The Battle for Vehicle Data
- By Dr Martyn Taylor, Jay Modrall, Dietrich Marquardt, Dr David Fila & Damien Vickovich
- Aug 6
- 16 min read

How Europe and Australia are regulating connected car data
Vehicle data is becoming a regulated commercial asset. Traditional battles over car data focused on repair and maintenance information (RMI) controlled by original equipment manufacturers (OEMs). While such data remains important, cars now generate vast amounts of real-time data that is collected, shared and used among a wide range of stakeholders. Regulatory frameworks are evolving both in Europe and Australia to address the car data revolution.
Antitrust rules apply alongside regulations. The collection, sharing and use of car data can also raise antitrust issues. Cooperative relationships, which are common in the sector, must avoid antitrust infringements and may trigger more formal review and approval requirements. Stakeholders with dominant positions or market power by virtue of their access to car data or collection systems may also have special obligations.
European regulatory frameworks aim to create a market in connected-car data. The European Union’s (EU’s) regulatory framework is ambitious but fragmented. The EU has long required OEMs to give repair shops access to RMI. Vehicle-generated data is now also subject to digital and privacy regulations, including notably the EU Data Act, which gives users greater control over data generated by their connected products. Using that data, however, requires the development of common standards and data marketplaces, which are contemplated by other EU regulations.
Australia regulates vehicle data through existing legal categories. Australia has no dedicated connected-vehicle regime, but instead regulates vehicle data through generic privacy, repair-information sharing, competition, consumer law and security controls. However, protection depends on whether information falls within an established category such as personal or repair information. The framework is narrower, but capable of incremental expansion.
3D regulatory chess. Stakeholders seeking to capture and monetise car data globally need to move strategically to take advantage of emerging opportunities while navigating a complex and evolving regulatory landscape.
Cars as data-generating platforms
Connected vehicles operate within wider digital ecosystems, generating and receiving information continuously throughout their operating lives. Manufacturers can continue transmitting data to their vehicles after they are sold, updating functionalities through over-the-air software updates, while the vehicles generate status and diagnostic data that supports manufacturers’ future product development.
Vehicles also exchange location data, environmental and other information both with one another and with public infrastructure for a wide range of public safety and traffic management purposes. Drivers can receive and communicate data through online platforms using vehicle systems, while vehicles collect data on driving behaviour. The introduction of artificial intelligence (AI), for instance for autonomous vehicles, further accelerates the data exchange.
Car data is therefore generated, collected and used by a wide range of stakeholders. Most obviously, these include OEMs as well as Tier 1 suppliers and repair shops, but many other stakeholders are involved. Car data is collected and distributed via platforms ranging from vehicle architectures in so-called software-defined vehicles (SDVs); vehicle control and autonomous driving systems (sometimes referred to as real-time operating systems, or RTOS); and infotainment and smart cockpit systems.
Infotainment and smart cockpit systems such as Android Auto and CarPlay may connect to broader, non-vehicle-specific platforms operated by large consumer technology companies. Who controls vehicle data depends in part on which system collects it.
Developing and operating these systems requires extensive cooperation, but the form of cooperation depends on the stakeholders’ business models. Some OEMs prefer to retain greater data control via proprietary vehicle architectures, RTOS and even infotainment and smart cockpit systems. Others may rely more heavily on platforms from large digital companies such as Alphabet and Apple.
Cooperative relationships range from standard-setting and open-source initiatives like the Automotive Grade Linux (AGL) and Eclipse Foundation’s SDV projects to tight joint ventures like Coretura, Mobile Drive, RV Tech and SiliconAuto. Some of these cooperations are long-standing: the AUTOSAR consortium was founded in 2003; the AGL working group was formed in 2012.
As illustrated below, SDV architectures capture not only basic vehicle status and diagnostic information, but also information on driving behaviour such as speed, braking and lane position data. Infotainment and smart cockpit systems recognise and record voice data and contain cameras, as well as sensing biometric driver data. Such data can be used not only for vehicle maintenance and development but also support a wide range of services.
The regimes and the purpose
Which regulatory regimes apply to car data can turn on many factors, including the purposes for which the data is used, how the data is generated, whether the data relates to an identified or identifiable individual and the nature of the entity collecting it.
OEM data required for repairs and maintenance may be subject to vertical, sector-specific regulations requiring OEMs to share data with repair shops. Data generated by drivers using connected cars may be governed by digital regulations giving users rights in data they generate, even if the data is controlled by an OEM or other third party. Other regulations may apply to data collected by large digital “gatekeepers.” Data relating to an identified or identifiable person may be protected by data privacy laws, with more stringent protections applying especially to biometric data.
