Skip to content
A car's dashboard with a map of Australia in the background, highlighting the need for data protection laws

Australian EV Association Calls for Data Protection Laws as 70 Brands Collect Driver Data

Stephen M 3 min read

The Australian Electric Vehicle Association is urging the government to adopt a connected-vehicle cybersecurity framework to protect driver data.

Key Takeaways

  • The Australian Electric Vehicle Association (AEVA) is calling for the government to adopt a connected-vehicle cybersecurity framework.
  • Almost 70 car brands in Australia are collecting driver data, which is often stored overseas.
  • The AEVA wants in-car data to be processed in the vehicle by default and stored in Australia.
  • Locals should have the rights to access, delete, and manage vehicle data.
  • Australia’s current laws do not provide sufficient protection for driver data.

What’s the Issue with Data Protection in Australia?

Australia’s car market is highly competitive, with almost 70 different brands available. However, the country’s data protection laws have not kept up with the increasing amount of data being collected by new cars.

New vehicles, particularly EVs, are collecting not only location data but also uploading voice recordings and images from in-car cameras to manufacturer cloud storage systems, often overseas.

How Does Australia Compare to Europe?

The AEVA is calling on the Australian government to adopt a connected-vehicle cybersecurity framework similar to Europe. This would require manufacturers to maintain a certified cybersecurity management system, a software update management system, and clear lifecycle processes for vulnerability management, incident response, and secure software updates.

What Should Be Done?

The AEVA wants in-car data to be processed in the vehicle by default and stored in Australia. There should also be strict limits on overseas data feeds from Australian vehicles to overseas manufacturers, and locals should have the rights to access, delete, and manage vehicle data.

Even China has implemented stricter data protection laws, prioritizing in-vehicle processing of data and a default non-collection principle.

What Are the Consequences of Inaction?

If Australia does not adopt stricter data protection laws, driver data will continue to be vulnerable to exploitation by overseas manufacturers.

This could have serious consequences for individuals and the country as a whole, including the potential for data breaches and cyber attacks.

What’s Next?

The AEVA is urging the Australian government to take action and adopt a connected-vehicle cybersecurity framework to protect driver data.

This would not only provide peace of mind for drivers but also support innovation and enable safe software-defined vehicles.

Frequently Asked Questions

Q: What is the current state of data protection in Australia?

Australia’s current laws do not provide sufficient protection for driver data. The country relies on the 1988 Privacy Act’s Australian Privacy Principals, which requires open and transparent handling of personal information.

Q: Why is the AEVA calling for a connected-vehicle cybersecurity framework?

The AEVA wants to protect driver data from exploitation by overseas manufacturers and ensure that locals have the rights to access, delete, and manage vehicle data.

Q: How does Australia compare to other countries in terms of data protection?

Australia’s data protection laws are less stringent than those in Europe and China, which have implemented stricter regulations to protect driver data.

Related Articles