In the 21st century, the digital footprint of an average consumer extends far beyond smartphones, laptop computers, and smart home devices. According to a groundbreaking new joint study conducted by researchers at Northeastern University and consumer advocacy organization Consumer Reports, the modern vehicle sitting in the driveway is actively gathering intimate details about its driver and transmitting that information to advertisers, major technology conglomerates, and a wide array of unexpected third parties—often entirely without the owner’s knowledge or explicit consent.
For privacy-conscious consumers who routinely turn off location tracking on mobile applications, decline cookie permissions on web browsers, and scrutinize software privacy settings, the findings of this new investigation present an alarming reality. The connected vehicle ecosystem has rapidly transformed personal automobiles into rolling data-harvesting machines, capturing everything from granular geographic movements to personal device identifiers and tying them directly back to individual ownership records.
To understand the full scope of data collection happening inside modern transport, Northeastern University researchers collaborated with Consumer Reports to analyze a diverse fleet of 21 connected vehicles. The tested sample covered 19 prominent automotive brands sold widely across the United States, representing model years ranging from 2022 to 2025. Additionally, the study evaluated the official companion smartphone applications associated with these vehicles, such as HondaLink, MyNissan, and myCadillac, which drivers frequently download to manage remote start features, check tire pressures, or monitor electric vehicle charging statuses.
Gathering telemetry and network traffic from modern automobiles proved to be a formidable technical challenge. Because modern vehicles route communications through encrypted cellular and Wi-Fi channels, researchers had to develop innovative, specialized methods to intercept and reroute data packets from both the vehicles and their companion smartphone applications directly to dedicated data collection servers. For electric vehicles specifically, the research team went so far as to utilize a specialized Faraday Cage tent. This portable signal-blocking enclosure allowed them to completely isolate the cars from cellular towers to observe whether onboard computers would automatically reroute sensitive data streams over local Wi-Fi networks instead.
Privacy and the Connected Vehicle Ecosystem
What the researchers ultimately uncovered paints a troubling picture of an automotive industry deeply intertwined with the data broker economy. When looking at the connected vehicle ecosystem as a whole, the concept of data privacy appears largely relative—if not entirely nonexistent—for anyone operating a modern car equipped with connected infotainment systems or manufacturer apps.
The investigation revealed that an extensive network of data pipelines regularly channels information collected by the vehicle and its associated mobile apps straight to some of the world’s largest technology companies. Among the primary recipients identified in the network traffic analysis were digital giants such as Alphabet, the parent company of Google; Amazon; streaming platform Spotify; Microsoft; and Meta, the parent company of Facebook and Instagram. Perhaps more surprisingly, the top tier of data recipients also included Liberty Media Corporation, the multinational mass media company that owns major international racing properties including Formula 1 and MotoGP.

The trail of data grows even more bizarre and intricate the deeper one investigates the network destinations. Vehicles and their companion apps were frequently found transmitting telemetry and behavioral data to third-party entities spanning diverse consumer sectors, including Yahoo, Comscore, Comcast, social media platform X, The Walt Disney Company, Nielsen Holdings, and even the corporate owners of the neighborhood networking app Nextdoor.
Companion smartphone applications painted an equally concerning picture regarding third-party data sharing. Among the unexpected corporate names appearing on the receiving end of app-driven data transmissions were visual discovery platform Pinterest, social forum Reddit, electronic signature provider Docusign, business data firm Dun & Bradstreet, and Press Ganey Forsta, a major healthcare experience software company. For millions of Americans who have ever visited a doctor’s office, clinic, or hospital, the name Press Ganey is likely familiar as the entity responsible for sending post-visit satisfaction surveys.
The most legally and privacy-sensitive finding of the study, however, involved the direct transmission of Vehicle Identification Numbers—commonly known as VINs—to third-party tracking sites. Researchers discovered that a subset of major automotive brands routinely bundled unique VINs alongside persistent user identifiers such as precise geographic locations, personal email addresses, and phone numbers.
This specific practice carries significant implications for drivers. By linking a permanent vehicle identification number to personal contact information and location data, third-party data brokers can seamlessly bridge the gap between offline physical travel habits and online behavioral profiles. This effectively allows advertisers to merge a driver’s daily commuting patterns and destination history with purchase histories and browsing data collected by unrelated mobile applications on their smartphones. The automotive brands identified by researchers as actively sharing VINs alongside user identifiers included Honda, Nissan, Lincoln, and the broader General Motors vehicle suite, which encompasses Cadillac, Chevrolet, Buick, and GMC.
Opt-in to Drive, Opt-out with Problems
Following the conclusion of their technical analysis, researchers directly confronted the participating automotive manufacturers with their findings to seek explanations for the extensive data pipelines. In the wake of the discussions, some responsiveness was observed. Honda, for instance, instructed its third-party application partner to completely purge all previously received location data from its databases and subsequently deployed an application update designed to halt the ongoing collection and transmission of location metrics.
Other manufacturers, however, displayed a marked lack of concern regarding the privacy implications. When Northeastern University asked the various brands to justify why such extensive data sharing arrangements existed with third-party advertising and analytics companies, many manufacturers defended the practice by stating that the data transfers fully complied with existing third-party service contracts. Several companies casually noted that data transmission is simply an inherent byproduct of utilizing embedded web browsers and software services that power modern vehicle infotainment applications.

A few manufacturers pointed out that their connected applications prompt users to either accept or reject cookies upon initial setup, though researchers noted that these consent prompts were not always functioning reliably or transparently in practice.
When pressed on how consumers could prevent their vehicles from gathering and transmitting personal information, manufacturers frequently placed the burden squarely on the shoulders of the consumer. While certain modern vehicles do feature settings allowing drivers to opt out of data collection programs, exercising that choice often comes with severe operational penalties that effectively compromise the usability of the vehicle.
Documentation highlighted in the study reveals that Tesla’s data opt-out warning explicitly cautions drivers that disabling data sharing "may result in your vehicle suffering from reduced functionality, serious damage and inoperability." Similarly, electric vehicle manufacturer Rivian provides a stark warning to owners attempting to opt out of data tracking, noting that doing so will "limit or disable certain functionality in the vehicle (e.g., navigation, lane keeping assistance, and over-the-air updates, which provide new features, better performance, safety enhancements, and bug fixes)." For modern vehicle owners, the practical choice is stark: either accept continuous data harvesting as a mandatory condition of modern transportation, or accept a crippled vehicle with disabled safety features and navigation systems.
In an era where public sentiment has grown increasingly hostile toward automated surveillance, automated license plate readers, and artificial intelligence-driven data collection in public spaces, the pervasive tracking emanating from consumer automobiles represents a largely unregulated frontier of digital monitoring. The findings highlight deep vulnerabilities for owners of modern vehicles, particularly those driving models produced by General Motors, Nissan, and Lincoln. As scrutiny mounts over how personal information flows from the dashboard to corporate servers, these revelations add fuel to ongoing national debates surrounding consumer digital rights and transportation independence.