Contemporary vehicles, equipped with advanced connectivity features like Wi-Fi and GPS, are continuously gathering vast amounts of information about their users. A new investigation, conducted collaboratively by researchers at Northeastern University and Consumer Reports, indicates that this collected data is frequently not kept confidential. This phenomenon is not entirely novel, as numerous previous inquiries and legal actions have shed light on the practices of collecting and sharing driving-related data with various third parties, including insurance providers. However, the current study underscores the sheer scale of this issue and the inherent difficulty for consumers to circumvent it, unless they forgo using their vehicles or convenient functionalities such as remote start and unlock systems.
The research involved assessing 21 late-model automobiles from 17 different manufacturers, encompassing brands like Cadillac, Chevrolet, Ford, Lucid, Rivian, Tesla, and Toyota. Additionally, 30 associated mobile applications were scrutinized to comprehend the privacy implications within the connected vehicle ecosystem. The findings, which will soon be published in a peer-reviewed study, suggest significant implications for consumer privacy. Personal data is being routinely transmitted to major technology companies, including Adobe, ContentSquare, Google, Microsoft, Meta, Snap, and Yahoo.
Specifically, 19 of the 21 tested vehicles were found to transmit data to at least one external party. Furthermore, seven of the 30 examined applications shared sensitive details, such as the vehicle identification number (VIN), email addresses, phone numbers, and precise geographical locations, with third-party entities involved in tracking and advertising. This data transmission often extends to multiple forms of information being sent to the same third party, thereby facilitating advertisers and data brokers in constructing comprehensive consumer profiles. These profiles are particularly challenging for individuals to manage or dispute, as they are distributed among a diverse array of companies, including insurers and financial institutions.
The study also revealed that linking a companion application to a vehicle approximately doubled the exposure of user data to advertising and tracking companies. When these findings were presented to the manufacturers, most, with the notable exception of Honda, attributed the issue to other parties or to consumers themselves. Honda, however, responded constructively by enhancing its data collection practices after reviewing the results and instructed its vendor, Amplitude, to erase all previously obtained geolocation data. Several other automakers informed Consumer Reports that certain links within their companion applications led to external webpages, which might incorporate cookies designed to collect customer data. Irrespective of the method of collection, drivers were largely unaware of these data-sharing practices.
The research emphasizes the critical need for increased transparency and stronger consumer protections regarding personal data generated by modern vehicles. The intricate web of data collection and sharing poses substantial privacy risks, transforming everyday driving into an activity that continuously feeds information to a broad spectrum of tech and data firms. This situation necessitates a more proactive approach from both manufacturers and regulators to safeguard consumer data in the evolving landscape of connected automotive technology.
