Civil Law And Connected Vehicle Data Privacy Litigation In Europe .

Civil Law and Connected Vehicle Data Privacy Litigation in Europe

1. Introduction

Connected vehicles are no longer merely mechanical products. Modern vehicles can continuously generate, receive, store and transmit large quantities of information through GPS systems, cameras, microphones, telematics units, smartphones, infotainment systems, vehicle-to-vehicle communications and cloud platforms.

Examples include:

vehicle location and journey history;

driving speed and driving style;

acceleration and braking patterns;

vehicle identification and registration information;

battery and charging information;

maintenance and diagnostic information;

information about passengers;

biometric information;

camera and audio data;

information exchanged with mobile applications;

insurance-related driving data;

data transmitted to manufacturers, dealers, insurers and repairers.

The European Data Protection Board (EDPB) specifically recognises that connected vehicles may process driving habits, location, biometric and other information and has issued dedicated Guidelines 01/2020 on connected vehicles and mobility applications. (European Data Protection Board)

Therefore, disputes involving connected-vehicle data may combine civil law, contract law, data-protection law, consumer law, tort/delict principles, cybersecurity and private international law.

2. Meaning of Connected Vehicle Data Privacy Litigation

Connected vehicle data privacy litigation means legal proceedings arising from the collection, access, use, disclosure, retention, transfer or security of data generated by or connected to a vehicle.

Typical dispute:

A car manufacturer collects GPS and driving-behaviour data through the vehicle, transfers it to a cloud provider and uses it for analytics or insurance purposes. The driver alleges that the processing was unlawful, insufficiently disclosed or excessive and seeks an injunction, deletion of data or compensation.

The litigation can be brought against:

vehicle manufacturers;

software providers;

mobility platforms;

leasing companies;

insurers;

repair companies;

dealerships;

telecommunications providers;

cloud providers;

fleet operators;

application developers.

3. European Legal Framework

A. GDPR

The principal framework is the General Data Protection Regulation (EU) 2016/679.

Important provisions include:

GDPR provisionImportance
Article 4Definitions, including personal data and processing
Article 5Data-processing principles
Article 6Lawful bases for processing
Article 7Conditions for consent
Article 9Special categories of personal data
Articles 12–14Transparency and information
Articles 15–22Data-subject rights
Article 25Privacy by design and default
Article 32Security of processing
Articles 44–49International transfers
Article 82Compensation
Articles 77–79Remedies and judicial protection

4. Why Vehicle Data Can Be Personal Data

A major issue is whether information produced by a vehicle is actually personal data.

The answer is frequently yes.

For example, a vehicle's technical identifier may be capable of being connected with:

the registered owner;

driver account;

smartphone;

manufacturer account;

lease agreement;

insurance account;

location history.

The EDPB explains that even technical vehicle data may become personal data where it permits direct or indirect identification of the driver or another individual. (European Data Protection Board)

Thus:

Vehicle data + identifiable person = potentially personal data

This is particularly important for litigation because a manufacturer cannot necessarily avoid GDPR obligations merely by arguing:

“We collected the vehicle's data, not the driver's name.”

5. Types of Connected-Vehicle Privacy Disputes

5.1 GPS and Location Tracking

Connected vehicles can record:

starting location;

destination;

travel routes;

regular journeys;

workplace location;

home location;

charging locations.

Location data can reveal highly sensitive patterns about an individual's life.

A dispute may arise where a manufacturer or insurer uses continuous location tracking without an appropriate legal basis.

5.2 Driving Behaviour Monitoring

Vehicles can monitor:

acceleration;

braking;

cornering;

speed;

driving frequency;

driving times.

Insurance companies may use such information for telematics-based insurance.

The legal question becomes:

Was the driver properly informed, and was the processing lawful and proportionate?

6. Consent Problems

Consent is particularly complicated in connected vehicles.

