Every technological device we possess, ranging from smartphones to refrigerators and even dog collars, remains online around the clock. They gather insights about us, hold information regarding our preferences, and often utilize this data to simplify our lives. Automobiles, in particular, gather critical driving and behavior analytics, making it almost impossible to decline this data collection if one wishes to enjoy the contemporary features of their vehicle. A recent study uncovered that your private information (much of which may not even pertain to the vehicle) is being disseminated to more parties than you might expect.
The only individuals who might find what follows unexpected are those who have been disengaged from society for the last ten to twenty years. However, for those of us who have a basic understanding of how the technology we depend on interacts with us and the data we generate, this recent study conducted by Boston’s Northeastern University in collaboration with Consumer Reports will likely raise your eyebrows on multiple occasions.
This investigation examined 21 vehicles from 19 different brands (detailed below) and 30 associated mobile apps that handle and process user data.
You can explore the full 18-page report here, but you can also find the key points summarized below:
- Companion Apps Transmit Data That Extends Beyond Vehicle-Related Information: 70% of companion apps interacted with over five unique ATA (advertising, tracking, analytics) domains, typically sharing data such as location, timing, and other information packets. For the majority of test vehicles, adding the manufacturer’s or a third-party (usually pre-loaded) app at least doubles the number of ATA companies exposed to the owner’s data. The Envista and Nissan Ariya, which were nearly silent independently, each reached over 20 ATA companies once the app is factored in. myCadillac linked to 51 ATA domains.
- The Number of Third-Party Apps Contacting Your Vehicle Varies Drastically: Over Wi-Fi, vehicles reached a maximum of four first-party domains but averaged around nine integrated third parties. The Tesla Model 3 contacted 34 ATA domains while the Cybertruck reached 23; however, the Mercedes EQS and Buick Envista reached no third parties. Thirteen of the 21 vehicles connected to Google ATA domains, including some like doubleclick.net that aren’t necessary for core functions. Vehicles utilizing Android Automotive and Google services contacted significantly more trackers, and even vehicles from the same manufacturer behaved differently; it is particularly noteworthy that the Envista, Lyriq, and Blazer did not exhibit similar behaviors.
- Certain Apps Transmit Your VIN to Vendors, Something Your Smartphone Can’t Perform: Seven apps (19 out of 21 cars) relayed personal data to ATA third parties: all four GM apps, HondaLink, Lincoln, and MyNissan. VINs were the most frequently transmitted, sent to recipients such as Google, Microsoft, and Meta. The concern is that having a VIN alongside an email, phone number, or location allows an advertising company to link an individual to their online activity and purchase history. The study also underscores that a VIN cannot be reset as a phone’s advertising ID can. Additionally, I recently posted a blog discussing how I enjoyed Honda’s infotainment with Google Built-in and made a lighthearted comment about the cost I’m willing to incur for convenience.
- OEMs Primarily Shift Responsibility to Their Partners and Suppliers: Out of 17 manufacturers contacted for the study, 14 responded, all stating that their vendor contracts addressed data flows. Five blamed embedded browsers within their apps, while seven insisted that it is the consumer’s duty to read third-party terms. Naturally, if you choose to opt out or simply do not utilize the features, you will not be maximizing your vehicle’s capabilities. Tesla cautioned about diminished functionality or complete inoperability, while Rivian mentioned issues with disabled navigation and over-the-air updates. The privacy policies stated that data could be shared with third parties but did not specify which ones or the reasons why. Only Honda adjusted its approach, instructing Amplitude to delete the location data it retrieved and prevented the app from sending it. Kudos to Honda.
- Collecting This Data Was Challenging: Even if you solely utilize the official apps installed in your vehicle, some of them might connect to your mobile phone, ultimately leading to the opening of your browser. Once that occurs, the entire data flow is altered as it adheres to your phone’s browser settings rather than your car’s. This means your vehicle is now receiving cookies and browsing information and sharing them in ways you might not be aware of.
