Connected cars and their associated apps are increasing interactions with third-party services, according to a study conducted on 21 vehicles and 30 apps by Northeastern University researchers with Consumer Reports. The work is not limited to analyzing privacy policies: it looks at the network traffic actually generated by recent models sold in the United States.

Cars observed on the road and in a Faraday cage.
The researchers tested 21 vehicles of 19 brands in various situations: stopped, in traffic and while using multimedia functions. They placed a small computer in the cabin to route the car’s Wi-Fi through a controlled access point. For 11 electric models, they also used a Faraday enclosure large enough to contain the vehicle. By blocking the cellular connection, this installation forced some cars to transfer their communications to Wi-Fi, where their destinations became visible.
This method has an important limitation. Because the packets were encrypted, the computer generally could not read their contents. However, it identified the areas contacted, the frequency and volume of exchanges, as well as variations depending on the scenario. IAutomatic transmission study Therefore, it measures network relationships and exposure to third-party actors, without claiming that each connection systematically transmits all data available in the vehicle.
According to the results reported by the researchers, 19 cars out of 21 have contacted at least one domain outside of their manufacturer. Infotainment systems that integrate additional services logically create more connections: cartography, music, advertising, audience measurement or usage analysis are added to the servers necessary for the operation of the vehicle. We had already mentioned the arrival of Gemini in cars, which illustrates the growing place of software and online services in the cabin.
Apps add a second layer of tracers
The mobile dashboard is more directly revealing, as application flows can be examined more precisely. among the 30 companion apps Of the tests, 28 contacted at least one advertising, analytics or tracking company. More than 70% included at least five. Overall, combining the app with the vehicle has nearly doubled the number of businesses likely to receive usage-related signals.
Seven apps (HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick, and myGMC) transmitted at least one sensitive identifier to a third party. Investigators cite in particular the vehicle serial number, telephone number, email address or exact location. The risk arises from their combination: an isolated VIN describes a car, but a VIN associated with an identity and a location allows a much more detailed profile of the driver to be built.
This circulation does not necessarily mean that manufacturers sell all this information directly. Technical services, analysis libraries and advertising modules may receive data under contracts. The study highlights, however, that the user rarely distinguishes between these roles when accepting, sometimes at the dealership and on an awkward screen, various legal texts to activate the expected functions. Refusal may also disable location, remote control or service history.
Honda changed its application after the report
The researchers contacted 17 manufacturers and got 14 responses. Several claimed that their partners were contractually limited by confidentiality policies. Others shifted the responsibility to the choice of cookies or the user’s acceptance of the terms. These explanations do not eliminate the readability problem, while the vehicle remains an expensive and long-lasting purchase, very different from a free online service.
Honda took a concrete step: after being informed of the observations, the manufacturer asked its service provider Amplitude to delete the collected location data and modified HondaLink so that it no longer transmitted the precise position. This precedent serves as a reminder that transfers can be corrected once documented. In France and the European Union, its legality would depend in particular on the purpose, legal basis and quality of consent; The CNIL has already sanctioned the insufficiently authorized transmission of customer data to a social network.
The sample refers to vehicles marketed in the United States and does not allow brand-by-brand extrapolation to European versions, whose software, contracts and obligations may differ. However, the authors publish their methods and network targets to allow later verifications. Manufacturers that have not yet responded have not announced a fix schedule or a common mechanism for disabling trackers without losing essential connected functions.