A manufacturer might ask the purchaser to accept a long digital privacy policy when the vehicle is activated.

Questions include:

Was consent genuinely voluntary?

Was it sufficiently specific?

Was the purpose clearly explained?

Could the user refuse unnecessary processing?

Was consent bundled with essential vehicle functions?

Could consent later be withdrawn?

Was data collected before consent?

The EDPB stresses user control and privacy-protective design in connected vehicles. (European Data Protection Board)

7. Lawful Basis for Processing

A manufacturer does not automatically require consent for every processing operation.

Possible legal bases under Article 6 GDPR include:

1. Consent

The user voluntarily agrees to processing.

2. Contract

Processing may be necessary to provide a connected service purchased by the customer.

3. Legal obligation

For example, processing required by applicable legislation.

4. Vital interests

Relevant only in limited circumstances.

5. Public task

Potentially relevant to certain governmental transport functions.

6. Legitimate interests

A company may rely on legitimate interests where the legal requirements are satisfied and the individual's rights do not override those interests.

This balancing exercise is important in connected-vehicle disputes.

8. Data Minimisation

Article 5 GDPR requires data minimisation.

The principle can be expressed simply:

Collect only what is reasonably necessary for the identified purpose.

For example, if an application merely needs information about battery level, continuously transmitting precise GPS coordinates may raise a data-minimisation question.

The EDPB recommends, where possible, processing information locally within the vehicle rather than unnecessarily transferring personal data to external systems. (European Data Protection Board)

9. Privacy by Design

Article 25 GDPR requires data protection by design and by default.

This means privacy should be incorporated into the vehicle's technology from the beginning.

Examples:

local processing;

encryption;

pseudonymisation;

limited data retention;

privacy-protective default settings;

user-controlled data sharing;

restricted access;

deletion mechanisms.

The EDPB specifically states that connected-vehicle technologies should minimise personal-data collection and provide privacy-protective default settings. (European Data Protection Board)

10. Data Controller and Processor Disputes

A complicated issue is identifying who controls the data.

Possible actors include:

Driver → Vehicle → Manufacturer → Cloud Provider → Insurer → Repairer

Each participant may have a different legal role.

A dispute may ask:

Is the manufacturer a controller, processor, joint controller or merely another recipient?

This question determines responsibility for GDPR compliance.

11. Joint Controllership

Where two businesses jointly determine purposes and means of processing, joint-controllership principles can become relevant.

For example:

Vehicle manufacturer + digital-service provider

may jointly determine:

what data is collected;

why it is collected;

how it is analysed;

how it is transferred.

The CJEU's jurisprudence on joint controllers is therefore highly relevant to connected-car litigation.

12. Employee and Fleet Vehicle Data

Connected-vehicle disputes are not limited to private consumers.

Businesses increasingly use connected fleet vehicles.

Employers may receive:

employee location;

driving behaviour;

route information;

working hours;

vehicle usage;

accident information.

This creates potential employment-privacy disputes.

The question becomes whether monitoring is:

necessary;

proportionate;

transparent;

limited to legitimate purposes.

13. Insurance and Telematics

Connected vehicles are increasingly capable of supplying data to insurers.

An insurer may use:

mileage + braking + speed + acceleration + driving time

to calculate insurance risk or premiums.

Potential litigation can concern:

lack of transparency;

inaccurate data;

automated decision-making;

profiling;

discriminatory effects;

unlawful sharing;

excessive retention.

14. Automated Decision-Making

Article 22 GDPR may become relevant where connected-vehicle data is used to make decisions based solely on automated processing that produce legal or similarly significant effects.

Examples could include:

automated insurance decisions;

automated fraud assessments;

vehicle-access decisions;

credit decisions related to leasing;

automated employee monitoring.

The legal analysis depends heavily on the precise decision-making architecture and applicable exceptions.

