Civil Law And Connected Vehicle Data Privacy Litigation In Europe .
Civil Law and Connected Vehicle Data Privacy Litigation in Europe
1. Introduction
Connected vehicles are no longer merely mechanical products. Modern vehicles can continuously generate, receive, store and transmit large quantities of information through GPS systems, cameras, microphones, telematics units, smartphones, infotainment systems, vehicle-to-vehicle communications and cloud platforms.
Examples include:
vehicle location and journey history;
driving speed and driving style;
acceleration and braking patterns;
vehicle identification and registration information;
battery and charging information;
maintenance and diagnostic information;
information about passengers;
biometric information;
camera and audio data;
information exchanged with mobile applications;
insurance-related driving data;
data transmitted to manufacturers, dealers, insurers and repairers.
The European Data Protection Board (EDPB) specifically recognises that connected vehicles may process driving habits, location, biometric and other information and has issued dedicated Guidelines 01/2020 on connected vehicles and mobility applications. (European Data Protection Board)
Therefore, disputes involving connected-vehicle data may combine civil law, contract law, data-protection law, consumer law, tort/delict principles, cybersecurity and private international law.
2. Meaning of Connected Vehicle Data Privacy Litigation
Connected vehicle data privacy litigation means legal proceedings arising from the collection, access, use, disclosure, retention, transfer or security of data generated by or connected to a vehicle.
Typical dispute:
A car manufacturer collects GPS and driving-behaviour data through the vehicle, transfers it to a cloud provider and uses it for analytics or insurance purposes. The driver alleges that the processing was unlawful, insufficiently disclosed or excessive and seeks an injunction, deletion of data or compensation.
The litigation can be brought against:
vehicle manufacturers;
software providers;
mobility platforms;
leasing companies;
insurers;
repair companies;
dealerships;
telecommunications providers;
cloud providers;
fleet operators;
application developers.
3. European Legal Framework
A. GDPR
The principal framework is the General Data Protection Regulation (EU) 2016/679.
Important provisions include:
| GDPR provision | Importance |
|---|---|
| Article 4 | Definitions, including personal data and processing |
| Article 5 | Data-processing principles |
| Article 6 | Lawful bases for processing |
| Article 7 | Conditions for consent |
| Article 9 | Special categories of personal data |
| Articles 12–14 | Transparency and information |
| Articles 15–22 | Data-subject rights |
| Article 25 | Privacy by design and default |
| Article 32 | Security of processing |
| Articles 44–49 | International transfers |
| Article 82 | Compensation |
| Articles 77–79 | Remedies and judicial protection |
4. Why Vehicle Data Can Be Personal Data
A major issue is whether information produced by a vehicle is actually personal data.
The answer is frequently yes.
For example, a vehicle's technical identifier may be capable of being connected with:
the registered owner;
driver account;
smartphone;
manufacturer account;
lease agreement;
insurance account;
location history.
The EDPB explains that even technical vehicle data may become personal data where it permits direct or indirect identification of the driver or another individual. (European Data Protection Board)
Thus:
Vehicle data + identifiable person = potentially personal data
This is particularly important for litigation because a manufacturer cannot necessarily avoid GDPR obligations merely by arguing:
“We collected the vehicle's data, not the driver's name.”
5. Types of Connected-Vehicle Privacy Disputes
5.1 GPS and Location Tracking
Connected vehicles can record:
starting location;
destination;
travel routes;
regular journeys;
workplace location;
home location;
charging locations.
Location data can reveal highly sensitive patterns about an individual's life.
A dispute may arise where a manufacturer or insurer uses continuous location tracking without an appropriate legal basis.
5.2 Driving Behaviour Monitoring
Vehicles can monitor:
acceleration;
braking;
cornering;
speed;
driving frequency;
driving times.
Insurance companies may use such information for telematics-based insurance.
The legal question becomes:
Was the driver properly informed, and was the processing lawful and proportionate?
