Study reveals widespread data sharing by connected vehicles

Modern cars share a lot of personal and sensitive data with major tech companies, including Google, Meta, and Microsoft.
Researchers from Northeastern University and Consumer Reports tested 21 late-model vehicles from 17 car manufacturers and 30 mobile apps to understand the privacy implications of the connected vehicle ecosystem.
Analysts tried to determine what data was transmitted and who received it. All vehicles were tested both while stationary and during driving. To see how cars communicated over Wi-Fi, researchers blocked cellular connections.
To minimize background traffic, researchers deleted all non-essential apps from the test phones. The remaining apps were tested one-by-one. All permission requests were accepted during installation and login, such as tracking, location, Bluetooth, notifications, and Calendar access.
The cars that were investigated included models from companies like Ford, General Motors, Honda, Toyota, Mercedes-Benz, Renault, Rivian, and Tesla.
The results show that 19 out of 21 vehicles contacted at least one third party over Wi-Fi, including known advertising and tracking domains such as Adobe, Acxiom, ContentSquare, FullStory, Google, Meta, Microsoft, Pinterest, Snap, and Yahoo.
In addition, 7 out of 30 apps transmitted sensitive identifiers, such as vehicle identification numbers (VINs), phone numbers, email addresses, and location data, to the aforementioned third parties.
“We disclosed our findings to manufacturers, leading to a variety of responses, but with a prevailing theme of shifting the burden of responsibility for data to the end user,” the researchers say in their report.
There was one exception: Honda improved its data collection practices to prevent sending precise geolocation to third parties.
“Our study revealed a large gap between what vehicle manufacturers publicly disclosed and how the connected vehicle ecosystem actually shares data over the Internet, which has explicit privacy implications,” the researchers conclude.
They recommend that there’s a need for more transparency about the privacy risks built into the entire vehicle ecosystem.
Recently, the Dutch General Intelligence and Security Service (AIVD) warned drivers of modern cars to be aware of all the data that is collected and shared through cameras, microphones, GPS, infotainment systems, and connected services.
“Malicious actors are interested in this data and most likely also have access to it. For state actors, these data streams are an attractive source of information,” the intelligence service explained.