Connected Car Data Ownership .
1. Introduction
A connected car is no longer merely a mechanical vehicle. A modern vehicle can continuously collect, process, store and transmit information through GPS, cameras, sensors, infotainment systems, telematics units, mobile applications and cloud platforms.
Examples of connected-car data include:
- GPS/location data;
- speed and acceleration;
- braking and steering patterns;
- vehicle diagnostic information;
- battery condition;
- fuel consumption;
- tyre pressure;
- driving behaviour;
- trip history;
- infotainment activity;
- voice commands;
- photographs/video from cameras;
- emergency/SOS information;
- vehicle-identification information;
- information about passengers;
- charging history for electric vehicles;
- maintenance and repair records.
This creates a difficult legal question:
Who owns the data generated by a connected car—the vehicle owner, driver, manufacturer, software provider, insurer, dealer, or data-processing company?
The most important point is that "data ownership" and "data protection" are not the same thing.
In India, there is presently no simple statutory rule saying:
"All data generated by a car belongs to the registered owner of the car."
Instead, the legal position has to be constructed from privacy law, data-protection law, contract law, intellectual-property law, competition law and constitutional principles.
The issue becomes especially important because India's Digital Personal Data Protection Act, 2023 regulates personal data processing, while the EU has moved further toward giving users access to data generated by connected products, including cars. The EU Data Act has applied since 12 September 2025 and expressly covers connected products such as cars.
2. First Principle: The Car Is Owned, But That Does Not Necessarily Mean the Data Is "Owned"
Suppose A purchases a connected car.
A owns the physical vehicle.
But the vehicle may generate data through:
Car → sensors → telematics unit → manufacturer's server → cloud → apps → third-party services.
There may therefore be several different legal interests in the same dataset.
For example:
Data
GPS coordinates of the car at 5:00 PM.
Possible interests:
- Driver: privacy interest;
- Vehicle owner: contractual/user interest;
- Manufacturer: legitimate business interest in vehicle performance;
- Cloud provider: technical processing role;
- Insurer: possible contractual interest;
- Government: potentially lawful regulatory/investigative access;
- Third party: only where a lawful basis exists.
Therefore, asking simply "Who owns the data?" may be legally misleading.
The better questions are:
- Who generated the data?
- Whose personal information does it reveal?
- Who controls the data?
- Who is legally permitted to process it?
- Who has the right to access it?
- Who can commercially exploit it?
- Who can transfer it to another party?
- Who owns intellectual-property rights in derived databases or software?
- Can the user demand portability or deletion?
3. Three Categories of Connected-Car Data
A very useful way to understand the subject is to divide connected-car data into three categories.
A. Personal Data
Suppose the car records:
"Vehicle travelled from the owner's home at 8:00 AM to the owner's office at 9:00 AM."
This can reveal an individual's identity and behaviour.
It may therefore constitute personal data.
Under India's DPDP Act, "personal data" essentially concerns data about an individual who is identifiable by or in relation to that data.
Examples:
- driver's location;
- phone number connected to vehicle;
- account information;
- driver's preferences;
- identifiable driving profile;
- voice recording linked to an individual.
B. Non-Personal/Technical Data
Examples:
- engine temperature;
- generic component failure codes;
- aggregated traffic patterns;
- anonymised vehicle-performance statistics.
Not every piece of vehicle data identifies an individual.
Therefore, it may fall outside personal-data protection rules, depending on the circumstances.
C. Derived or Inferred Data
This is particularly important.
Suppose a manufacturer collects:
- acceleration;
- braking;
- GPS;
- steering;
- trip duration.
It then uses an algorithm to conclude:
"This driver is an aggressive driver."
That conclusion is derived/inferred information.
The legal treatment can differ from the raw sensor data.
The EU Data Act, for example, expressly distinguishes raw/product data from certain inferred or derived data. Its connected-product framework is primarily concerned with data generated through use of the product and related services.
