IT Pro Expert
Search
IT · 22 Jun 2026 · 36 min read

Your car is literally spyware on wheels - are you safe?

So we benchmarked 25 of the world's biggest car brands the way we'd bench-test any other computer — and read out their secrets.

Car spyware report ranking risks 2026
Benchmark report

Your car is literally spyware on wheels — are you safe?

We expose your car's secrets.

So we benchmarked 40 of the world's biggest car brands the way we'd bench-test any other computer — and read out their secrets. Who lets you reach your own data. Who bleeds you with subscriptions after you've already paid. Who is genuinely hard to steal. Whose own corporate network got taken apart last year. And which famous names are quietly running out of road.

  • Report · August 2026
  • 40 brands
  • 8 metrics
  • ~16 min read
25/25car brands that failed a basic privacy test (Mozilla)
$400bntop of McKinsey's revised annual car-data forecast for 2030 — it first said $750bn
2027US model year from which Chinese- and Russian-linked car software is banned
10%+of the UK new-car market now held by Chinese-owned brands
The new rules

The engine stopped being the product

For a century you bought a car for its mechanicals. Today the drivetrain is the easy part — the real product is the computer, the software and the data pipe bolted to it. That quietly rewrites every question worth asking before you sign.

We boiled it down to eight, scored every brand out of ten on each, and ranked them. Higher is always better for you, the owner.

  1. Access — can you reach your own data?

    An open API or Home Assistant link — or are you locked out of the car you bought?

  2. Cost — will they nickel-and-dime you?

    Total connected-service subscriptions after the free trial (we left self-driving out of this one).

  3. Security — is it actually hard to steal?

    Keyless-theft exposure, unpatched flaws, and how seriously the maker takes it.

  4. Money — will the company survive?

    A computer on wheels needs its maker alive to keep patching it.

  5. Safety — is it safe in the real world?

    Not just the crash-test star — actual on-road outcomes and assist tech.

  6. Silicon — is the tech any good?

    Software, EV/performance computing and over-the-air updates.

  7. Screen — is the thing you stare at any good?

    Responsiveness, interface, maps, and whether it lags on a car you've just paid £40,000 for.

  8. Data — who holds it, and can they keep it?

    Privacy practice and breach record, adjusted for the jurisdiction the data lands in.

The leaderboard

The computer-on-wheels league table

Eight metrics, ten points each, eighty on offer. The brands at the top aren't the fastest or the flashiest — they're the ones that are cheap to run, open to your own data, hard to steal, safe, well-built, made by a company that will still be here to patch them — and judged on both the screen you'll stare at every day and on how safely they handle your data.

#1 Tesla — 69/80

Open API, almost impossible to steal, top-tier crash safety, rock-solid finances and the best screen in the business — its one weak spot is data privacy.

#2 Volvo — 60/80

The safest brand, cheap to run, a sharp Google-built-in screen, the only official Home Assistant integration — and now the only Geely-owned brand cleared by US regulators on data governance.

#3 Hyundai — 59/80

Free-for-life services, healthy finances, a slick screen and a rock-solid community data link. The value champion.

#4 Kia — 57/80

Hyundai's twin — open, well-funded, good value and easy to use, with a theft flaw it has since fixed.

Brand API Subs Theft Fin Safe Tech Screen Data Total
1Tesla107108101010469
2Volvo Geely89561079660
3Hyundai91049688559
4Kia Hyundai9839788557
5Renault8856878555
6Polestar Geely7952989453
7Rivian5774799553
8BYD2969797352
9Lucid not yet UK4873897551
10MG SAIC6957876351
11Mercedes-Benz4366998550
12BMW3366988649
13Chery Omoda/Jaecoo parent2969776349
14GWM Great Wall · Ora/Haval2968786349
15XPeng2965798349
16Jaecoo Chery2968776348
17Peugeot Stellantis6964755446
18Audi VW3265987545
19Chevrolet GM · US only5357776444
20Dacia Renault7967334544
21Škoda VW3548955544
22Alfa Romeo Stellantis5654766443
23Cupra VW · SEAT3556865543
24Honda3566747543
25Lexus Toyota2438957543
26MINI BMW3356767643
27Jeep Stellantis5744666442
28Subaru4575844542
29Vauxhall Stellantis · Opel6844655442
30Ford3544767541
31Toyota2439756541
32Fiat Stellantis5854445439
33Mazda1475845539
34Porsche VW2136777639
35Suzuki2768334639
36Maserati Stellantis4443566436
37Volkswagen3444754536
38Jaguar JLR · Tata2452756334
39Land Rover JLR · Tata2443756334
40Nissan3343745231