This briefing focuses on the regulatory regimes for collecting and sharing car data in the EU and Australia. It should be noted, however, that other regimes may also apply, including consumer protection, product safety, product liability, cyber security and geolocation rules.
European Union: creating access rights over vehicle data
EU regulations covering vehicle data fall into two main regulatory frameworks, neither of which was originally designed for connected cars. The first involves sector-specific regulations requiring OEMs to share RMI with independent repair shops. The second involves the EU’s data-economy agenda, which seeks to promote free markets in data, while giving end users who generate data more control. Overlaying both frameworks are the EU’s data privacy rules.
1. Vertical regulation for aftermarkets
EU regulation of RMI long predates the connected car. The EU type-approval framework (Regulation (EU) 2018/858) requires manufacturers to give independent operators standardised and non-discriminatory access to RMI, together with the relevant tools, training and remote diagnostic services, but this requirement dates back to 2007.
This sector-specific regulation was not originally intended to cover driver-generated data, but diagnostic data collected from modern connected cars and relevant to repair and maintenance functions is also caught. This sectoral regime is reinforced by EU antitrust rules: the Motor Vehicle Block Exemption Regulation (EU) No 461/2010 treats the foreclosure of independent operators from technical information as a potential violation of the Article 101 of the Treaty on the Functioning of the European Union (TFEU) prohibition of anticompetitive agreements and practices.
2. Horizontal data-economy regulations:
The EU’s data-economy agenda is implemented through horizontal digital regulations not specifically designed for connected cars. The most relevant is the EU Data Act (Regulation (EU) 2023/2854, or the Data Act), which promotes sharing data generated by “connected products,” including cars.
The Data Act grants users of connected products rights to access the data those products generate and direct that it be shared with third parties of the users’ choice. As from September 2026, connected products must be designed so that data is directly accessible to the user.
The European Commission’s guidance on the Data Act’s application to vehicle data distinguishes between raw and pre-processed data, which are more likely to fall within scope; and inferred or derived data, including proprietary analytics, which it treats as outside scope. This line is not always intuitive: simple calculations on in-scope data (for example, deriving fuel consumption from fuel-flow rate and speed) are in scope, while only genuinely complex or proprietary processing takes derived data outside it.
The guidance also indicates that manufacturers should consider providing access to data points important for independent aftermarket use cases, such as vehicle speed, location and odometer value, again focusing on RMI.
Although OEMs operating in Europe have created portals allowing end users to access car data under the Data Act, developing a free market for such data requires technical standards and interoperability. The Data Act and related EU legislation aim to develop such standards and create the infrastructure for “common European data spaces,” including the European Mobility Data Space (EMDS). The EMDS is intended as a common technical and governance framework linking transport-data ecosystems to improve interoperability and discoverability across them. As at mid-2026, however, the EMDS remains in development, and there is no clear target by which it will be operational.
As mentioned, the Data Act sits alongside a number of other digital sector measures. One of these is the Digital Markets Act (Regulation (EU) 2022/1925 or the DMA), which regulates designated “gatekeepers” providing core platform services, including “embedded digital services in vehicles” (Recital 14). Designated gatekeepers such as Apple and Google are required, among other things, to ensure interoperability for their core platform services. However, the Data Act prohibits DMA gatekeepers from soliciting, incentivising, or even receiving data from users under the Data Act. Unfortunately, the Commission has no immediate plans to develop additional guidance on the Data Act’s application to vehicle data.
The EU AI Act (Regulation (EU) 2024/1689) adds another layer of complexity, as AI is increasingly introduced in advanced driver assistance systems (ADAS), autonomous driving perception, driver monitoring and predictive maintenance. Where such systems do qualify as high-risk (for example, AI acting as a safety component of a vehicle subject to type-approval) the AI Act’s data-governance obligations under Article 10 will be relevant: providers must be able to identify the training, validation and testing data on which the system relies, ensure those datasets are relevant, representative and, to the best extent possible, free of errors, and detect and correct bias.
3. Data privacy
Overlaying all these regulations is the General Data Protection Regulation (GDPR). EU data protection authorities consider most data generated by connected vehicles as personal data protected by the GDPR, because a driver can usually be identified, directly or indirectly, from location histories, behavioural patterns or device identifiers.
