Advertisement

Study reveals how much data modern cars send to third parties

Toyota Corolla 60th Anniversary (Foto: Toyota)
Fullscreen image

A study by Northeastern University and Consumer Reports found that 19 of the 21 connected cars tested contacted at least one third-party server. The cars' mobile apps behaved even more problematically: 28 of the 30 apps tested communicated with advertising, analytics or tracking services, and some also transmitted the vehicle identification number (VIN), the user's name or precise location.

Advertisement

An important qualification is that the study did not prove that every data packet a car sent to a third party contained personal data. The cars' network traffic was encrypted, so researchers could see which servers a car communicated with, but not always what information the packets contained. For the apps, they were able to identify the contents of the data much more precisely.

Tesla communicated with dozens of tracking and advertising domains

The researchers tested 21 cars from 19 brands in various situations, including while stationary, while driving and while using the infotainment system. All the cars communicated with their manufacturer's own servers, as would be expected for a connected car to function.

In addition, 19 of the cars contacted at least one third party. The Tesla Model 3 and Cybertruck stood out in the tests. The Model 3 contacted 34 advertising, tracking or analytics domains, along with another 37 domains used by in-car apps. Some cars, such as the Buick Envista and Mercedes-Benz EQS, did not show the same pattern in testing and communicated mainly with their manufacturer's own services.

The large share of Google domains is not surprising, as several manufacturers use Android Automotive. However, researchers also found connections to services such as DoubleClick and Google Syndication, whose primary function is advertising and user tracking, rather than operating the car.

The mobile app may share more than the car itself

Even clearer privacy risks emerged from manufacturers' smartphone apps.

Of the 30 apps, 28 communicated with at least one advertising, analytics or tracking company. Some apps added more than 20 new third parties to the user's data flow. Researchers identified the most such contacts in apps from General Motors, Toyota and Nissan.

According to Northeastern University, third parties in some cases received the user's name, email address, VIN and precise location. This makes it possible to link a specific car and its owner to other profiles compiled online and in apps.

After communicating with the researchers, Honda changed its system and stopped transmitting precise location data to at least one tracking company.

Consent is given, but control is often lacking

Car manufacturers told the researchers that contracts and privacy policies govern the use of data. The problem is that buyers often give consent simply by accepting the terms of use for an app or connected service.

Seven manufacturers said it was the customer's responsibility to read the terms. Yet refusing to share data can remove features that the car buyer has effectively already paid for, such as remote start, location display or other connected services.

This makes the choice rather conditional: users can limit data sharing, but in return they must give up some of the car's functionality.

GDPR protects European drivers, but the problem remains

The study covered cars and apps in the US market, so its findings cannot be applied directly to the European market. In the European Union, GDPR imposes considerably stricter requirements on the collection and processing of personal data, and users have stronger rights to access their data, request its deletion or restrict its processing.

The technical problem nevertheless remains the same. Modern cars incorporate mobile data connectivity, GPS, microphones, cameras, phone connectivity and cloud services. The car has effectively become a networked computer on wheels.

The study's most important conclusion is therefore not that “all cars spy”. The more precise conclusion is more uncomfortable: much of a connected car's data flow is simply beyond its owner's ability to see or control.