Artifact GuideEUData Act

EU Data Act Vehicle Data Guidance

Use the Commission's vehicle-data guidance to assess connected vehicles, vehicle-related services, user and third-party access, aftermarket use cases, and the safeguards that shape access under Data Act Chapter II.

The guide separates binding Data Act duties from non-binding Commission guidance and keeps GDPR, trade secret, safety, cybersecurity, and sector-law questions visible.

Author
Sorena AI
Published
May 6, 2026
Updated
Jul 25, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 6, 2026
Updated Jul 25, 2026
Overview

The Data Act has applied since 12 September 2025, and the Commission published its non-binding vehicle-data guidance in the Official Journal on 15 September 2025. Automotive teams can use this page to assess whether a vehicle is a , whether a service is a , which data is raw or pre-processed, which access route delivers the required quality, and which safeguards apply before sharing or refusing access.

Section 3

Separate raw and pre-processed vehicle data from inferred or derived information

The central data-scope question is whether the requested vehicle data is raw or pre-processed data, with the metadata needed to interpret and use it, or whether it is that falls outside the Data Act access obligation unless otherwise agreed.

Product data are data generated by the use of a that the manufacturer designed to be retrievable. Data processed only inside the vehicle and immediately deleted, with no party able to retrieve it, fall outside that product-data boundary. If raw or pre-processed data are stored, externally transmitted, or otherwise retrievable, assess whether they are readily available even when the OEM does not routinely keep them.

For vehicles, raw data may include sensor signals, raw image or point-cloud data, radar signals before object detection, CAN bus messages, direct commands, and component status. Pre-processed data may include measured speed, acceleration, battery level, odometer value, fault codes, tyre pressure, liquid levels, brake-pad wear where not predictive, and other data that still describes vehicle operation or status.

  • Treat basic formatting, calibration, normalisation, filtering, conversion, aggregation, correction, timestamping, and similar preparation as not automatically excluding a data point.
  • Treat proprietary insights such as driving scores, object classification, route-planning outputs, driver analysis, crash-severity analysis, or ADAS risk assessment as likely inferred or derived unless the underlying data itself is requested.
  • For predictions, record whether the output is a future-looking inferred insight or whether an alternative raw or pre-processed data point is readily available.
  • Keep metadata with the data package, including context needed to interpret time, vehicle state, collection source, and quality.
Section 4

Choose an access route that satisfies same-quality and easy-access duties

The Data Act does not mandate one automotive technical route. Direct access under Article 3(1) applies where relevant and technically feasible and is subject to the 12 September 2026 market-placement rule. Where direct access is unavailable, Article 4(1) requires the to provide the with ; Article 5(1) covers a third party acting at the user's request. Remote backend access, onboard access, or a data intermediation service may support those routes.

For vehicle data, the practical control is quality parity. Data made available to the or user-chosen third party must not be less accurate, complete, reliable, relevant, or up to date than the data available to the through another route, unless a different arrangement is justified under the Data Act or other applicable law. Articles 4 and 5 require access without undue delay but do not set one fixed numeric response period for ordinary Chapter II vehicle-data requests.

The receives access free of charge. When the makes data available to a business data recipient under Article 5, Articles 8 and 9 can permit reasonable compensation from that recipient. The user cannot choose an undertaking designated as a gatekeeper under the Digital Markets Act as the Article 5 third party.

  • If data is sent to an OEM backend under an extended-vehicle model, assess it as readily available to the OEM.
  • If the OEM does not retrieve or store a data point, document whether it can lawfully obtain it without disproportionate effort going beyond a simple operation.
  • If OBD-II or another onboard route is used, do not design access so that the must buy specialised tools or have advanced technical skills.
  • Compare the quality offered to independent repair shops or other independent service providers with the quality available to the , subsidiaries, authorised partners, dealers, and repairers.
  • Record the recipient's intended use. Data obtained through Articles 4 or 5 cannot be used to develop a competing , but the Data Act does not prohibit developing a competing related or aftermarket service.
Recommended next step

Turn vehicle-data requests into an evidence file

This guide helps structure request intake, data classification, access-route selection, GDPR and trade-secret review, and delivery or refusal records for connected vehicle data.

Section 5

Build safeguards around GDPR, trade secrets, safety, and sector law

Vehicle data can be personal, commercially sensitive, safety-relevant, or tied to sector-specific automotive rules. The Data Act does not displace the GDPR, privacy law, trade secret protection, type-approval rules, or other sector law. Where personal data is involved, the GDPR boundary must be assessed before a or third-party transfer is approved.

The Commission FAQ states that GDPR rules prevail in a conflict. A who is not the data subject, or a making personal data available, needs a valid GDPR basis for the relevant processing. The Data Act does not itself create a legal basis to collect or generate personal data.

