IS YOUR CAR WATCHING YOU? CONNECTED CARS, PERSONAL DATA, CYBERSECURITY AND THE NEW ERA OF AUTOMOTIVE LIABILITY

What Is a Connected Car and What Legal Issues Does It Create?

Introduction

A modern vehicle is no longer merely a mechanical product consisting of an engine, transmission, brakes and four wheels.

Through GPS, cameras, microphones, sensors, mobile connectivity, driver-assistance technologies, smartphone integration, cloud services and remote software updates, vehicles are increasingly becoming mobile digital platforms that continuously generate and exchange data.

The European Data Protection Board has described connected vehicles as increasingly significant data hubs capable of collecting information ranging from engine performance, driving habits and visited locations to, in certain circumstances, eye movements, pulse information and biometric data capable of uniquely identifying a person.

This technological model is generally referred to as the connected car.

A connected car can communicate through the internet or other electronic networks with manufacturers, mobile applications, cloud services, infrastructure and other digital-service providers.

Once the car becomes connected, however, a new set of legal questions emerges.

The issue is no longer simply:

“Who owns the vehicle?”

Lawyers must increasingly ask:

Who controls the data generated by the car? Can a manufacturer continuously monitor location? Can an insurer analyse driving behaviour? What happens to personal information when the car is sold? Who is liable if the vehicle is hacked? Can a defective software update turn an otherwise mechanically sound car into a defective product?

These questions define the emerging field of connected-car law.


1. A Connected Car Is Not Necessarily an Autonomous Car

Connectivity and autonomous driving are different concepts.

A vehicle may be connected because it receives live traffic information, transmits diagnostic data to the manufacturer, allows remote control through an application or receives over-the-air software updates.

None of these features necessarily means that the vehicle can drive autonomously.

Autonomous-driving technology concerns the ability of the vehicle to perform defined driving tasks by analysing its environment.

The two technologies are increasingly integrated, but their legal implications should still be distinguished.


2. What Data Can a Connected Car Collect?

Connected cars may process information including:

location history;

travel routes;

speed;

braking and acceleration behaviour;

steering inputs;

mileage;

battery or fuel consumption;

engine and component performance;

contacts from connected phones;

voice commands;

infotainment activity;

in-cabin camera footage;

driver-monitoring information;

accident data; and

maintenance records.

Importantly, technical data does not cease to be personal data merely because the driver’s name is absent.

The EDPB notes that driving style, distance travelled, wear of vehicle parts, location data and camera information may relate to identifiable drivers, passengers or even persons passing by the vehicle.

A dataset identified only by a vehicle ID may therefore still constitute personal data where an individual can be identified directly or indirectly.


3. Who Owns Vehicle Data?

This is one of the most commercially significant questions in connected mobility.

Buying the physical car does not automatically provide a complete answer as to who may control or use all data generated by that vehicle.

The European Union’s Data Act, Regulation (EU) 2023/2854, introduced a new framework for access to and use of data produced by connected products. It has applied since 12 September 2025. In September 2025, the European Commission also issued specific guidance addressing vehicle data and the implementation of Chapter II of the Data Act in the automotive sector.

The Data Act creates rights relating to access to product data and, in qualifying circumstances, the sharing of such data with third parties.

It should not, however, be simplified into a proposition that “all data generated by the car belongs to the owner.”

Where personal data is involved, the GDPR continues to apply. Data-access rules and personal-data protection must operate together.

This distinction is particularly important for independent repairers, insurers, fleet operators and the automotive aftermarket.


4. Connected Cars and Turkish Data Protection Law

Where vehicle data relates to an identified or identifiable individual, Türkiye’s Personal Data Protection Law No. 6698 may become applicable.

A location record, for example, may effectively reveal where a specific driver lives, works or travels even if the dataset itself primarily identifies the vehicle.

Every processing operation must have an appropriate legal basis.

The Turkish Personal Data Protection Authority has expressly clarified that consent is not the default legal basis for every processing operation. Controllers should first determine whether another processing condition under Law No. 6698 applies; consent should be relied upon where no other lawful processing condition exists.

A manufacturer therefore cannot safely reduce the entire compliance exercise to:

“The customer accepted our terms when purchasing the vehicle.”

Diagnostic processing necessary to deliver a connected service may have a different legal basis from behavioural profiling performed for advertising purposes.


5. Consent Does Not Solve Every Privacy Problem

A single “I Agree” button displayed on the infotainment screen does not automatically make all future processing lawful.

The processing must also satisfy requirements relating to transparency, purpose limitation, proportionality and the general principles of data protection.

Under the GDPR, data protection by design and by default requires organisations to incorporate data-protection safeguards into the architecture of their products and services rather than treating privacy as an afterthought.

For connected vehicles, this raises practical questions:

Does precise location really need to be uploaded continuously?

Can certain processing remain locally within the car?

Can tracking be disabled?

How long is telemetry retained?

What happens when another person drives the vehicle?


6. Passengers Have Privacy Rights Too

A connected car may collect information about persons other than its owner.

A vehicle may be used by family members, friends, rental customers, taxi passengers or employees.