The GDPR requires a lawful basis for the use of personal data, imposes heightened conditions on special-category data (e.g., health-related data), gives individuals rights of access, portability and erasure of their personal data and imposes obligations on data controllers (e.g., regarding governance, data minimisation, and storage limitations). The GDPR also limits businesses’ transfer of personal data outside the EU, including connected vehicle data stored in the cloud.
The Data Act’s access and portability requirements extend users’ GDPR rights to non-personal data, but the GDPR’s limitations on business’ ability to use car data only applies to personal data. Business’ ability to comply with both regimes thus requires clear distinctions between personal and non-personal data, RMI and other data and potentially procedures to anonymise personal data to be retained longer or used for different purposes than the GDPR would permit. Minimum standards for anonymisation are currently under development.
Australia: extending existing legal categories
Rather than creating a new legal category for connected-product data, Australia extends existing regulatory frameworks, mainly personal information, repair information, competition law and security controls.
The current political momentum suggests that the Australian regulatory regime will continue to broaden and deepen, likely taking into account developments in the EU and other jurisdictions. However, any broader vehicle-data regime in Australia is more likely to emerge by extending those frameworks than by creating a single connected-vehicle statute.
Five regulatory pathways are most relevant:
1. MVIS expansion
The Motor Vehicle Service and Repair Information Sharing Scheme (MVIS), in the Competition and Consumer Act 2010 (Cth) (CCA) since 1 July 2022, requires service and repair information to be available to Australian repairers and registered training organisations at no more than fair market value. However, the scheme covers only information prepared by or for manufacturers for use in diagnosing faults with, servicing or repairing vehicles. It does not extend to data generated by the vehicle itself about driver or vehicle performance, so real-time telematics data from connected vehicles currently sits outside the scheme.
Treasury’s February 2026 MVIS review found the scheme broadly realising its objectives and identified improvement opportunities, including electronic logbooks, intermediaries such as data aggregators and tool manufacturers, and safety and security information. Treasury has recently consulted on those improvements and on extending right-to-repair settings beyond light vehicles, including to agricultural machinery. Read closely, it is arguably Australia’s first real debate about access to operational industrial data, even though it is framed as a repair-information reform.
2. Consumer Data Right designation
The Consumer Data Right (CDR) creates data-portability rights, but only in sectors the Government designates. It now covers banking and energy, with non-bank lending being added. Automotive has not been designated, so a vehicle-data access right could be created through designation rather than a new statute.
The United Kingdom is instructive here, since the Data (Use and Access) Act 2025 (UK) builds Smart Data schemes switched on sector by sector. The UK has formally examined Smart Data opportunities in transport, including journey planning, ticketing, EV charging, network management, freight and logistics. Designation would be the most plausible route to a broad Australian access right, though there have been no recent suggestions of any such extension in Australia.
3. Privacy law reform
The Privacy Act 1988 (Cth) remains central for personal information. The first tranche, the Privacy and Other Legislation Amendment Act 2024 (Cth) (Royal Assent 10 December 2024), strengthened enforcement and provided for a Children’s Online Privacy Code. A new statutory tort for serious invasions of privacy commenced on 10 June 2025, and automated-decision transparency requirements (Schedule 1, Part 15) will commence on 10 December 2026.
The application of the personal information category is contested. Information is personal information under the Privacy Act where the information is about an individual who is reasonably identifiable, but that is a matter of fact and degree. Published privacy terms for connected vehicles in Australia often treat vehicle-generated data as falling outside that definition, an approach criticised in some academic analysis.
The reasoning of the Australian Information Commissioner in its recent determinations also indicates that the scope of personal information may be broader than what the corporate sector may have understood. Where personal information (as defined in the Privacy Act) is disclosed to overseas recipients, including a manufacturer’s offshore cloud infrastructure, the accountability requirements of Australian Privacy Principle 8 also apply.
On 20 July 2026, as part of a broader announcement relating to AI consumer safety priorities, the Albanese Government confirmed it would consult on a second tranche of privacy reforms to responsibly strengthen, modernise and simplify Australia's personal data protection laws, led by the Attorney-General. While the consultation package is not yet known, the previous indications were that a second tranche of reforms could relevantly lead to an expanded definition of personal information, a fair-and-reasonable test for collection, use and disclosure, and tightened consent for precise geolocation. That would not, by itself, create access rights over non-personal vehicle data.
