Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Automakers Share PII from Connected‑Car Apps with Advertisers and Data Brokers

A joint study by Northeastern University and Consumer Reports revealed that most major automakers transmit personally identifiable data from connected‑car apps to advertising and analytics firms. The practice raises privacy compliance concerns and underscores the need for continuous third‑party oversight. Organizations must map data flows and collect evidence to satisfy audit and regulator expectations.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
therecord.media

Automakers Share PII from Connected‑Car Apps with Advertisers and Data Brokers

What Happened — A study by Northeastern University and Consumer Reports found that 19 of 21 major auto manufacturers collect and broadly disseminate personally identifiable information (PII) from connected‑car apps. Seven of the 30 apps examined transmitted names, email addresses, VINs and precise geolocation to third‑party advertising or analytics firms, including large tech platforms. California regulators have already fined GM $12 million for similar practices.

Why It Matters for Trust & Control Assurance

  • Continuous third‑party risk monitoring is needed to prove that data‑sharing agreements align with privacy policies and audit requirements.
  • Documented evidence of data‑flow mappings helps demonstrate due‑diligence during regulator or auditor inquiries.
  • A robust vendor‑oversight program provides a defensible trail that can mitigate liability when PII is shared beyond the original purpose.

Who Is Affected

  • Automotive manufacturers and their connected‑car app developers.
  • Consumers whose vehicle data is being shared.
  • Advertising and analytics firms that receive the data.

Recommended Actions

  • Conduct a comprehensive inventory of all data elements collected by connected‑car apps and map each to a lawful purpose.
  • Perform third‑party risk assessments for every advertising or analytics partner, focusing on privacy controls and data‑handling agreements.
  • Implement continuous monitoring to capture evidence of data transfers and enforce consent‑management policies. Source: The Record

Technical Notes – The study identified that apps for GM, Honda, Nissan and Lincoln shared VINs combined with location or email data. Links embedded in the apps direct users to external webpages where cookies and tracking pixels are placed, enabling further profiling. The FTC warned automakers about privacy risks in 2024, and California’s CPPA fined GM for illegal sharing with credit agencies and data brokers. Source: The Record

📰 Original Source
https://therecord.media/automakers-routinely-share-connected-car-data-third-parties ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →