Security1 publisher2 min readPublished
Carmaker companion apps pass driver data to ad or analytics firms in 28 of 30 tested
Northeastern and Consumer Reports found 28 of 30 connected-car apps share data with at least one third-party ad or analytics firm. The data leaves through apps installed at purchase, so a vehicle privacy review starts with the companion app and its partners.
The Watch · Security desk

What happened
- Seven of the 30 apps sent at least one piece of personally identifiable data, such as a name, email address or precise location, to an outside company.
- GM's myCadillac, myChevrolet, myBuick and myGMC apps, plus Honda, Nissan and Lincoln apps, send vehicle identification numbers bundled with location data or email addresses.
- The researchers found that 19 of the 21 major automakers studied collect customers' private data and disseminate it broadly.
- After Consumer Reports notified it, Honda told an analytics and tracking vendor to wipe all ingested location data and stop sharing it with third parties.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A VIN paired with a location or an email lets a data broker tie driving patterns to a specific person and sell them, the researchers said.
- contradiction The opt-in defense automakers offer is disputed: Consumer Reports says drivers often do not know what they accepted, and some are warned the car may be inoperable if they opt out.
- decision Contract terms barring some recipients from independent use or sale are the automakers' stated control, and a privacy review has to weigh them against recipients that also run ad auctions.
No exploit is involved. The researchers followed data from the car to the companion app a buyer downloads at the point of sale, and from the app to third-party companies [15]. Advertising and analytics sharing covers 93 percent of the apps tested [1].
Consumer Reports named Alphabet, Amazon, Microsoft, Meta, Reddit and Pinterest among the recipients, alongside advertisers and analytics firms [7]. "Many of these companies play two roles in the driver data ecosystem, as both providers of software ... and as operators of advertising 'auction' platforms that marketers use to target specific types of customers," Consumer Reports said in its release [8]. "As such, the companies that collect driver data are often the first node in a vast personal data ecosystem," the release said [9].
A second path runs through the browser. Several manufacturers told Consumer Reports that links embedded in their apps lead to external webpages where third-party firms can place cookies and pixels [11]. Those pages can collect consumer data, typically without the driver knowing, according to the release [11].
Regulators have moved on connected-car data twice. The Federal Trade Commission warned automakers to step carefully in 2024 [14]. In May, California Attorney General Rob Bonta, the California Privacy Protection Agency and four local prosecutors fined GM more than $12 million [6]. The same order barred GM from sharing driver data with credit reporting agencies and data brokers for five years [6]. GM's brand apps are among those the new study found pairing VINs with location or email [4]. The coverage does not say when that app traffic was captured relative to the California order, or whether fleet and commercial accounts were in the test set.
None of the automakers named immediately responded to The Record's request for comment [16].
What to watch
- Whether California regulators or the FTC act on the Honda, Nissan and Lincoln VIN findings the way California acted on GM in May.
- Whether the full report dates the GM app traffic before or after the May California order.
- Whether other named automakers follow Honda in ordering vendors to delete collected location data.