The Federal Chamber of Automotive Industries has separately published a voluntary code of conduct on automotive data and privacy protection, but it is not a registered code under the Privacy Act and compliance is therefore not directly enforceable by the privacy regulator.
4. Vehicle standards and cyber security
Australia currently has no Australian Design Rule addressing vehicle cyber security or software updates. During 2026, the Australian Government consulted on adopting United Nations (UN) Regulation No 155 on cyber security and UN Regulation No 156 on software updates as new Australian Design Rules, together with associated changes under the Road Vehicle Standards framework, and further consultation is expected in the second half of 2026.
Both UN Regulations have applied to new vehicle types in the EU since July 2022. If adopted in Australia, these requirements would regulate the security of the same vehicle connectivity that generates the data discussed above.
5. General competition law
Section 46 of the CCA, the Australian prohibition on misuse of market power, together with the MVIS, may in some cases reach data-related conduct by a firm with substantial market power even without a dedicated access regime, though how far those tools extend to data gatekeeping is untested.
Antitrust and Competition Law Considerations
The collection, sharing and use of car data can give rise to antitrust issues in many contexts. These issues should be identified and addressed alongside the regulatory issues discussed above.
Anticompetitive agreements: The collection, sharing and use of car data involves overlapping levels of cooperation among multiple stakeholders, ranging from multilateral cooperative projects such as setting technical standards and designing and operating shared charging networks and mobility platforms to bilateral R&D or data-sharing agreements. These cooperations could potentially involve sharing of competitively sensitive information such as prices, volumes, capacity utilisation or strategy and require important restrictions or safeguards such as firewalls and compliance training. Cooperation on standards development may also trigger transparency and non-discrimination requirements.
Abuse of dominance or substantial market power: Given car data’s central role across multiple businesses, control over such data or the systems collecting them can give rise to a dominant position or substantial market power, in turn triggering potentially far-reaching implications. These can range from commercial limitations on discrimination, self-preferencing, bundling, pricing etc. or to access requirements. In the EU, the EU courts found that Android Auto’s refusal to ensure interoperability for third-party applications could be an abuse of its dominant position.
Merger control: Car data plays a growing role in merger control, in various ways. As mentioned, joint ventures in the connected car space may trigger notification requirements, and the potential for such ventures to create formal or de facto standards, bottlenecks or incentives to foreclose may become key substantive issues. Similarly, horizontal or even vertical acquisitions giving one stakeholder control over another’s systems or datasets may raise substantive concerns. Where data represent an important part of the value proposition, regulatory compliance is likely to become a significant due diligence issue.
Playing 3D Regulatory Chess
Stakeholders that collect, use and share car data are now required to navigate overlapping regulatory considerations both in their own internal businesses and their relationships with third parties. Many stakeholders operate globally and want to minimise regional or national variations, even though applicable laws vary from jurisdiction to jurisdiction. Stakeholders also want to future-proof their activities as far as possible, even though the regulatory landscape is evolving rapidly.
To ensure that they can comply with applicable regulations, stakeholders need to understand the types of rights and obligations attached to different types of data. They must have the technical ability to identify and treat that data accordingly and the necessary contractual rights vis-à-vis any third parties with which they want or need to share that information. An example can help illustrate this point.
OEMs receive large volumes of data from connected cars they manufacture. OEMs must be able to identify the data that qualify as RMI and share it with repair shops. Some of that data likely qualifies as personal information covered by data protection rules. While sharing personal RMI data with repair shops may qualify as a legitimate use (and consented to by car owners), OEMs must comply with additional substantive requirements applicable to personal data, such as limiting the data shared with repair shops to the minimum required and complying with higher protection standards for biometric data, erasure/right-to-be-forgotten requests etc.
Stricter requirements may apply to OEMs sharing data with third parties such as CarPlay Ultra, since such sharing is not legally mandated. Where AI systems are used, additional obligations may apply in relation to data traceability and correction of errors. In the EU, and possibly later in Australia, OEMs also need to be able to identify connected car data to which users have access rights and to transfer that data to designated third parties.
These relationships are documented in contracts. The contractual terms therefore need to reflect regulatory requirements relevant to any data to be shared, allocate responsibility for authentication and security, and address numerous data-related issues, including:
Access and pricing: Who may obtain what data, in what format, on what terms, at what price and within what time.
Use: Permitted purposes, retention periods and restrictions on combining, profiling or secondary use.
Sharing: Onward disclosure to affiliates, intermediaries, cloud providers, insurers, repairers, analytics providers and other third parties.
