Most of the connected vehicles tested by Northeastern University researchers shared data with outside companies, often without drivers having a clear understanding of what was happening. The study examined 21 vehicles from 19 brands and their companion smartphone apps, finding that 19 vehicles contacted at least one third party during testing.

The results apply to both the vehicle and the phone app used to control or monitor it. Researchers said the findings show that data collection is widespread across the modern auto industry rather than limited to one automaker, vehicle type or business model.

Which vehicles shared data?

Researchers conducted the vehicle tests at Northeastern's Auto Test Center in Connecticut between October 2024 and August 2025. They recorded network traffic while the cars were parked, used their available features and drove them at speeds between 5 and 45 mph.

The tested vehicles included the Cadillac Lyriq, Chevrolet Blazer, Lucid Air, Tesla Model 3 and Tesla Cybertruck. Those vehicles contacted a comparatively wide range of outside advertising and analytics companies during the research, although the study covered a broader group of 21 vehicles.

To examine whether cellular connections were the only path for data transmission, the researchers drove 11 electric vehicles into a car-sized Faraday enclosure. The enclosure blocked cellular signals, allowing the team to check whether traffic continued over Wi-Fi.

Companion apps exposed more personal information

The smartphone-app findings were more specific. Of 30 companion apps tested, 28 sent data to at least one outside advertising or analytics company. About one-quarter transmitted personally identifiable information, including owners' names, vehicle identification numbers and precise locations.

A vehicle's technical telemetry is not necessarily the same as personal information. However, a VIN connected to a name, email address or location can identify a particular vehicle and help associate it with a driver or household.

Four General Motors apps—myCadillac, myChevrolet, myBuick and myGMC—were found pairing VINs with either an email address or location data. The study also places the app issue alongside separate concerns about Ford's telematics practices and the sharing of driving data with insurers.

Big tech companies appeared among recipients

Amazon, Google, Meta, Microsoft, Pinterest, Snap and Yahoo were among the outside companies that appeared as recipients across the tested vehicles and apps. Automakers told the researchers that contracts can prohibit third parties from reselling or independently reusing the information they receive.

Those restrictions were difficult for researchers to verify externally, and the study found limited evidence showing how consistently they are enforced. The researchers also noted that most drivers do not closely read the terms accepted while setting up a vehicle app.

What the findings mean for car buyers

The study is a snapshot of 21 vehicles and 30 apps, not a complete survey of every new car on sale. It also does not suggest that every connected feature creates the same risk: many sensors support safety and driver-assistance systems without necessarily transmitting personally identifiable data.

Still, the results indicate that avoiding data collection can be difficult for buyers of new connected vehicles. The researchers' testing suggests that technical consent during app setup often happens without meaningful awareness of where information goes after it leaves the car.