Some Car Apps Transmit VINs, Contacts, and Location to Advertising & Analytics Services
What Happened – Researchers from Northeastern University and Consumer Reports examined 21 vehicles spanning 19 brands and the companion apps that ship with them. In Wi‑Fi‑only tests, 19 vehicles sent vehicle identification numbers (VINs), email addresses, phone numbers, or location data to domains owned by major advertising, tracking, and analytics companies—including Google‑owned services.
Why It Matters for Trust & Control Assurance
- This behavior tests the control objective of third‑party data handling and privacy safeguards – a single control that maps to many frameworks (e.g., NIST CSF 2.0 Identify‑Govern and Protect‑Data‑Privacy).
- Continuous control‑assurance programs need verifiable evidence that data flows are documented, consent is captured, and third‑party contracts enforce privacy obligations.
- Verisq’s CookiePLUS privacy capability helps organizations inventory, monitor, and enforce consent for data shared from embedded vehicle apps, providing audit‑ready proof of compliance.
Who Is Affected – Automotive manufacturers, OEM‑supplied infotainment providers, and any organization that integrates connected‑car applications (automotive / manufacturing sector).
Recommended Actions
- Conduct a privacy impact assessment (PIA) of all connected‑car data flows.
- Map each data element (VIN, email, location) to its destination domain and verify that a lawful basis (e.g., consent) exists.
- Update contracts and data‑processing agreements with third‑party analytics providers to include GDPR‑style safeguards.
- Deploy continuous monitoring of outbound traffic from vehicle apps to detect unauthorized destinations.
Source: Help Net Security
Technical Notes
- Test methodology: vehicles connected to a Raspberry‑Pi Wi‑Fi access point; traffic captured for 30 min parked, 30 min interactive, and 15 min on‑road.
- Encrypted TLS traffic was not decrypted; however, domain‑level metadata showed contacts with advertising domains (e.g., doubleclick.net, googlesyndication.com).
- Cellular‑only traffic could not be inspected for most models; a Faraday tent with a custom LTE/5G network revealed additional tracking domains when cellular was blocked.
Source: Research paper