The EDPB specifically notes that the connected vehicle may function as a terminal used by multiple users and that multiple users do not remove the personal character of the data being processed.

In-cabin cameras and microphones create additional concerns.

The owner’s consent cannot necessarily be treated as a universal legal basis for processing every passenger’s voice, image or behaviour.


7. Biometrics and Driver Monitoring

Modern driver-monitoring systems may analyse whether the driver is looking at the road, becoming drowsy or otherwise losing attention.

Depending on the technical architecture, such systems may also process facial or other biometric information.

The legal assessment differs considerably between a system that momentarily analyses an image locally and deletes it, and a system that creates and centrally stores a biometric template.

Under Turkish law, biometric data falls within the special categories of personal data governed by Article 6 of Law No. 6698. The Turkish Data Protection Authority has issued updated guidance explaining the processing conditions applicable to special-category data under the amended framework.


8. What If Turkish Vehicle Data Is Stored Abroad?

Connected-car manufacturers often rely on global cloud infrastructure.

Vehicle data generated in Türkiye may therefore be transferred to servers or service providers located abroad.

This brings Article 9 of Law No. 6698 into consideration.

Türkiye significantly amended its international personal-data-transfer regime in 2024. The current framework uses mechanisms including adequacy decisions, appropriate safeguards, standard contractual clauses and binding corporate rules, together with defined exceptional-transfer grounds.

The Turkish Authority’s current guidance also explains that making personal data available to a controller or processor abroad can constitute an international transfer.

The fact that the physical vehicle remains in Istanbul therefore does not prevent a cross-border data-transfer issue where the relevant cloud infrastructure is abroad.


9. What Happens If a Connected Car Is Hacked?

Cybersecurity in an automobile is fundamentally different from cybersecurity in an ordinary consumer device.

A compromised laptop may expose information.

A compromised vehicle may create both informational and potentially physical safety risks.

This is why automotive cybersecurity has become a vehicle-safety issue.

UN Regulation No. 155 establishes an international vehicle-type-approval framework concerning cybersecurity and Cyber Security Management Systems. It requires manufacturers within its scope to maintain an appropriate cybersecurity-management framework relevant to the vehicle type.

Cyber incidents may lead to unauthorised access to personal data, disruption of connected services or interference with vehicle systems.

In Türkiye, Article 12 of Law No. 6698 separately requires controllers to take necessary technical and organisational measures to prevent unlawful processing, prevent unlawful access and ensure proper preservation of personal data.

Cybersecurity is therefore simultaneously an engineering, product-safety and data-protection issue.


10. Over-the-Air Software Updates

Vehicles increasingly receive Over-the-Air, or OTA, software updates.

A manufacturer can remotely correct cybersecurity vulnerabilities, improve battery management, change system behaviour or introduce new functionality.

UN Regulation No. 156 establishes the international regulatory framework concerning vehicle software updates and Software Update Management Systems.

OTA technology also creates a private-law problem.

What happens if an update:

reduces driving range;

removes an existing feature;

causes repeated software failures;

interferes with a driver-assistance function; or

renders the vehicle unusable?

At that point, software engineering becomes a consumer and product-liability question.


11. Can Defective Software Make a Car Legally Defective?

Under Turkish consumer law, a defect need not necessarily be a broken physical component.

The conformity regime under Law No. 6502 evaluates whether the goods comply with agreed and objectively expected characteristics. The statute provides consumer remedies including termination, price reduction, repair and, where legally available, replacement with conforming goods.

Where important functionality of a modern car depends upon software, a serious software failure may therefore become relevant to the legal assessment of whether the vehicle is defective.

Türkiye’s Product Safety and Technical Regulations Law No. 7223 creates an additional product-safety and liability framework. The Ministry of Trade identifies manufacturer/importer liability for death, injury or damage to another product caused by an unsafe product as one of the mechanisms introduced by the legislation.

For connected vehicles, the boundary between hardware and software will consequently become increasingly difficult to maintain in product-liability litigation.


12. Usage-Based Insurance

Connected cars make usage-based insurance commercially possible.

Driving behaviour can potentially be analysed by reference to factors such as mileage, time of use, braking behaviour and acceleration.

The EDPB expressly identifies usage-based insurance as one of the services operating within the connected-vehicle ecosystem.

But technical availability of the data does not mean unrestricted legal availability.

Insurers and manufacturers must still consider the purpose of the original collection, legal basis for disclosure, profiling implications, retention period and transparency towards the driver.


13. Vehicle Data as Evidence Following an Accident

Connected-vehicle data may become increasingly important in accident litigation.

Telemetry may potentially assist in determining vehicle speed, braking, steering input, system warnings and technical faults immediately before a collision.

Such information may be valuable in criminal proceedings, insurance claims and civil compensation cases.

Its evidential value, however, does not automatically displace data-protection law.

In a 20 May 2026 principle decision, the Turkish Personal Data Protection Board emphasised that personal data relating to accident victims should be processed only for purposes connected with managing the post-accident process and in compliance with the general principles and legal processing conditions of Law No. 6698.

