HOW MUCH DOES YOUR CAR KNOW ABOUT YOU? DRIVER DATA, HIDDEN PROFILING AND PRIVACY RISKS IN CONNECTED VEHICLES

When a car can record where you go, how you drive and even who is inside the vehicle, who may legally use that information?

Modern vehicles are no longer merely transportation devices.

Connected cars increasingly operate as sophisticated digital platforms combining sensors, cameras, microphones, navigation systems, telematics, mobile applications, artificial intelligence and internet connectivity.

As a result, a vehicle may potentially determine:

where the driver travels,

when the vehicle is used,

how fast it is driven,

how often the driver brakes aggressively,

which smartphone is connected,

which destinations are entered into navigation,

who is inside the vehicle,

and, in certain systems, even the driver’s face, voice or attention level.

This technological development creates a fundamental legal question:

Who may use the data generated by a connected vehicle, and for what purpose?

An equally important question is:

Can vehicle-generated data be used against the driver by a manufacturer, insurer, employer or another third party?

The answer requires consideration of data protection, consumer law, insurance, employment law, cybersecurity and rules governing evidence.


1. What Data Can a Connected Vehicle Collect?

Connected vehicles may generate several categories of information.

These can include:

location and journey data: GPS coordinates, routes, destinations and parking locations;

driving behaviour data: speed, acceleration, braking patterns, mileage and driving time;

in-cabin data: camera images, microphone recordings and driver-monitoring information;

infotainment data: contacts, paired phones, calls and navigation destinations;

biometric data: facial recognition, fingerprints or voice authentication;

and

technical and telematics data: fault codes, battery status, vehicle performance and event data.

Not every piece of vehicle data will automatically constitute personal data.

However, where information can be related to an identified or identifiable individual, data protection law may become applicable.

The European Data Protection Board specifically recognises mobility and connected vehicles as presenting significant privacy challenges because of the extensive use of location data, biometric information and automated systems.


2. Is Vehicle Location Personal Data?

In many circumstances, yes.

Türkiye’s Personal Data Protection Authority has expressly recognised location information capable of identifying or making a natural person identifiable as personal data.

The significance of geolocation extends far beyond a single coordinate.

Continuous location history may reveal or allow inferences about:

a person’s home,

workplace,

family routines,

medical visits,

religious activities,

social relationships

and other aspects of private life.

In its decision concerning vehicle-rental software, the Turkish Data Protection Board specifically warned that vehicle location monitoring may reveal lifestyle patterns and facilitate profiling capable of exposing even highly sensitive aspects of an individual’s life.

Accordingly:

The fact that a vehicle contains a GPS system does not give the manufacturer an unlimited right to monitor its driver.


3. Does Vehicle-Generated Data Belong to the Manufacturer?

Not necessarily.

Data protection law does not analyse this issue purely through traditional concepts of property ownership.

Instead, concepts such as data controller, processor and data subject become central.

Within a single connected vehicle ecosystem, relevant actors may include:

the vehicle manufacturer,

operating-system provider,

navigation provider,

mobile-application provider,

insurer,

fleet operator

and leasing or rental company.

The decisive question is often who determines the purposes and essential means of processing.

The Turkish Data Protection Board has also recognised that parties jointly determining purposes and essential processing arrangements may in appropriate circumstances bear joint-controller responsibilities.

Therefore:

“Our vehicle generated the data, therefore we may use it as we wish”

is not a sufficient legal justification.


4. Does Every Processing Activity Require Consent?

No.

Under Article 5 of the Turkish Personal Data Protection Law, consent is only one possible lawful basis.

Depending on the circumstances, processing may also rely on grounds including necessity for performance of a contract, compliance with a legal obligation, establishment or protection of a legal right and legitimate interests that do not override the fundamental rights and freedoms of the individual.

Consequently, processing technical sensor information to detect a critical braking-system defect is legally different from analysing years of location history for behavioural advertising.

Every purpose must be examined independently.


5. Can Manufacturers Hide Consent Inside Vehicle Terms?

A long privacy notice or vehicle-service agreement does not automatically make every processing activity lawful.

Drivers should be able to understand:

what data are collected,

why they are collected,

who receives them,

how long they are retained,

and whether they are transferred internationally.

Processing unrelated data simply because the driver cannot practically use the vehicle without accepting an entire package of terms may also raise questions concerning whether any purported consent was genuinely freely given.

Connected-car privacy should therefore not operate on the principle:

“By driving the vehicle, you agree to everything.”


6. Can Location Data Be Used for Advertising?

This creates an important purpose-limitation problem.

A manufacturer may process GPS data to provide navigation.

Using the same information later to determine:

where the driver shops,

which restaurants the driver visits,

what commercial interests the driver may have,

or which advertisements should be displayed

is a different processing purpose.

Lawful collection does not automatically authorise unlimited secondary use.

The legal basis, transparency and proportionality of any secondary use must therefore be separately assessed.


7. Can an Insurer Use Driving Behaviour to Calculate Premiums?

Connected vehicles make usage-based insurance increasingly realistic.

