Product1 publisher3 min readPublished
Every car in Northeastern's 21-vehicle privacy test sent data to third parties
Northeastern and Consumer Reports found all 21 cars they tested sent data to third-party domains, with more than half reaching ad or analytics firms. For fleet buyers and carmakers' product teams, the brand's phone app is the first place to check.
The Product Desk · Product desk

What happened
- The sample was 21 late-model vehicles from 19 brands sold in the US, plus 30 companion apps linked to active vehicles.
- Seven companion apps, including HondaLink, MyNissan and myChevrolet, sent VINs, phone numbers and precise locations directly to advertising networks.
- The researchers could identify where the cars' own traffic went but could not decrypt its contents without hacking the vehicles.
- The FTC penalized GM last year for collecting and selling precise location and driving behavior data without informed consent.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- exposure Drivers who paired one of the seven apps have a VIN and a phone number sitting together at ad networks, enough for an outside firm to tie a named person to a specific car.
- decision Fleet buyers and automakers can treat the choice of infotainment platform as a privacy decision, since the lead researcher ties the platform directly to how much data leaves the car.
- constraint Regulators cannot build a GM-style sale case on the car-side results alone, because the study shows recipients and never the contents of what the cars sent.
- precedent Penalties so far have turned on consent and hard-to-use opt-outs, so an automaker's settings screen is where its legal exposure is easiest for an outsider to check.
Working with Consumer Reports and cars from its test fleet [5], the Northeastern team put a Raspberry Pi inside each vehicle and joined it to the car's Wi-Fi. The Pi's internet ran through a mobile hotspot, so the team could log outgoing traffic while the car was driven [8]. Cars also talk over cellular networks. To avoid running an unauthorized cellular base station, the researchers built a car-sized Faraday tent that cut the link to cell towers and pushed each vehicle onto the Wi-Fi they were watching [9].
That rig records destinations. For the cars, destinations are all it could record, because the payloads stayed encrypted [7]. The finding that every car reached a third party [1], and that at least 11 of the 21 reached advertising, tracking or analytics domains [1], describes who receives the traffic. GM was penalized for selling location and driving data without informed consent [3]. Encrypted car traffic cannot show a sale, and it cannot show what an owner agreed to.
In my view the evidence supports a narrower claim than an industry-wide version of the GM case. Outside recipients are standard across the 19 brands in the sample [6]. The car-side data does not establish whether other carmakers sell what those recipients get. David Choffnes, the project lead and a former director of Northeastern's Cybersecurity and Privacy Institute, said the aim was to show how little visibility or control owners have [17]. "I think the conclusion is that there's a lot to be worried about," he said [15].
The phone apps are where the contents showed up. An owner who pairs a brand's companion app sees a way to reach the car. In seven of the 30 apps tested, about 23 percent, the same app sent that owner's details to ad networks [3]. More than 21 of the 30 contacted at least five distinct ATA domains [2]. According to The Verge, firms in that category, such as Adobe, LexisNexis and Amplitude, gather vehicle and driving details to sell to insurers or to target ads [10]. Honda's app is one of the seven [13], and Honda has already faced a minor fine over an opt-out that was too hard to use [4].
The infotainment platform changes the count too. Choffnes said an automaker's choice of software directly affects how much data reaches third parties, and Google's platform has built-in routines that talk to Google and to outside companies [12]. "A lot of the tracking we also see through the apps that are built into the car," Choffnes said. "So now, cars are essentially turning into the global smartphones." [16]
For a fleet manager or an automaker's product lead, I'd sort each data flow on a 2x2. One axis is the recipient: a service the driver asked for, or an advertising, tracking or analytics company. The other is control: whether the owner can find the off switch and use it. Every penalty in the record so far turned on the control axis [3] [4]. I'd start the review with the companion app, the one channel where the researchers could read personal data reaching ad networks [13]. The tradeoff is in the infotainment. Cars with advanced systems, especially those on Android Automotive with Google Automotive Services, contacted the most third-party domains [11].
What to watch
- Any FTC or state action against another automaker whose cars or apps appear in the study, which would show whether the GM case is being applied more widely.
- Per-brand results from Northeastern or Consumer Reports for the car-side traffic, showing which of the 19 brands reach advertising domains.
- Changes to the seven companion apps' ad-network connections or to Google Automotive Services defaults after publication.