6. Consent Problems
Consent is particularly complicated in connected vehicles.
A manufacturer might ask the purchaser to accept a long digital privacy policy when the vehicle is activated.
Questions include:
Was consent genuinely voluntary?
Was it sufficiently specific?
Was the purpose clearly explained?
Could the user refuse unnecessary processing?
Was consent bundled with essential vehicle functions?
Could consent later be withdrawn?
Was data collected before consent?
The EDPB stresses user control and privacy-protective design in connected vehicles. (European Data Protection Board)
7. Lawful Basis for Processing
A manufacturer does not automatically require consent for every processing operation.
Possible legal bases under Article 6 GDPR include:
1. Consent
The user voluntarily agrees to processing.
2. Contract
Processing may be necessary to provide a connected service purchased by the customer.
3. Legal obligation
For example, processing required by applicable legislation.
4. Vital interests
Relevant only in limited circumstances.
5. Public task
Potentially relevant to certain governmental transport functions.
6. Legitimate interests
A company may rely on legitimate interests where the legal requirements are satisfied and the individual's rights do not override those interests.
This balancing exercise is important in connected-vehicle disputes.
8. Data Minimisation
Article 5 GDPR requires data minimisation.
The principle can be expressed simply:
Collect only what is reasonably necessary for the identified purpose.
For example, if an application merely needs information about battery level, continuously transmitting precise GPS coordinates may raise a data-minimisation question.
The EDPB recommends, where possible, processing information locally within the vehicle rather than unnecessarily transferring personal data to external systems. (European Data Protection Board)
9. Privacy by Design
Article 25 GDPR requires data protection by design and by default.
This means privacy should be incorporated into the vehicle's technology from the beginning.
Examples:
local processing;
encryption;
pseudonymisation;
limited data retention;
privacy-protective default settings;
user-controlled data sharing;
restricted access;
deletion mechanisms.
The EDPB specifically states that connected-vehicle technologies should minimise personal-data collection and provide privacy-protective default settings. (European Data Protection Board)
10. Data Controller and Processor Disputes
A complicated issue is identifying who controls the data.
Possible actors include:
Driver → Vehicle → Manufacturer → Cloud Provider → Insurer → Repairer
Each participant may have a different legal role.
A dispute may ask:
Is the manufacturer a controller, processor, joint controller or merely another recipient?
This question determines responsibility for GDPR compliance.
11. Joint Controllership
Where two businesses jointly determine purposes and means of processing, joint-controllership principles can become relevant.
For example:
Vehicle manufacturer + digital-service provider
may jointly determine:
what data is collected;
why it is collected;
how it is analysed;
how it is transferred.
The CJEU's jurisprudence on joint controllers is therefore highly relevant to connected-car litigation.
12. Employee and Fleet Vehicle Data
Connected-vehicle disputes are not limited to private consumers.
Businesses increasingly use connected fleet vehicles.
Employers may receive:
employee location;
driving behaviour;
route information;
working hours;
vehicle usage;
accident information.
This creates potential employment-privacy disputes.
The question becomes whether monitoring is:
necessary;
proportionate;
transparent;
limited to legitimate purposes.
13. Insurance and Telematics
Connected vehicles are increasingly capable of supplying data to insurers.
An insurer may use:
mileage + braking + speed + acceleration + driving time
to calculate insurance risk or premiums.
Potential litigation can concern:
lack of transparency;
inaccurate data;
automated decision-making;
profiling;
discriminatory effects;
unlawful sharing;
excessive retention.
14. Automated Decision-Making
Article 22 GDPR may become relevant where connected-vehicle data is used to make decisions based solely on automated processing that produce legal or similarly significant effects.
Examples could include:
automated insurance decisions;
automated fraud assessments;
vehicle-access decisions;
credit decisions related to leasing;
automated employee monitoring.
The legal analysis depends heavily on the precise decision-making architecture and applicable exceptions.