4. Indian Constitutional Position: Right to Privacy
The most important Indian constitutional case is:
Justice K.S. Puttaswamy (Retd.) v. Union of India (2017)
Facts
The Supreme Court was asked to determine whether the Constitution protects a fundamental right to privacy.
A nine-judge Constitution Bench unanimously recognised privacy as a constitutionally protected right.
Importance for connected cars
The judgment is extremely relevant because a connected car can become a device for continuous surveillance.
Consider what a car's location history can reveal:
- where a person lives;
- where they work;
- whom they visit;
- religious or political activities;
- medical appointments;
- relationships;
- daily routines.
Thus, connected-car data can reveal much more than merely information about a machine.
It can reveal the life of the person using the machine.
The Supreme Court's privacy jurisprudence recognises privacy as connected with dignity, liberty and autonomy, and later Supreme Court decisions have expressly discussed informational privacy as part of the Puttaswamy framework.
Principle
The important principle is:
A person does not lose privacy merely because information is generated through a technological device.
This is highly relevant to connected cars.
5. Informational Privacy
Puttaswamy is particularly important because privacy is not restricted to physical privacy.
It also encompasses informational privacy.
Informational privacy concerns a person's ability to exercise control over information about themselves.
A connected vehicle therefore creates a serious privacy issue.
Example
Imagine a vehicle records:
Monday — Home → hospital
Tuesday — Home → lawyer's office
Wednesday — Home → political meeting
The manufacturer might argue:
"The data belongs to our vehicle ecosystem."
But the constitutional privacy question is:
What does this information reveal about the individual?
That is why "ownership" alone cannot determine the legal position.
6. District Registrar & Collector v. Canara Bank (2005)
This case is important for understanding privacy in relation to documents and information.
The Supreme Court considered governmental access to private records.
The Court recognised that privacy interests can extend to information and documents held in private custody.
Later Supreme Court judgments have relied upon Canara Bank as an important part of the development of Indian privacy jurisprudence.
Connected-car relevance
Suppose a manufacturer or service provider possesses:
- GPS history;
- diagnostic records;
- driver's account information;
- trip history.
The fact that the information is physically stored on someone else's server does not automatically eliminate the individual's privacy interest.
This is an important distinction:
Possession of data ≠ unlimited legal authority over the data.
7. R. Rajagopal v. State of Tamil Nadu (1994)
This is popularly known as the Auto Shankar case.
The Supreme Court recognised important principles concerning privacy and publication of private information.
Relevance
Connected-car data can expose extremely personal information.
For example:
- location history;
- visits to particular places;
- passenger information;
- communications;
- private routines.
A company possessing such information cannot simply assume that technological access means unlimited freedom to disclose it.
The privacy principle therefore provides a constitutional background against which data-processing practices must be examined.
8. People's Union for Civil Liberties v. Union of India (1997)
This case concerned telephone tapping.
The Supreme Court established safeguards concerning interception of communications.
Why is this relevant to connected cars?
Modern connected cars may contain:
- microphones;
- voice assistants;
- communication systems;
- mobile connectivity.
A vehicle may therefore become a communication device.
If communications or voice data are collected, the legal analysis cannot simply be:
"The microphone is inside a car."
The real question becomes:
What legal authority exists for collecting, retaining and using the communication?
This illustrates how technological evolution can transform an ordinary physical object into a source of constitutionally significant information.
9. K.S. Puttaswamy (Aadhaar) v. Union of India (2018)
The Aadhaar judgment is particularly useful for understanding the relationship between:
- identity;
- authentication;
- personal information;
- state access;
- proportionality.
The Court examined whether collection and use of personal information satisfied constitutional requirements.
Connected-car analogy
Imagine the State asks automobile companies to continuously provide:
- GPS location;
- driver identity;
- trip history;
- biometric information;
- vehicle-camera data.
