← IoT Privacy Database

Mazda Connected Services

Mazda Motor Corporation · Connected Car

✓ Reviewed

4.6Surveillance
Index
Policy — what its policy permitsD
Evidence — what research provesC

Mazda Connected Services and the MyMazda app collect geo-location, driving-behavior and vehicle-health data that (unless you opt out) the car transmits automatically to Mazda, plus voice commands, linked to your account. Mazda's policy shares data with affiliates, dealers for marketing offers, and service providers, and de-identified data with outside research and marketing groups. Mazda was one of the automakers the Senate found disclosing location data to police without a warrant, and its Mazda Connect infotainment carried multiple unpatched security flaws.

Why this rating

Policy shares with affiliates/dealers for marketing and outside research groups (sells-data, broker-disclosure), auto-transmits precise geolocation and driving behavior (sensitive-collection), and Mazda was named as disclosing location to police without a warrant (law-enforcement-loose); an opt-out for transmission avoids the no-opt-out penalty. Evidence: Wyden/Markey named Mazda in the warrantless-location-disclosure probe (law-enforcement-pipeline), and Trend Micro ZDI disclosed multiple unpatched Mazda Connect infotainment vulnerabilities in 2024 (security-negligence); no mass consumer-data breach is documented.

What it is

Manufacturer
Mazda Motor Corporation
Category
Connected Car
Model years
2020-present
Market status
Current
Companion app
MyMazda

The evidence 2

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Regulatory action · The Record (Recorded Future News) · 2024-04

    Wyden and Markey found several automakers, including Volkswagen, disclose customer location data to government on a mere subpoena rather than a warrant, and asked the FTC to investigate.

    Why it matters here: Directly implicates Mazda Connected Services location data in a law-enforcement pipeline.

  2. Security advisory · BleepingComputer · 2024-11

    Trend Micro's ZDI disclosed multiple unpatched vulnerabilities (CVE-2024-8355 through -8360) in the Mazda Connect CMU allowing code execution and persistence via USB.

    Why it matters here: Security weakness in the exact infotainment unit that gathers and holds Mazda Connected Services data; physical access required.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database