1. Home
    2. Car News
    3. Toyota
    4. News

    Toyota Australia says sensitive connected-car data "never transmitted"

    Customer data security is a priority, says Toyota, amid concerns over privacy and the potential for connected vehicles to be hacked.

    Damion Smy

    Damion Smy

    Deputy News Editor

    Damion Smy

    Damion Smy

    Deputy News Editor

    Toyota Australia has confirmed highly sensitive customer data is encrypted and never transmitted from its vehicles, following recent calls for greater government regulation of information generated by ‘connected vehicles’.

    A recent investigation by ABC program Four Corners raised concerns over data security and the potential for connected vehicles to be hacked, with BYD, Xpeng and Leapmotor vehicles featuring in its report.

    The term ‘connected car’ refers to vehicles connected to the internet, enabling functions such as over-the-air software updates, but also providing automakers with unprecedented access to information including vehicle location and customer driving behaviour.

    Toyota Australia said at a recent business update at its Port Melbourne headquarters that there are now more than one million connected Toyotas on Australian roads, after it launched Toyota Connected Services in November 2020.

    Apple CarPlay interface displayed on the touchscreen infotainment system of a 2026 Toyota RAV4 PHEV GR Sport, showing apps including Google Maps, ChatGPT, and Spotify

    Almost every model across Toyota Australia’s current passenger and commercial vehicle range offers Toyota Connected Services, with the LandCruiser 70 Series, GR86 sports car and Tundra full-size pickup among the exceptions.

    Speaking to CarExpert, John Pappas, Toyota Australia vice president of sales, marketing and franchise operations, said the automaker is extremely diligent when it comes to handling data, with customer privacy a priority.

    “Our data systems are hosted in secure data centres, the majority of which are located in Australia, with some data also processed and stored in secure Toyota-managed environments in North America and Singapore,” Mr Pappas explained.

    “What’s most important for us is with Toyota vehicles, we look at safety of protection and safety of our customers’ data and their privacy, the same as we do when we look at safety of our vehicle. For us, we call it hardware equals software.

    A red 2026 Toyota RAV4 PHEV GR Sport SUV seen from the front-side angle, parked on a dirt surface with mountains and a sunset sky in the background

    “What’s most important is that the data, the customer data, and privacy is highly governed with Toyota, highly governed.”

    Asked whether a Toyota vehicle could be hacked, and what protections Toyota Australia vehicles have, Mr Pappas reiterated the automaker’s use of data encryption.

    “Hacking protections, for other brands, I really can’t comment,” Mr Pappas said.

    “I can't comment on any other brand because I don’t know what they do; that’s their call, but what I do know is about Toyota, and it’s highly governed, the data and the privacy side. Any highly sensitive data is fully encrypted inside the car, is never transmitted.”

    Toyota is currently the subject of an ongoing investigation by the Office of the Australian Information Commissioner (OAIC), which is also investigating Hyundai over connected-vehicle privacy.

    The OAIC hasn't publicly detailed its investigation, nor announced any findings of wrongdoing by either Toyota or Hyundai. It began preliminary inquiries into connected-car privacy in February 2024, but the vehicle brands involved were not made public until 2026.

    Toyota updated its Connected Services Privacy Policy in March 2026, with the current policy stating that, outside specified circumstances, Toyota doesn't share information about a customer’s use of Connected Services with anyone else unless the customer asks it to.

    It also states that personal information collected through Connected Services isn't used for direct marketing.

    For example, SOS Emergency Call – which forms part of ANCAP’s 2026 assessment protocols and is included by Toyota free for the life of the relevant mobile network – can transmit information required to provide emergency assistance.

    Toyota says the service has already been used more than 10,000 times in Australia.

    Stolen Vehicle Tracking data may similarly be provided to police. Toyota models including the RAV4 SUV, HiLux ute and LandCruiser 300 Series have been among vehicles targeted during a rise in vehicle thefts in Australia, including in Victoria, where thefts have reached two-decade highs.

    A white Toyota LandCruiser leads a convoy of SUVs along a rough dirt track through green hilly terrain during an off-road drive

    BYD also changed its privacy policy, as noted by Four Corners in the episode aired on September 21, 2026. The program reported the revised policy removed previous references to 16 countries to which customer data could be sent.

    The automaker launched an investigation into the program’s findings and subsequently said it would implement software changes, “thereby eliminating the access path identified during the investigation”.

    Canberra-based Fortify Labs, which carried out the vehicle ‘attacks’ for Four Corners, said on its website it hoped the program would be a catalyst for change. It suggested introducing a cyber-security star rating to allow customers to compare the level of protection offered by different brands.

    MORE: Explore the Toyota showroom

    Ready to find the right new car at a great deal?

    Research cars in our Showroom, compare your options or let our New Car Specialists do the running around to find you a great deal.

    Damion Smy

    Damion Smy

    Deputy News Editor

    Damion Smy

    Deputy News Editor

    Damion Smy is an award-winning motoring journalist with global editorial experience at Car, Auto Express, and Wheels.

    Read more

    You might also like