"Your car is a data collector: connected vehicle privacy in Australia in 2026"
Your car is a data collector: connected vehicle privacy in Australia in 2026
A modern car is a phone with wheels: an embedded cellular modem with its own SIM, a satellite receiver, and a direct tap into the vehicle's internal network. It knows where you drive, how hard you brake, where you park overnight, and in many models what the interior cameras and microphones pick up. It streams all of this to the manufacturer, sometimes continuously, sometimes only when you have consented, and the difference between those two states is exactly what Australian law has been slow to pin down.
The past few months have made the picture unusually clear. In August 2026 the NRMA published a policy paper, Secure and Connected Vehicles: Stronger data, privacy and cyber rules in Australia, calling for enforceable consumer rights over vehicle data. Lexus Australia publicly backed national rules. And a detailed analysis of Australian connected-vehicle law confirmed the underlying problem: there is no vehicle-specific data law in Australia, only a 1988-era privacy statute, an unenforceable industry code, and three separate reform processes in three portfolios with nobody holding carriage.
What the car actually collects and where it goes
The hardware is the telematics control unit, and a key point from the legal analysis is worth repeating: it does not power down because you declined a subscription. It stays registered to a mobile network so emergency features like automatic crash notification work. What your consent toggles is which data streams get published upstream. Location, speed, odometer and diagnostic data sit in the same collection bucket as your finance details, and privacy notices typically bind only the owner or primary driver, not passengers, and not the pedestrians your exterior cameras recorded.
The scale is moving fast. The Australian Electric Vehicle Association's submission to government cites projections that up to 95 per cent of new vehicles sold in Australia by 2035 will be internet-enabled, across roughly 70 brands headquartered in 12 overseas jurisdictions. This is not an EV quirk; any modern car with an internal SIM is in scope.
The legal gaps, in one table
The autoexec analysis lays out what covers you and what does not:
| Instrument | Status | The catch |
|---|---|---|
| Privacy Act 1988 and the APPs | In force | Applies because vehicle data is personal information, but the employee-records and small-business exemptions leave holes; enforcement is slow |
| Statutory tort for serious invasion of privacy | Live since June 2025 | Lets individuals sue directly, still largely untested against carmakers |
| FCAI data privacy code of conduct | Voluntary | Not registered under the Privacy Act, so the OAIC cannot enforce it; membership discipline, not law |
| Right-to-repair scheme (MVIS) | Operating since 2022 | Expressly excludes data generated while driving and GPS data, so independent repairers are locked out of the telematics stream |
| Cyber Security Act 2024 | In force | Sets standards for smart devices but carves road vehicles out entirely |
The consequence, as the analysis puts it, is that diagnostics migrate from the OBD-II port to the telematics stream and the practical scope of right-to-repair narrows every model year without a word of legislation changing.
The regulator is moving
The NRMA report matters because it documents that the OAIC's investigations into vehicle suppliers are already underway, examining whether manufacturers collect more personal information than necessary and share it without informed, voluntary consent. Vehicle location tracking also sits explicitly on the OAIC's regulatory priorities, under new surveillance technologies including location data tracking in cars. Given the OAIC's recent record, the RentTech determination, the tracking-pixel findings against health providers, that is not an idle threat.
Industry is unusually split here. The NRMA's paper calls for consumers to have enforceable rights to refuse non-essential collection without losing warranty entitlements or safety features. Lexus Australia told Open Road its connected services ship switched off by default except for emergency functions, with layered per-feature consent, call-centre opt-outs and data deletion requests, and claims the customer always has control. The AEVA's submission goes further, urging Australia to combine Europe's GDPR-style protections with China's mandated in-vehicle processing and default non-collection principles, plus binding UNECE R155/R156 security standards.
Read the Lexus position carefully, though, because even the friendly example has a catch the autoexec analysis highlights: consent is a software gate on a hardware capability that never leaves. And Lexus concedes some connected-services data routes to North America or Japan regardless of its onshore preference.
Insurance is the quiet multiplier
One mechanism deserves its own paragraph because it changes your costs without any visible decision. If driving-behaviour data reaches an insurance intermediary, through an opt-in telematics policy, a shared-data partnership, or simply because your manufacturer's data reaches a consumer reporting agency, it becomes an underwriting input like a claims history. The autoexec analysis describes the result plainly: telematics data does not need to be labelled a policy discount to affect your premium, and you may never see the file that repriced you. There is no Australian equivalent of the transparency the US Senate has demanded; senators Wyden and Markey, for example, formally asked American regulators to examine whether eight automakers misled customers about requiring a warrant before handing location data to government agencies. No such mechanism exists here, and no Australian law currently forces a carmaker to disclose government requests for your vehicle data at all.
Overseas rules show the alternative. Europe ties market access to the UNECE R155 and R156 standards, which require certified cyber security and software-update management systems, and prohibits transferring personal data outside the vehicle in certain contexts. China mandates in-vehicle processing, default non-collection, precision limits on cameras and radar, and desensitisation of anything that leaves the car. The AEVA submission argues Australia should take the best of both. Until something along those lines passes, the direction of any given feature, useful or extractive, is decided by the manufacturer's product team, not by your legislature.
Practical takeaways for Australian owners
The law is unfinished, but your controls are not. What actually works today:
- Go feature by feature, not master switch. Open your vehicle's app and read the per-service toggles rather than the single connected-services switch. You can usually keep remote start and emergency functions while refusing behaviour analytics and route sharing.
- Deregister before you sell. Lexus's own disclosure warns that failing to notify a transfer means data keeps flowing to the previous subscriber's account. If you sell, remove the car from your account; if you buy used, assume the previous owner did not and ask for a full account reset at handover.
- Ask at the dealership. Which data streams does this model transmit, where are they stored, and which are required for the features I actually want? The NRMA frames the data handover conversation as a legitimate pre-purchase question, on par with tyre size.
- Remember your general rights. Under the Privacy Act you can request access to and correction of personal information a manufacturer holds about you, and since June 2025 the statutory tort gives you a direct avenue for serious invasions of privacy. Slow and imperfect, but real.
If location tracking broadly is your concern rather than cars specifically, our metadata retention explainer covers what your telco keeps and why, and the two problems are converging on the same infrastructure.
The honest summary: Australia is regulating connected-car data at the speed of a committee, the voluntary code is wallpaper, and the gap is being filled partly by regulators pushing through general privacy law and partly by buyers asking questions. Until a vehicle-specific regime passes, labelled correctly here as pending, not enacted, your consent screen is the only real control surface. Spend fifteen minutes in it.
Sources: NRMA Open Road, Lexus boss on car data privacy, August 2026, The AutoExec, connected vehicle data in Australia, 30 July 2026, Region Canberra, AEVA submission, 2026, OAIC regulatory priorities 2025-26. This article is general information, not legal advice.