The mere existence of a public purpose would not automatically settle the constitutional question.
The relevant issues would include:
- Is there a law?
- Is there a legitimate objective?
- Is the collection necessary?
- Is it proportionate?
- Are safeguards available?
- Is excessive data being collected?
That is highly relevant to future connected-car surveillance.
10. Digital Personal Data Protection Act, 2023
India has now enacted the Digital Personal Data Protection Act, 2023.
The Act is designed to regulate processing of digital personal data while recognising both the individual's interest in protecting personal data and the need for lawful processing.
The important conceptual distinction is that the Act does not create a traditional property-ownership model for personal data.
Instead, it creates relationships between:
- Data Principal — the individual to whom personal data relates;
- Data Fiduciary — the entity determining the purpose and means of processing;
- Data Processor — an entity processing personal data on behalf of a Data Fiduciary.
Connected-car example
Suppose:
Driver → uses connected vehicle → manufacturer collects location data.
The driver may be the Data Principal.
The manufacturer may be the Data Fiduciary, depending on who determines the purpose and means of processing.
A cloud company processing the manufacturer's data could be a Data Processor.
This framework is much more sophisticated than simply saying:
"The manufacturer owns the data."
11. Consent Is Not the Same as Ownership
This is a very important examination point.
Suppose a vehicle owner agrees to:
"Allow the manufacturer to collect vehicle data."
That does not necessarily mean:
"I have transferred ownership of all my personal information permanently to the manufacturer."
Consent concerns lawful processing.
Ownership is a different legal concept.
Therefore:
Consent ≠ ownership transfer.
A contractual clause may give a company extensive rights to process data, but that does not automatically erase constitutional privacy interests.
12. Contractual Ownership
Connected-car companies commonly operate through:
- purchase agreements;
- subscription agreements;
- software licences;
- privacy policies;
- connected-services terms;
- mobile-app terms.
A contract may provide that the company can:
- collect vehicle information;
- analyse performance;
- provide software updates;
- provide navigation;
- detect faults;
- improve products;
- provide personalised services.
But the legal validity of such contractual provisions depends upon applicable law.
A contract cannot automatically authorise something that is prohibited by mandatory law.
13. Intellectual Property and Connected-Car Data
Another important distinction:
Raw data
A GPS coordinate or engine temperature is not automatically equivalent to copyrighted software.
Database
A company may potentially have intellectual-property interests in:
- database structure;
- software;
- algorithms;
- compilation;
- proprietary analytics.
Software
The manufacturer may own copyright or other rights in:
- ECU software;
- telematics software;
- cloud platform;
- analytics algorithms.
Therefore:
The driver may have privacy/access rights over information without owning the manufacturer's software or algorithm.
This prevents an overly simplistic "data belongs to the car owner" argument.
14. Who Owns the Vehicle's Diagnostic Data?
Consider this example:
A car develops a transmission problem.
The ECU generates:
Error Code X1234.
Who owns it?
There are several possibilities.
Manufacturer's argument
The data is generated by proprietary equipment and transmitted into its system.
Consumer's argument
The information concerns my vehicle and I paid for the vehicle.
Repairer's argument
I need the information to diagnose and repair the vehicle.
Legal reality
The strongest modern legal approach is increasingly access and control rather than absolute ownership.
This is particularly clear under the EU Data Act.
15. EU Data Act — Important Comparative Development
The European Union has gone considerably further than traditional ownership concepts.
The EU Data Act applies to connected products, including connected cars, and gives users rights concerning data generated through their use of connected products.
The EU framework is significant because it recognises that:
The person who uses a connected product should have meaningful access to data generated through that use.
This is not exactly the same as declaring:
"The consumer owns all car data."
Instead, it creates rights of access, use and sharing.
16. Why the EU Approach Is Important
Imagine:
You purchase a connected vehicle from Manufacturer A.
After two years, you want to take it to Independent Repairer B.
