Security4 publishers2 min readPublished
Seven of 30 car companion apps sent sensitive identifiers to ad and tracking firms in Northeastern tests
Northeastern University and Consumer Reports found 7 of 30 car companion apps sending sensitive identifiers to advertising and tracking firms. Paired with a VIN or precise location, such identifiers can link a car's movements to the profiles ad firms and data brokers already hold.
The Watch · Security desk

What happened
- Consumer Reports read thousands of pages of privacy policies and questioned BMW, Ford, GM, Honda, Hyundai, Kia, Mazda, Mercedes-Benz, Mitsubishi, Nissan, Stellantis, Subaru, Tesla, Toyota and Volkswagen.
- The same consent forms can also pop up in a connected mobile app, and many owners accept the terms without reading them.
- Insurers and lenders receive the data as partners in telematics data exchanges that compile driving data on millions of drivers.
- Local and state government agencies working on planning, traffic and safety projects are also among the recipients.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Drivers who finance a car or buy insurance can be assessed on trip data they did not knowingly hand over.
- decision Fleet operators have to treat vehicle provisioning as a consent event and decide who accepts the first-start forms, and whether anyone should.
- constraint The controls are the consent screens and the purchase or lease terms, so privacy and procurement staff own this exposure and the security team supports them.
No exploit is involved. The data leaves under terms someone accepted, and Consumer Reports wrote that "you may agree without knowing you've done so" [5]. The agreement arrives as a series of consent forms, privacy policies among them, on the infotainment display that also controls heat and AC, navigation and music [6].
CR's account assumes the person at that screen is the buyer of a new car [6]. In a fleet, the person at the screen is whoever provisions the vehicle. The terms they accept then cover data from the drivers who take it out later [1].
On insurance, CR's evidence is about who buys the data. CR reviewed corporate, regulatory and legal filings from insurtech brokers, the companies that help insurers set their rates [3]. Thousands of data brokers on the receiving end build personalized risk scores [9]. The schneier.com post that carried the excerpt went further: "Basically, your car's manufacturer has you under constant surveillance, and they use that data against you" [11]. The research supports the collection half of that sentence. The excerpt does not say which of the 15 automakers send data to which buyers, or show a premium that changed because of one driver's trips [2].
The buyers extend past insurance. Companies selling infotainment and WiFi hotspot products receive the data too [12]. Several car privacy experts CR spoke with have described the profit potential of individual driving data as the "new oil" at industry conferences and in market reports [4].
What to watch
- Per-automaker results showing which of the 15 brands send data to telematics exchanges or insurtech brokers.
- An insurer or lender disclosure tying a rate or credit decision to data bought from a telematics data exchange.
- Regulatory or legal action over consent captured on first-start infotainment screens.