' privacy policies concluded that “cars are the worst product category we have ever reviewed for privacy.” The new work logged traffic from real cars while idle, driven and using their infotainment systems. Eleven EVs sat in a Faraday tent that blocked cellular signals; packet contents were unreadable, but DNS lookups and handshake data still showed where traffic went.
What the cars sent, and to whom
Every vehicle contacted its manufacturer's own domain, and a few went no further: the Buick Envista and Mercedes-Benz EQS reached no third-party advertising or analytics domains. Tesla's Model 3 contacted 34 advertising, tracking and analytics domains, plus 37 tied to apps built into its infotainment system, the highest count in the test; the Cybertruck contacted 26 more third-party domains while driving than while parked. Alphabet's domains were the most frequent, which the authors link to the reach of Android Automotive OS; these included doubleclick.net and googlesyndication.com, which the paper says are not needed for core services. Spotify, HERE, TomTom and Mapbox also appeared.
Apps pass on names, VINs and locations
The companion apps proved the bigger problem: 28 of 30 sent data to at least one outside advertising or analytics company, and seven sent personally identifiable information, such as the owner's name, the VIN or precise location, outside. Four General Motors apps (myCadillac, myChevrolet, myBuick and myGMC), HondaLink and MyNissan shared VINs paired with email addresses or location data. The paper names General Motors, Toyota and Nissan as the worst app makers, and Alphabet, Amazon, Meta, Microsoft, Pinterest, Snap and Reddit among top data recipients.
Consent, contracts and regulators
Researchers contacted 17 automakers; 14 replied (Fisker had shut down). All said contracts bar third parties from using personal data outside the agreed scope. Some blamed the browser embedded in the infotainment system and cookie prompts; seven said reading every service agreement is the customer's responsibility. Declining often costs functionality: Tesla warns owners who refuse its data-sharing agreement that the car “may suffer from reduced functionality, serious damage, or inoperability.” After seeing the findings, Honda told its vendor Amplitude to delete the location data it had received and stopped sending it. Consumer Reports notes that regulators have reprimanded and fined automakers over insufficient disclosure, and several have been sued.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.