The vehicles involved in the study are as follows:
- 2024 Buick Envista
- 2024 Cadillac Lyriq
- 2024 Chevrolet Blazer
- 2023 Dodge Hornet
- 2024 Fiat 500e
- 2025 RAM 1500 Bighorn
- 2023 Fisker Ocean
- 2022 Ford F-150 Lightning
- 2024 Ford Mustang GT Fastback
- 2024 Honda Prologue Touring AWD
- 2023 Land Rover Range Rover Sport
- 2024 Lexus NX450h+ PHEV
- 2023 Toyota Corolla Cross
- 2023 Subaru Solterra
- 2023 Lucid Air Touring
- 2023 Mercedes-Benz EQS450 4Matic
- 2023 Nissan Ariya Platinum
- 2022 Rivian R1S
- 2024 Tesla Cybertruck
- 2024 Tesla Model 3
- 2024 Volvo C40
Have a suggestion? Reach out to us at [email protected]
**Your Vehicle Is Revealing More Personal Data Than Your Smartphone: Who Is Receiving This Data?**
In today’s connected era, our automobiles have become intricate machines outfitted with advanced technology that frequently outmatches our smartphones. Contemporary vehicles are now capable of gathering and transmitting extensive amounts of data, heightening concerns about privacy and the possible misappropriation of personal information. This article delves into the kinds of data vehicles gather, who receives this data, and the ramifications for consumers.
### Types of Data Captured by Modern Vehicles
1. **Geolocation Data**: The majority of contemporary automobiles are fitted with GPS systems that continuously track the vehicle’s whereabouts. This data can disclose driving patterns, regularly visited places, and even personal routines.
2. **Vehicle Performance Metrics**: Cars monitor a range of performance indicators, including speed, fuel efficiency, engine diagnostics, and maintenance requirements. This information can optimize vehicle performance or forecast maintenance needs.
3. **Driver Conduct**: Advanced driver-assistance systems (ADAS) and infotainment platforms can monitor driver actions, such as acceleration trends, braking habits, and even the frequency of phone usage while driving.
4. **In-Car Connectivity**: Numerous vehicles come equipped with Wi-Fi hotspots and Bluetooth connectivity, enabling them to link to the internet and other devices. This connectivity may lead to data collection concerning browsing habits, app usage, and personal preferences.
5. **User Profiles**: Certain vehicles allow drivers to create custom profiles that save preferences for seating, climate control, and entertainment options. This data may be attributed to the driver’s identity.
### Who Receives This Data?
The vehicle data collected is sent to several entities, including:
1. **Automakers**: Car manufacturers frequently collect data to enhance vehicle performance, improve user experience, and develop new features. This information can also be used for marketing purposes.
2. **Third-Party Service Providers**: Numerous vehicles depend on third-party services for navigation, entertainment, and various functionalities. These providers may gather and utilize data for their services, which can include targeted advertisements.
3. **Insurance Firms**: Some insurance providers offer usage-based policies that rely on data gathered from vehicles to evaluate risk and calculate premiums. This can result in personalized insurance rates based on driving behavior.
4. **Government Organizations**: In certain instances, governmental bodies may access vehicle data for regulatory compliance, traffic control, or safety investigations.
5. **Hackers and Cybercriminals**: As vehicles become increasingly connected, they also become more susceptible to cyber threats. Hackers could exploit vulnerabilities to access personal data and vehicle controls.
### Implications for Consumers
The extensive data collection by modern vehicles raises significant privacy issues. Consumers might not be entirely aware of the volume of data being gathered or how it is utilized. The risk of data breaches and unauthorized access to personal information remains a growing concern.
To mitigate these risks, consumers should:
– **Evaluate Privacy Policies**: Prior to purchasing a vehicle, consumers should review the privacy policies of automakers to understand what information is collected and how it’s used.
– **Modify Settings**: Many vehicles permit users to adjust privacy settings. Drivers should take advantage of these options to limit data sharing.
– **Stay Informed**: Keeping up with advancements in automotive technology and data privacy can empower consumers to make informed choices regarding their vehicles.
### Conclusion
As vehicles grow increasingly interconnected and data-centric, they are sharing more personal information than ever before. Grasping the types of data collected, who receives it, and the implications for privacy is vital for consumers in today’s digital environment. By being proactive and knowledgeable, drivers can better safeguard their personal information while reaping the benefits of modern automotive technology.
