A modern car is not merely a mechanical means of transport. It can communicate with applications, send data to the manufacturer, record journeys, faults, driving behaviour or events, and interact with insurers, repair shops and service providers. The difficult question is not whether data are generated, but which data exist, who receives them, for what purpose, and which of them you can actually request.
There is no single "vehicle file" and no general rule that all data belong to the driver. The owner or lessee of the vehicle is one role, the person to whom information relates is another, and the company that decides why and how it will be used is yet another. The correct answer follows from the combined application of the European Data Act, the GDPR, the rules on electronic communications, and the specific contracts.
First practical step: open the vehicle's application and account, record which services are active, and download the available reports before disconnecting a device, changing ownership, or sending the car for repair. Do not hastily delete an account when there has been an accident, a dispute with an insurer, or suspected unauthorised access.
1. Where the data of a connected car are stored
Information may be stored in different places and have different retention periods. Some of it is held inside the vehicle, some in the mobile application, and some in the infrastructure of the manufacturer or its partners. For this reason, a request sent only to the dealership will not necessarily cover the entire chain.
- Vehicle systems: diagnostic codes, component status, maintenance indicators, settings, connected devices and, depending on the model, a local journey history.
- Manufacturer account and application: parking location, locking, charging, planned journeys, notifications and remote commands.
- Telematics cloud: technical condition, consumption, safety events, communication with roadside-assistance services and usage data.
- Third-party providers: an insurer offering a pay-how-you-drive programme, a leasing or rental company, a repair shop, a charging application, an employer's fleet, or a navigation service.
- Mobile phone: contacts, call history, messages, voice commands and destinations that may have been synchronised with the infotainment system.
The presence of a sensor does not mean that every measurement is stored or transmitted. Ask for the privacy manual for the specific model, the application settings, and the list of active services. The commercial label "connected" does not, by itself, explain what actually happens.
2. Owner, user and data subject are not the same
The Data Act, Regulation (EU) 2023/2854, uses the concept of a "user" of a connected product. A user may be the person who owns the vehicle or has a temporary contractual right to use it, such as a lessee or rental customer. This does not mean that every passenger automatically acquires all access rights.
The GDPR addresses a different question: whether information relates to an identified or identifiable natural person. A journey, a driver identifier, an associated device, or a driving profile may be personal data even if the vehicle belongs to a company. Conversely, purely technical data with no link to a person may fall within the Data Act without being personal data.
The controller is the party that determines the purpose and essential means of processing. This may be the manufacturer for one service, the insurer for another, and the employer for fleet management. A separate mapping is needed for each purpose.
3. What the Data Act provides in practice and from when
The Data Act has applied since 12 September 2025. One of its aims is to enable the user of a connected product to access product data and related-service data that are readily available to the data holder and, subject to conditions, to request that they be made available to a third party.
The specific design obligation requiring data to be directly accessible to the user applies to connected products and related services placed on the market after 12 September 2026. It is not a general obligation to retrofit every older vehicle. The European Commission guidance on vehicle data assists with interpretation, but is non-binding.
The request should identify the vehicle, the applicant's relationship to it, the period, and the categories of data. Saying "give me everything you have" is not enough. The data holder may need to verify identity, authorisation, third-party rights, trade secrets, and technical availability.
Important limit: the Data Act does not establish "ownership of all vehicle data". It regulates access to and use of specific data. A user's access does not allow a company to circumvent the GDPR when the data are personal.
4. When the GDPR applies and what you can request
When data relate to you, you may exercise the right of access under Article 15 GDPR. You may request confirmation that processing is taking place, a copy of the personal data, and information about the purposes, categories, recipients, retention period, source, and any automated decision-making. The Hellenic Data Protection Authority explains the procedure and its limits.
A response must in principle be provided within one month, with a possible extension of two further months when the request is complex or numerous requests have been made, provided that you are informed in good time. Portability covers data that you provided or that are generated by observing your use, where processing is based on consent or a contract and is carried out by automated means. It does not generally cover every inference, score, or profile created by the company.
Erasure is not an absolute right. It may be refused where there are legal obligations, a need to establish legal claims, safety grounds, or other grounds for retention. Consent is also not the only possible legal basis, while a contract does not legitimise any and all collection. Processing involving location, communications, or access to terminal equipment may also require an assessment under the ePrivacy rules.
5. Measurements are different from inferences about the driver
Raw or preprocessed data must be distinguished from inferences produced through additional analysis. Speed, battery level, temperature, a fault code, or a timestamp is different from a "high-risk driver" score, a fault prediction, or a commercial profile.
The distinction has practical significance. The Data Act focuses on product data and related-service data that are readily available, not necessarily on every complex model or commercial inference. The GDPR may entitle you to information about personal profiles and automated decisions, but the precise scope of the right depends on the process and on whether the result concerns you.
If an insurer raises a premium or rejects a claim because of a driving score, do not request only the "GPS data". Also request the main factors used in the assessment, their source, the period involved, how the data were linked to you, and whether there was human review.
6. GPS, cameras and insurance telematics
The vehicle's location may reveal a home address, workplace, medical visits, religious or political activities, and daily habits. Continuous collection therefore requires a clear purpose, limits on scope and duration, security, and intelligible information. In a corporate fleet, it is also necessary to assess necessity in relation to employees and the possibility of private use.