Manufacturer A says:
"Only our authorised dealership can access the vehicle data."
The EU Data Act moves toward preventing this kind of exclusive control by giving users access to relevant data and allowing them, subject to the statutory framework, to share it with third parties.
The European Commission specifically explains that users of connected products such as cars can access data generated through their use and can share it with third parties of their choice.
The Commission also issued specific guidance for the automotive sector covering OEMs, suppliers, aftermarket providers and insurers.
17. Important EU Distinction: Raw Data vs Derived Data
This distinction is extremely important.
Suppose a car produces:
- speed;
- acceleration;
- braking;
- GPS.
These are raw/product-generated data.
But the manufacturer uses AI and says:
"This driver has a 92% probability of being a high-risk driver."
That is an inference.
The EU Data Act's connected-product access framework focuses primarily on product data and related metadata, and excludes certain inferred or derived data.
This demonstrates why the question:
"Who owns the data?"
must be broken down into:
Which data?
18. Competition Law Dimension
Connected-car data also creates a competition-law problem.
Suppose one manufacturer controls:
- 90% of diagnostic information;
- all repair APIs;
- all telematics;
- all software updates.
Independent repair companies may be unable to compete.
This can produce:
Data monopoly → restricted access → reduced competition → higher repair costs.
Therefore, connected-car data is increasingly being considered not merely a privacy issue but also a competition and market-access issue.
Recent European regulatory developments show the conflict between manufacturers, independent repairers, insurers and other service providers over access to vehicle data.
19. Right to Repair and Connected-Car Data
Suppose your car's brake system generates diagnostic data.
The manufacturer has access.
The independent mechanic does not.
The mechanic says:
"Give me the diagnostic information so I can repair the car."
The manufacturer says:
"That information is proprietary."
This creates a conflict between:
Manufacturer's interests
- cybersecurity;
- trade secrets;
- intellectual property;
- safety;
- proprietary technology.
Consumer's interests
- repair choice;
- lower costs;
- portability;
- competition.
Repairer's interests
- access to technical information;
- ability to compete.
The EU Data Act specifically aims to make connected-product data more accessible for aftermarket services.
20. Connected Car Data and Insurance
Insurance is another major issue.
Imagine an insurer receives:
- speed;
- braking frequency;
- acceleration;
- night driving;
- mileage;
- location;
- accident data.
It develops a driver score:
Risk Score = 87/100
The insurer may then increase the premium.
Legal questions
- Did the driver consent?
- Was the information lawfully collected?
- Was the driver informed?
- Can the driver access the data?
- Can the driver challenge an incorrect inference?
- Is automated profiling involved?
- Was excessive data collected?
- Was the data shared with third parties?
Therefore, ownership is only one part of the problem.
21. Connected Car Data and Law Enforcement
Suppose police want to know:
"Where was this vehicle between 10 PM and 2 AM?"
The manufacturer has GPS records.
Can the manufacturer simply provide them?
The answer depends upon the legal authority and applicable safeguards.
The constitutional privacy jurisprudence discussed above becomes important.
The State cannot simply say:
"The information is held by a private company, therefore privacy is irrelevant."
Nor can the individual automatically say:
"I own the car, therefore government can never access its data."
The correct analysis requires consideration of:
- statutory authority;
- legitimate governmental purpose;
- necessity;
- proportionality;
- procedural safeguards.
22. Connected Car Data and Passengers
A particularly difficult problem is that the car owner is not necessarily the only person whose data is collected.
Suppose:
A owns the car.
B is the passenger.
The vehicle's camera captures B.
The infotainment system records B's voice.
GPS records the journey involving B.
Who has the privacy interest?
B, even though B does not own the car.
This proves why:
Vehicle ownership cannot be equated with ownership of every piece of data generated inside the vehicle.
The data may relate to several individuals simultaneously.
23. Children's Data
Suppose a connected vehicle records information about a child travelling in the car.