Do not treat trade-secret status as an automatic refusal. The or trade-secret holder must identify the protected data and seek proportionate technical and organisational measures before disclosure. It may withhold or suspend only the identified trade-secret data if measures are not agreed or implemented, or confidentiality is undermined. Refusal is exceptional and case-specific: the trade-secret holder must objectively substantiate that serious economic damage is highly likely despite the safeguards.

  • Identify whether the requested dataset includes personal data about the driver, passengers, previous users, fleet staff, or other data subjects.
  • For mixed datasets, assess anonymisation, data-subject separation, minimisation, pseudonymisation, encryption, and -specific filtering before transfer.
  • For trade secrets, document the protected information, agreed safeguards, any failed or undermined measure, the objective evidence for any claimed serious economic damage, the written reasons given without undue delay, and the competent-authority notification.
  • For safety or security, Article 4(2) permits a contractual restriction or prohibition only where the processing could undermine a connected-product security requirement laid down in Union or national law and cause a serious adverse effect on people's health, safety, or security; notify the competent authority if access is refused on that basis.
  • For safety, cybersecurity, OBD, emissions, and roadworthiness data, check the Data Act position against applicable automotive sector rules instead of using the vehicle guidance as the only source.
  • Tell the or third party how to challenge a withholding, suspension, or refusal through the competent authority, an agreed dispute settlement body, or a Member State court or tribunal.
Section 6

Keep an evidence file for each vehicle-data request

A defensible vehicle-data decision should be traceable from the request to the data package, role map, access route, safeguards, delivery terms, and any refusal or exclusion. This is especially important where the same company may be an OEM in one flow, a supplier in another, a data recipient for a -directed request, and a processor or platform operator in a separate service.

The evidence file should be useful to legal, product, security, engineering, customer operations, and partner teams. It should also be readable by a regulator or dispute body without relying on internal shorthand.

  • Request record: vehicle identifier or model context, , requester, recipient, requested data, purpose, and user instruction.
  • Role record: OEM, supplier, , , data recipient, service provider, processor or controller assumptions, and reviewer names.
  • Data record: raw, pre-processed, inferred or derived classification; metadata; backend, onboard, or edge location; readily available analysis; and quality comparison.
  • Safeguard record: GDPR basis or data-minimisation analysis, trade secret measures, safety and cybersecurity review, sector-law checks, compensation position where relevant, delivery proof, and refusal rationale.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • States that the Data Act is without prejudice to personal-data and privacy law and does not create a legal basis to collect or generate personal data.
Related guides

