Study finds many new cars share your data with third-party companies
The report analyzed traffic from 21 vehicles and 30 automaker apps.
Pinterest probably doesn't need your car's VIN, but General Motors' apps were sending it there anyway — and to Snap, Yahoo, Meta, Google and the data broker Acxiom. At least, that's according to a recent study from Northeastern University, which tested 21 late-model cars and 30 automaker apps on Consumer Reports' fleet between October 2024 and August 2025.
Nineteen of those cars sent data to at least one third-party company via Wi-Fi, with seven of the apps passing identifiers like VINs, email addresses and precise locations to advertising and analytics companies. Four of those seven belong to GM, which has been under a 20-year FTC privacy order since January.
Those four GM apps are myCadillac, myChevrolet, myBuick and myGMC, and each sent VINs to 10 companies including Microsoft and Adobe. Meanwhile, HondaLink sent VINs and location to the analytics firm Amplitude, with the Lincoln and MyNISSAN apps making up the remainder of the list. But unlike a phone's advertising ID, a VIN can't be reset, so pairing one with an email address lets ad companies tie an owner to activity on other apps and websites.
According to Consumer Reports' per-vehicle summary, 10 of the 21 cars contacted no advertising or tracking domains on their own. The Buick Envista and Nissan Ariya were among them, yet pairing their apps exposed owners to 23 and 25 ad and tracking companies respectively. Tesla went the opposite way, with the Model 3 reaching 22 such companies from the car while its app added two. Since the team couldn't decrypt vehicle traffic and could only capture cellular data from the Model 3, these cars' real totals are likely to be higher. For most of the cars tested, the bulk of the ad-tech exposure came from the phone app. Meanwhile, 28 of the 30 apps contacted at least one advertising or analytics company, according to Consumer Reports.
Automakers point to vendor contracts and privacy policies
Back in January, the FTC finalized GM's punishment over its driver data sharing scandal. It handed down an order banning the company from selling driver data for five years to consumer reporting agencies, and says GM must receive express consent before it collects or shares connected vehicle data. It's important to note that Northeastern's testing predates that order, and the researchers haven't alleged a breach of it. GM told Northeastern Global News that it only discloses data to service providers that are contractually barred from selling or using it for their own purposes.
That aside, the researchers did approach 17 manufacturers with their findings and heard back from 14, all of which said the data flows matched their vendor contracts. Seven said it's ultimately the responsibility of the owner to read and accept the terms for every third-party service in the car, including pre-installed software, while five attributed the tracking to web pages opened inside their apps.
The researchers also read the privacy policies of the seven apps that shared identifiers, finding that each disclosed that it may pass personal data to third parties, without saying which ones or why. Owners who decline Tesla's data sharing agreement are warned of "reduced functionality, serious damage, or interoperability," while Rivian says that switching off data collection will limit or disable features like navigation and over-the-air updates.
Honda seems to be the only one willing to change anything, asking Amplitude to delete the location data and updating HondaLink to stop sending it, which a Honda spokesperson confirmed to Northeastern Global News. Northeastern professor and study co-author David Choffnes told the outlet that regulators should step in.