15. Cybersecurity and Data Breaches

Connected vehicles create another category of civil litigation:

Vehicle hacking → unauthorised access → personal-data breach → financial/non-material harm

Examples include:

stolen vehicle-account credentials;

unauthorised remote access;

exposure of location history;

compromise of smartphone integration;

cloud database breaches;

disclosure of camera data.

Article 32 GDPR requires appropriate technical and organisational security measures.

A breach may therefore produce:

regulatory proceedings;

civil compensation claims;

contractual claims;

consumer claims;

injunction applications.

16. Right of Access

A driver may ask:

“What personal data does my vehicle manufacturer hold about me?”

Article 15 GDPR can potentially require access to relevant personal data, subject to applicable limitations.

The dispute may concern whether the manufacturer must provide:

GPS history;

driving profiles;

diagnostic records;

account information;

inferred information;

data shared with third parties.

The Nowak case is important for understanding the broad concept of personal data.

17. Right to Erasure

Article 17 GDPR provides the right to erasure in specified circumstances.

A consumer may therefore request deletion of vehicle-related personal data where the legal conditions are satisfied.

However, erasure is not absolute.

A company may retain certain information where, for example:

a legal obligation requires retention;

legal claims must be established or defended;

another GDPR exception applies.

18. Data Portability

Article 20 GDPR can become particularly significant for connected vehicles.

A consumer might want to move vehicle-generated information from:

Manufacturer A → Service Provider B

The dispute may concern whether the relevant data falls within the scope of data portability and whether it is processed by automated means on the basis required by Article 20.

19. Compensation for Privacy Harm

Article 82 GDPR provides a compensation mechanism for damage resulting from infringement of the GDPR.

Possible harm may include:

financial loss;

identity-related harm;

loss of control over personal data;

privacy-related distress;

reputational consequences.

However, the CJEU has clarified that a GDPR infringement by itself does not automatically establish compensable damage.

This is particularly important in connected-car litigation.

20. At Least 6 Important European Case Laws

Because reported CJEU cases dealing specifically with connected cars remain comparatively limited, the following cases are important GDPR/data-protection authorities that can be applied by analogy to connected-vehicle disputes.

Case 1 — Breyer v Bundesrepublik Deutschland

Case C-582/14, Patrick Breyer v Bundesrepublik Deutschland

Principle

The CJEU held that a dynamic IP address can constitute personal data where the controller has legal means enabling identification of the individual through additional information.

Relevance to connected vehicles

Vehicle data may not contain a person's name but may still identify the person when combined with:

account data;

registration information;

smartphone data;

manufacturer databases.

Therefore:

Indirect identifiability can be enough.

This is one of the strongest conceptual authorities for connected-vehicle data. (curia)

Case 2 — Nowak v Data Protection Commissioner

Case C-434/16, Peter Nowak v Data Protection Commissioner

Principle

The CJEU adopted a broad approach to the concept of personal data, including information connected with an identifiable individual.

Relevance

Vehicle-generated information may become personal data even when it looks like technical or objective information.

For example:

braking records;

driving scores;

diagnostic information;

route information.

The important question is whether the information relates to an identifiable person.

Case 3 — Rīgas satiksme

Case C-13/16, Valsts policijas Rīgas reģiona pārvalde v Rīgas pašvaldības SIA Rīgas satiksme

Facts

The case concerned disclosure of information relating to a person involved in a road accident.

Principle

The CJEU considered legitimate interests and the disclosure of personal data for the purpose of pursuing a legal claim.

Connected-vehicle relevance

Suppose connected-vehicle data is required to establish:

who caused an accident;

what the vehicle was doing;

whether a driver was speeding;

whether an automated system malfunctioned.

The case demonstrates the importance of balancing data protection with the legitimate exercise of legal claims. (InfoCuria)

Case 4 — Wirtschaftsakademie Schleswig-Holstein

Case C-210/16, Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein v Wirtschaftsakademie Schleswig-Holstein GmbH

Principle

The CJEU developed the concept of joint controllership.

