BlackVue sells dash cams to employers who can watch live video from any work vehicle, track where every driver goes, and monitor how they drive. The privacy policy is written for consumers who choose to buy the camera. When your employer installs one in your work vehicle, you have no real choice about being surveilled throughout your entire working day. Your BlackVue keeps recording and uploading to Korean cloud servers even when your car is parked. People walking past your parked car have no idea they are being filmed and that their images are being sent to servers in South Korea. Bystanders never consented to being part of your dash cam's continuous surveillance operation.
What they claim: BlackVue actively markets dash cams for fleet management with real-time GPS tracking, speed monitoring, driving behaviour analysis, and remote live view
What we found: Fleet management features create a workplace surveillance infrastructure: employers can watch live video from any vehicle, track driver locations in real time, monitor driving speed and behaviour, and access all recorded footage. Pittasoft's privacy policy focuses on individual consumer consent but does not address the power asymmetry in employer-deployed systems. Employees in fleet vehicles may have no meaningful ability to consent to continuous video and GPS surveillance as a condition of employment.
What they claim: DR900X parking mode operates as a 24/7 surveillance camera covering public spaces around parked vehicles
What we found: The DR900X's parking mode with motion/impact detection continuously records video and GPS location when the vehicle is parked. With cloud connectivity, this footage is uploaded to blackvuecloud.com servers in South Korea. Under Australian law, recording in public spaces is generally permitted, but continuous cloud upload of surveillance footage of public spaces — capturing pedestrians, license plates, and activity around the vehicle — raises privacy concerns for bystanders who have no knowledge they are being recorded and whose images are being transferred overseas.
What they claim: BlackVue app (v3.37) embeds 6 trackers: Google Firebase Analytics, Google CrashLytics, Google Tag Manager, Google AdMob, Facebook Login, Facebook Share
What we found: Pittasoft's privacy policy discloses collection of "personal data, usage data, and cookies." The app embeds Google AdMob (advertising SDK that serves ads and shares user data with Google's ad network), Facebook Login (links BlackVue account to Facebook identity), and Facebook Share (enables sharing dash cam footage to Facebook, creating a bridge between driving data and social media profiles). A dash cam surveillance app sends data to advertising and social media networks.
What they claim: BlackVue app requests ACCESS_BACKGROUND_LOCATION, RECORD_AUDIO, CAMERA, READ_PHONE_STATE, and AD_ID — 36 permissions total
What we found: The DR900X has its own GPS receiver, 4K camera (Sony STARVIS IMX307), and built-in microphone. FCC ID YCK-DR900X-2CH confirms the camera has all these sensors onboard. The app's ACCESS_BACKGROUND_LOCATION duplicates the camera's GPS, tracking the phone's location even when the app is closed. RECORD_AUDIO and CAMERA duplicate the dash cam's own sensors. AD_ID provides an advertising identifier for a device whose sole purpose is security recording. The app tracks the user separately from the camera.
What they claim: Pittasoft (BlackVue) is headquartered in Seoul, South Korea. Personal data from users worldwide is processed and stored in South Korea and the United States
What we found: Pittasoft's privacy policy states data may be "transferred to the Republic of Korea for processing." Cloud storage at blackvuecloud.com, api.blackvuecloud.com, and fota.blackvuecloud.com holds video recordings, GPS location data, speed data, G-sensor impact data, and timestamps from every connected camera. For Australian customers, continuous driving surveillance data (where you drive, how fast, impact events) is transferred to South Korea with no Australian data sovereignty protections.
What they claim: BlackVue markets its dashcams as secure private recording devices for personal vehicles.
What we found: Andy Gill discovered that the public-by-default exposure extended to emergency services vehicles. Ambulances and police cars running BlackVue dashcams were broadcasting their live video feeds and GPS locations to anyone with the free app. Registration plates were visible in camera feeds, creating what Gill called an easy shopping list of cars to steal.
