Published: September 30, 2026 Category: Data Brokers, Privacy, Connected Cars, Guide Reading time: ~11 minutes Meta description: A new Northeastern University study tested 21 cars and 30 companion apps: 19 of 21 vehicles sent driver data to third parties, and those profiles reach insurers. Here is how to stop it.
Car data privacy has a blunt answer in 2026: your car is a data broker. Not metaphorically — literally, in the sense that it collects detailed records about where you go, when you drive, and how you brake, and then passes that information into the same commercial pipeline that feeds insurance pricing and marketing databases.
That pipeline just got measured properly for the first time. On September 29, 2026, researchers at Northeastern University, working with Consumer Reports, published a peer-reviewed study that tested 21 late-model vehicles from 17 automakers alongside 30 companion mobile apps. The headline number: 19 of the 21 vehicles sent data traffic to at least one third party.
If you drive a connected car built in the last several years, this affects you — and the practical question is not whether your data is being collected, but whether anything can be done about it. It can. This guide covers what the study found, how the data actually travels from your dashboard to a broker's database, what the FTC has already forced one automaker to stop doing, and the specific steps that limit the damage.
What the 2026 study found
The Northeastern and Consumer Reports researchers did something unusual: instead of reading privacy policies, they instrumented the vehicles. They watched the network traffic that cars and their companion apps actually generate.
| Finding | Result |
|---|---|
| Vehicles tested | 21 late-model cars, 17 automakers (including Cadillac, Chevrolet, Ford, Lucid, Rivian, Tesla, Toyota) |
| Companion apps tested | 30 |
| Vehicles sending traffic to at least one third party | 19 of 21 |
| Apps sharing sensitive data (VIN, email, phone number, precise location) with tracking or advertising firms | 7 of 30 |
| Companies receiving driver data | Adobe, ContentSquare, Google, Microsoft, Meta, Snap, Yahoo |
| Effect of pairing the companion app to the car | Roughly doubled exposure to advertisers and trackers |
First, the data is sensitive at a level most apps never see. Vehicle identification numbers, email addresses, phone numbers, and precise geolocation were all handed to third-party advertising and tracking companies. A VIN is a persistent identifier that ties a physical vehicle to an owner record. Precise location, tied to a VIN, is a map of a person's life.
Second, the profile is durable because it is sold. The researchers found that multiple data types from the same vehicle were frequently sent to the same third party, which is exactly the pattern that lets advertisers and data brokers assemble in-depth consumer profiles. Those profiles are then sold onward to banks and insurance companies.
In other words: this is not just an advertising problem. It is a data broker problem, and it reaches into decisions about your money.
How car data privacy breaks down: from your dashboard to a broker
There is nothing mysterious about the mechanism once you see it laid out. It is a supply chain.
Stage 1 — The car collects. Modern vehicles ship with built-in cellular modems, Wi-Fi, and GPS. That hardware is not passive. Telematics systems record trip data, hard braking events, speeding, night driving, and location fixes on a continuous basis.
Stage 2 — The app widens the pipe. Automakers pair their vehicles with companion apps for remote start, charge status, and lock control. As the 2026 study showed, connecting the app to the car roughly doubles the number of third parties receiving data. Some of that leakage happens through analytics and advertising SDKs embedded in the app, and some through external pages the app links out to.
Stage 3 — The automaker shares or sells. This is the step the FTC has already litigated. Driving behavior and precise geolocation data go to consumer reporting agencies — the companies that compile the reports insurers rely on.
Stage 4 — Insurers price you. A consumer reporting agency turns telematics into a risk score, an insurer pulls the score, and your premium reflects it. That is the entire point of collecting the data.
If you want the fuller picture of how the brokerage layer works underneath all of this, our explainer on what a data broker actually is covers the industry structure, and our guide to how data brokers affect your insurance rates goes deeper on the pricing side.
The FTC has already banned one automaker from doing this
The most important precedent in connected-car privacy is also the least widely known.
On January 16, 2025, the FTC announced an action against General Motors and OnStar — its first-ever case involving connected vehicle data. The complaint alleged that GM used a misleading enrollment process to sign drivers up for OnStar and the OnStar Smart Driver feature, failed to clearly disclose what it collected, and sold precise geolocation and driving behavior data to consumer reporting agencies without proper consent.
The FTC's numbers were startling. GM collected precise geolocation data as often as every three seconds for some users. The data set included every instance of hard braking, late-night driving, and speeding. That information went to consumer reporting agencies, which used it to compile reports that insurers relied on to deny insurance and set rates.
As FTC Chair Lina Khan put it at the time: "GM monitored and sold people's precise geolocation data and driver behavior information, sometimes as often as every three seconds."
The order was finalized on January 14, 2026, and the case status is now formally "Under Order" (FTC Docket C-4828). Under it, GM and OnStar must:
- Stop disclosing geolocation and driver behavior data to consumer reporting agencies for five years — a ban that runs through January 2031.
- Obtain affirmative express consent before collecting connected vehicle data, with narrow exceptions such as emergency responders.
- Let consumers access and delete their data. GM now runs a consumer privacy request form for exactly this.
- Let consumers disable the collection of precise geolocation data from their vehicles where the hardware allows it, and opt out of geolocation and driver behavior collection.
- Not misrepresent how location and driver behavior data is collected, used, or shared.
Each violation of the order can carry a civil penalty of up to $51,744.
