Online Safety

Modern Cars Are Monitoring You: Here's How We Know

Most of us have accepted that our phones and the websites we visit keep track of what we do. Far fewer people realise that the car in the driveway may be collecting more about them than either. This is not a theory: we know because the car makers have written it down themselves, and because regulators, journalists and security researchers have caught the data going places it never should have.

A dark SUV parked on a hilltop road at sunset, with red recording lights on its mirrors, grille and roof, and streams of light carrying location pins and fingerprint icons flowing from the car into the sky

The ordinary stuff: data you would expect

The data collection starts before you own a car at all. When you browse listings, watch review videos or read up on a particular model, that interest gets noticed, and soon enough you start seeing ads for that car, or its competitors, everywhere you go online. That sounds invasive, but this part is actually fairly tame.

Large ad platforms like Google generally do not hand a car company a file with your name on it saying you are shopping for a new SUV. Instead, the car company pays the platform to show its ads to "people interested in SUVs", and the platform decides who that is. The car maker gets the audience, but not your identity. Visiting a manufacturer's own website will drop cookies and record your IP address, which is standard behaviour for almost every website you have ever visited. None of that is ideal, but on its own none of it singles you out as a person.

Things become more personal once you actually buy the car. The vehicle gets registered to your name and address, and the manufacturer or importer typically ends up with those details too. There is a genuinely good reason for this one: if a safety recall is issued for a faulty airbag or brake part, they need to be able to reach the person driving that car, even if it was bought privately years later. If the data collection stopped here, this article would not need to exist.

The stranger stuff: what else is on the list

Read through a modern car maker's privacy policy and some odd categories start showing up. Alongside the expected things like your name, contact details and vehicle identification number, some policies have listed things like health information, "inferences" drawn about your characteristics and abilities, and in a couple of notorious cases, details about your sex life. That raises an obvious question: how could a car possibly know any of that?

Part of the answer is that a lot of it does not come from the car. Most of these policies say they also collect information from "third parties", which frequently includes data brokers, companies whose entire business is buying, combining and reselling information about people. Some of this has a sensible purpose: a dealer arranging finance needs to run a credit check. The problem is how vague the policies are about everything else, and how much can be pieced together once your name is matched up with your car.

The other part of the answer is the car itself. A modern vehicle is packed with sensors, and plenty of them are entirely innocent: oil pressure, tyre pressure, battery health. But the list keeps going.

  • Cameras outside the car for parking, blind spot warnings, lane keeping and automatic braking, which between them can record a full view of the surroundings
  • Cameras inside the car, sold as driver attention monitoring or a way to keep an eye on children in the back seat, and in some models able to recognise who is driving
  • Microphones for hands-free calls and voice commands, and on some vehicles, microphones on the outside as well
  • GPS location, often precise and continuous, giving a full history of where the car has been and when
  • How you drive: how hard you brake and accelerate, how sharply you corner, your speed, whether you indicate, what time of night you are on the road and how far you travel
  • What happens in the cabin: seat weight sensors, door locks, window positions, which phone is paired, who you call, what you listen to and how you use the touchscreen

Many of these features started out as genuine safety tools. The classic example is the built-in emergency button, which can call for help and send your location after a crash. That is a brilliant idea. But the same always-connected system that can call an ambulance can also send home a steady stream of driving data, and that is exactly where things started to go wrong.

How we know: the companies told us themselves

The most direct evidence is the paperwork. In 2023 the Mozilla Foundation reviewed the privacy practices of 25 major car brands for its Privacy Not Included guide, and every single one failed. Mozilla called cars the worst product category it had ever reviewed, worse than fitness apps, smart speakers and dating apps. The large majority of brands said they could share personal data with service providers, data brokers and other businesses, most said they could sell it, more than half said they would hand it to the government or police on a simple request rather than a court order, and almost none gave drivers a real way to have their data deleted. Nissan's policy was the one that made headlines, listing sexual activity and genetic information among the categories it might collect.

None of that was leaked or hacked. It was sitting in the privacy policies the whole time, in documents almost nobody reads before driving off the lot.

How we know: following the data to insurance companies

In early 2024, a New York Times investigation found that General Motors had been passing detailed driving behaviour from millions of cars, including hard braking, rapid acceleration and speeding, to data brokers that build risk profiles for insurers. Some drivers only found out when their insurance premiums jumped and they asked for the reports behind the decision. Many said they had never knowingly signed up for anything.

That reporting led somewhere. The Texas Attorney General sued GM over the practice, US senators revealed that other manufacturers had shared driving data with brokers too, sometimes for a few cents per car, and in January 2025 the US Federal Trade Commission announced a proposed order that would ban GM from sharing that kind of driving data with consumer reporting agencies for five years. When a government regulator steps in and orders a company to stop doing something, that is about as clear as proof gets.