Risk models may take account of information such as:

mileage,

driving times,

braking,

acceleration,

speed

and journey characteristics.

A system might then generate:

“Driver Risk Score: 82/100.”

That score could affect premium pricing.

Such models are not necessarily prohibited, but they raise significant questions about profiling and automated decision-making.

Under Article 11 of the Turkish Personal Data Protection Law, individuals have the right to object where an adverse result is produced through the analysis of their data exclusively by automated systems.

The GDPR similarly contains specific protections concerning automated decision-making and profiling.

The question:

“Why did my insurance premium double because my car recorded my braking behaviour?”

may therefore become a significant data-protection dispute.


8. Can an Employer Continuously Monitor a Company Car?

The fact that a company owns a vehicle does not automatically permit unlimited surveillance of the employee driving it.

Monitoring a delivery route during working hours and tracking every movement of an employee during private time represent very different levels of interference.

The employer should consider:

necessity,

proportionality,

transparency,

less intrusive alternatives,

and whether monitoring can be disabled when the business purpose ends.

Power imbalance is particularly relevant when consent is relied upon in the employment context. Türkiye’s Data Protection Board again emphasised this issue in its 2026 decision concerning biometric attendance systems.


9. In-Cabin Systems Also Process Passenger Data

Connected-car privacy does not concern only the owner or registered driver.

Passengers may also be captured by:

cameras,

microphones,

voice systems

or biometric sensors.

The owner may have accepted the connected-service agreement.

A passenger generally has not.

Accordingly, connected-vehicle privacy architecture should consider everyone whose data may be processed inside or around the vehicle.

EDPB guidance concerning video and biometric processing emphasises necessity, proportionality, transparency and data minimisation when such technologies are deployed.


10. Facial and Voice Recognition Create Higher Risks

Some vehicles use biometric technology to recognise a driver and automatically configure seats, mirrors, climate settings, navigation or entertainment.

Where facial, fingerprint or other biometric information is technically processed for unique identification, special-category data rules may become relevant.

Türkiye’s Data Protection Authority stresses that special-category personal data require heightened protection because misuse may lead to discrimination or serious harm.

The fact that biometric identification is technologically convenient does not necessarily make centralised or long-term retention proportionate.

Technological possibility is not the same as legal necessity.


11. Can Driver-Monitoring Technology Generate Health Information?

Driver-monitoring systems may analyse eye movement, facial position or reaction time to detect fatigue.

Initially, this may constitute driving-safety information.

However, where the system begins drawing conclusions concerning an individual’s medical condition, a substantially more sensitive processing environment may arise.

Future connected-car disputes will therefore increasingly focus not only on the data originally collected, but also on what is inferred from those data.


12. Can Vehicle Data Be Used as Evidence After an Accident?

Potentially, yes.

A connected vehicle may preserve information concerning:

speed,

braking,

steering,

location,

sensor warnings

or other circumstances immediately before a collision.

The fact that this information constitutes personal data does not mean that it can never be used in legal proceedings.

Article 5 of the Turkish Personal Data Protection Law includes processing necessary for the establishment, exercise or protection of a legal right among the lawful grounds for processing.

Vehicle data may therefore potentially be processed in connection with the establishment or defence of an accident claim.

However, two questions should be distinguished:

whether processing complies with data-protection law

and

whether the material constitutes admissible evidence under the relevant procedural rules.

The manner in which the information was obtained remains important.


13. Can Vehicle Data Be Used to Reject a Warranty Claim?

Potentially.

A manufacturer might argue that telematics demonstrate excessive use, unauthorised modification or operation contrary to warranty requirements.

Such processing may potentially rely on contractual necessity or the establishment and defence of legal rights.

However, where an automated record affects a valuable consumer right, data accuracy becomes particularly important.

The individual may have rights to access information, request correction and seek compensation where unlawful data processing causes damage.


14. Can Law Enforcement Obtain Connected-Car Data?

Vehicle location and telematics may become important in criminal investigations.

They might potentially demonstrate where a vehicle was located, when it moved or which route it followed.

However, storing such information does not automatically create unrestricted access for public authorities.

The request must have an appropriate legal basis and be limited to the scope authorised by applicable procedural law.

Likewise, manufacturers must consider the lawful basis and scope of disclosure rather than treating every request as authorisation to release an individual’s entire historical movement record.


15. What Happens When Vehicle Data Are Transferred Abroad?

A vehicle may be driven in Türkiye while its connected-services infrastructure is hosted abroad.

The transmission of personal data to foreign servers can therefore trigger international-transfer rules.

Article 9 of the Turkish Personal Data Protection Law was substantially amended with effect from 1 June 2024. The current framework includes mechanisms involving adequacy decisions, standard contractual clauses, binding corporate rules and other appropriate safeguards.

Interestingly, the Authority’s international-transfer guidance expressly refers to the automotive sector when discussing the possibility of sector-specific adequacy decisions.

For international vehicle manufacturers, privacy compliance therefore extends far beyond an in-car notice.

The architecture of the global data flow itself must be lawful.


16. What Happens to Personal Data When the Car Is Sold?

Second-hand vehicles create an underestimated privacy risk.

