Automakers Share PII from Connected‑Car Apps with Advertisers and Data Brokers
What Happened — A study by Northeastern University and Consumer Reports found that 19 of 21 major auto manufacturers collect and broadly disseminate personally identifiable information (PII) from connected‑car apps. Seven of the 30 apps examined transmitted names, email addresses, VINs and precise geolocation to third‑party advertising or analytics firms, including large tech platforms. California regulators have already fined GM $12 million for similar practices.
Why It Matters for Trust & Control Assurance
- Continuous third‑party risk monitoring is needed to prove that data‑sharing agreements align with privacy policies and audit requirements.
- Documented evidence of data‑flow mappings helps demonstrate due‑diligence during regulator or auditor inquiries.
- A robust vendor‑oversight program provides a defensible trail that can mitigate liability when PII is shared beyond the original purpose.
Who Is Affected
- Automotive manufacturers and their connected‑car app developers.
- Consumers whose vehicle data is being shared.
- Advertising and analytics firms that receive the data.
Recommended Actions
- Conduct a comprehensive inventory of all data elements collected by connected‑car apps and map each to a lawful purpose.
- Perform third‑party risk assessments for every advertising or analytics partner, focusing on privacy controls and data‑handling agreements.
- Implement continuous monitoring to capture evidence of data transfers and enforce consent‑management policies. Source: The Record
Technical Notes – The study identified that apps for GM, Honda, Nissan and Lincoln shared VINs combined with location or email data. Links embedded in the apps direct users to external webpages where cookies and tracking pixels are placed, enabling further profiling. The FTC warned automakers about privacy risks in 2024, and California’s CPPA fined GM for illegal sharing with credit agencies and data brokers. Source: The Record