15. Cybersecurity and Data Breaches
Connected vehicles create another category of civil litigation:
Vehicle hacking → unauthorised access → personal-data breach → financial/non-material harm
Examples include:
stolen vehicle-account credentials;
unauthorised remote access;
exposure of location history;
compromise of smartphone integration;
cloud database breaches;
disclosure of camera data.
Article 32 GDPR requires appropriate technical and organisational security measures.
A breach may therefore produce:
regulatory proceedings;
civil compensation claims;
contractual claims;
consumer claims;
injunction applications.
16. Right of Access
A driver may ask:
“What personal data does my vehicle manufacturer hold about me?”
Article 15 GDPR can potentially require access to relevant personal data, subject to applicable limitations.
The dispute may concern whether the manufacturer must provide:
GPS history;
driving profiles;
diagnostic records;
account information;
inferred information;
data shared with third parties.
The Nowak case is important for understanding the broad concept of personal data.
17. Right to Erasure
Article 17 GDPR provides the right to erasure in specified circumstances.
A consumer may therefore request deletion of vehicle-related personal data where the legal conditions are satisfied.
However, erasure is not absolute.
A company may retain certain information where, for example:
a legal obligation requires retention;
legal claims must be established or defended;
another GDPR exception applies.
18. Data Portability
Article 20 GDPR can become particularly significant for connected vehicles.
A consumer might want to move vehicle-generated information from:
Manufacturer A → Service Provider B
The dispute may concern whether the relevant data falls within the scope of data portability and whether it is processed by automated means on the basis required by Article 20.
19. Compensation for Privacy Harm
Article 82 GDPR provides a compensation mechanism for damage resulting from infringement of the GDPR.
Possible harm may include:
financial loss;
identity-related harm;
loss of control over personal data;
privacy-related distress;
reputational consequences.
However, the CJEU has clarified that a GDPR infringement by itself does not automatically establish compensable damage.
This is particularly important in connected-car litigation.
20. At Least 6 Important European Case Laws
Because reported CJEU cases dealing specifically with connected cars remain comparatively limited, the following cases are important GDPR/data-protection authorities that can be applied by analogy to connected-vehicle disputes.
Case 1 — Breyer v Bundesrepublik Deutschland
Case C-582/14, Patrick Breyer v Bundesrepublik Deutschland
Principle
The CJEU held that a dynamic IP address can constitute personal data where the controller has legal means enabling identification of the individual through additional information.
Relevance to connected vehicles
Vehicle data may not contain a person's name but may still identify the person when combined with:
account data;
registration information;
smartphone data;
manufacturer databases.
Therefore:
Indirect identifiability can be enough.
This is one of the strongest conceptual authorities for connected-vehicle data. (curia)
Case 2 — Nowak v Data Protection Commissioner
Case C-434/16, Peter Nowak v Data Protection Commissioner
Principle
The CJEU adopted a broad approach to the concept of personal data, including information connected with an identifiable individual.
Relevance
Vehicle-generated information may become personal data even when it looks like technical or objective information.
For example:
braking records;
driving scores;
diagnostic information;
route information.
The important question is whether the information relates to an identifiable person.
Case 3 — Rīgas satiksme
Case C-13/16, Valsts policijas Rīgas reģiona pārvalde v Rīgas pašvaldības SIA Rīgas satiksme
Facts
The case concerned disclosure of information relating to a person involved in a road accident.
Principle
The CJEU considered legitimate interests and the disclosure of personal data for the purpose of pursuing a legal claim.
Connected-vehicle relevance
Suppose connected-vehicle data is required to establish:
who caused an accident;
what the vehicle was doing;
whether a driver was speeding;
whether an automated system malfunctioned.
The case demonstrates the importance of balancing data protection with the legitimate exercise of legal claims. (InfoCuria)
Case 4 — Wirtschaftsakademie Schleswig-Holstein
Case C-210/16, Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein v Wirtschaftsakademie Schleswig-Holstein GmbH
Principle
The CJEU developed the concept of joint controllership.
