Your membership has expired

The payment for your account couldn't be processed or you've canceled your account with us.

Re-activate

Your Car Is Sharing Data With Big Tech Companies, Study Finds

Data sent by vehicles and companion apps included locations, VINs, and other identifiers. Amazon, Google, Meta, and Microsoft were among the top receivers of driver data.

Inside of car with communication overlay
Researchers used CR cars and facilities to document exactly what kind of data gets siphoned off our vehicles—and which companies are receiving that information.
Photo Illustration: Consumer Reports, Getty Images

Your car may be spying on you—and transmitting what it learns to some of the world’s biggest tech companies. 

That’s the core finding of a series of tests conducted by privacy researchers at Northeastern University in Boston, using Consumer Reports’ vehicles and Auto Test Center in Connecticut. A study about the results will be published this week.

It has been known for some time that many late-model automobiles collect detailed data about our driving and share it with companies that may use it for marketing purposes and even to individualize insurance premiums or auto loan rates. Regulators have reprimanded and fined automakers for allegedly failing to clearly disclose this practice, and several automakers have been sued for it.   

The new Northeastern study shows, for the first time, data flowing among the vehicles, the vehicle apps you download when you buy your car, and third-party companies, documenting exactly what kind of data gets siphoned from our vehicles and which companies are receiving that information. 

More on car insurance and privacy

Nearly every automaker sent data to outside companies.

Even more troubling, almost a quarter of the vehicle apps were found to be sending out personally identifiable information, including vehicle owners’ names, vehicle identification numbers (VINs), and precise geographic locations. That information can make it easy for companies to link driving behavior to personal data profiles created by data brokers and marketers. Such profiles are routinely sold to banks, insurers, pharmaceutical companies, lenders, and retailers, who can use it for personalized loan terms and filtered bank and insurance offers, a CR and CalMatters investigation found. 

The top recipients of the driver data were some of the country’s largest tech companies, including Amazon, Google, Meta, Microsoft, Pinterest, Snap, and Yahoo. 

“Whether or not consumers are aware, big tech companies are all over the vehicles that we drive,” said Nicole Zagson, a doctoral candidate in cybersecurity at Northeastern and a study co-author. 

Another co-author, Sarah Elizabeth Gillespie, says: "It does not appear that a customer can buy a new car that does not track you."

To find out what kind of driver data was being collected, and by what companies, the team of privacy researchers from Northeastern University tested 21 vehicles and their companion mobile apps at CR’s Connecticut auto testing facility.

To isolate the data flowing to and from the vehicles, the vehicles were placed inside a specially built Faraday tent, a structure made of a material that prevents electromagnetic signals from passing through.  

Many of the tested vehicles were EVs—to avoid the risk of running combustion engines in an enclosed space—and included both mass-market and luxury-brand autos from model years 2022 through 2025. 

CR contacted all the automakers whose models were part of our testing, and we heard back from many of them. In statements to CR, several automakers said that some links in their connected apps open outside webpages and that third-party companies can embed pixels and cookies on those webpages, which may, in turn, collect customer data. Northeastern researchers noted that this occurred without warning or the driver’s knowledge.

General Motors, Honda, Nissan, and Stellantis (which owns 14 auto brands, including Chrysler, Dodge, Fiat, and Jeep), said some recipients of driver data were prohibited from independently using or selling any data they are provided. But the Northeastern researchers found those restrictions aren’t necessarily effective: After they showed their findings to Honda, the company instructed one of its vendors, Amplitude, to delete all of the location data it had received and stopped sending it going forward.

Several automakers also noted that many of the apps and services they provide are “opt-in,” meaning that drivers consent to handing over their data when they first register and log in, putting the onus on them. Indeed, the researchers accepted all of the vehicles’ terms and conditions in order to evaluate what types of data were being sent where.  

But popular features sometimes won’t function without this step, and in some cases the vehicle can’t be driven at all. If a Tesla owner declines that company’s data-sharing agreement, they are shown the following warning: “This may result in your vehicle suffering from reduced functionality, serious damage, or inoperability.”

The researchers also note that many users don’t know what they are opting into. Several surveys have shown that most people routinely accept terms and conditions without reading them.

Three Ways Researchers Measured How Much Data Cars Transmit

A team of privacy experts from Northeastern university spent time at CR's Connecticut text facility intercepting network traffic from 21 vehicles and 30 automaker mobile apps.

