Privacy researchers at Northeastern University, working with Consumer Reports, plugged into 21 cars in the United States, model years 2022 to 2025, and the 30 phone apps that pair with them. Seven of those apps, about one in four, were sending out personal information. Between them, the researchers observed email addresses, vehicle identification numbers and precise location leaving the apps: the kind of data that can reveal where someone lives, where they work and when they are home.

Where the data went matters as much as what it was. The researchers traced it to advertisers, a data broker and analytics firms. Consumer Reports' own write-up names companies that ended up receiving data from the cars and apps, including Amazon, Google, Meta and Microsoft. "We don't actually know what the companies are doing with that data," said the study's lead, Northeastern professor David Choffnes, who called for regulation and for carmakers to make data collection something drivers opt into rather than out of.
The apps named in the report are the versions used in the United States: HondaLink, four General Motors apps (myChevrolet, myBuick, myGMC and myCadillac), MyNissan and Lincoln's app were among those observed sending a VIN paired with an email address or location. Honda is the one the report credits with acting. After the researchers contacted it, the report says, Honda asked the analytics firm to delete the location and VIN data it had received, and changed the app to stop sending geolocation.

Here is the catch for Malaysia. Every app in the study is a version sold in the United States. Honda's app in Malaysia is HondaTouch, not the HondaLink build the researchers examined, and it was not part of the test. Nor were the local apps for any other brand. We know of no comparable Malaysian teardown that has been made public, for Honda's app or anyone else's. So drivers here have no answer to the plain question the American test asked: what is my car's app sending, and to whom?
That gap is worth naming because the cars Malaysians are buying increasingly rely on the same setup, a companion app tied to an account, from app-linked EVs like BYD and Tesla to the apps carmakers now ship with their vehicles. The study shows what such an app can send. It does not show what any Malaysian version does, because none was tested, so nothing here is a claim that they leak. It is a reason to check. We saw the same buried trade-off when WhatsApp added third-party AI agents whose chats were not end-to-end encrypted.
Malaysia does have a law that reaches this. The Personal Data Protection Act governs the commercial handling of personal data and puts consent at its centre, and its 2024 amendment added biometric data to the categories treated as sensitive, a change that took effect in 2025. But there is no rule we are aware of written specifically for connected vehicles, and no enforcement action against a carmaker over app data sharing that has publicly tested the point here. Location is sensitive precisely because it maps a person's routine, and the same categories of personal data turn up in the scams we keep tracking, from a voice cloned from seconds of audio to a number that lands on a broker's list.
The one control you can reach today is the app's own settings. Open your car's companion app and look for anything labelled data sharing, personalised ads or analytics, and switch off what you find. Check what the app is allowed to reach on your phone, and deny background location when it does not need it. Some data can still travel from the car itself, beyond any app toggle, which is exactly why the researchers are asking for regulation rather than leaving it to each driver. And if you are buying a connected car, ask what the app collects and whether you can decline.
Honda changed its United States app after the researchers asked. The version Malaysians actually drive with has not been put to the same test.
Image(s) courtesy of why kei and Dominik Garbera on Unsplash.