The child does not own the vehicle.
Yet the data can still be personal data.
Therefore, connected-car privacy cannot be based exclusively on the property rights of the registered vehicle owner.
Data protection follows the person to whom the information relates, not merely the person who purchased the machine.
24. Case: Justice K.S. Puttaswamy — Key Principle for Connected Cars
Let's apply the case directly.
Hypothetical
A manufacturer collects every location of your car for five years.
You never actively use the location feature.
The company argues:
"You bought the vehicle subject to our software terms."
Under the constitutional privacy framework, the question would not end there.
The analysis would consider:
- privacy;
- autonomy;
- purpose;
- proportionality;
- legal basis;
- reasonable expectations;
- safeguards.
The Puttaswamy decision therefore provides the constitutional foundation for challenging excessive connected-car surveillance.
25. Case: Canara Bank — Control by the Data Holder Is Not Everything
Suppose the manufacturer's server contains your vehicle records.
The manufacturer has physical/technical custody.
But Canara Bank's privacy reasoning supports an important principle:
Private custody of information does not eliminate privacy considerations.
Thus:
Data possession ≠ unrestricted legal access.
26. Case: PUCL — Communication Data Requires Safeguards
Suppose a vehicle has an always-on microphone.
The manufacturer records conversations to "improve the voice assistant."
The question becomes significantly more serious if conversations are retained indefinitely or disclosed.
The PUCL telephone-tapping case illustrates the constitutional importance of safeguards when communications are intercepted.
Thus:
Connected vehicle + microphone + cloud recording = significant privacy implications.
27. Case: Aadhaar — Proportionality and Data Collection
The Aadhaar litigation demonstrates why the State's legitimate objective does not automatically justify unlimited data collection.
Apply the principle to connected vehicles:
Suppose the government wants real-time location information from every connected vehicle to combat crime.
The government would need to justify:
- legal authority;
- purpose;
- necessity;
- proportionality;
- safeguards;
- retention;
- access controls.
A broad demand for continuous location data would raise much greater privacy concerns than a narrowly targeted and legally authorised request.
28. Case: Karmanya Singh Sareen v. Union of India
The litigation concerning WhatsApp privacy is also relevant conceptually.
The Supreme Court proceedings raised concerns about:
- privacy;
- data sharing;
- private companies;
- user information;
- the need for a data-protection framework.
The Supreme Court's records note that the Puttaswamy judgment had recognised the need for a legal framework concerning data protection.
Connected-car relevance
The same issue appears in automobile technology:
Consumer → manufacturer → cloud → analytics provider → insurer/advertiser/other third party.
The more actors that receive the information, the greater the need for transparency and lawful processing.
29. Case: Anuradha Bhasin v. Union of India
The Supreme Court considered restrictions on internet access and emphasised principles of proportionality and constitutional scrutiny of restrictions.
Although it was not a connected-car ownership case, its proportionality reasoning is useful when considering government restrictions or surveillance involving digital technologies.
The Supreme Court's records identify the decision as 2020 INSC 31.
Connected-car application
If government demands access to vehicle-generated digital information, the question should not simply be:
"Is there a security purpose?"
It should also be:
"Is the measure proportionate to that purpose?"
30. Case: Shreya Singhal v. Union of India (2015)
Again, this was not specifically a connected-car case.
But it is an important digital-rights decision.
The Supreme Court struck down Section 66A of the Information Technology Act.
Relevance
The broader lesson is that technological regulation remains subject to constitutional protections.
A connected-car system cannot become a legal black box simply because it uses sophisticated technology.
31. Is Connected-Car Data Property?
This is probably the most important conceptual question.
Traditional property model
Property generally involves concepts such as:
- possession;
- transfer;
- exclusion;
- ownership;
- alienability.
Data behaves differently.
The same data can simultaneously exist in:
- the vehicle;
- manufacturer's server;
- cloud backup;
- insurer's system;
- repairer's system.