  1. Illustration of a car on a road emitting WiFi signals near a cell tower

    WiFi interception: WiFi traffic was captured while vehicles were stationary and while being driven at moderate speeds, and with bursts of rapid acceleration, hard braking, and swerving meant to simulate reckless driving.

  2. Illustration of a car inside a Faraday tent

    Faraday tent: Data was captured with vehicles placed in an electromagnetic wave-blocking Faraday tent in order to block cellular signals from the vehicles and isolate their WiFi signals.

  3. Illustration of a phone running a car app sending data to a laptop

    App traffic: Once logged in, testers used all app functionality, including geolocating the car, checking its service history, and, when possible, opening the trunk.

Advertising, Tracking, and Analytics Traffic Coming From Tested Vehicles
Researchers connected each vehicle to a custom WiFi access point and logged all outgoing traffic. Red bars show domain addresses classified as advertising, tracking, and analytics. Gray bars show other third-party contacts, such as apps integrated into infotainment systems (navigation, roadside assistance) and cloud providers.
  • Tesla Model 3
    34
    45
  • Tesla Cybertruck
    23
    43
  • Cadillac Lyriq
    10
    25
  • Lucid Air
    9
    21
  • Chevrolet Blazer
    7
    22
  • Honda Prologue
    5
    21
  • Volvo C40
    3
    9
  • Rivian R1S
    2
    18
  • Ford F-150
    1
    20
  • Ford Mustang
    1
    6
  • Toyota Corolla Cross
    1
    2
  • RAM 1500 Bighorn
    0
    6
  • Fiat 500e
    0
    6
  • Dodge Hornet
    0
    6
  • Subaru Solterra
    0
    6
  • Lexus NX 450h
    0
    5
  • Fisker Ocean
    0
    4
  • Nissan Ariya
    0
    3
  • Land Rover Range Rover
    0
    2
  • Mercedes-Benz EQS
    0
    1
  • Buick Envista
    0
    1
Source: Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem.

Of the vehicles tested, 28 of 30 connected mobile apps sent data to at least one outside advertising and/or analytics company, and seven sent at least one piece of personally identifiable information—the vehicle owner’s name, the car’s VIN, or its precise geographic location—to at least one outside company. 

Four GM companion apps—myCadillac, myChevrolet, myBuick, and myGMC—as well as the HondaLink, MyNissan, and Lincoln apps, were found to be sharing VINs paired with either email addresses or location data. 

The top recipients of driver data included many of the largest tech companies operating in the U.S., including Alphabet (which runs Google), Amazon, Meta (which runs Facebook), Microsoft, Pinterest, and Reddit, among dozens of others. Many of these companies play two roles in the driver data ecosystem, as both providers of software (such as the Android Automotive operating system) and as operators of advertising “auction” platforms that marketers use to target specific types of customers. As such, the companies that collect driver data are often the first node in a vast personal data ecosystem.

The vehicles that sent data to the largest number of outside advertising and analytics companies were the Cadillac Lyriq, Chevrolet Blazer, Lucid Air, and Tesla Model 3 and Cybertruck. Connected mobile apps from BMW, General Motors brands (including Buick, Cadillac, and GMC), and Toyota contacted the largest number of outside companies.

The findings underscore the immense personal data ecosystem that American consumers are unwittingly drawn into when they purchase and use everyday consumer products, including autos. 

The most worrisome privacy finding, the researchers say, is that some of the vehicles and their connected mobile apps shared both a VIN and another identifier, such as the vehicle owner’s name or email address. With those two pieces of info, a major advertising or technology company can link the owner to one of many commercially available consumer profiles, which are sold by data brokers and other companies. The data often includes online behavior and shopping history.

Here’s some advice that may enable you to opt out of sharing and delete your driver behavior data.  

Northeastern Car Data Testing
Researchers built a Faraday tent at CR’s Connecticut auto test track to zero in on the data coming from the tested vehicles.

Photos: John Powers/Consumer Reports Photos: John Powers/Consumer Reports


Derek Kravitz

Derek Kravitz is an investigative journalist on the special projects team at Consumer Reports. He joined CR in 2024, covering the digital marketplace. He has worked as a reporter and editor for more than 15 years and teaches at Columbia University. Three projects he has worked on, for The Washington Post and ProPublica, have been finalists for the Pulitzer Prize. Send him tips or feedback at derek.kravitz@consumer.org or via Signal: @derek_kravitz.31