A party can have controller responsibility even though another company performs substantial parts of the technical processing.

Connected-vehicle relevance

Consider:

Car manufacturer + cloud provider + mobility platform

If their roles involve jointly determining relevant purposes and means of processing, simply outsourcing the technical operation does not necessarily eliminate responsibility.

This is particularly important in connected-car ecosystems. (curia)

Case 5 — Fashion ID

Case C-40/17, Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW e.V.

Principle

The CJEU considered when a website operator can be regarded as a controller in relation to transmission of personal data to another company through an embedded technological function.

The case is highly relevant to modern connected technology because it demonstrates that responsibility can arise at the point where data is collected and transmitted to another actor. (InfoCuria)

Connected-vehicle application

A vehicle manufacturer may integrate a third-party:

navigation service;

entertainment service;

insurance application;

cloud platform.

The manufacturer cannot automatically assume that the third party alone bears all responsibility.

Case 6 — Österreichische Post

Case C-300/21, UI v Österreichische Post AG

Principle

The CJEU examined Article 82 GDPR and compensation for damage caused by unlawful personal-data processing.

Importantly, the Court held that mere infringement of the GDPR is not, by itself, sufficient to create a right to compensation; damage must also exist. (InfoCuria)

Connected-vehicle relevance

A consumer claiming compensation for unlawful vehicle-data processing would therefore need to establish the relevant damage, rather than merely pointing to an infringement.

This could be important in cases involving:

unlawful location tracking;

disclosure of driving records;

unauthorised sharing;

data breaches.

Case 7 — European Parliament and Council / Vehicle Registration Data

Joined Cases C-14/15 and C-116/15

These proceedings concerned automated exchange of Vehicle Registration Data between Member States.

Relevance

The case illustrates the relationship between vehicle-related information systems and EU data-protection principles.

Vehicle registration information is especially important because it can link a vehicle to an identifiable person.

The case therefore provides useful background for cross-border vehicle-data processing. (InfoCuria)

21. Case-Law Comparison Table

CaseMain principleConnected-vehicle application
Breyer, C-582/14Indirect identification can constitute personal dataVehicle identifiers, IP/device data
Nowak, C-434/16Broad concept of personal dataDriving/technical information
Rīgas satiksme, C-13/16Legitimate interest and legal claimsAccident and vehicle data disclosure
Wirtschaftsakademie, C-210/16Joint controller responsibilityManufacturer/cloud-provider relationships
Fashion ID, C-40/17Responsibility for data transmissionThird-party connected-car services
Österreichische Post, C-300/21Compensation requires damage, not merely infringementPrivacy damages from vehicle-data misuse
C-14/15 & C-116/15Vehicle-registration data exchangeCross-border vehicle information

22. Civil Remedies

A claimant may potentially seek several remedies.

A. Injunction

The court may be asked to stop unlawful processing.

Example:

Stop continuous GPS monitoring that lacks a lawful basis.

B. Deletion

The claimant may seek deletion of unlawfully retained data where Article 17 requirements are satisfied.

C. Access

The claimant may seek disclosure of personal data held by the manufacturer or service provider.

D. Correction

Incorrect information may need correction.

For example:

A vehicle's system incorrectly records a driver as repeatedly exceeding speed limits.

E. Compensation

Article 82 GDPR may support compensation where the statutory requirements are established.

F. Declaratory Relief

A claimant may seek a judicial declaration that particular processing is unlawful.

23. Evidence in Connected-Vehicle Litigation

Evidence can be technically complex.

Important evidence may include:

vehicle logs;

telematics records;

GPS records;

ECU data;

server logs;

smartphone records;

consent records;

privacy notices;

data-processing agreements;

cybersecurity logs;

API records;

cloud-storage records;

data-retention policies.

Digital evidence may need expert examination because ordinary consumers often cannot understand how vehicle software generates or transfers information.

