19 of 21 Connected Cars Shared Data, Northeastern Study Finds

Nineteen of 21 late-model cars tested sent data to third parties in a Northeastern University study of connected-car privacy.
The work looked at late-model vehicles and their companion phone apps, according to Road & Track. The cars sent location data, vehicle identification numbers (VINs) and other identifiers to Big Tech companies, according to Consumer Reports. A VIN is the unique serial number assigned to each car for its life. The researchers described the scope as an investigation into what data car manufacturers are collecting.
Northeastern published the research on Sept. 29, 2026, in a news article titled 'Your car is collecting more data about you than you think' about connected-car privacy-violation research (Northeastern News). Khoury College hosts a dedicated site for the project titled 'Automatic Transmission' at automatictransmission.khoury.northeastern.edu. Coverage included an Oct. 2, 2026 Yahoo Autos article titled 'Northeastern Study Catches Connected Cars and Their Apps Feeding Driver Data to Ad Tech'.
In my view, that share is the point. Nineteen out of 21 is not a rare bug in one head unit or one app version. It points to data leaving cars as a normal part of how the systems are set up.
Looking at what this means for systems design, the combination of data types is the central problem. Location shows where a person goes in fine detail. A VIN stays with one car for its life. Other identifiers act as matching keys. When those leave the car or phone together to outside-company servers, it becomes straightforward to link trips to a single vehicle even if no name, email address or account ID is included.
Looking at it from a builder's perspective, the split between car and app widens the problem. Cars and companion apps update on different schedules and have different permission rules, consent screens and data-reporting software. That creates two paths out. An app can ask for location through the phone's operating system while the car sends VIN and trip status through its built-in cellular link, with the matching done on company servers.
The broader context here will be familiar to anyone who has followed phone privacy. Once lasting identifiers and location go to outside firms, the issue moves from collection to how long data is kept, who it is shared with and how it is matched. Common fixes are to collect less at the source, keep data for a short time, share only rough location and change identifiers often. That last fix is hard when the identifier is designed not to change.
Looking at what this means for operators and company buyers, connected cars now belong in the same data list as phones and laptops. Fleet cars, take-home vehicles and employee-installed companion apps all carry exposure of location and identifiers. Recording which internet addresses cars and apps contact, and which data fields are sent, is basic hygiene. The Northeastern project gives teams a public reference to ask vendors for data-flow documents and opt-out steps.
Worth flagging as an open question is how much of this flow drivers can see, and which settings actually stop it. The confirmed findings cover collection and sharing. They do not by themselves settle consent or legal compliance. For owners, the practical step is the same as with any sensor-filled platform. Assume collection, check privacy settings in both the dashboard system and the app, and turn off permissions not needed for the feature in use. Clearer reporting of this kind has, over time, led to better tools and clearer defaults.


