> ## Content Index
> Fetch the complete content index at: https://bytevyte.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Study Finds Connected Car Data Privacy Failing as 19 of 21 Vehicles Share Driver Data
- URL: https://bytevyte.com/study-finds-connected-car-data-privacy-failing-as-19-of-21-vehicles-share-driver-data/
- Published: 2026-10-04T08:09:50.000Z
- Updated: 2026-10-04T08:09:50.000Z
- Description: A Northeastern University study with Consumer Reports finds connected car data privacy failing: 19 of 21 vehicles and 28 of 30 apps shared driver data.
- Author: Bytevyte Editorial
- Tags: quick-beats

**Connected car data privacy** is failing on a broad scale, according to a Northeastern University study carried out with Consumer Reports. Of 21 vehicles tested, 19 contacted at least one outside company over Wi-Fi, and 28 of the 30 automaker companion apps examined sent data to at least one advertising or analytics firm. Seven apps passed along personally identifiable information, including owners' names, email addresses, vehicle identification numbers (VINs), phone numbers and precise location.

The findings, released this week ahead of the paper's presentation at an academic conference, cover vehicles from model years 2022 through 2025\. Researchers captured network traffic while the cars sat parked, were driven, and were operated through their phone apps, with testing run at Consumer Reports' facility between October 2024 and August 2025\. The paper is titled "Automatic Transmission."

Scope is what separates this work from earlier privacy audits. Past studies usually inspected one layer of the stack, such as an infotainment menu or an automaker's published privacy policy. This project followed traffic across three layers at once: the vehicle, the companion app an owner installs at purchase, and the third-party companies on the receiving end. That combination lets the researchers tie a specific model to a specific data recipient.

## Connected Car Data Privacy: What the Tests Recorded

| Measure                                                          | Result                       |
| ---------------------------------------------------------------- | ---------------------------- |
| Vehicles tested                                                  | 21, model years 2022 to 2025 |
| Companion apps tested                                            | 30                           |
| Vehicles contacting a third party over Wi-Fi                     | 19 of 21                     |
| Vehicles contacting an advertising, tracking or analytics domain | 11 of 21                     |
| Apps sending data to an advertising or analytics firm            | 28 of 30                     |
| Apps transmitting personally identifiable information            | 7 of 30                      |
| Apps contacting more than five ad, tracking or analytics domains | 70%                          |

The two middle rows are where the story sharpens. Almost every vehicle reached an outside server, but only 11 of the 21 connected to a domain tied to advertising, tracking or analytics. The apps leaked far more widely, with 70 percent of them touching more than five unique advertising, tracking or analytics domains.

The researchers sorted the traffic into three groups: first parties such as the automaker itself, car-specific support services, and third parties known to provide advertising and tracking. Only the last group sits outside the job a driver asked the car to do when they bought it. Automakers market connectivity as a safety and convenience feature, and the recorded traffic shows ad and analytics domains moving alongside those functions.

## Who Sits on the Receiving End

Amazon, Google, Meta and Microsoft appear among the recipients, joined by Pinterest, Snap, Yahoo and Adobe. The vehicles that sent data to the largest number of outside advertising and analytics companies included the Cadillac Lyriq, Chevrolet Blazer, Lucid Air, Tesla Model 3 and Tesla Cybertruck. Traffic from companion apps tied to BMW, General Motors brands and Toyota also appeared in the capture.

VINs deserve separate attention. A vehicle identification number is not an anonymous device tag, because it maps to registration and service records, so sharing it links a physical car and often a household to whatever profile an advertising or analytics company assembles. Email addresses and phone numbers do the same job for the owner. Seven of 30 apps is roughly one in four, a small share that carries outsized risk because the identifiers are durable rather than resettable.

Breadth matters as much as volume here. Nearly every automaker in the test sent driver-related data to outside companies, so brand loyalty offers no insulation, and switching from one tested marque to another would not remove the traffic. The recipients were also familiar names rather than obscure brokers, which widens the reach of any single profile built from the data while narrowing the list of parties a driver could realistically contact to limit exposure.

## The App Multiplier and the Opt-Out Problem

Pairing a phone app to a car roughly doubled that vehicle's exposure to advertising and tracking companies on average. The mechanism is straightforward: the app adds a second data channel, running on a device that already knows where the owner is and who they are, on top of the telematics link built into the car. Researchers observed the apps under the same conditions as the cars, parked, driven and operated remotely, so the traffic is not limited to moments when a driver deliberately opens the app.

For owners, the practical remedy is thin. Data-sharing controls exist, but the flows are woven into features people use daily, so switching them off carries a functional cost. That tension is the core of the connected car data privacy problem: the connectivity behind remote start, navigation and over-the-air updates is the same channel carrying the data out.

## Where This Leaves Drivers

Three conclusions follow from the numbers. The exposure is not limited to the newest models, since the tested fleet covered model years 2022 to 2025 and recent used cars carry the same traffic patterns. The app is the weaker link, which means the risk travels with the phone rather than staying in the driveway. And most recipients are companies that already hold detailed profiles of the same people through search, social and shopping services, so vehicle data adds a location and identity layer to an existing picture.

No source in the study points to a rule that would force automakers to stop sending this traffic, and the researchers place the burden on how the connected vehicle ecosystem is designed. For a buyer, the practical shift is that a car's data terms are now a purchase consideration in the same category as range or warranty, because they govern a device that sits at the owner's home address.

## Why this matters

The study turns a general worry about smart cars into a measurable one. Drivers now have a documented account of which brands and apps pass data to whom, and the pattern shows the problem sits in the product architecture rather than in one company's policy choices. The next signal to watch is whether automakers adjust their data-sharing defaults, since the same connectivity that makes modern cars useful is the channel the researchers measured.

## Sources

[Your car's app could be telling Big Tech who you are and where you go](https://www.malwarebytes.com/blog/news/2026/09/your-cars-app-could-be-telling-big-tech-who-you-are-and-where-you-go?ref=bytevyte.com)

Photo by [Anil Baki Durmus](https://unsplash.com/@anldrms?utm%5Fsource=bytevyte&utm%5Fmedium=referral) on [Unsplash](https://unsplash.com/?utm%5Fsource=bytevyte&utm%5Fmedium=referral)

✔Human Verified

---

*Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.*