24. Data Accuracy Problems

Connected vehicles may produce automated records that are not always accurate.

For example:

A system records that the vehicle was travelling at 110 km/h, while the driver claims the recorded speed was incorrect.

The dispute can involve:

Accuracy → reliability → causation → liability

This becomes especially important when data is used for:

insurance;

accident litigation;

employment monitoring;

criminal investigations;

warranty disputes.

25. Third-Party Data

A connected vehicle may collect information not only about the driver but also about:

passengers;

pedestrians;

other drivers;

nearby individuals captured by cameras.

This creates difficult questions about who is the data subject and whether appropriate information and safeguards were provided.

The EDPB specifically recognises that connected vehicles can process information relating to drivers, passengers and other persons encountered by vehicle systems. (European Data Protection Board)

26. International Data Transfers

Modern vehicles frequently transmit information to cloud systems.

A European vehicle may send information to:

EU vehicle → EU manufacturer → non-EU cloud provider

GDPR Chapter V may then become relevant.

Litigation can concern:

adequacy decisions;

Standard Contractual Clauses;

supplementary safeguards;

government access;

encryption;

transfer-risk assessments.

27. Data Retention

Another important civil-law issue is:

How long may connected-vehicle data be retained?

A company may have legitimate reasons for retaining information for a certain period, but indefinite storage can create GDPR concerns.

Retention should be connected to:

purpose;

legal obligations;

contractual requirements;

limitation periods;

security requirements.

28. Consumer Contract Issues

Connected vehicles frequently operate through contractual ecosystems.

The purchaser may have separate agreements with:

manufacturer;

dealership;

software provider;

navigation provider;

insurer;

charging provider.

A privacy dispute may therefore also involve:

unfair contractual terms;

inadequate disclosure;

limitation clauses;

warranty obligations;

service suspension;

termination.

Thus, connected-vehicle litigation can be both data-protection litigation and civil contract litigation.

29. Manufacturer Liability

A manufacturer may potentially face several categories of claim where its vehicle-data architecture causes harm:

Data-protection liability

Unlawful processing.

Contractual liability

Failure to provide promised privacy or connected services.

Tort/delict liability

Damage caused by negligent conduct.

Consumer liability

Unfair or misleading information.

Cybersecurity liability

Failure to implement appropriate security safeguards.

These legal bases can overlap.

30. Relationship Between GDPR and Civil Law

A useful formula is:

GDPR duty → unlawful processing → damage → causation → remedy

For example:

Manufacturer collects excessive location data
↓
Processing lacks adequate legal basis
↓
Data is disclosed to an unauthorised third party
↓
Individual suffers legally recognised damage
↓
Claim for appropriate relief/compensation

The exact civil-law consequences remain dependent on the applicable national procedural and substantive law.

31. Special Problem: Ownership of Vehicle Data

An important conceptual distinction is:

Data protection rights are not the same as ownership of data.

The consumer may have GDPR rights over personal data without necessarily being the proprietary “owner” of every item of technical information generated by the vehicle.

Therefore, litigation should distinguish between:

personal-data rights;

contractual access rights;

database rights;

intellectual-property rights;

trade secrets;

technical information;

vehicle ownership.

32. Connected Vehicles and the Data Act

The EU's newer data-governance framework also increases the importance of access to data generated by connected products.

For connected products, the legal landscape increasingly addresses questions such as:

who can access product-generated data;

how data should be made available;

contractual fairness;

data sharing;

switching between services.

This is particularly important for connected cars because vehicle manufacturers historically control much of the technical infrastructure through which vehicle data is generated and accessed.

The Data Act therefore complements, rather than simply replaces, GDPR protection.

33. Key Litigation Questions

In an actual connected-vehicle privacy dispute, a court may need to ask:

Question 1

Is the information personal data?

Question 2

Who is the data subject?

Question 3

Who is the controller?

