You remote-start your car from your phone, check the charging status, pull up the trip history. It feels like convenience. A joint study by Northeastern University and Consumer Reports, reported September 29, 2026, tested 21 late-model vehicles from 19 brands and 30 companion apps. Every single tested vehicle transmitted data to at least one third-party domain over Wi-Fi, a pattern reminiscent of apps secretly tracking users without their knowledge. The Federal Trade Commission had already finalized an order against General Motors and OnStar in early 2026, and the window for assuming this is someone else’s problem is closed.
What the Study Found
All 21 tested vehicles contacted outside domains, and more than half reached advertising or analytics networks.
Researchers connected Raspberry Pi devices to vehicle Wi-Fi and routed traffic through a controlled hotspot to observe outgoing connections. For cellular traffic, they used a vehicle-sized Faraday enclosure that blocked cellular signals and forced cars onto their monitored Wi-Fi. The method let researchers identify where data was sent. It generally could not decrypt the payloads, so the study establishes destination patterns more confidently than the exact contents of every transmission.
The companion-app findings are harder to dismiss. Twenty-eight of 30 tested apps contacted at least one outside advertising or analytics company. Seven specific apps transmitted at least one personally identifiable item to an outside company: HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick, and myGMC. The shared items included VINs, phone numbers, and precise location data. More than 70 percent of tested apps contacted at least five distinct advertising, tracking, or analytics domains.
Vehicles running Google’s Android Automotive OS with Google Automotive Services contacted the highest number of third-party domains in the study’s observations. That finding does not mean the platform is definitively less private than every alternative. It does show that the software embedded in your dashboard can shape how much of your vehicle’s activity reaches the outside world. David Choffnes, the project lead at Northeastern University, described cars as becoming “the global smartphones” in terms of their tracking ecosystem.
The Regulator Already Knocked on One Automaker’s Door
The FTC’s finalized order against GM and OnStar signals that connected-vehicle data practices are now a live enforcement issue.
In January 2025, the FTC accused General Motors and OnStar of collecting and selling precise geolocation and driving-behavior data without adequate consumer notice or affirmative consent. That data covered hard braking, speeding, and late-night driving. The commission alleged that information reached consumer-reporting agencies in ways that could affect insurance decisions , part of a broader concern around vehicle location surveillance infrastructure.
The FTC finalized its order in early 2026, requiring affirmative express consent before GM and OnStar collect, use, or share covered connected-vehicle data. The order also includes consumer access, deletion, and control mechanisms. Automaker responses to the broader study were uneven: Honda requested that Amplitude delete collected location data and updated HondaLink to stop transmitting geolocation information after researchers presented their findings. Other manufacturers defended their practices as legally compliant. Those fixes are meaningful, but they do not confirm that historical data was deleted across every downstream recipient.
Combine your VIN with your name, phone number, and location history and the result is closer to a detailed dossier than a car registration. That is exactly the kind of profile data brokers actively seek out.
Start with one practical question: is the companion app required for your car to function, or does it primarily enable remote start and maintenance alerts? Check your app’s privacy settings and deletion procedures directly, because deleting the app from your phone does not, by itself, delete data already held by the automaker or its vendors. For broader guidance on how to stay safe from device-level data risks, reviewing your connected-device habits is a useful parallel step. The distinction between opt-in and opt-out consent is not fine print. It is where your privacy is actually won or lost.




