Dashcams are not inherently lawful or unlawful. The field of view, purpose, continuous or event-based recording, audio, retention period, and publication determine the risk. The guidelines on video devices require necessity and proportionality; a video needed for a claim should not be thoughtlessly uploaded to social media.
For a usage-based insurance programme, read which events affect the premium, who has access, what happens when another person drives, and how an incorrect measurement can be challenged. Disabling a device in breach of the contract may have consequences, but it does not cure opaque or excessive processing.
7. eCall, the event data recorder and cloud telematics are different
Public 112 eCall is activated automatically or manually in a serious accident and transmits the minimum set of data needed by the emergency response centre. Regulation (EU) 2015/758 prohibits continuous tracking by the 112 eCall system. The last three locations are used to determine position and direction when the incident occurs.
The event data recorder, informally known as the "black box", records parameters for a short period shortly before, during, and immediately after a collision. Regulation (EU) 2019/2144 sets requirements for this function. It is not a complete journey log, does not by itself prove fault, and does not mean that every private individual has a direct technical means of retrieving the file.
The manufacturer's commercial cloud telematics is a third category. It may operate every day for maintenance, applications, navigation, or safety services. Do not use the term eCall for every transmission of data from the vehicle.
8. How to write a useful access request
A specific request usually receives a more substantive response than a general text. Send it through the privacy or data channel of the actual controller and retain proof of submission.
- Identify the vehicle by VIN or another necessary detail, without publishing it.
- Explain whether you are the owner, lessee, service user, or person to whom the information relates.
- Specify a particular period and service, for example the application, telematics, charging, or insurance programme.
- Request the data categories, purposes, recipients, retention period, and an available copy.
- Request clarification of any score, profile, or automated decision that affected you.
- If you request transmission to a repair shop or provider, identify the recipient and the lawful request.
- Ask for reasons for any part that is refused, rather than merely a general response referring to confidentiality.
Do not send a photograph of your identity document unless it is necessary. Ask what minimum information is needed for verification and use the official, secure channel. A GDPR request and a Data Act request may coexist, but it is useful to state clearly which basis you invoke for each part.
9. What to do when selling, renting, leasing, or servicing a vehicle
Before handing over a car, remove driver profiles, addresses, connected phones, application keys, charging cards, and authorised users. Perform a factory reset only after lawfully retaining anything needed for a warranty, accident, or pending claim. Deletion on the vehicle's display does not guarantee that the data in the cloud have also been deleted.
For rental or leasing, check whether the company can see the location in real time, when it is allowed to use it, whether driving behaviour is recorded, and when the data are deleted. When taking a vehicle to a repair shop, create a temporary profile or use valet mode if available, and do not leave unnecessary access to contacts and messages.
If you buy a used connected car, make sure that the previous holder has disconnected from the application. Otherwise, they may retain remote visibility of its location or functions even if they have handed over all the physical keys.
10. How to preserve evidence after an accident or dispute
After a collision, theft, fire, disputed charge, or dispute with an insurer, time matters. Some logs are overwritten quickly. Send a written preservation request to the potential data holders without assuming that any one of them has all the data.
- retain original files, complete exports, emails, and proof of submission,
- record the application version, vehicle software version, and connected services,
- do not edit original screenshots or videos, and preserve their metadata,
- request a technical extraction through a lawful procedure when specialist equipment is required,
- correlate the measurements with other evidence rather than treating them as automatic proof of fault.
A speed or location reading may require interpretation, an accuracy check, and correlation with the time, sensor, and software version. Integrity and chain of custody are often more important than a single screenshot.
11. What happens if there is no response or the data were used unlawfully
If you receive no response to a personal-data request, if the response is vague, or if you believe that unlawful processing has occurred, you may use the complaint procedure of the Hellenic Authority. Before submitting a complaint, it is useful to have exercised the right with the controller and to attach the request and response.
A dispute under the Data Act may follow a different mechanism, depending on the data holder, the contract, and the competent body. Parallel action may be needed in an insurance dispute, an accident, or a consumer contract. Do not expect a single privacy complaint to resolve a compensation or contractual-liability issue automatically.
Compensation under the GDPR is not automatic. An infringement, material or non-material damage, and a causal link are required. The judgment of the Court of Justice of the EU in case C-300/21 clarified that an infringement alone is not sufficient.
12. The practical conclusion for the driver
Do not begin with the question "who owns all the data?" Begin with four specific points: which service generated the information, who holds it, what your relationship to the vehicle is, and whether the information relates to you personally. Then choose the Data Act, the GDPR, the contract, or a combination of them.
The most useful steps are simple: check the settings before a problem arises, disconnect accounts when selling or handing over the vehicle, preserve complete records when an event occurs, and send a targeted request to the correct recipient. A connected car can provide useful evidential data, but only when we know exactly what it measures and what its limits are.
Legal update: this article reflects the framework in force on 24 August 2026. Its practical application depends on the model, the contract, the active services, and the applicant's status. A specific accident, insurance dispute, or intended use in court requires an individual legal and technical assessment.
Comments
Share your thoughts about this article.
No comments yet. Be the first to comment.
Submit a comment