Almost a quarter of the vehicle apps examined were found to be sending personally identifiable information — including owners’ names, vehicle identification numbers (VINs), and precise geographic locations.
Northeastern University and Consumer Reports mapped data flowing from cars to third parties
Researchers at Northeastern University, working in collaboration with Consumer Reports, produced what the study describes as the first clear documentation of how modern vehicles exchange data: among the vehicles themselves, the vehicle apps buyers install, and a web of outside companies. The work traces “exactly what kind of data gets siphoned from our vehicles and which companies are receiving that information,” the study reports.
Who receives vehicle data: telematics exchanges, data brokers, infotainment vendors, and governments
The investigation catalogs a diverse set of recipients. Car insurers and lenders are among the recipients through partnerships in what the study calls “telematics data exchanges,” platforms that the report says compile driving data on millions of drivers. The study also identifies thousands of data brokers that use that material to create personalized risk scores. Other buyers of vehicle data include companies selling infotainment and Wi‑Fi hotspot products, and, notably, local and state government agencies that obtain information for planning, traffic, and safety initiatives.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleNearly every automaker sent data to outside companies
One striking finding in the study is the breadth of data outflows: “nearly every automaker sent data to outside companies,” the report found. The researchers describe this as more than incidental telemetry — it amounts to an ongoing stream of information about drivers and their vehicles leaving manufacturers’ systems and entering external ecosystems where it can be combined, analyzed, and resold.
Vehicle apps leaking identity, location, and VINs
Almost a quarter of the vehicle apps analyzed were observed transmitting personally identifiable information. The study lists specific categories of exposed data: vehicle owners’ names, VINs, and precise geographic locations. That combination, the report notes, can make it straightforward for outside firms to link driving behavior to broader personal profiles maintained by data brokers and marketing firms.
Profiles built from driving data are routinely bought and sold
The investigation connects the dots from raw vehicle signals to commercial use of the resulting profiles. It cites a Consumer Reports and CalMatters investigation that found such profiles are routinely sold to banks, insurers, pharmaceutical companies, lenders, and retailers. Those buyers, the reporting says, can use the profiles to present personalized loan terms and to filter bank and insurance offers — turning driving patterns into a commercial input for credit and pricing decisions.
What this means for consumers, insurers, and local/state government agencies
- Consumers: Drivers now risk having behavioral telematics linked to their names and VINs, enabling companies that buy or broker that data to fold driving signals into larger consumer profiles used for targeted pricing and offers.
- Insurers and lenders: These entities already participate in telematics data exchanges that aggregate driving data on millions of drivers; the study underscores how those shared pools can feed personalized risk scores that affect underwriting and offers.
- Local and state government agencies: Agencies obtaining vehicle data for planning, traffic, and safety initiatives are positioned as downstream recipients of the same feeds sold to commercial buyers, raising questions about how data gathered for civic use may intersect with commercial profiling.
The study’s record is blunt: modern connected cars are not merely transportation devices, they are nodes in a surveillance pipeline that traces behavior, identity, and location into commodity profiles. With nearly every automaker sending data outward, apps leaking identifiers, and brokers packaging driving signals for banks, insurers, pharmaceutical companies, lenders, and retailers, the empirical chain from vehicle sensor to commercial offer is now documented rather than assumed. Whether consumers, companies, or governments alter practices in response to that documentation remains an open practical and policy question.