Swipe the table sideways · tap a column heading to re-rank

9–10 excellent 7–8 good 5–6 average 3–4 weak 0–2 poor

Screen rates the in-car display — responsiveness, interface, maps and freedom from lag (Tesla sets the bar; VW's Cariad, Dacia's deliberately basic units and Subaru's Starlink drag). Data rates data security and privacy and is adjusted for data jurisdiction — so the Chinese brands take a hit for the state-access risk detailed further down, JLR and Stellantis take a hit for breaches of their own corporate systems, and no brand scores above 6: on data, nobody is truly clean. Brands are numbered 1–40 by total; where two brands share a total they rank equally and are listed alphabetically. Self-driving is excluded from the subscription column. Chevrolet/GM isn't sold in the UK, Lucid isn't here yet, and Jaguar currently has no new car on sale in Britain at all.

Your data

Your car, your data — except it isn't

Here's the asymmetry nobody mentions in the showroom: your car streams intimate data out all day — where you go, how you drive, sometimes what you say — but getting it back, or sending a single command of your own, is often blocked.

BMW's CarData will hand you a feed of your data but won't let you send one instruction — they log, you observe. Volkswagen broke the popular Home Assistant link in 2026, pushing owners onto an EU Data Act portal to claw their own data back — and because Škoda, Cupra and Audi sit on the same Cariad backend, they inherited the same lockout. The open exceptions are mostly the names at the top of the table: Tesla (a proper official API), Volvo (an official Home Assistant integration), Renault and Dacia (a Home Assistant integration shipped in the core distribution — the most open mainstream European brand by some distance) and Hyundai/Kia (a community bridge so good it's the gold standard). Mazda went the other way entirely and had the community project taken down with a legal notice.

If you can't export your own data or automate your own car, you don't really own it — you're licensing it.

The surprise in the middle of the table is MG. Alone among the Chinese brands, it has an actively maintained community bridge into Home Assistant, so an MG owner can automate their car in ways a BYD, GWM, Chery or XPeng owner simply cannot — which is why MG scores 6 for access where its compatriots score 2. Stellantis owners are in a similar grey zone: reverse-engineered community integrations exist for both halves of the group, but the company publishes no consumer API, so the bridges work until the day they don't.

The lever slowly forcing this open is the EU Data Act. The escape hatch for anyone technical is older and simpler: a cheap OBD-II reader that talks to the car directly and skips the manufacturer's cloud entirely — the privacy-maximising way to get your own telemetry.

Subscriptions

The subscription trap — what it costs to switch everything on

Once the data's flowing, the meter starts: the model is to sell you the car, then rent you back the features it already has. We added up the maximum annual cost to switch on every connected feature after the free trial ends — excluding self-driving and optional power boosts. The spread is enormous, from nothing to around £700 a year.