Question 4

Is there a processor or joint controller?

Question 5

What is the legal basis?

Question 6

Was the individual adequately informed?

Question 7

Was the processing necessary and proportionate?

Question 8

Was data minimisation respected?

Question 9

Were appropriate security measures used?

Question 10

Was the information transferred outside the EU?

Question 11

Was the information retained for too long?

Question 12

Did unlawful processing actually cause compensable damage?

34. Major Challenges for European Courts

1. Rapid technological change

Vehicles develop faster than traditional civil-law concepts.

2. Multiple controllers

Several businesses can simultaneously participate in processing.

3. Cross-border processing

The vehicle, manufacturer and cloud provider may be located in different countries.

4. Huge volumes of data

Modern vehicles can continuously generate information.

5. Technical complexity

Judges may require expert evidence.

6. Mixed data

One dataset may contain information concerning several individuals.

7. Automated decisions

Algorithms may transform vehicle information into insurance, employment or commercial decisions.

8. Cybersecurity

A privacy dispute may originate from a cyberattack rather than intentional disclosure.

35. Simple Example

Suppose A buys a connected electric car.

The car continuously sends:

GPS location;

battery information;

driving behaviour;

speed;

charging history

to the manufacturer's cloud platform.

The manufacturer then sells an analytics service to an insurer.

The driver alleges:

inadequate information;

no valid legal basis;

excessive GPS collection;

unlawful sharing with the insurer;

inaccurate driving profile;

financial and non-material harm.

A court could analyse:

Personal data? → Yes/potentially

Controller? → Manufacturer and possibly another actor

Legal basis? → Article 6 analysis

Transparency? → Articles 12–14

Data minimisation? → Article 5

Privacy by design? → Article 25

Security? → Article 32

Compensation? → Article 82

Evidence? → Vehicle/cloud logs

This demonstrates how several areas of European civil and data law operate together.

36. Important Principles from the Case Law

The cases can be reduced to the following principles:

PrincipleLeading case
Indirectly identifiable information may be personal dataBreyer
Personal data has a broad functional meaningNowak
Data protection must be balanced with legitimate legal interestsRīgas satiksme
Several actors may share controller responsibilityWirtschaftsakademie
Data transmission through technology can create controller responsibilityFashion ID
GDPR compensation requires legally relevant damageÖsterreichische Post
Vehicle-registration information can form part of cross-border information systemsC-14/15 & C-116/15

37. Exam-Oriented Conclusion

Connected vehicle data privacy litigation in Europe is an emerging area where traditional civil law intersects with GDPR, consumer protection, cybersecurity, contract law and technological regulation.

The central legal issue is not simply whether a vehicle produces data. It is whether the data relates to an identifiable individual and how organisations collect, use, disclose, retain and secure it.

The most important principles are:

Personal data → lawful basis → transparency → minimisation → security → controller responsibility → data-subject rights → damage → compensation.

The Breyer, Nowak, Rīgas satiksme, Wirtschaftsakademie, Fashion ID and Österreichische Post judgments provide particularly useful CJEU foundations for analysing connected-vehicle privacy disputes, even though several arose outside the automotive sector. The EDPB's dedicated connected-vehicle guidance is especially important because it directly addresses the automotive ecosystem and recommends privacy-by-design measures, including local processing where feasible. (European Data Protection Board)

Quick Revision Formula

Connected Vehicle Privacy Litigation =

Vehicle Data + Identifiable Person + GDPR + Controller/Processor + Lawful Basis + Transparency + Security + Data Rights + Damage + Civil Remedy

Key cases:

Breyer — C-582/14

Nowak — C-434/16

Rīgas satiksme — C-13/16

Wirtschaftsakademie — C-210/16

Fashion ID — C-40/17

Österreichische Post — C-300/21

European Parliament and Council — Joined Cases C-14/15 and C-116/15

LEAVE A COMMENT