A party can have controller responsibility even though another company performs substantial parts of the technical processing.
Connected-vehicle relevance
Consider:
Car manufacturer + cloud provider + mobility platform
If their roles involve jointly determining relevant purposes and means of processing, simply outsourcing the technical operation does not necessarily eliminate responsibility.
This is particularly important in connected-car ecosystems. (curia)
Case 5 — Fashion ID
Case C-40/17, Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW e.V.
Principle
The CJEU considered when a website operator can be regarded as a controller in relation to transmission of personal data to another company through an embedded technological function.
The case is highly relevant to modern connected technology because it demonstrates that responsibility can arise at the point where data is collected and transmitted to another actor. (InfoCuria)
Connected-vehicle application
A vehicle manufacturer may integrate a third-party:
navigation service;
entertainment service;
insurance application;
cloud platform.
The manufacturer cannot automatically assume that the third party alone bears all responsibility.
Case 6 — Österreichische Post
Case C-300/21, UI v Österreichische Post AG
Principle
The CJEU examined Article 82 GDPR and compensation for damage caused by unlawful personal-data processing.
Importantly, the Court held that mere infringement of the GDPR is not, by itself, sufficient to create a right to compensation; damage must also exist. (InfoCuria)
Connected-vehicle relevance
A consumer claiming compensation for unlawful vehicle-data processing would therefore need to establish the relevant damage, rather than merely pointing to an infringement.
This could be important in cases involving:
unlawful location tracking;
disclosure of driving records;
unauthorised sharing;
data breaches.
Case 7 — European Parliament and Council / Vehicle Registration Data
Joined Cases C-14/15 and C-116/15
These proceedings concerned automated exchange of Vehicle Registration Data between Member States.
Relevance
The case illustrates the relationship between vehicle-related information systems and EU data-protection principles.
Vehicle registration information is especially important because it can link a vehicle to an identifiable person.
The case therefore provides useful background for cross-border vehicle-data processing. (InfoCuria)
21. Case-Law Comparison Table
| Case | Main principle | Connected-vehicle application |
|---|---|---|
| Breyer, C-582/14 | Indirect identification can constitute personal data | Vehicle identifiers, IP/device data |
| Nowak, C-434/16 | Broad concept of personal data | Driving/technical information |
| Rīgas satiksme, C-13/16 | Legitimate interest and legal claims | Accident and vehicle data disclosure |
| Wirtschaftsakademie, C-210/16 | Joint controller responsibility | Manufacturer/cloud-provider relationships |
| Fashion ID, C-40/17 | Responsibility for data transmission | Third-party connected-car services |
| Österreichische Post, C-300/21 | Compensation requires damage, not merely infringement | Privacy damages from vehicle-data misuse |
| C-14/15 & C-116/15 | Vehicle-registration data exchange | Cross-border vehicle information |
22. Civil Remedies
A claimant may potentially seek several remedies.
A. Injunction
The court may be asked to stop unlawful processing.
Example:
Stop continuous GPS monitoring that lacks a lawful basis.
B. Deletion
The claimant may seek deletion of unlawfully retained data where Article 17 requirements are satisfied.
C. Access
The claimant may seek disclosure of personal data held by the manufacturer or service provider.
D. Correction
Incorrect information may need correction.
For example:
A vehicle's system incorrectly records a driver as repeatedly exceeding speed limits.
E. Compensation
Article 82 GDPR may support compensation where the statutory requirements are established.
F. Declaratory Relief
A claimant may seek a judicial declaration that particular processing is unlawful.
23. Evidence in Connected-Vehicle Litigation
Evidence can be technically complex.
Important evidence may include:
vehicle logs;
telematics records;
GPS records;
ECU data;
server logs;
smartphone records;
consent records;
privacy notices;
data-processing agreements;
cybersecurity logs;
API records;
cloud-storage records;
data-retention policies.