Brand What you're paying for (excl. self-driving) Max / yr*
1PorscheConnect ~£255 + car-security ~£220 + in-car data ~£240~£700
2BMWÀ-la-carte bundle + internet + remote + traffic + concierge — and not transferable to a used car~£500
3Mercedes-BenzConnect + navigation + remote/cockpit extras (the optional power-boost rental is excluded — see note)~£450
4AudiAudi connect Plus + one-time "Functions on Demand" (≈£260 to make the headlights swivel)~£400+
5Chevrolet / GMOnStar tiers + Wi-Fi — US only, not sold in the UK~£280
6Nissan~£12.99/mo for anything beyond basic + £99/yr stolen-vehicle tracking~£255
7ToyotaRemote Connect + cloud navigation (Drive Connect)~£220
8LexusSame connected stack as Toyota~£220
9JaguarSame InControl stack as Land Rover — academic for now, as no new Jaguar is on sale in the UK~£200
10Land RoverInControl remote + Wi-Fi + Secure Tracker~£200
11MINIConnected Plus + BMW-store functions~£200
12VolkswagenWe Connect Plus + In-Car Shop functions — and it just locked the API~£180
13Alfa RomeoAlfa Connect — the same Uconnect menu as the rest of the group~£150
14CupraCupra Connect — same VW Group structure, longer free period than VW itself~£150
15FiatBasic Connect free for years; premium Wi-Fi/remote tier on top~£150
16JeepConnect ONE free for 10 years; Connect Wi-Fi Plus (hotspot, remote, tracking) ~£13/mo on top~£150
17MaseratiMaserati Connect — a £100k car running the same Uconnect subscription menu as a Jeep~£150
18RivianCore app & Google-Maps nav free; ~£150/yr optional Connect+ (Autonomy+ self-driving excluded)~£150
19ŠkodaInfotainment Online included for years; Care Connect extension after~£150
20SubaruStarlink Safety + remote~£150
21VolvoOlder Sensus cars only — new / Google-built-in cars are free~£150
22MazdaConnected Services~£120
23TeslaCore app/remote free for life; ~£120/yr optional Premium Connectivity — FSD excluded~£120
24HondaHondaLink / Honda+~£110
25FordFordPass connected services + Wi-Fi (BlueCruise excluded)~£100
26HyundaiBluelink renewal — often free for the years you own it~£100
27PeugeotRenewal after 10 free years~£100
28VauxhallVauxhall Connect — long free period on the basics, then renewal~£100
29KiaKia Connect renewal after up to 7 free years~£90
30RenaultStandard pack free for 8 years, Advanced for 3 — then tiers from about £85~£85
31DaciaDeliberately thin feature set — there is very little to switch on in the first place~£50
32SuzukiSuzuki Connect free for 36 months — then a renewal price the company only tells you when the trial endsNot published
33BYDBundled — effectively nothing extra~£0
34CheryBundled — free for the ownership period~£0
35GWMConnected services bundled (Ora/Haval)~£0
36JaecooControl & voice free for life; navigation free for 3 years, then a possible fee~£0
37LucidConnectivity included — but a tiered autonomy subscription is scheduled from 2027~£0
38MGiSMART bundled — nothing to renew~£0
39PolestarGoogle built-in and connected services included~£0
40XPengConnectivity bundled; tech-first but closed app~£0

*Indicative annual recurring cost to switch on the full connected-services menu after the trial — UK £ (some converted from US$); varies by model, trim and software. We've deliberately excluded optional luxury performance unlocks — Mercedes' £480–600/yr "Acceleration Increase", VW's paid ID.3 horsepower and Tesla's one-off £1,500 Acceleration Boost — because they sell you power the car already makes and aren't features you need to switch on. One-off functional unlocks like Audi's swivel headlights are reflected in the table.

  • Nissan

    Cut the UK free period to one year, then locks most of the app behind ~£12.99/mo plus £99/yr for stolen-vehicle tracking — and is even switching features off.

  • VW

    The worst of both worlds: pricey connected packages, a trial of paid horsepower on the ID.3 in Britain, and in 2026 it cut off the API third-party apps relied on.

  • Suzuki

    Three years free, then a renewal price it declines to publish in advance — you find out what your car's app costs only when the trial runs out. Cheap today, unbudgetable tomorrow.

  • Lucid

    Everything's included now, but the company has told investors that connectivity and autonomy subscriptions are meant to become the bulk of a new services revenue line from 2027. Watch this one.

  • BMW

    Tried charging monthly for heated seats — hardware already fitted — and scrapped it after backlash. The à-la-carte menu still tops ~£500/yr.

  • Hyundai · Kia · Volvo · MG · Polestar · BYD

    The honourable exceptions: free for life or for years — proof none of this needs to cost what the others charge.

The screen

The screen is the car now — and some are dire

You'll spend every journey staring at it, yet in-car software is wildly inconsistent. The same £40k buys a phone-fast, beautifully judged system in one car and a laggy, half-translated one in another. This is the bit no spec sheet scores — so here's the honest pecking order.

