Automotive data regulation
EU Data Act, Connected Vehicles and the Dealer DMS
Connected-vehicle access is becoming a practical service workflow. Dealers need to distinguish product data, personal data and regulated repair information before moving any record into the DMS.

The EU Data Act has generally applied since 12 September 2025. It gives users rights to access data generated by connected products and to direct data holders to make in-scope data available to third parties, subject to conditions and safeguards. For dealers, the opportunity is permissioned diagnostics and service preparation. The obligation is to verify the requester, purpose, data category, recipient, security and GDPR basis before integrating data into DMS workflows.
1. What changed and when
Regulation (EU) 2023/2854, the Data Act, entered into force on 11 January 2024 and generally became applicable on 12 September 2025. [1] As a regulation, it applies directly across the EU, although Member States designate competent authorities and set enforcement arrangements. Some provisions have their own temporal scope, so contracts and products need a date-specific assessment.
The Act addresses access to and use of data generated by connected products and related services. A vehicle is a connected product when it obtains, generates or collects data concerning its use or environment and can communicate product data. The framework identifies users, data holders and data recipients. These are legal roles, not simply the driver, manufacturer and workshop in every case.
The European Commission published sector-specific automotive guidance in September 2025. [2] It explains how the Commission understands key Data Act concepts for vehicle data. The guidance is useful but non-binding; courts and competent authorities ultimately interpret the law.
2. Separate three data regimes
A productive dealer conversation starts by naming the legal route. The Data Act concerns readily available product data and related-service data within its scope. GDPR governs personal data. Vehicle type-approval law creates access rules for repair and maintenance information, known as RMI. The same service event can involve all three without making them interchangeable.
| Route | Primary purpose | Example | Main question |
|---|---|---|---|
| Data Act | User access and third-party sharing of in-scope product data | Vehicle status requested for a service provider | Who is the user and data holder? |
| GDPR | Protection of identifiable people | Location, driver profile or linked VIN history | What is the lawful basis and purpose? |
| Type approval RMI | Non-discriminatory repair and maintenance access | Diagnostic, service and technical information | Is the requester an independent operator? |
| Commercial contract | OEM, fleet or platform service | Warranty feed or fleet consent portal | What rights, limits and service levels apply? |
Regulation (EU) 2018/858 requires manufacturers to provide independent operators with unrestricted, standardised and non-discriminatory access to vehicle OBD information, diagnostic equipment and RMI, subject to its framework. [3] The Court of Justice has interpreted aspects of this access in case C-296/22. [4] A Data Act request should not be used to obscure an existing RMI obligation or its conditions.
3. Understand the user, holder and recipient
The user can be a natural or legal person who owns a connected product, has temporary rights to use it or receives a related service. In automotive settings, ownership, leasing, fleet management, rental and shared use can make identity and authority complex. A driver may not have authority to share every fleet dataset; an owner may not be the person represented in location data.
The data holder is the entity obliged or entitled under the Data Act or other law to use and make available data. It may often be the manufacturer or related-service provider, but the role requires analysis. A dealer receiving data at the user's request can be a data recipient and takes on relevant obligations.
Build verification into the service journey. Capture who requested the data, evidence of product or service rights, the requested purpose, recipient, duration and revocation. Avoid requesting a complete vehicle history when a small current dataset is enough for a repair estimate.
4. Apply GDPR whenever a person is identifiable
The Data Act does not replace GDPR. It states that EU personal-data law continues to apply and that GDPR prevails in case of conflict. [1] A user's Data Act request does not by itself create a lawful basis for every processing operation involving another person's data.
The EDPB's connected-vehicle guidance explains that location, driving behaviour, identifiers and other vehicle data can be personal data. [5] Dealers should minimise collection, define purpose and retention, control employee access, inform data subjects and support rights. If data reveals passengers, drivers or previous owners, their interests require assessment.
Do not use service access as a quiet marketing feed. A dataset obtained to diagnose a fault should not automatically enrich behavioural advertising. Keep purpose tags and source lineage in the DMS so downstream users and systems can enforce the original context.
5. Engineer a trustworthy DMS workflow
A connected-data workflow needs more than an API. Record vehicle and customer identity separately; validate VIN and entitlement; capture the user's request; authorise exact data fields; timestamp receipt; bind data to a repair order or case; show provenance; limit roles; and delete or detach the feed when the purpose ends.
Use machine-readable scopes and short-lived credentials. Verify webhook signatures, prevent replay, encrypt transport and storage, monitor unexpected volume and isolate partner credentials. Handle unavailable, delayed or contradictory data explicitly. A technician should see freshness and source, not a value presented as timeless fact.
Preserve human judgement for safety and warranty. Remote signals may support triage, but do not necessarily prove physical condition or causation. Record which diagnostic step, technician or manufacturer procedure confirmed a conclusion. Give users a route to correct vehicle association or withdraw sharing.
6. Turn access into a fair service proposition
Useful dealer cases include pre-visit triage, accurate parts preparation, maintenance reminders tied to actual condition, fleet downtime planning, EV charging or battery context and evidence-led appraisal. Start with a use case where the customer sees a clear benefit and the minimum data is obvious.
Measure appointment preparation, repeat visits, parts availability, diagnostic time and customer complaints. Compare against a baseline and account for vehicle mix. Access alone does not guarantee improvement; integration quality, technician practice and data accuracy determine results.
Publish a simple explanation: which data is requested, from whom, for what service, how long it is used and how sharing can stop. Avoid implying that refusal will prevent unrelated contractual service. Transparent choice can become a trust advantage without exaggerating the law.
Where Omnetic fits
Omnetic's documented products connect customer, vehicle, inspection, price, stock and deal context. That can provide the operational destination for authorised connected-vehicle evidence, linking it to a service, appraisal or inventory decision rather than leaving it in a separate portal. Product materials also reference interfaces such as APIs, webhooks, external IDs and exports.
There is no complete public interface catalogue establishing which connected-vehicle datasets or Data Act roles Omnetic supports. Dealers should request a demonstration of identity, consent or request evidence, field-level scope, lineage, retention, revocation, access controls and partner security for their exact use case.
Limitations
This article is not legal advice. Vehicle architecture, user relationships, data-holder roles and personal-data content vary. Commission guidance is non-binding, and enforcement practice will develop. Verify Member State authorities, contracts and current case law before implementation.
Frequently asked questions
Most provisions have applied since 12 September 2025, with some specific provisions following different dates.
No. GDPR continues to apply whenever connected-vehicle data is personal data. The instruments must be applied together.
No. Access depends on the user's request, the Data Act's scope, technical availability, rights and applicable safeguards.
No. Data Act rights and the vehicle type-approval regime for repair and maintenance information overlap in context but have different scopes and mechanisms.