Digital evidence may need expert examination because ordinary consumers often cannot understand how vehicle software generates or transfers information.
24. Data Accuracy Problems
Connected vehicles may produce automated records that are not always accurate.
For example:
A system records that the vehicle was travelling at 110 km/h, while the driver claims the recorded speed was incorrect.
The dispute can involve:
Accuracy → reliability → causation → liability
This becomes especially important when data is used for:
insurance;
accident litigation;
employment monitoring;
criminal investigations;
warranty disputes.
25. Third-Party Data
A connected vehicle may collect information not only about the driver but also about:
passengers;
pedestrians;
other drivers;
nearby individuals captured by cameras.
This creates difficult questions about who is the data subject and whether appropriate information and safeguards were provided.
The EDPB specifically recognises that connected vehicles can process information relating to drivers, passengers and other persons encountered by vehicle systems. (European Data Protection Board)
26. International Data Transfers
Modern vehicles frequently transmit information to cloud systems.
A European vehicle may send information to:
EU vehicle → EU manufacturer → non-EU cloud provider
GDPR Chapter V may then become relevant.
Litigation can concern:
adequacy decisions;
Standard Contractual Clauses;
supplementary safeguards;
government access;
encryption;
transfer-risk assessments.
27. Data Retention
Another important civil-law issue is:
How long may connected-vehicle data be retained?
A company may have legitimate reasons for retaining information for a certain period, but indefinite storage can create GDPR concerns.
Retention should be connected to:
purpose;
legal obligations;
contractual requirements;
limitation periods;
security requirements.
28. Consumer Contract Issues
Connected vehicles frequently operate through contractual ecosystems.
The purchaser may have separate agreements with:
manufacturer;
dealership;
software provider;
navigation provider;
insurer;
charging provider.
A privacy dispute may therefore also involve:
unfair contractual terms;
inadequate disclosure;
limitation clauses;
warranty obligations;
service suspension;
termination.
Thus, connected-vehicle litigation can be both data-protection litigation and civil contract litigation.
29. Manufacturer Liability
A manufacturer may potentially face several categories of claim where its vehicle-data architecture causes harm:
Data-protection liability
Unlawful processing.
Contractual liability
Failure to provide promised privacy or connected services.
Tort/delict liability
Damage caused by negligent conduct.
Consumer liability
Unfair or misleading information.
Cybersecurity liability
Failure to implement appropriate security safeguards.
These legal bases can overlap.
30. Relationship Between GDPR and Civil Law
A useful formula is:
GDPR duty → unlawful processing → damage → causation → remedy
For example:
Manufacturer collects excessive location data
↓
Processing lacks adequate legal basis
↓
Data is disclosed to an unauthorised third party
↓
Individual suffers legally recognised damage
↓
Claim for appropriate relief/compensation
The exact civil-law consequences remain dependent on the applicable national procedural and substantive law.
31. Special Problem: Ownership of Vehicle Data
An important conceptual distinction is:
Data protection rights are not the same as ownership of data.
The consumer may have GDPR rights over personal data without necessarily being the proprietary “owner” of every item of technical information generated by the vehicle.
Therefore, litigation should distinguish between:
personal-data rights;
contractual access rights;
database rights;
intellectual-property rights;
trade secrets;
technical information;
vehicle ownership.
32. Connected Vehicles and the Data Act
The EU's newer data-governance framework also increases the importance of access to data generated by connected products.
For connected products, the legal landscape increasingly addresses questions such as:
who can access product-generated data;
how data should be made available;
contractual fairness;
data sharing;
switching between services.
This is particularly important for connected cars because vehicle manufacturers historically control much of the technical infrastructure through which vehicle data is generated and accessed.
The Data Act therefore complements, rather than simply replaces, GDPR protection.
33. Key Litigation Questions
In an actual connected-vehicle privacy dispute, a court may need to ask:
Question 1
Is the information personal data?
Question 2
Who is the data subject?
Question 3
Who is the controller?