A sold vehicle may still contain:

home addresses,

work locations,

contact lists,

paired phones,

navigation history

and user profiles.

If these data remain accessible to the next owner, a serious security issue may arise.

Likewise, retaining the former owner’s driving history indefinitely may be inconsistent with storage-limitation requirements once there is no longer a lawful need for it.

Turkish data-protection law requires deletion, destruction or anonymisation when the reasons requiring processing cease to exist, subject to the applicable legal framework.

A vehicle’s factory-reset function is therefore increasingly becoming a privacy feature, not merely a technical convenience.


17. Connected-Car Cybersecurity Is Also a Privacy Issue

Modern vehicles are effectively computers on wheels.

A successful cyberattack may expose not only vehicle systems but also:

location history,

contacts,

driver profiles,

account credentials

and camera information.

Under Turkish data-protection law, controllers are required to implement appropriate technical and organisational safeguards against unlawful access and processing. The Data Protection Authority also provides specific guidance concerning such security obligations.

In connected vehicles:

cybersecurity and privacy are increasingly inseparable.


18. What Does the EU Data Act Change for Vehicle Data?

Connected-vehicle regulation in Europe is no longer limited to the GDPR.

Regulation (EU) 2023/2854 — the Data Act — creates a legal framework concerning access to and use of data generated by connected products.

The Data Act generally became applicable on 12 September 2025. The Article 3(1) design obligation concerning accessibility of connected-product data applies to connected products and related services placed on the market after 12 September 2026.

On 15 September 2025, the European Commission also issued specific guidance concerning vehicle data under the Data Act. The guidance addresses the rights of vehicle users and third parties selected by those users to access and use relevant vehicle-generated data.

This reflects an important change in the automotive data economy.

Vehicle-generated data can no longer necessarily be treated as a closed asset controlled exclusively by the manufacturer.

Nevertheless, the Data Act does not create an unrestricted entitlement to process personal data.

Where vehicle information constitutes personal data, GDPR requirements remain applicable.


19. Can Drivers Ask What Their Car Knows About Them?

Yes.

Under Article 11 of the Turkish Personal Data Protection Law, individuals may ask controllers whether their data are being processed and may request information concerning:

the processing,

its purpose,

recipients,

correction,

deletion where the legal conditions exist,

and compensation for unlawful processing.

They may also object to adverse outcomes produced exclusively through automated analysis.

The Turkish Data Protection Board has further recognised that the statutory right to request information can, in appropriate circumstances, encompass access to the individual’s personal data.

Accordingly:

“What does my vehicle know about me?”

is not merely a technological question.

It is increasingly a legal right.


20. Can Smart Vehicles Violate Fundamental Rights?

Yes, although the existence of connected technology does not automatically constitute a violation.

The greatest risks arise where:

excessive information is collected,

location tracking occurs secretly or continuously,

data are reused for unrelated purposes,

information is disclosed to unknown third parties,

behavioural profiles are created without adequate transparency,

automated decisions negatively affect drivers,

data are retained indefinitely,

international transfers lack appropriate safeguards,

or cybersecurity weaknesses expose personal information.

The most serious privacy risk often comes not from a single data point but from combining multiple datasets.

GPS records, driving times, phone connections, navigation history and in-cabin information together may reconstruct an extremely detailed picture of an individual’s life.

The Turkish Data Protection Board’s approach to vehicle geolocation illustrates precisely this risk: mobility patterns can permit profiling and reveal highly sensitive aspects of a person’s private life.


CONCLUSION: IN THE CAR OF THE FUTURE, DATA MAY BECOME MORE VALUABLE THAN THE ENGINE

Connected vehicles are changing the legal and economic structure of the automotive industry.

Manufacturers may increasingly operate not merely as car companies but also as:

software providers,

digital-service platforms,

data intermediaries

and information providers to insurers, mobility businesses and other actors.

The legal consequence is fundamental:

The ability of a vehicle to collect information does not create an unlimited right to use that information.

Every processing activity should be assessed by asking:

What data are being collected?

For what purpose?

On which legal basis?

For how long?

Who receives the data?

Are the data transferred internationally?

Are they used for profiling or automated decisions?

Driving information may legitimately be used in appropriate circumstances for safety, maintenance, accident investigation, warranty administration or the establishment and protection of legal rights.

The same data, however, can create serious privacy violations when transformed without adequate justification into advertising profiles, employee surveillance, hidden consumer scoring or discriminatory automated decisions.

The defining legal question of the connected-car era is therefore no longer:

“What data can the car collect?”

It is:

“How far may the car — and the companies behind it — use what it learns about you?”

Categories:

No Responses

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Our Client

    We provide a wide range of Turkish legal services to businesses and individuals throughout the world. Our services include comprehensive, updated legal information, professional legal consultation and representation

    Our Team

    .Our team includes business and trial lawyers experienced in a wide range of legal services across a broad spectrum of industries.

    Why Choose Us

    We will hold your hand. We will make every effort to ensure that you understand and are comfortable with each step of the legal process.

    Call Now Button