Skip to content

Of 21 cars tested, 19 sent data to third parties: the information ends up with Google, Meta and Microsoft, and carmakers shift the blame, often onto drivers themselves

1 min read
Share
Of 21 cars tested, 19 sent data to third parties: the information ends up with Google, Meta and Microsoft, and carmakers shift the blame, often onto drivers themselves

A modern car with Wi-Fi, GPS and a phone app collects piles of data about its owner - and that data doesn't stay with them. Researchers at America's Northeastern University, working with consumer protection organisation Consumer Reports, tested 21 cars from the latest model lines of 17 manufacturers, as well as 30 companion apps. The peer-reviewed study comes out this week.

The vehicles tested include GM brands Cadillac and Chevrolet, plus Ford, Lucid, Rivian, Tesla and Toyota. The result: 19 of 21 vehicles sent traffic to at least one third party, and 7 of 30 apps handed sensitive data - vehicle identification numbers (VIN), email addresses, phone numbers and precise location - to companies involved in tracking and advertising. Among the firms receiving the data are Google, Meta, Microsoft, Adobe, Snap and Yahoo.

Worse still, the same company often gets several kinds of data at once. That's how advertisers and data brokers build detailed profiles of people, and those profiles are then sold on - including to insurers and banks. Once you're in a profile like that, it's hard to get out. Pairing the app with the car roughly doubled exposure to advertising and tracking companies.

The phenomenon itself isn't new - there have been investigations and lawsuits over how driving data reaches insurers. What's new is the scale, and how hard it is to avoid. There's really only one way out: not using the car, or conveniences like remote start and unlocking. Who buys a new car so they can not use its features?

And how did the carmakers react? All of them except Honda pointed the finger elsewhere, often at consumers themselves. Honda improved its practices and ordered its supplier Amplitude to delete all the geolocation data it had received. Several manufacturers told Consumer Reports that some links in their apps open external pages with cookies that collect data. However the data got there, drivers were never told.

The study is American, but most of these brands are on our streets too, with the same apps on our phones. Has a single regulator in the region even asked where the data from cars sold here ends up?