What they claim: Pittasoft's privacy policy states "usage data is retained for internal analysis purposes" and data collection is for "improving services"
What we found: The app embeds Google AdMob — an advertising SDK that serves ads and shares data with Google's advertising ecosystem. AdMob is not an internal analysis tool; it is a third-party advertising platform. Combined with AD_ID (persistent Google advertising identifier) and Facebook Login/Share integrations, the data pipeline extends far beyond internal analysis to Google's ad network and Meta's social graph. "Improving services" is doing heavy lifting to cover advertising revenue generation.
What they claim: BlackVue Australia publishes a Cyber Security Commitment page stating compliance with the Cyber Security Act 2024 and Security Standards for Smart Devices Rules 2025
What we found: CVE-2023-27748 (critical): FOTA service on port 9771/TCP accepts firmware uploads without authentication or signature verification. An attacker on the same network can upload malicious firmware by extracting official packages, modifying files, and recalculating checksums. On LTE-connected models, this service is accessible from the internet. A company claiming compliance with cyber security standards ships devices that accept unsigned firmware from anyone on the network.
What they claim: CVE-2023-27747: BlackVue webserver on port 80 exposes live video, vehicle telemetry, recording downloads, configuration uploads, and credential extraction without authentication
What we found: When connected to the camera's Wi-Fi AP, the webserver on port 80 requires no authentication for: live video feed access, vehicle GPS telemetry retrieval, recording downloads, configuration uploads, and credential extraction. The DR900X uses HiSilicon Hi3559 SoC with Sony STARVIS IMX307 sensor capturing 4K UHD video. CVE-2023-27746: Wi-Fi passphrase is only 8 lowercase alphanumeric characters, brute-forceable in ~4 days for ~0 using commercial GPU rental.
What they claim: BlackVue's Cyber Security Commitment page (updated February 2026) claims compliance with mandatory security standards for connected products
What we found: The DR900X uses HiSilicon Hi3559 SoC — a chip manufactured by Huawei's wholly-owned subsidiary. HiSilicon chips have been subject to US export controls and security scrutiny. The camera's firmware runs on this Chinese-manufactured chipset while Pittasoft's security commitment makes no mention of the supply chain dependency on Huawei hardware. The firmware accepts unsigned updates (CVE-2023-27748) running on a chip from a company under international sanctions.
What they claim: BlackVue states the sharing of GPS, video, or audio data on the public World Map is opt-in only.
What we found: In September 2018, security researcher Tim Woodruff discovered that public location and live video were enabled by default on new camera registrations. Anyone could download the free app (no email verification required) and tap into random dashcams, watching live feeds and tracking car speed and GPS location with enough resolution to identify driveways. In January 2020, Vice/Motherboard reverse-engineered the iOS app and wrote scripts that collected GPS coordinates of every BlackVue user with mapping enabled across the eastern US, polling every two minutes for a week. In January 2022, researcher Andy Gill found GPS access was STILL enabled by default, contradicting BlackVue's claim of having fixed it in October 2018. BlackVue's response: it's a feature, not a bug.
What they claim: BlackVue Cloud service requires internet connectivity (via phone hotspot, car-embedded connection, or LTE module) for remote features
What we found: The cloud service terms page failed to load content ("You need to enable JavaScript to run this app"). The privacy policy for the cloud service is embedded in a JavaScript application that cannot be read without executing code — making it inaccessible to users with accessibility needs, privacy-focused browsers, or anyone trying to review terms before creating an account. FCC ID YCK-DR900X-2CH confirms optional LTE connectivity means the camera can maintain cloud connection independent of the owner's phone.
What they claim: BlackVue announced in October 2018 that it set all users' camera location, name, video and audio sharing settings to private as a server-level change.
What we found: CSO Online reported that even if users opted out of public sharing, re-registering their camera (e.g. after a factory reset or switching vehicles) would opt them back in without their knowledge or consent. The fix was a one-time server-side change that did not persist through the normal product lifecycle.
What they claim: BlackVue Cloud is presented as a feature for remote live view and video backup that users actively choose to use.
What we found: Dashcam Insight's 2026 privacy test found that BlackVue with a cloud account transmitted 184MB of footage thumbnails in 24 hours without the user actively using cloud features. Cloud upload is default-on when a BlackVue Cloud account exists, and data retention is set to unlimited by default. Users must actively disable auto-upload, review retention policies, and opt out of traffic pattern data collection.