If A "owns" a piece of data in the traditional physical sense, B cannot simultaneously own the same physical object.
But digital information can be duplicated infinitely.
Therefore, modern data law increasingly uses concepts such as:
- access;
- control;
- processing;
- consent;
- portability;
- confidentiality;
- licensing;
- contractual rights.
rather than simply:
"Who owns the data?"
32. The Better Legal Model: A Bundle of Rights
For connected cars, think of data as a bundle of rights.
Driver/User
May have:
- privacy rights;
- access rights;
- transparency rights;
- certain control over processing;
- rights under applicable data-protection law.
Vehicle manufacturer
May have:
- contractual rights;
- software rights;
- database interests;
- trade-secret interests;
- rights to process data for legitimate purposes;
- technical control over systems.
Data processor/cloud company
May have:
- processing responsibilities;
- security obligations;
- contractual duties.
Repairer
May have:
- lawful access rights under applicable law;
- rights necessary for repair/service.
Insurer
May have:
- contractual/statutory rights to relevant information.
Thus:
No single party necessarily has absolute ownership of the entire connected-car data ecosystem.
33. Important Distinction: Raw Data, Personal Data and Proprietary Technology
Consider a connected vehicle's GPS system.
GPS coordinate
May be personal data if linked to an identifiable person.
GPS software
May be proprietary software protected by intellectual property.
Aggregated traffic dataset
May be commercially valuable and potentially non-personal if properly anonymised.
Algorithm predicting congestion
May be proprietary intellectual property/trade secret.
Therefore, saying:
"I own the car, so I own everything generated by the car"
is legally too broad.
34. The Manufacturer's Strongest Argument
The manufacturer can argue:
"We designed the sensors, software and telematics infrastructure. We invest heavily in collecting, processing and securing this information. Some data is necessary to provide the service, while algorithms and databases are proprietary."
This argument becomes stronger where the dispute concerns:
- software;
- algorithms;
- trade secrets;
- cybersecurity;
- derived analytics.
35. The Consumer's Strongest Argument
The consumer can argue:
"I purchased the vehicle. The data describes my vehicle and my behaviour. Location information reveals my private life. I should not be prevented from accessing information generated by my own use of the vehicle."
This argument is particularly strong for personal data and increasingly strong, comparatively, for access to raw connected-product data under the EU Data Act.
36. The Right-to-Access Approach Is Better Than Absolute Ownership
Suppose the user asks:
"Do I own my vehicle's data?"
A sophisticated legal answer is:
Not necessarily in the traditional property-law sense.
But the user may have:
- privacy rights;
- statutory data-protection rights;
- contractual rights;
- access rights;
- potentially portability/sharing rights under applicable regimes.
This is more accurate than saying either:
"The manufacturer owns everything."
or
"The car owner owns everything."
37. Current Indian Position vs EU Position
| Issue | India | European Union |
|---|---|---|
| Constitutional privacy | Strongly recognised | Strong privacy/data protection framework |
| Personal data | DPDP Act 2023 | GDPR + Data Act |
| General ownership of data | No simple blanket ownership rule | No blanket ownership model |
| Connected-product access | Developing | Explicitly addressed by Data Act |
| Connected-car data | Mainly privacy/data-protection/contract issues | Specific Data Act framework |
| Raw vehicle data access | No equivalent comprehensive horizontal right like EU Data Act | User access rights |
| Independent repair | Legal framework developing | Stronger data-access framework |
| Manufacturer trade secrets | Protected subject to law | Protected, but not absolute |
| Judicial privacy protection | Article 21 | Charter/GDPR framework |
The EU Data Act specifically describes connected cars as connected products and creates access/use/sharing rights around data generated through use.
38. Important Practical Hypothetical
Suppose X buys a connected electric vehicle.
The car records:
- GPS;
- battery health;
- speed;
- acceleration;
- charging location;
- voice commands.