Here is the part that matters for everyone who does not drive a GM vehicle: the FTC acted against one automaker, not against the practice. The 2026 study found 19 of 21 vehicles from 17 different brands sending data to third parties. The enforcement action defined what is illegal. It did not end the category.
The excuses the automakers gave
One of the more revealing findings in the 2026 study is qualitative rather than quantitative. When researchers shared their results with the manufacturers, every automaker except Honda shifted responsibility elsewhere — often to the drivers themselves.
The typical defense: some links inside companion apps open external web pages, which may set cookies that collect customer data. That is a real mechanism, and it is also a dodge. A cookie set on a page your car's app sent you to is still a data transfer that originates in the connected-vehicle ecosystem, and drivers were not told it was happening.
Honda's response was the notable exception. After learning about the findings, it improved its data collection practices and instructed its vendor Amplitude to delete the geolocation data it had received.
One automaker fixing its pipeline after being caught is not a privacy framework. It is a demonstration that the problem is fixable — and that the rest of the industry has chosen not to fix it.
How to stop your car from selling your data
None of what follows is a single switch. Connected-car privacy is a settings problem layered on top of a broker problem, so it takes two passes: one at the vehicle, one at the data brokers holding the resulting profiles.
Step 1: Check what your car is set to share. Open your vehicle's infotainment settings and look for data sharing, privacy, or connectivity options. Look specifically for telematics, usage-based insurance, driving-score, or "smart driver" style features. Many vehicles let you decline all of it. Turn off what you can and photograph the screen so you can verify later that the setting stuck — automaker settings have a habit of resetting after software updates.
Step 2: Request and delete your connected-vehicle data. Under the FTC order, GM must let you request a copy of your data and seek its deletion — the request form is at consumerprivacy.gm.com. Other automakers publish their own privacy portals; GM's U.S. Consumer Privacy Statement is a useful reference for the categories of data a modern automaker holds, including driver behavior and precise geolocation. Ask for both a copy and deletion, and keep the confirmation.
Step 3: Check the insurance data already assembled about you. The FTC's complaint makes clear that driving data was flowing into consumer reporting agencies used by insurers. Those agencies are regulated, and you have a right to see what they hold. LexisNexis Risk Solutions, for example, publishes a consumer disclosure request page. Reviewing that report tells you whether telematics data has already reached your insurance profile — and if it is wrong or was collected without proper consent, you have grounds to dispute it.
Step 4: Remove the broker layer that accumulated around you. Car telematics is one input. The rest of your exposure — addresses, phone numbers, relatives, property records, and marketing profiles — sits on data broker and people-search sites that have nothing to do with your car. Our complete data broker opt-out list walks through the manual removals, and the free removal guide covers the no-cost path end to end.
Step 5: Re-check, because removal does not stay done. Data brokers repopulate from public records, and automakers ship software updates that can flip privacy settings back. Our guide to how long data broker removal actually takes explains the recurring cycle — the short version is that this is maintenance, not a one-time cleanup.
If you would rather see the scope of your exposure before deciding what to do, run a free scan — it maps which brokers are holding your information and what they have, without requiring you to work through dozens of opt-out forms by hand first.
Car data privacy and your insurance: what to do if your rate already went up
If you suspect telematics data has already influenced your premium, the sequence is straightforward:
1. Pull your consumer disclosure report from the consumer reporting agency involved, and check whether driving behavior or trip data appears. 2. If the data was collected without your informed consent — which is precisely the conduct the FTC found at GM — dispute it with the agency and raise it with your state insurance regulator. 3. Turn the collection off at the source. A dispute removes the current report. It does not stop the vehicle from generating a new one next quarter. 4. Ask your insurer directly whether they used telematics data in your rating, and under which programme.
The uncomfortable structural point is that the FTC's order only covers GM and OnStar. If you drive a different brand, the equivalent protection is whatever that automaker's privacy settings and state law happen to provide — which is why Step 1 above matters more than any legal remedy.
The bottom line
Connected cars are the most comprehensive consumer tracking device most people will ever own. The 2026 Northeastern and Consumer Reports study confirms what researchers suspected: 19 of 21 vehicles sent data to third parties, and the resulting profiles flow to advertisers, banks, and insurers.
The FTC has already defined the boundary of what is legal here, and it defined it narrowly — one automaker, one five-year ban, one order that is currently in force. The rest of the industry has, so far, mostly deflected.
That leaves the work with you, and it divides cleanly: shut off what your car shares, delete what it already sent, and then clean up the broker layer those signals fed. Those are three separate jobs, and the third one is the largest.
Start with a free scan to see what data brokers already know about you — the same exposure that connected-vehicle data feeds into.
Sources:
- Federal Trade Commission, FTC Takes Action Against General Motors for Sharing Drivers' Precise Location and Driving Behavior Data Without Consent (January 16, 2025)
- Federal Trade Commission, General Motors LLC., et al., In the Matter of — Docket C-4828, final order January 14, 2026, status: Under Order
- TechCrunch, Your car and its mobile app are probably handing over all kinds of data to tech companies (September 29, 2026)
- The Verge, Your car is selling your data (September 13, 2026)
- General Motors, U.S. Consumer Privacy Statement and Consumer Privacy Request Form
- LexisNexis Risk Solutions, Consumer Disclosure Request
🔒 Take Control of Your Data
Ready to remove your personal information from data broker sites? CyberForget automates the entire process. Scan 190+ sites in seconds.
Start Free Scan →