  • Tesla · Rivian

    The benchmark: fast, clean, genuinely well-designed and improved over the air. The trade-off is lock-in — neither offers Apple CarPlay or Android Auto, so you live entirely in their world (Tesla's is good enough that few mind; on a worse system it'd be a dealbreaker).

  • Google built-in

    Volvo, Polestar, Renault, newer Honda and Ford run Android Automotive — native Google Maps, Assistant and Play, slick and familiar. It's the single biggest reason Renault and Polestar score so well here. Caveat: GM dropped CarPlay/Android Auto on its EVs to force you onto its own, rougher system.

  • German luxury

    Mercedes MBUX, BMW iDrive and Audi are powerful and sharp-looking, but increasingly menu-heavy and touch-dependent — and the best maps and voice often sit behind the very subscriptions listed above.

  • Stellantis Uconnect

    Genuinely one of the group's better assets — Android-based, Alexa built in, sensible layout. The catch is that a Maserati, an Alfa and a Jeep all get broadly the same system, so the £100k car doesn't buy you a better screen than the £30k one.

  • Built-in sat-nav

    Frequently worse than your phone, with live traffic locked behind a paid connection. Which is why most people just plug in CarPlay/Android Auto and never touch the native nav.

  • Some Chinese systems

    Modern and feature-packed on the likes of BYD and XPeng — but cheaper or early-import models can ship with clunky menus, machine-translated "Chinglish" labels and maps that lag well behind Google. Improving fast, but check the actual car.

  • VW Group's early software

    Cariad became a byword for laggy, buggy infotainment that shipped unfinished and took years of patches — part of why VW's whole digital strategy has been such a mess, and why Škoda, Cupra and Audi all carry the same handicap.

  • Budget by design

    Dacia and Suzuki keep screens deliberately basic — on entry Dacias your phone is the screen. Honest and cheap, but don't expect over-the-air improvement, and it's the same philosophy that produces their three-star crash results.

There's also a data catch nobody warns you about. The moment you pair a phone — by cable or wirelessly — most cars quietly copy your contacts, call history and sometimes text messages onto the car's own storage so they show on screen. That data stays in the car.

Security

Theft is now a software problem

The smash-and-hotwire is history. In 2025, 54,145 cars were stolen in the UK — about one every ten minutes — and 60–70% involved keyless exploitation, not force. The methods are electronic: relaying the key fob's signal from inside your house, or reaching the car's wiring through an external panel (the "headlight" attack that specifically targets Toyota and Lexus).

54,145UK cars stolen in 2025 — roughly one every 10 minutes
60–70%of those thefts using keyless exploitation, not force
£1.9bncost to the UK economy of the 2025 Jaguar Land Rover hack
18mStellantis customer records taken in a single 2025 breach

The most-stolen make in Britain is Ford, with more than 7,600 cars taken in 2025, ahead of BMW and Toyota — a reminder that theft tracks how many of a car are on the road, not how expensive it is. The most-stolen individual variant is now the Toyota C-HR hybrid, hit for its valuable parts, with thefts up 28% year on year.

Two brands are moving in opposite directions, and both are instructive. Land Rover — for years the poster child for keyless theft — has seen thefts fall almost 30% in a single year, dropping it from third to fourth in the most-stolen table, with Range Rover Sport thefts down 47% in 2024 and another 20% in 2025. That's what sustained investment in ultra-wideband keys and tracking actually looks like, and it's why Land Rover's theft score has moved up in this year's table. The standout the other way is Tesla — barely stolen at all, because over-the-air security and embedded tracking genuinely work. It's the one place Tesla's relentless connectivity is a clear win.

At the quiet end, Dacia, Suzuki and MG are rarely targeted for the least glamorous reason imaginable: cheap parts, low resale value and not much worth stripping. Being unfashionable is a security feature.

Makers are responding (motion-sensing "sleeping" fobs from BMW, Mercedes and Audi; ultra-wideband keys from Land Rover), and the law caught up in 2025 — simply possessing relay or signal-jamming kit is now an offence. Your cheapest, most effective defences remain low-tech: a Faraday pouch for the keys, a Thatcham-approved tracker, and a ghost immobiliser (a hidden PIN sequence that defeats relay, wiring and key-cloning attacks alike).