The manufacturer stores everything on its cloud.
Question 1: Does X own the GPS data?
Not necessarily in the traditional property sense.
But X may have privacy/data-protection rights because the data may relate to X.
Question 2: Can the manufacturer process it?
Potentially, if there is an applicable lawful basis and the processing complies with applicable law.
Question 3: Can the manufacturer sell it to an insurer?
Not automatically.
The legal basis, purpose, disclosures and applicable data-protection requirements must be examined.
Question 4: Can X demand access?
The answer depends upon the applicable legal regime. Under the EU Data Act, users of connected products have specific access rights concerning relevant product data.
Question 5: Can X demand the manufacturer's algorithm?
Not necessarily.
The raw data and the manufacturer's proprietary software/algorithm are legally distinct.
39. Ten Major Case Laws to Remember
For an examination answer, these cases give you a strong legal foundation:
1. R. Rajagopal v. State of Tamil Nadu (1994)
Privacy and publication of private information.
2. People's Union for Civil Liberties v. Union of India (1997)
Privacy safeguards concerning interception of communications.
3. District Registrar & Collector v. Canara Bank (2005)
Privacy interests in private documents and information.
4. Justice K.S. Puttaswamy v. Union of India (2017)
Privacy is a fundamental right; dignity, autonomy and informational privacy.
5. Puttaswamy (Aadhaar) v. Union of India (2018)
Privacy, data collection, proportionality and informational autonomy.
6. Karmanya Singh Sareen v. Union of India
Important litigation concerning digital privacy and data sharing.
7. Shreya Singhal v. Union of India (2015)
Constitutional limits on digital regulation.
8. Anuradha Bhasin v. Union of India (2020)
Digital rights, proportionality and governmental restrictions.
9. I.R. Coelho v. State of Tamil Nadu (2007)
Not a data case, but important for understanding that legislative action remains subject to constitutional limitations.
10. Supreme Court's Electoral Bonds judgment (2024)
Important modern authority concerning informational privacy, particularly the relationship between privacy and information. The Court expressly described informational privacy as part of the constitutional privacy framework.
40. The Most Important Legal Principle
The most accurate statement is:
A connected car does not produce a single category of "owned data." Instead, different legal rights may attach to different categories of information.
For example:
Personal/location data → privacy + data-protection rights
Vehicle diagnostic data → access/contract/service rights
Manufacturer's software → intellectual-property rights
Algorithmic model → potentially trade secret/IP
Aggregated non-personal data → potentially commercial/data-economy rights
Passenger information → privacy rights of passenger
Government-access data → constitutional and statutory safeguards
This is why connected-car data law is fundamentally a multi-layered legal problem.
41. Conclusion
Connected-car data ownership is evolving from an old property-based concept toward a rights-and-access model.
In India, the strongest foundation is currently:
Article 21 → Right to Privacy → Informational Privacy → DPDP Act → Contract/IP/Competition principles.
The Supreme Court's privacy jurisprudence, particularly Puttaswamy, means that information revealing an individual's movements, behaviour and personal life cannot simply be treated as an ordinary commercial commodity.
At the same time, the manufacturer does not automatically lose all rights merely because a consumer owns the vehicle. Software, algorithms, databases, trade secrets and proprietary technologies can remain protected.
The emerging legal solution is therefore:
The consumer may not necessarily "own" every byte of connected-car data, but the manufacturer cannot necessarily treat every byte as its unrestricted property either.
The EU Data Act represents an important development because it expressly gives users of connected products, including cars, rights to access and share relevant data generated through their use, while preserving other legal interests such as intellectual property and trade secrets.
For India, the likely future question will therefore shift from:
"Who owns connected-car data?"
to the more legally precise question:
"Who has the right to access, process, use, share, commercialise, retain and control each category of connected-car data, and subject to what safeguards?"
That is the central legal issue in connected-car data governance.

comments