Explore more topics

Data Act and Common European Data Spaces
How Data Act Article 33 connects data-space participation with metadata, vocabularies, APIs, access terms, data quality, governance, and standards monitoring.
Data Act and Data Governance Act Overlap FAQ
FAQ explaining where the EU Data Act and Data Governance Act overlap, how they differ, and how to route product, cloud, public-sector reuse, intermediary, and data altruism workflows.
Data Act Audit Evidence and Request Logs FAQ
FAQ for Data Act request logs covering user and third-party access, B2G exceptional need requests, cloud switching records, contract terms, trade secrets, and GDPR boundaries.
Data Act B2B Data-Sharing Contract Clauses
Clause guide for EU Data Act B2B data sharing: FRAND terms, compensation, trade secret safeguards, recipient limits, termination, logs, and GDPR boundaries.
Data Act B2B Data-Sharing Contract Template
A usable EU Data Act B2B data-sharing template outline covering access requests, data schedules, permitted use, trade secrets, security, compensation, GDPR boundaries, audit records, and termination.
Data Act B2G Exceptional-Need Requests
An official source guide to EU Data Act Chapter V requests from public bodies: exceptional need, public emergencies, request contents, limits, safeguards, costs, and records.
Data Act Cloud Switching Compliance Checklist
A cited EU Data Act checklist for cloud and data processing service providers covering switching clauses, notices, export formats, charges, interoperability, and evidence.
Data Act Cloud Switching Contract Terms FAQ
FAQ on EU Data Act cloud switching contract terms: Article 25 clauses, assistance, notice, transition, charges, export, termination, interoperability, and records.
Data Act Cloud Switching Fees and Deadlines FAQ
FAQ on EU Data Act cloud switching charges, 2027 fee removal, notice periods, transition windows, data retrieval, contract terms, and evidence records.
Data Act Complaints and Dispute Settlement FAQ
FAQ on EU Data Act complaints, competent authorities, dispute settlement bodies, B2B data-sharing disputes, B2G requests, cloud switching disputes, and evidence records.
Data Act Exportable Data and Metadata FAQ
FAQ explaining which product, related service, metadata, and cloud switching data must be exportable under the EU Data Act, and which data can be excluded.
Data Act FAQ for Aftermarket Repair and Mobility Services
FAQ on EU Data Act vehicle-data access for repairers, independent service providers, fleets, insurers, and mobility services.
Data Act Smart Contracts for Data Sharing
Data Act Article 36 smart contract guide for data-sharing agreements: scope, robustness, access control, termination, interruption, archiving, standards status, and conformity evidence.
Data Act SME Exceptions and Startups FAQ
FAQ on where the EU Data Act gives micro, small, medium-sized, startup, and SME actors narrower treatment for access duties, compensation, and B2B terms.
Data Act Trade Secret Technical Protection Measures FAQ
FAQ on how EU Data Act data holders can protect trade secrets with confidentiality safeguards, technical measures, limited withholding, suspension, refusal, and evidence.
Data Act Trade Secrets and Protection Measures
Data Act guide for protecting trade secrets during access and sharing: classification, safeguards, refusal thresholds, notices, evidence records, and reviews.
Data Act Unfair Contractual Terms | Article 13 B2B Contract Review
Review B2B data-sharing clauses under EU Data Act Article 13: unilateral terms, always unfair examples, presumed unfair terms, model clauses, evidence, and remediation.
Data Act vs GDPR: connected-product data access
Compare EU Data Act connected-product access duties with GDPR personal-data rules: scope, roles, lawful basis, data subject rights, third-party sharing, trade secrets, and conflicts.
EU Data Act and Common European Data Spaces FAQ
FAQ on how EU Data Act interoperability duties, Data Governance Act rules, and sector data-space governance fit together without treating participation as a general obligation.
EU Data Act and GDPR: Personal Data Overlap FAQ
FAQ on how the EU Data Act works when connected-product or related-service data includes personal data, mixed datasets, GDPR roles, lawful basis, trade secrets, and third-party sharing.
EU Data Act Applicability Test
Check whether a product, related service, data holder, cloud service, data-space role, smart contract, or B2G request is in scope of the EU Data Act.
EU Data Act Application Dates and Transition FAQ
FAQ on when the EU Data Act applies, which obligations are delayed, and what product, contract, cloud, and evidence records teams should maintain.
EU Data Act Article 3 Pre-Contract Information
What Article 3 of the EU Data Act requires before connected-product purchase, rent, lease, or related-service contracting: data categories, access, data holder identity, third-party sharing, complaints, and evidence.
EU Data Act Article 32: Foreign Government Access FAQ
FAQ on EU Data Act safeguards for non-EU government access to non-personal data held in the Union by data processing service providers.
EU Data Act Article 36 Smart Contract Controls FAQ
FAQ explaining when EU Data Act Article 36 applies to smart contracts for data-sharing agreements and what controls, conformity evidence, and limits it requires.
EU Data Act B2B Data Sharing Compensation FAQ
FAQ on when Data Act data holders may charge B2B data recipients, what reasonable compensation can include, SME limits, unfair terms, disputes, and trade secret safeguards.
EU Data Act B2G Compensation and Costs FAQ
FAQ on when Data Act B2G exceptional-need requests are free, when fair compensation may be claimed, which costs can be included, and what records to keep.
EU Data Act B2G Exceptional Need FAQ
When public-sector bodies can request business-held data under the EU Data Act, what a valid request must contain, and how data holders handle limits, trade secrets, compensation, and evidence.
EU Data Act Checklist for Product, Cloud, and Contract Teams
A cited EU Data Act checklist for connected-product data access, third-party sharing, B2G requests, cloud switching, unfair terms, smart contracts, personal data boundaries, evidence, and owners.
EU Data Act Cloud Switching and Exit Plans
A cited EU Data Act guide for data processing service exit plans: switching contracts, exportable data, assistance, charges, interoperability, retrieval, erasure, and records.
EU Data Act Cloud Switching Procurement FAQ
