

Anthony Crawford
Worth the Detour: Why the Jaecoo J8 SHS is built for the great Australian road trip
15 Hours Ago
An electric vehicle advocacy group has called for tighter data laws for connected cars, citing regulations already introduced in Europe and China.

Deputy News Editor


Deputy News Editor
The Australian Electric Vehicle Association (AEVA) has called on the federal government to introduce tougher laws governing the growing number of internet-enabled 'connected vehicles' on Australian roads.
The EV advocacy body said Australia's privacy framework, based on the Privacy Act 1988 and voluntary industry standards for connected vehicles, is no longer robust enough to protect motorists or clearly define how vehicle data is collected, used, shared and owned.
"With the expectation that 95 per cent of all new vehicles, including electric vehicles, sold in Australia by 2035 will be internet-enabled, consumer protection and national security risks will likely escalate without intervention," said the AEVA in a statement issued yesterday.

Most major brands, including Ford, Toyota, BYD, GWM and Tesla, offer connected services, typically accessed through a smartphone app or built-in SIM card, allowing vehicles to communicate via the internet.
Examples include Toyota Connected Services, FordPass, MG iSmart, Nissan Connected Services and the MySkoda app, which are available across petrol, diesel, hybrid and electric vehicles.
"The threat extends to any modern vehicle equipped with an internal SIM card or telematics system capable of transmitting data to external locations – not just electric ones," the AEVA statement said.
"Consumers nationwide continue to be let down by insufficient data privacy legislation," added AEVA president James Pickering.

"Instead of instigating fear and distrust in the connected vehicles we drive, policymakers have the power to make effective changes to protect drivers and consumer choice."
Earlier this year, the Australian Privacy Commissioner confirmed it was investigating two unnamed automakers over potential breaches of privacy laws. No findings from those investigations have been released publicly.
The submission also references national security concerns surrounding connected vehicles. In 2018, the Australian Government banned Chinese telecommunications company Huawei from participating in the rollout of the nation's 5G network, citing national security concerns.

"We are great believers in compliance over country-of-origin and will continue our discussions with government to support consumer choice and protection, while also maintaining national security," Mr Pickering said.
The AEVA said it has submitted what it describes as a "comprehensive suite" of recommended policy solutions to the federal government, integrating measures already introduced in Europe and China.
Europe adopted its General Data Protection Regulation (GDPR) in 2016, with the privacy laws taking effect in 2018.
New vehicles sold in Europe have also been required to comply with UNECE R155 cybersecurity regulations since 2022, while the European Union's Data Act gave motorists legal rights to access vehicle-generated data from 2025.

China introduced automotive data security rules in 2021, followed by updated cross-border automotive data guidelines this year governing how vehicle data is classified and transferred overseas.
"From a consumer perspective, the key principle is simple: the vehicle should not behave like an uncontrolled data-harvesting platform," the AEVA submission said.
"The point of this recommended approach is not to ban connectivity. It is to ensure that connectivity serves the owner and driver first."
Key recommendations include keeping the most sensitive data, such as voice recordings, facial scans, cabin camera footage and driving routes, within the vehicle instead of storing it in an automaker's cloud.

Where data is stored outside the vehicle, the AEVA said it should be kept in cloud infrastructure located in Australia rather than transferred overseas.
The AEVA also called for mandatory cybersecurity requirements to replace today's largely voluntary framework, requiring automakers to meet internationally recognised standards designed to reduce hacking risks.
It also said vehicle data collection should be switched off by default, requiring motorists to actively opt in before manufacturers can collect their data.
Motorists should also be able to see what data has been collected from their vehicles, and have the option of deleting their history before selling them, for example.

The association said greater transparency would also allow motorists to share vehicle data with an independent repairer of their choice, rather than requiring access through a manufacturer's dealership network.
"It should also ensure that consumers and consumer-authorised third parties are not locked out of legitimate access to vehicle data, functions and resources by manufacturer-controlled digital gatekeeping," the report said.
"That is the balance this policy recommendation seeks to strike."
MORE: Zeekr responds to cybersecurity concerns around Chinese vehicles
Damion Smy is an award-winning motoring journalist with global editorial experience at Car, Auto Express, and Wheels.


Anthony Crawford
15 Hours Ago


Damion Smy
16 Hours Ago


James Wong
18 Hours Ago


Marton Pettendy
18 Hours Ago


Gautam Sharma
19 Hours Ago


Damion Smy
20 Hours Ago
Add CarExpert as a Preferred Source on Google so your search results prioritise writing by actual experts, not AI.