Modern connected cars collect location, driving-behavior and even biometric data (via driver-monitoring cameras), and regulation is catching up unevenly. In the US, around 20 states now have comprehensive consumer privacy laws that apply to connected-vehicle data alongside other personal data, led by California's CCPA/CPRA framework, but there's still no single comprehensive federal vehicle-data privacy law. In the EU, the Data Act, which took effect in 2024 and became broadly applicable from September 2025, specifically addresses access to data generated by connected products including vehicles, giving owners and third parties (like independent repairers) clearer rights to that data. The result: your rights over your own car's data depend heavily on where you live.
At a glance
| Region/law | What it covers |
|---|---|
| California CCPA/CPRA | General consumer privacy rights extended to connected-vehicle data |
| Other US state privacy laws | ~20 states with comprehensive laws covering personal data broadly, incl. vehicle data |
| EU Data Act | Applicable from Sept 2025; governs access/sharing of data from connected products incl. vehicles |
| Manufacturer privacy policies | Vary significantly; often the main practical rulebook where law is silent |
What data a modern connected car actually collects
Beyond the obvious GPS location history, today's connected vehicles can log driving behavior (speed, braking, acceleration patterns), infotainment usage, phone-pairing data, and — increasingly, as driver-monitoring systems spread for safety compliance — camera-based data about the driver's attention or drowsiness state. Some of this data stays on the vehicle; a growing share gets transmitted to the manufacturer's servers for features like remote diagnostics, over-the-air updates, or usage-based insurance partnerships.
The US: a state-by-state patchwork
There is still no single comprehensive federal law governing vehicle data privacy in the US. Instead, roughly 20 states now have general comprehensive consumer privacy laws — California's being the most established and closely watched — that apply to personal data broadly and, by extension, to the kind of data connected vehicles generate. Massachusetts's right-to-repair law also touches this space from a different angle, focused specifically on repair-data access rather than privacy per se. The upshot is that a car owner's actual data rights (to access, delete, or opt out of sale of their data) can differ meaningfully depending on which state they live in.
The EU Data Act: a more unified approach
The EU's Data Act, which became broadly applicable from September 2025, takes a more horizontal approach — rather than being vehicle-specific, it sets rules for data generated by connected products generally, including cars, giving users clearer rights to access data their own device/vehicle generates and to share it with third parties of their choosing, such as independent repair shops or alternative service providers. This overlaps meaningfully with right-to-repair goals while being framed primarily as a data-rights measure.
- User access rights: the Data Act aims to let vehicle owners access data their car generates, not just the manufacturer.
- Third-party sharing: owners can generally direct that data be shared with independent repairers or other service providers.
- Overlap with right-to-repair: the practical effect supports many of the same goals as dedicated right-to-repair campaigns, via a data-rights framework instead.
Even where a law grants data-access or deletion rights, exercising them in practice usually requires going through the manufacturer's specific privacy portal or customer service process — rights on paper and ease of access in practice aren't always the same thing.
What this means for owners right now
Check your specific vehicle manufacturer's privacy policy and your state's (or country's) applicable law before assuming a particular right — such as deleting your driving history or opting out of data sales to insurers or advertisers — is guaranteed everywhere. If privacy is a significant concern, features like usage-based insurance telematics and some connected-services subscriptions are generally opt-in and can often be declined or limited.
Where this is heading
Expect continued state-by-state expansion of US privacy law covering connected-vehicle data in the absence of a federal statute, and continued EU emphasis on the Data Act framework as the primary lever for both privacy and repair-access goals, with driver-monitoring camera data likely to become a specific focus point as that hardware becomes near-universal under safety mandates like Euro NCAP's 2026 protocols.
Frequently asked questions
Is there a federal vehicle data privacy law in the US?
What does the EU Data Act do for car owners?
Can I opt out of my car sharing driving data with my insurer?
Does driver-monitoring camera data count as personal data?
Sources & further reading
- European Commission — EU Data Act
- California Privacy Protection Agency — CCPA/CPRA
- NHTSA — Safety ratings, recalls & research
Figures, prices and policy details were current at the last-updated date above. Automotive pricing, incentives and regulations change frequently — verify time-sensitive details with the linked primary sources. Read our editorial policy and fact-checking standards.