EU Data Act (vehicle data)
The EU regulation giving users rights to data generated by connected products — with major consequences for who can access vehicle data.
The EU Data Act (Regulation (EU) 2023/2854) governs access to data generated by connected products, and vehicles are among its most consequential targets. In force since January 2024 and applicable from September 2025, it gives users — private owners and fleets alike — the right to access data their connected products generate, and to share that data with third parties of their choosing.
For vehicles, this cuts into a long-contested area: repair shops, insurers, leasing companies and app developers have argued for years that OEMs control vehicle data generated by customers. Under the Data Act, manufacturers must make readily available data accessible on fair terms, design new products for data access, and cannot lock users’ data into their own ecosystems.
What the act requires
The Data Act is horizontal — it applies to connected products generally, from industrial machines to home appliances — but its core mechanism maps directly onto cars. The user of a connected product (owner, lessee or renter, so fleets and leasing companies qualify) has the right to access the product’s readily available data, including relevant metadata, easily and where technically feasible continuously and in real time. The user can also direct the data holder — in practice usually the vehicle manufacturer — to share that data with a third party of the user’s choice.
Data holders must provide data to third parties on fair, reasonable and non-discriminatory terms, and may charge third parties no more than a margin-limited compensation, with lighter terms for small and medium-sized enterprises. Two boundaries are built in: companies designated as gatekeepers under the Digital Markets Act cannot be eligible third-party recipients, and trade secrets must be protected through proportionate safeguards agreed before disclosure — though secrecy cannot serve as a blanket refusal. Beyond the access rights, the act regulates unfair terms in business-to-business data contracts, business-to-government access in exceptional need, and switching between cloud services.
Timing comes in two steps. The obligations generally apply from September 12, 2025. The design obligation — building connected products so users can access data directly where feasible — applies to products placed on the market from September 12, 2026, which is the date vehicle electronics programs actually engineer toward.
Why vehicles are the hard case
Cars generate data across a spectrum, from high-rate sensor and bus traffic that never leaves an ECU to curated telematics signals already sent to the manufacturer’s cloud. The act’s access right attaches to “readily available” data — data the holder can obtain without disproportionate effort — which makes the vehicle’s data architecture itself a legal boundary: what the manufacturer chooses to collect and surface determines what users can claim. That design freedom is narrowed, but not removed, by the 2026 access-by-design obligation.
The commercial stakes explain the intensity of the argument. Independent repair depends on access that goes beyond the standardized on-board interface used for emissions-related diagnostics; insurers want driving data for usage-based products; fleets want their operational data portable across service providers. On the other side, manufacturers point to platform investment, trade secrets and the security implications of opening data paths into vehicles. The Data Act settles the principle — the user, not the manufacturer, decides where the data goes — while leaving much of the engineering and pricing detail to negotiation and enforcement practice.
How it interacts with vehicle-specific regulation
The Data Act operates alongside, not inside, the type approval framework. Approval law already mandates specific access channels — most prominently standardized access to repair and maintenance information under Regulation (EU) 2018/858 — and those sector rules continue to apply; the Data Act adds a general-purpose access right on top. Cybersecurity obligations under UNECE R155 bound how access can be implemented: a manufacturer must treat any new data interface as attack surface within its certified risk process, and regulators have accepted that access rights do not override the duty to keep vehicles secure — though security cannot become a pretext for refusal. The GDPR remains fully applicable where vehicle data relates to identifiable people, which much of it does; the Data Act’s rights operate in addition to, and within the limits of, data-protection law.
For the software-defined vehicle, the act adds a design driver: data access becomes a product requirement with a compliance date, not a business choice, pushing architectures toward well-defined signal layers rather than ad hoc extraction.
Common misconceptions
The act does not make vehicle data public, and it does not give third parties independent rights — every third-party access flows from a user’s decision. It does not require manufacturers to hand over raw in-vehicle bus traffic; the obligation covers readily available data and, from 2026, reasonable direct access by design. It is not a pricing free-for-all either: users access their data free of charge, while third parties can be charged within regulated limits. And it did not resolve the sector’s oldest dispute — whether a dedicated vehicle-data regulation with mandated technical interfaces should exist — it changed the baseline against which that dispute continues.
What to watch
Enforcement is the near-term story: national competent authorities took over supervision from September 2025, and the first disputes over what counts as readily available vehicle data, acceptable compensation and adequate trade-secret safeguards will set the practical meaning of the text. The September 2026 access-by-design date is the next engineering deadline. Standardization will decide how workable the rights become — signal models such as COVESA VSS are the leading candidates for serving vehicle data in a form third parties can actually consume. And the question of a sector-specific in-vehicle data instrument remains politically alive in Brussels; whether the Commission revives it, and in what form, is the single biggest open variable in European vehicle-data regulation. The Commission maintains a policy overview at digital-strategy.ec.europa.eu.
Related: COVESA · Software-defined vehicle (SDV) · Type approval / homologation · UDS / vehicle diagnostics