Remote takeover

Worse than theft: when someone else can drive it

Stealing a car is one thing; driving it while you're sitting in it — from the other side of the world — is another. In 2025, researchers at PCAutomotive hacked a Nissan Leaf over the internet through its infotainment Bluetooth: they could track it, screenshot the dashboard, listen to conversations in the cabin through the microphone, and work the doors, wipers, horn and even the steering while it was moving. The infamous benchmark is worse still — the 2015 Jeep Cherokee hack reached the brakes, engine and transmission of a car doing 70 mph from miles away, and triggered a 1.4-million-car recall.

Unnerving — but the question that actually matters to a buyer is blunt: did the manufacturer fix it? Mostly yes, and fast. With one glaring exception.

  • Fixed in 24h

    Subaru — patched its Starlink flaw within a day of being told; never exploited.

  • Fixed

    Kia — closed the number-plate flaw within weeks; the proof-of-concept tool was never released.

  • Fixed over the air

    Tesla — patched its remote-control research over the air within days. Over-the-air updates are a security feature.

  • Fixed

    16+ brands (BMW, Mercedes, Ford, Toyota and more) — a 2022 remote-control study, all fixed before going public.

  • Recalled

    Jeep — a 1.4-million-vehicle recall plus a network-level block. Decisive, if forced.

  • Slow · unclear

    Mazda — six infotainment flaws disclosed in 2024, reported unpatched, in keeping with a poor track record.

  • Unresolved

    Nissan — acknowledged the Leaf takeover-and-eavesdropping flaws back in 2024, but still won't confirm a fix and gave the researchers no patch details.

Every connected car has flaws. The ones worth trusting are the brands that fix them — and tell you they have.

Supply chain

When the factory gets hacked, not the car

Here's the failure mode almost nobody buying a car thinks about, and it's the one that actually bit British motorists hardest. Your car was never touched. The manufacturer's corporate network was — and everything downstream stopped.

On 31 August 2025, attackers got into Jaguar Land Rover. JLR shut down its own global IT systems to contain them, and with that, production stopped dead at Solihull, Halewood and Wolverhampton for roughly five weeks. The Cyber Monitoring Centre put the total cost to the UK economy at £1.9 billion, making it the most economically damaging cyber event in British history, with knock-on effects at around 5,000 other organisations. JLR booked £196m in direct costs in one quarter and swung to a £485m quarterly loss; the government stepped in with a £1.5bn loan guarantee to stop suppliers going under. The Bank of England cited it as a drag on UK GDP. Data was confirmed stolen.

Meanwhile Stellantis — Jeep, Peugeot, Vauxhall, Fiat, Alfa Romeo, Maserati and the rest — confirmed in September 2025 that attackers had reached a third-party platform holding North American customer data. The group behind it claimed more than 18 million records: names, emails and phone numbers. Not payment data, but precisely the raw material for convincing scam calls from someone who knows what you drive.

A cyber attack on your car maker doesn't have to touch your car to ruin your month.

For an owner, this is not abstract. During the JLR shutdown, dealers could not register cars or get parts; servicing slipped; deliveries stalled. If you rely on a vehicle for work, your maker's security posture is now part of your own business continuity — which is exactly why both JLR brands and every Stellantis brand carry a reduced Data score in the league table. This is the same class of supply-chain risk we spend our days managing for clients: the weakest link is rarely the thing you bought.

Safety & silicon

Safety and performance are computing problems now

Real-world safety belongs to Volvo, the German luxury set, Škoda — singled out by Euro NCAP for pushing safety hard across the Kodiaq and Superb — and now Tesla, whose Model Y and Model 3 won their Euro NCAP classes in 2025 with some of the highest Safety Assist scores ever recorded, with the Model Y also an IIHS Top Safety Pick+. (Tesla's optional Autopilot / "Full Self-Driving" remains under US federal investigation — a separate question from how the car protects you in a crash.)