Question 4
Is there a processor or joint controller?
Question 5
What is the legal basis?
Question 6
Was the individual adequately informed?
Question 7
Was the processing necessary and proportionate?
Question 8
Was data minimisation respected?
Question 9
Were appropriate security measures used?
Question 10
Was the information transferred outside the EU?
Question 11
Was the information retained for too long?
Question 12
Did unlawful processing actually cause compensable damage?
34. Major Challenges for European Courts
1. Rapid technological change
Vehicles develop faster than traditional civil-law concepts.
2. Multiple controllers
Several businesses can simultaneously participate in processing.
3. Cross-border processing
The vehicle, manufacturer and cloud provider may be located in different countries.
4. Huge volumes of data
Modern vehicles can continuously generate information.
5. Technical complexity
Judges may require expert evidence.
6. Mixed data
One dataset may contain information concerning several individuals.
7. Automated decisions
Algorithms may transform vehicle information into insurance, employment or commercial decisions.
8. Cybersecurity
A privacy dispute may originate from a cyberattack rather than intentional disclosure.
35. Simple Example
Suppose A buys a connected electric car.
The car continuously sends:
GPS location;
battery information;
driving behaviour;
speed;
charging history
to the manufacturer's cloud platform.
The manufacturer then sells an analytics service to an insurer.
The driver alleges:
inadequate information;
no valid legal basis;
excessive GPS collection;
unlawful sharing with the insurer;
inaccurate driving profile;
financial and non-material harm.
A court could analyse:
Personal data? → Yes/potentially
Controller? → Manufacturer and possibly another actor
Legal basis? → Article 6 analysis
Transparency? → Articles 12–14
Data minimisation? → Article 5
Privacy by design? → Article 25
Security? → Article 32
Compensation? → Article 82
Evidence? → Vehicle/cloud logs
This demonstrates how several areas of European civil and data law operate together.
36. Important Principles from the Case Law
The cases can be reduced to the following principles:
| Principle | Leading case |
|---|---|
| Indirectly identifiable information may be personal data | Breyer |
| Personal data has a broad functional meaning | Nowak |
| Data protection must be balanced with legitimate legal interests | Rīgas satiksme |
| Several actors may share controller responsibility | Wirtschaftsakademie |
| Data transmission through technology can create controller responsibility | Fashion ID |
| GDPR compensation requires legally relevant damage | Österreichische Post |
| Vehicle-registration information can form part of cross-border information systems | C-14/15 & C-116/15 |
37. Exam-Oriented Conclusion
Connected vehicle data privacy litigation in Europe is an emerging area where traditional civil law intersects with GDPR, consumer protection, cybersecurity, contract law and technological regulation.
The central legal issue is not simply whether a vehicle produces data. It is whether the data relates to an identifiable individual and how organisations collect, use, disclose, retain and secure it.
The most important principles are:
Personal data → lawful basis → transparency → minimisation → security → controller responsibility → data-subject rights → damage → compensation.
The Breyer, Nowak, Rīgas satiksme, Wirtschaftsakademie, Fashion ID and Österreichische Post judgments provide particularly useful CJEU foundations for analysing connected-vehicle privacy disputes, even though several arose outside the automotive sector. The EDPB's dedicated connected-vehicle guidance is especially important because it directly addresses the automotive ecosystem and recommends privacy-by-design measures, including local processing where feasible. (European Data Protection Board)
Quick Revision Formula
Connected Vehicle Privacy Litigation =
Vehicle Data + Identifiable Person + GDPR + Controller/Processor + Lawful Basis + Transparency + Security + Data Rights + Damage + Civil Remedy
Key cases:
Breyer — C-582/14
Nowak — C-434/16
Rīgas satiksme — C-13/16
Wirtschaftsakademie — C-210/16
Fashion ID — C-40/17
Österreichische Post — C-300/21
European Parliament and Council — Joined Cases C-14/15 and C-116/15

comments