Northeastern researchers tested 21 vehicles and their accompanying mobile apps to investigate what data manufacturers are collecting.
Major car manufacturers are sharing drivers' personal information with third-party companies and data brokers, new Northeastern University research shows.
As part of a partnership with Consumer Reports, privacy and cybersecurity professors at Northeastern tested 21 vehicles from 19 car brands. The investigation—covering vehicles and companion mobile apps—found companies sharing details such as Vehicle Identification Numbers (VIN), location data, and email addresses.
David Choffnes, a Northeastern cybersecurity professor and one of the report's authors, said the work followed reporting that General Motors collected data from cars and sold it to insurance companies. The team wanted a wider-scale analysis of cars on the road today.
How they measured
Researchers rerouted internet traffic vehicles sent to networks they controlled. Vehicle payloads were often encrypted end-to-end, but app traffic could be decrypted on phones the researchers owned. From there they identified personal information flowing to third parties including Adobe Analytics, Axiom, and ContentSquare among the most contacted.
Manufacturers disclosed in privacy policies that they may share personal information with third parties, but typically do not name which parties or for what purpose.
"We have these companies that have nothing to do with car functionality that are getting information about you, what car you have, and sometimes also your GPS location," Choffnes said.
Such stable identifiers can enable cross-context tracking linking vehicle ownership to behavioral data and purchase history elsewhere.
Industry response
Some automakers made changes when presented with the data. Honda asked Amplitude to delete location and VIN data and updated its app to stop sending geolocation to that advertising company. Honda said VIN and location shared with the company were never available for independent use or sale under contract, and that app use is voluntary.
General Motors said it is committed to keeping customer data secure and only discloses data to service providers under strict contract limits that prohibit selling, sharing, or using data for the providers' own purposes.
Choffnes argues automakers must be more transparent, and that regulators should require clearer disclosure of what happens to the data. Researchers also argue opting out should not brick core vehicle functionality, and that defaults should be opt-in.
The peer-reviewed paper—Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem—will be presented at ACM IMC 2026 (Oct 12–16, Karlsruhe).
Original: Northeastern Global News