Future litigation will therefore increasingly involve not only the question:

“What does the vehicle data show?”

but also:

“Who obtained that data, under what legal authority, and can its integrity be demonstrated?”


14. Selling a Used Connected Car

Selling a connected vehicle can involve more than transferring registration and keys.

The vehicle may still contain:

home and work addresses;

navigation history;

contacts;

Bluetooth pairings;

call information;

mobile-app credentials; and

connected-home integrations.

A proper second-hand transfer should therefore include a digital handover.

Accounts should be removed, personal data erased appropriately and the manufacturer’s connected-service account transferred or disconnected.

In the connected-car era, failure to perform this digital handover can create privacy and security risks long after legal ownership of the physical vehicle has changed.


15. Do You Own the Software Inside Your Car?

A consumer may own the car but merely receive a licence to use some of its software.

That distinction becomes commercially significant where the vehicle offers subscription-based:

premium connectivity;

advanced driving features;

navigation;

remote-access services; or

software-enabled hardware functions.

The physical hardware may have been purchased while continued operation of a digital feature depends on a separate service contract.

The contractual structure should therefore make clear before sale which capabilities are permanently included and which depend on subscriptions or licences.

Otherwise, consumer-law questions concerning transparency, contractual conformity and potentially unfair terms may arise.


16. Who Is the Data Controller?

The connected-car ecosystem may involve numerous parties:

the vehicle manufacturer;

national distributor;

mobile-application operator;

cloud provider;

telecommunications company;

authorised workshop;

insurance company; and

navigation provider.

The EDPB expressly recognises that the connected-vehicle ecosystem is no longer limited to traditional automotive manufacturers and may involve digital service providers, telecommunications operators, infrastructure managers and insurers.

It cannot therefore simply be assumed that every third party is a processor.

Controller, processor and potentially joint-controller roles must be determined by examining who actually determines the purposes and means of each processing operation.


17. Why the EU Data Act Matters Beyond the EU

The EU Data Act is not Turkish domestic legislation.

Nevertheless, it can have substantial commercial significance for Turkish manufacturers placing connected products on the European market and for Turkish businesses participating in European automotive data ecosystems.

Since 12 September 2025, the Data Act has established an important new framework for the relationship between users, data holders and third parties regarding data generated by connected products. The Commission’s September 2025 vehicle-data guidance specifically addresses implementation in the automotive sector.

For the automotive industry, this may materially affect the traditional concentration of vehicle data in the hands of manufacturers and influence competition, servicing and aftermarket business models.


18. Connected Cars and Artificial Intelligence

Connected mobility is increasingly intertwined with artificial intelligence.

Driver monitoring, automated emergency braking, lane assistance, voice systems and advanced driving functions may all involve increasingly sophisticated algorithmic technologies.

The EU AI Act has entered a staged application process, with major parts of the Regulation applying from 2 August 2026. However, whether a specific automotive system falls within a particular AI Act category depends on the system and its interaction with applicable product-safety legislation; it would be incorrect to describe every automotive AI system automatically as “high risk.”

The future of automotive law will consequently involve the interaction of:

traffic regulation, data protection, cybersecurity, consumer law, product liability and AI regulation.


Conclusion: Is the Modern Car Becoming a Data Centre on Wheels?

Connected vehicles fundamentally change traditional automotive-law assumptions.

Historically, the key questions were:

Who owns the car?

Who caused the accident?

Is the vehicle defective?

Today, lawyers increasingly need to ask:

What data does the vehicle collect?

Who can access it?

Where is the data stored?

Can the driver delete it?

Can the owner share vehicle data with an independent repairer?

Can the manufacturer remotely alter the vehicle through software?

Who is liable for damage caused by a cyberattack?

Can defective software constitute a defective vehicle?

What happens to personal data when the vehicle is sold?

The EU Data Act, the EDPB’s connected-vehicle data-protection framework and UNECE’s cybersecurity and software-update regulations demonstrate that the modern vehicle is increasingly being regulated not merely as a mechanical product but as a continuously connected, software-driven and data-generating platform.

For businesses operating in Türkiye, compliance increasingly requires simultaneous consideration of KVKK, international data transfers, cybersecurity, consumer protection and product liability. Türkiye’s revised international-data-transfer regime makes this particularly relevant for automotive businesses relying on global cloud infrastructures.

Purchasing a future vehicle may therefore mean acquiring far more than a physical automobile.

The transaction may simultaneously involve a software licence, cloud service, personal-data relationship, cybersecurity ecosystem and continuing digital-services contract.

This leaves connected-car law with one fundamental question:

As the vehicle learns more and more about its driver, can the law ensure that the driver’s control over the car is matched by meaningful control over the digital life taking place inside it?

Categories:

No Responses

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Our Client

    We provide a wide range of Turkish legal services to businesses and individuals throughout the world. Our services include comprehensive, updated legal information, professional legal consultation and representation

    Our Team

    .Our team includes business and trial lawyers experienced in a wide range of legal services across a broad spectrum of industries.

    Why Choose Us

    We will hold your hand. We will make every effort to ensure that you understand and are comfortable with each step of the legal process.

    Call Now Button