Procurement checklist FAQ for EU Data Act cloud switching: contract terms, exit support, exportable data, switching charges, interoperability, termination, and supplier evidence.
EU Data Act Compliance Program
Build a Data Act compliance program for connected-product data access, contracts, B2G requests, cloud switching, smart contracts, GDPR boundaries, records, and ownership.
EU Data Act Connected Product Scope and Data Types
Classify EU Data Act connected products, related services, product data, related-service data, readily available data, metadata, and excluded derived outputs.
EU Data Act Connected Product Scope FAQ
FAQ explaining when connected products, related services, generated data, EU market placement, and SME exceptions fall within EU Data Act scope.
EU Data Act Data Processing Service Switching
A cited EU Data Act guide for provider and customer switching duties: exit assistance, exportable data, contract clauses, charges, interoperability, retrieval, and erasure.
EU Data Act data spaces interoperability FAQ
FAQ explaining Article 33 Data Act interoperability requirements for data-space participants, common European data spaces, standards, APIs, metadata, and architecture evidence.
EU Data Act deadlines and compliance calendar
A cited calendar for EU Data Act application dates, product design timing, contract remediation, cloud switching charges, response periods, standards work, and evidence records.
EU Data Act Direct Access by Design FAQ
FAQ for product and legal teams designing user access to connected-product and related-service data under the EU Data Act.
EU Data Act Enforcement and Competent Authorities FAQ
FAQ on who enforces the EU Data Act, how complaints work, how Member States set penalties, when dispute settlement can be used, and when GDPR authorities remain responsible.
EU Data Act FAQ: scope, access rights, B2G, cloud switching, GDPR, and dates
EU Data Act FAQ index covering connected-product access, third-party sharing, B2G exceptional need, cloud switching, smart contracts, GDPR boundaries, unfair terms, and application dates.
EU Data Act Functional Equivalence: IaaS Switching FAQ
FAQ on Data Act functional equivalence for cloud switching: IaaS scope, customer outcomes, export support, interoperability duties, limits, and evidence.
EU Data Act Indirect Access Request Workflow FAQ
FAQ for Data Act teams handling user and third-party data requests when direct connected-product access is unavailable, incomplete, or limited.
EU Data Act Interoperability Standards: Articles 33-36
FAQ on EU Data Act interoperability standards for data spaces, cloud switching, smart contracts, harmonised standards, common specifications, and M/614.
EU Data Act Model Terms and Cloud Clauses FAQ
FAQ on the EU Data Act non-binding model contractual terms for data access and use, cloud switching clauses, B2B use, unfair terms, and evidence.
EU Data Act Non-Emergency Public-Sector Request FAQ
FAQ on EU Data Act requests where a public body claims exceptional need outside a public emergency, including scope, request contents, limits, compensation, confidentiality, and evidence.
EU Data Act Penalties and Enforcement
Official source guide to Data Act penalties under Article 40, Member State enforcement, penalty factors, complaints, judicial remedies, and the GDPR enforcement boundary.
EU Data Act Pre-Contractual Information FAQ
FAQ on EU Data Act Article 3 pre-contract information for connected products and related services, including data categories, access methods, data holder identity, third-party sharing, and GDPR boundaries.
EU Data Act Product Data vs Related-Service Data
FAQ explaining how the EU Data Act separates connected product data, related service data, readily available raw and pre-processed data, metadata, and inferred or derived outputs.
EU Data Act Public Emergency Request FAQ
FAQ on EU Data Act public emergency requests: exceptional need, request content, timing, data holder response, compensation, confidentiality, and records.
EU Data Act Readily Available Data FAQ
FAQ on what counts as readily available data under the EU Data Act, including product data, related service data, metadata, inferred data, and access mechanics.
EU Data Act Related Services FAQ
FAQ explaining when software is a Data Act related service, how it links to connected products, which product and service data are in scope, and what exclusions apply.
EU Data Act Requirements by Workstream
EU Data Act requirements for connected-product access, B2B terms, B2G exceptional need, cloud switching, smart contracts, interoperability, GDPR boundaries, and records.
EU Data Act Smart Contracts for Data Sharing FAQ
Answers on Article 36 Data Act smart-contract requirements for data sharing: scope, robustness, access control, termination, archiving, conformity assessment, contract terms, and standards status.
EU Data Act Third-Party Data Sharing FAQ
FAQ on user-directed third-party data sharing under the EU Data Act, covering data holder duties, recipient limits, trade secrets, security, GDPR, and gatekeepers.
EU Data Act Trade Secret Safeguards FAQ
FAQ on protecting trade secrets when handling EU Data Act user and third-party data access requests, including safeguards, withholding, suspension, refusal, notices, and records.
EU Data Act Unfair Contractual Terms FAQ
FAQ on Article 13 of the EU Data Act: B2B unfair contract terms, unilateral take-it-or-leave-it clauses, always-unfair terms, presumed-unfair terms, SMEs, model terms, and review evidence.
EU Data Act User Access and Portability Rights
Practical guide to EU Data Act user access, connected-product data portability, third-party sharing, trade secret safeguards, and the GDPR boundary.
EU Data Act Users, Data Holders, and Recipients FAQ
FAQ explaining Data Act users, data holders, data recipients, connected products, related services, user access, third-party limits, and GDPR boundaries.
EU Data Act Vehicle Data Guidance FAQ
FAQ on EU Data Act vehicle data guidance for connected vehicles, aftermarket repair, mobility services, third-party access, trade secrets, security, and GDPR boundaries.
EU Data Act vs Data Governance Act
Compare the EU Data Act with the Data Governance Act: connected-product access, cloud switching, B2B/B2G duties, protected public-sector reuse, intermediaries, altruism, governance, and enforcement.
EU Data Act: Non-Personal Data and Mixed Datasets
FAQ on how the EU Data Act treats non-personal data, mixed datasets, GDPR precedence, user and third-party access, trade-secret limits, and evidence records.