Quality and interoperability: Data definitions, completeness, latency, API performance, authentication, auditability and service levels.
Derived data and analytics: Rights in inferred data, models, scores, analytics outputs and AI training datasets.
Liability and security: Cybersecurity obligations, including United Nations (UN) Regulation No 155, breach notification, audit and verification rights, allocation of product-liability risk with the recast Product Liability Directive (Directive (EU) 2024/2853, to be transposed by 9 December 2026) in view, and change management for over-the-air updates.
Agreements should also incorporate relevant regulations by reference to capture any updates and provide for review and revision to reflect rule changes that cannot be applied under the existing contract rules.
These and other considerations crop up in a wide range of contracts, including not only OEM agreements with repair shops and car owners but agreements negotiated by corporate fleet owners, insurance companies, mobility service providers and many others. Some of these (especially joint ventures and multilateral agreements involving competitors) may also raise antitrust issues. Joint ventures and M&A agreements may also trigger review by antitrust authorities who increasingly scrutinise data-related concerns. Connected car data is also of growing importance in M&A due diligence, since data rights and obligations can have significant impacts on enterprise value.
Concluding observations: our new data world
Connected vehicles collecting large volumes of data are testing the limits of regulatory regimes designed for other purposes. Sectoral regulations originally designed to promote aftermarket competition by forcing OEMs to share their data with repair shops now also capture data generated by the cars themselves.
Such operational data may also trigger user rights to access and control data generated by their connected products, without necessarily limiting OEMs’ or other business stakeholders’ ability to use the same data.
With the growing potential for connected car data to be linked to identifiable individuals, however, this data also triggers consent and other requirements limiting business’ flexibility unless they are able successfully to anonymise it. The growing integration of car infotainment systems into digital ecosystems creates another intersection with consumer protection and other regulatory frameworks.
Europe and Australia are proceeding along parallel paths, although the EU regulatory system is so far more developed. Both jurisdictions require sharing of RMI. The EU has created user access and portability rights for car users under the Data Act, but the infrastructure to create an open market for vehicle data remains in the future. So far, Australia has not followed suit on user access and portability rights. Any action along these lines would likely be based on the CDR rather than a new data economy measure. Both jurisdictions’ data protection laws apply to car data, but the EU has issued more concrete guidance. And in both jurisdictions, similar antitrust principles apply to cooperation, unilateral conduct and M&A activity in this sector.
For business the direction is clear. Vehicle data should be treated as a regulated commercial asset, with rights allocated and with systems, contracts and governance built to withstand privacy, regulatory and antitrust scrutiny across markets. Although the EU’s regulatory landscape is still evolving, it seems likely to set the global benchmark for the foreseeable future.
Authored by Dr Martyn Taylor, Jay Modrall, Dietrich Marquardt, Dr David Fila, & Damien Vickovich.
of Norton Rose Fullbright.
Dr Martyn Taylor
Martyn’s practice covers transactional, contentious and advisory. He is a corporate and commercial lawyer and a well-known telecommunications, internet, media and technology (TMT), infrastructure/utilities, energy, competition and regulatory specialist.
Jay Modrall
James R. Modrall is an antitrust and competition lawyer based in Brussels. He joined Norton Rose Fulbright LLP in September 2013 as partner, having been a resident partner in a major US law firm since 1986. A US-qualified lawyer by background, he is a member of the bar in New York, Washington, D.C. and Belgium.
Dietrich Marquardt
Dietrich acts for Australian and international corporate clients on all aspects of competition law, including in relation to transactional, contentious and advisory work. He is highly commercial in his approach and has great rapport with clients. Dietrich regularly advises on the regulatory and competition aspects of highly complex, multi-jurisdictional matters, and consistently delivers outcomes that exceed clients' expectations, resulting in achievement of significant strategic and commercial objectives.
Dr David Fila
David supports multinational and German clients across all aspects of European and German competition law. He has particular experience in cartel investigations, European and German merger control, and private enforcement of competition law. He also regularly manages multijurisdictional foreign direct investment (FDI) matters and represents clients in FDI procedures before the German Ministry for Economic Affairs and Energy. In addition, David provides guidance on digital regulation, including the Digital Markets Act (DMA).
Damien Vickovich
Damien has experience advising clients on contentious and non-contentious competition issues such as cartel behaviour, market misconduct, access regimes and merger clearance. Damien also has experience advising clients on regulatory issues arising in the telecommunications, infrastructure, energy and transport sectors.







