Skip to Content

EU vehicle-data guidance: what OEMs and the aftermarket must receive

The Commission explains the Data Act for connected vehicles: data scope, access routes, quality and limits of the right.
16 September 2025 by
EU vehicle-data guidance: what OEMs and the aftermarket must receive

The Data Act has applied since 12 September 2025. At the same time, the European Commission issued specific guidance on vehicle data, published in the Official Journal on 15 September 2025. It addresses OEMs, suppliers, independent aftermarket providers and insurers and explains which data from connected vehicles must be accessible and through which route access may be provided.

Position covered: 16 September 2025. The guidance explains Chapter II of the Data Act but does not extend or modify its rights and obligations. Binding interpretation of the Regulation remains a matter for the competent courts.

Raw and pre-processed data are within scope

Chapter II covers product data and related service data, including the metadata required to interpret and use them. For vehicles, this includes data generated by use and data from vehicle-related services. The guidance gives user inputs and automatically generated sensor data as examples of raw data.

Pre-processed data may also be covered where they make physical quantities or states understandable and usable. By contrast, information inferred or derived from those data and creating additional insight is outside the access right. The right concerns data; the Data Act does not create a general right of access to vehicle functions, electronic control units or other technical resources.

Direct and indirect access must be distinguished

Article 3(1) requires direct data access only where relevant and technically feasible. If that route is unavailable, the data holder must make readily available data accessible to the user under Article 4. At the user's request, those data must also be made available to a third party chosen by the user under Article 5.

The data must in principle be provided at the same quality available to the data holder and be easily, securely and free of charge accessible to the user. The guidance identifies vehicle data transmitted to an OEM backend as an important example of readily available data. Data not stored may also be covered if the data holder can lawfully obtain them through a simple operation.

Aftermarket access requires a clear chain of entitlement

An owner, renter or lessee may be a user for the purposes of the Data Act. The relevant contract must therefore identify who may request access and select a third party. For fleets, leasing and changing drivers, roles, authorisations and the end of an entitlement must be reflected in both technical processes and contracts.

Disclosure to repairers, insurers or other service providers remains subject to data protection, security and the protection of trade secrets. Where the user is not the data subject, disclosure of personal data requires a legal basis under the GDPR. Security or confidentiality interests may justify protective measures and, in narrowly defined cases, refusal, but not a blanket block on all vehicle data.

Data architecture and contracts must describe the same facts

OEMs and suppliers should record for every data point where it arises, whether it is retrievable, who receives it and whether it is raw data, pre-processed data or derived information. This classification determines access, format, quality, metadata and permitted use. A technical inventory without clarification of the legal roles is insufficient.

Purchase, rental, lease and service contracts must contain the pre-contract information required by Article 3 and explain access and termination of data sharing. The specific design duty in Article 3(1) applies only to connected products and related services placed on the market after 12 September 2026. The access rights already in force cannot be postponed until that date.

Review points for vehicle data and access processes

  1. Classify the data catalogue into raw data, pre-processed data and derived information.
  2. Identify data holders, users and eligible third parties for sales, rental, leasing and fleets.
  3. Document direct in-vehicle access and indirect backend access separately.
  4. Define format, metadata, quality, timeliness and termination for each data-sharing route.
  5. Assess data protection, security and trade secrets separately for each data flow.

Related insights

Official sources

This article describes the position as at 16 September 2025 and is not a legal assessment of a particular data-access or contractual model. Data protection, trade secrets, vehicle security and sector-specific rules require individual review.

Review vehicle-data access processes and contracts

EU Commission fines Google €2.95 billion over adtech practices
Decision AT.40670 concerns preference for AdX, conflicts of interest in advertising technology and possible structural remedies.