At the other end sits a deliberate choice worth understanding before you buy. Dacia's Duster and Suzuki's Swift both scored three stars in 2024, and Euro NCAP was unusually blunt about why: both meet the legal minimum for automatic braking, lane keeping and speed limiting, but go no further, because both brands prioritise affordability. Euro NCAP's secretary general noted the growing split between makers who treat active safety as a selling point and those who don't — naming Mercedes, Škoda, VW, BMW and Renault in the first camp, Dacia and Suzuki in the second. Dacia's own Jogger managed a single star in 2021. That is not a defect; it's a price. Just know you're paying it.

The real differentiator now is software: driver-assist that prevents the crash, not just survives it. That same sensor suite is why insurance has crept up — a minor knock that disturbs a windscreen camera can turn a £300 repair into £1,500 of recalibration.

On self-driving, the reality is far narrower than the hype. Mercedes' Drive Pilot is the only true eyes-off system you can legally use, and in Britain Ford BlueCruise is the only approved hands-free motorway system — with full self-driving not expected before late 2027 under the Automated Vehicles Act. In North America, Lucid switched on hands-free highway driving for the Gravity over the air in June 2026, and says over 95% of that car's features can be updated remotely — the clearest sign yet that "software-defined vehicle" is now a product category, not a slogan. Performance has gone digital too: instant-torque EVs and over-the-air updates mean the quickest, smartest car in the range is increasingly defined by its code, not its cylinders.

The shakeout

Why the badge's bank balance is now your problem

A computer on wheels needs its maker alive to keep the lights on — security patches, app servers, over-the-air updates. So a brand's finances quietly become your risk. And the 2025 accounts were brutal reading.

Stellantis (Jeep, Peugeot, Vauxhall, Fiat, Alfa Romeo, Maserati) posted a €22.3bn net loss — its first annual loss ever — suspended its 2026 dividend and was downgraded by both S&P and Moody's. Renault reported a €10.9bn loss, though almost all of that was a non-cash writedown on its Nissan stake; strip it out and the group made €715m with €1.5bn of automotive free cash flow, so the operating business is in far better shape than the headline suggests. Nissan lost ¥533bn for the second year running, sold its headquarters, is closing its Oppama plant and has cut its model range from 56 to 45. Ford slipped to a net loss.

The recoveries are real but early: Stellantis returned to a small quarterly profit in Q1 2026, and Nissan posted a positive quarterly operating profit and is forecasting a modest full-year net profit. Neither is out of the woods. Meanwhile Toyota, Hyundai-Kia, Suzuki, Škoda (VW Group's most profitable brand) and China's BYD keep pulling away.

Britain's own casualty is JLR, which took the £1.9bn hit described above on top of an already expensive electric transition. Jaguar is the extreme case: it stopped selling new cars in the UK in November 2024 and still has none on sale, with everything riding on a £100,000-plus four-door GT whose reveal has already slipped. A brand with no product and a hacked parent is not a brand to buy a ten-year software relationship from just yet.

Behind BYD comes a second Chinese wave now firmly landed in Britain — Chery (a Fortune Global 500 firm and China's biggest car exporter, parent of Jaecoo and Omoda), GWM (Great Wall — privately owned, behind Ora and Haval), MG (SAIC-owned, over 85,000 UK sales in 2025 and now a top-ten UK brand) and the tech-first XPeng. Chinese-owned brands now take more than a tenth of the UK market, and the Jaecoo 7 was among Britain's best-selling cars in the first half of 2026. On the survival test, Chery, GWM and SAIC look financially solid; XPeng is growing fast but still loss-making. Their bigger asterisk isn't money, though — it's where your data lives, which is the next section.

The pure-play EV makers carry the sharpest version of this risk. Rivian — software-first, Tesla-rivalling on tech and screen, and the firm whose stack VW now licenses — lands in the UK around 2027, but is still losing billions a year and betting its survival on the cheaper R2. Lucid has not made a profit in a decade of trying, burned roughly $3.8bn in 2025, cut 18% of its US workforce and survives on Saudi sovereign-fund money that gives it runway into 2027. And Polestar — which builds one of the best cars in this table — has had a Nasdaq delisting warning, negative gross margin, repeated Geely bailouts and has now been shut out of the American market entirely. Brilliant kit; terrifying balance sheet.