How we know: the breaches and security flaws

The more data a company holds, the worse it is when that data escapes, and car makers have a rough track record here.

  • Toyota admitted in 2023 that a misconfigured cloud system had left vehicle location data for over two million customers in Japan exposed for roughly a decade
  • Volkswagen Group software subsidiary Cariad was found in late 2024 to have left location data for hundreds of thousands of electric vehicles exposed online, precise enough to trace where individual owners lived and worked
  • Security researchers have repeatedly found flaws in manufacturers' online systems; one disclosed in 2024 affected Kia vehicles and allowed someone with nothing more than a number plate to locate the car and unlock it remotely

That last one is worth sitting with for a moment. A number plate is visible to anyone you drive past. When a weakness like that exists, the car is no longer just collecting data about you, it is advertising where you are.

How we know: people on the inside

In 2023, Reuters reported that some Tesla employees had shared private video and images recorded by customers' car cameras among themselves through internal chat, including footage from inside people's garages. The cameras were working exactly as designed. The problem was who could see what they captured. It is a good reminder that "the data is stored securely" is only as reassuring as the people who have access to it.

How we know: when it gets into the wrong hands

The most serious cases do not involve hackers or data brokers at all. They involve someone the victim knows. Connected car apps let the account holder see where the car is in real time, check whether the doors are locked, and on some models view the camera feeds or control the car remotely. In a relationship that turns abusive, or after a breakup where one person still has access to the app, those same features become a tracking tool. Reporting from the US has documented people being followed and controlled this way, often struggling to get their access removed because the car or account was in the other person's name.

Pressure from those cases is the reason some US states, starting with California, now require car makers to let survivors of abuse cut off another person's remote access to a car. That is a step in the right direction, and it also proves something important: it was always technically possible to switch this access off. It simply was not a priority until the law said so.

Where the rules are actually working

The good news is that regulation clearly makes a difference. In Europe, privacy law has already forced real changes: Dutch regulators pushed Tesla to change how its Sentry Mode cameras record people around a parked car, and data protection authorities in several countries have fined or ordered companies to stop tracking employees' vehicles outside work hours. In the US, privacy policies across the industry became noticeably more detailed after California's consumer privacy law came into force, which is part of the reason researchers can now see as much as they can.

Here in New Zealand, the Privacy Act 2020 gives you the right to ask any organisation what personal information it holds about you, and they generally have to respond within 20 working days. That applies to car distributors and dealers operating here just like any other business. If you are curious what your car's maker has on file, asking is free.

What you can actually do

You do not need to swap your car for a 1990s hatchback to protect yourself, although an older, simpler car does collect far less. A few practical steps go a long way.

  • Check the privacy settings in the car's own menus and in the manufacturer's phone app. Many have options for location sharing, data sharing and voice recordings that are switched on by default
  • Look at who has access to the app. Most connected car apps allow extra drivers or users. Make sure every person on that list is someone you still want able to see where the car is
  • Be wary of "safe driver" insurance discounts and in-car offers that ask you to share driving data. Read what you are agreeing to before tapping accept
  • Clear your phone out of rental and loan cars. Pairing a phone can copy your contacts and call history into the car, where they sit until someone deletes them
  • Do a full reset before selling a car, and remove it from your account in the manufacturer's app so the next owner cannot see your history, and you cannot see theirs
  • Read the privacy policy before you buy. If it lists things a car has no business knowing, that tells you something about the company
  • Request your data under the Privacy Act if you want to know what has been collected about you

A word of caution on paid data removal services, too. Many of them only deal with "people search" websites, not with car makers or the brokers that buy driving data, so they are unlikely to do much for this particular problem.

Where to go from here

None of this means every connected car is spying on its owner in some sinister way. It means the capability is there, the companies have been open about collecting far more than most people realise, and there is a solid record of that data being sold, leaked and misused. Knowing that puts you in a much better position to decide what you are comfortable with.

If you would like a hand going through the privacy settings on your phone, your car's companion app or the other connected devices around your home, that is exactly the kind of thing we help with. See online safety tips for more plain advice, password managers explained simply for locking down the accounts these apps rely on, or ongoing support if you would like someone to check over your setup from time to time.

Samuel Coulson

Owner of Kapiti Computers, providing onsite and remote IT support and computer repairs across the Kāpiti Coast.

Back toAll Articles

Want Your Privacy Settings Checked?

Send a message and we will get right back to you.

Send a message

Contact details