19 of 21 Cars Sent Data to Third Parties, Study Finds

Nineteen of 21 late-model vehicles tested by researchers at Northeastern University and Consumer Reports contacted at least one third party over the network. The team studied production connected-car systems and their companion phone apps to see where vehicle and account data actually goes.
The test fleet covered 21 vehicles from 17 automakers, described as 19 brands across the reports, and the researchers also analyzed 30 companion mobile apps to map the full connected-vehicle system. Tested nameplates included GM brands Cadillac and Chevrolet as well as Ford, Lucid, Rivian, Tesla and Toyota, among others TechCrunch. The study was published on Sept. 29, 2026 Consumer Reports.
Cars sent driver data including locations, VINs and other identifiers to large technology companies, according to the Consumer Reports account of the findings. A VIN is the vehicle identification number, the permanent ID stamped on the car and its paperwork. At the app layer, researchers saw emails, phone numbers, VINs and precise location going to external parties.
Named recipients included Adobe, ContentSquare, Google, Microsoft, Meta, Snap and Yahoo. Seven of the 30 companion apps sent sensitive fields such as VIN, email, phone number and precise location to third-party tracking and advertising companies. On the vehicle side, 19 vehicles contacted at least one third party, whether or not a sensitive payload was confirmed in every flow.
Linking the companion app to the vehicle roughly doubled exposure to advertising and tracking companies. The phone holds contact identity, login state and location permission, while the car holds the VIN, trip history and location from its own sensors. Connect the two and the records are easier to link to one person.
Honda provided the one vendor-level fix disclosed in the reporting. The company said it had improved its data collection practices and ordered its vendor Amplitude to delete all geolocation data it had received.
The broader context here is why that combination is hard to reverse. A VIN does not rotate like a password can. Precise location reveals behavior over time in a way a network address rarely does. Once those are joined with an email or phone number from a logged-in app session, the record ties a specific person to a specific car and its movements, and that is difficult to anonymize after collection.
Looking at what this means for teams that ship connected products, the pattern is familiar. It comes from including third-party code by default, requesting broad permission scopes, and linking accounts in a way that merges car data with phone data. Deletion on instruction does not undo past collection, but it does show downstream control is possible. The correction is inventory of network destinations for each build, blocking third-party traffic by default, sending only minimum necessary fields to processors under contract, and logging what was sent to whom. For technically inclined drivers, careful permission settings and restraint around pairing can reduce exposure, though neither replaces minimization by the manufacturer.
In my view, there is reason for measured optimism. Independent network testing is getting cheaper and easier to repeat, and automakers have shown they will change collection and push vendors to delete data when findings are specific. I watched my own children treat location sharing as the cost of a useful app, then think twice once they grasped how long that history lasts. The same connected technology enables remote preconditioning, stolen-vehicle recovery and predictive maintenance. The task now is to keep those uses while removing the silent extra recipients.