Data jurisdiction

Whose government can reach your car's data?

A connected car constantly phones home — location, trips, voice, sometimes cabin camera. The question buyers rarely ask is which country's laws govern that data once it lands, because that depends on where the maker is headquartered, not where you drive. It's the one axis where the newest, cheapest, most impressive cars carry the biggest asterisk — and in 2026 it stopped being theoretical.

Home jurisdiction Data risk Government action / warning
China BYD · MG (SAIC) · GWM (Ora/Haval) · Chery · Jaecoo · XPengHighUS: sale banned from MY2027 (software) / MY2030 (hardware). Israel: being removed from state & security fleets. EU: tariffs up to 35% (SAIC took the highest rate) + data-localisation under review.
China-owned, EU-run Polestar (Geely)HighIn June 2026 US Commerce refused Polestar authorisation under the Connected Vehicle Rule — ending new-car sales in America from MY2027, despite Swedish HQ and a US-built model. Ownership, not geography, decided it.
China-owned, EU-run Volvo (Geely)ModerateFaced the same ban, but in May 2026 won a specific US authorisation after restructuring its data governance and technology architecture so owner data isn't routed to China. A waiver earned, not granted.
United States Tesla · Ford · Chevrolet/GM · Rivian · LucidLowerAn allied home jurisdiction for UK and US readers. The real-world problem here has been commercial, not state: GM was caught selling driver data and now sits under a binding US FTC order.
Japan Toyota · Lexus · Honda · Mazda · Subaru · Suzuki · NissanLowerAllied; Japan's APPI privacy regime. Toyota is among brands named in a US data inquiry. Suzuki collects the least of any brand here, simply by fitting the least.
South Korea Hyundai · KiaLowerAllied; Korea's PIPA regime. Hyundai is named in the same US data inquiry.
European Union VW · Audi · Porsche · Škoda · Cupra · Mercedes · BMW · MINI · Renault · DaciaLowGDPR — the strictest regime. (VW's Cariad leak exposed 800k owners' locations across VW, Audi, Škoda and SEAT: a breach, not a state-access issue.)
EU-domiciled group Peugeot · Vauxhall · Jeep · Fiat · Alfa Romeo · Maserati (Stellantis)ModerateDutch-incorporated, GDPR-bound — but a 2025 breach of a third-party platform exposed ~18m customer records. Strong law, weaker practice.
UK / India Jaguar · Land Rover (JLR · Tata)ModerateUK GDPR; Indian-owned, British-built — no state-access warning, but the 2025 attack on JLR's own network confirmed data theft and cost the UK economy £1.9bn.

The clearest official signal comes from Washington. In a final rule, the US Commerce Department is banning connected-vehicle software with Chinese or Russian links from model year 2027, and the hardware (the cellular, Wi-Fi, Bluetooth and satellite modules) from 2030 — effectively keeping Chinese smart cars off American roads.

Cameras, microphones, GPS tracking… connected to the internet.
— the reasoning behind the US Commerce Department's final rule: that a foreign state could use them to reach sensitive data

What makes 2026 the year this got real is the pair of decisions on Geely's two European brands. In May, Volvo was granted a specific authorisation to keep selling connected cars in America, after what the company described as constructive discussions about its governance, technology and data security — and, per reporting, a restructuring of its data architecture so information would not be sent to China. Five weeks later, Polestar was refused, and confirmed it will stop selling new cars in the US from model year 2027, redirecting to Europe where 80% of its sales already are. Same ultimate owner, same country of headquarters, opposite outcomes. The variable was how the data was engineered to flow.

Regulators are no longer asking where the car is built. They are asking where the data goes.

Israel has gone further in practice: it is phasing Chinese vehicles — Chery, Jaecoo, BYD and MG among them — out of government and security fleets, and intelligence-unit staff are already barred from arriving at bases in Chinese cars. The EU has hit Chinese EVs with trade tariffs (SAIC, MG's parent, drew the steepest rate at 35.3%) and is weighing whether to force their data to be stored inside the bloc.

The notable outlier is the UK. After a "pragmatic reset" in early 2026 it imposed no heavy tariffs and no consumer ban, so Chinese EVs remain markedly cheaper here than across the Channel and now take more than a tenth of the market. Buy one and nothing stops you — the decision is left to you.

For balance: security analysts warn that any Chinese-made comms module could, in theory, have its data extracted by the Chinese state or be remotely disabled — but there is no public evidence this is actually happening, and the same "computer on wheels" applies to a Tesla (which is itself restricted near Chinese government and military sites). For a private owner the day-to-day risk is low; for sensitive work it's a genuine consideration.

The fine print

Three things the spec sheet won't tell you

Reliability has split by fuel

Hybrids are now the most reliable thing on the road (~15% fewer faults than petrol), while EVs average ~80% more — overwhelmingly software and 12-volt gremlins, not worn-out batteries (degradation is only ~3% a year). The Korean EVs share a charging-control fault, and Tesla's reliability is genuinely disputed: top of one major survey, bottom of a German one.

Insurance punishes EVs and luxury hardest

Subaru, Dacia, Suzuki and the Hyundai i10 are among the cheapest to cover; Porsche, Land Rover, Maserati and Tesla are the dearest — driven less by sticker price than by how expensive they are to repair.

And privacy is the elephant in the garage

Mozilla rated cars the worst product category it has ever reviewed — every brand failed. GM was caught selling drivers' data to insurers (some saw premiums jump 80%) and now sits under a US federal order, with Ford, Hyundai, Toyota and Stellantis under investigation. That's why no brand scores above 6 in the league table's Data column — on privacy, there's no winner, only degrees of bad.

Before you buy

Eleven questions to ask before you sign

  1. Can I actually get at my own data?

    Is there an open API or Home Assistant integration — or are you locked out of automating and exporting data from the car you own?

  2. What do the connected features cost once the trial ends?

    Ask which features go à la carte and for how much, whether the basic app stays free — and, if you're buying used, whether the subscriptions transfer or reset to zero.

  3. Is the renewal price actually published?

    "Free for three years" means nothing if the maker won't tell you the year-four price until year four. Get it in writing before you sign, not after.

  4. Am I being charged to unlock hardware that's already fitted?

    Walk away from monthly or one-off fees to "switch on" heated seats, brighter headlights or extra power the car already physically has.

  5. How well does it resist keyless theft?

    Ask about relay-attack resistance, whether it has a motion-sensing key or a Thatcham-approved tracker/immobiliser, and what it does to your insurance group.

  6. Does it get over-the-air security updates — and does the maker patch fast?

    A brand that ships security fixes overnight is worlds apart from one that won't even confirm a known flaw has been fixed.

  7. How secure is the manufacturer itself?

    JLR's five-week shutdown stopped registrations, parts and servicing for owners who were never hacked themselves. Ask what happens to your warranty work and parts supply if the maker's systems go down.

  8. Whose laws govern my data, and is the brand under any warning?

    Check where the maker is based — and who ultimately owns it. Polestar's US ban and Volvo's US waiver came down to data architecture, not the address on the headquarters.

  9. What happens to my phone's data when I pair it?

    Pairing copies your contacts and often your texts onto the car's storage. Know how to delete your profile and factory-reset before you sell it — or before you hand back a hire car.

  10. Is the screen any good — and what's hidden behind a paywall?

    Is it fast and sensibly laid out, does the built-in nav need a paid connection for live traffic, and does it support Apple CarPlay / Android Auto if the native system disappoints?

  11. Will the maker still be here in ten years — and what am I trading for the price?

    A brand in financial trouble quietly becomes your problem. And if the car is unusually cheap, check what was left out: on a three-star Dacia or Suzuki, the saving is partly in the safety assist you don't get.

Same questions, your business devices

Managed IT, cyber security and networking — London, Kent & Sussex, and remote.

Get in touch

Benchmarked & written by IT Pro Expert

Data current to August 2026 · figures are indicative and vary by model, market and trim
Managed IT · cyber security · networking — and the occasional teardown of things that shouldn't need one