News

THE Australian Electric Vehicle Association (AEVA) has called on the federal government to introduce dedicated legislation governing the collection, storage, and security of connected vehicle data, warning that Australia’s existing regulatory framework is failing to keep pace with increasingly software-defined vehicles.

The consumer advocacy group says Australia’s reliance on the Privacy Act 1988 and voluntary industry standards leaves motorists exposed to privacy, cybersecurity, and national security risks as connected vehicles become the norm.

The association argues the issue extends well beyond battery electric vehicles, encompassing any modern vehicle equipped with embedded telematics, connected services or an internal SIM capable of transmitting vehicle and user data.

With industry forecasts suggesting as many as 95 per cent of new vehicles sold in Australia could be internet-enabled by 2035, AEVA believes legislative reform is becoming increasingly urgent.

The organisation – which says it is the longest continuously running EV society in the world – said Australia is particularly exposed given the diversity of its new-vehicle market, with more than 60 brands represented locally and manufacturers headquartered across more than a dozen international jurisdictions.

Member of AEVA’s policy and advocacy working group, Johannes Paul Lehmann, told GoAutoNews Premium that the organisation was urging the government to mandate compliance with the United Nations’ regulations UNECE R155 and R156 for cybersecurity and software updates rather than relying on manufacturers to adopt the standards voluntarily.

Member of AEVA’s policy and advocacy working group, Johannes Paul Lehmann

It also wants the regulation to establish consistent rules. Rather than focusing on country of origin, AEVA says regulation should establish consistent rules that govern how connected vehicle secondary/commercial data harvesting (aside from essential diagnostic, safety, legal, and requested-service processing will still be required) is collected, processed and stored, irrespective of manufacturer.

Mr Lehmann said that research by the AEVA found data privacy was lacking in regulation in Australia.

He said the issue was increasingly brought to the attention of the association by consumers and that it was “a recurring thing where people sometimes are a bit more susceptible to misinformation”.

“Our research found that cybersecurity – with data privacy – was a bit underregulated at the moment in Australia,” he said.

“Connected vehicles are really a benefit, but we felt as a consumer association that they also require the necessary safeguards.

“Connected vehicles can collect and transmit far more than speed and battery state. Depending on the model and settings, they may process location history, camera and sensor data, voice commands, phone contacts, driving behaviour, infotainment use and remote-control functions.”

In a statement on the subject, Mr Lehmann said that in his personal view “Australia needs a practical, technology-neutral framework”.

This would cover:

  • minimum cybersecurity and software update requirements
  • transparency on what vehicle data is collected, where it goes and who can access it
  • privacy settings that normal drivers can actually understand
  • safeguards for sensitive locations, critical infrastructure and government use cases
  • incident reporting, vulnerability disclosure and lifecycle support
  • secure, interoperable data access where it benefits consumers, repairers and innovation

“This should not become a simplistic ‘which country built the car?’ debate,” he said in reference to the withdrawal of some cars in the US, the most publicly being the US department of commerce declining to authorise the sale of Chinese-made, Swedish-headquartered Polestar vehicles from model-year 2027 in the US market.

“Rather, it should be a standards, resilience and sovereignty debate.”

He said that the cars we drive to work, kindergarten drop-off and weekend sports are becoming part of the cyber-physical environment that Australia depends on every day.

“In my opinion, the question is not whether we want smart cars. The question is whether we want smart cars with dumb governance.”Mr Lehmann said AEVA separately advocates for robust hardware segregation/firewalls between externally connected systems and safety-critical controls (like braking), as well as clearly disclosed software lifecycle-support periods for consumers.

“If you talk about safety critical systems, such as your automated emergency brakes, we really advocate for them to be separated from any kind of connected data,” he said.

“This comes back to the UNEC R155/R156 legislation. Proper software update management is vital to really ensure that over the vehicle’s life cycle the customer gets maximum safety.”

In its recommendations, AEVA wants a requirement for sensitive information – including voice recordings, facial recognition data, cabin camera footage, and precise location history – to be processed within the vehicle wherever possible rather than routinely uploaded to cloud-based servers.

Where information must leave the vehicle, AEVA argues it should be stored within Australia under locally administered privacy protections.

The association also wants optional data collection disabled by default, requiring owners to actively opt in before manufacturers can collect personal information.

It is further calling for motorists to be given the ability to view and permanently erase personal data before selling a vehicle, while ensuring independent repairers have access to relevant vehicle information under Australia’s existing right-to-repair framework.

AEVA said it advocates for secure, authorised access to data necessary for diagnosis and repair without compromising core network firewalls.

Cybersecurity forms another key pillar of AEVA’s submission.

The UNECE R155/R156 regulations require manufacturers to implement comprehensive cybersecurity management systems, maintain secure software update processes, and better isolate critical vehicle control systems, such as braking and steering, from infotainment and connectivity functions.

AEVA national president James Pickering

AEVA national president James Pickering said stronger legislation would improve consumer confidence while supporting the continued growth of connected vehicle technologies.

“2026 has been an unprecedented year for electric vehicle uptake in Australia, but consumers nationwide continue to be let down by insufficient data privacy legislation,” he said.

“Instead of instigating fear and distrust in the connected vehicles we drive, policymakers have the power to make effective changes to protect drivers and consumer choice.”

Mr Pickering said the association’s recommendations deliberately avoided targeting manufacturers from individual countries.

“From Europe to the US, to China and the rest of Asia, we are lucky to welcome such an incredible range of electric cars to our shores,” he said.

“We are great believers in compliance over country of origin and will continue our discussions with the government to support consumer choice and protection, while also maintaining national security.”

The AEVA policy statement adds to a growing international debate surrounding ownership of vehicle-generated data as connected technologies, over-the-air (OTA) software updates, and advanced driver assistance systems become increasingly central to modern vehicle design.

While Europe, China, and the United Nations have progressively strengthened regulatory oversight in recent years, Australia has yet to introduce a dedicated legislative framework governing connected vehicle data, leaving responsibility largely to existing privacy legislation and voluntary industry codes.

The AEVA has presented a series of policy recommendations to Canberra, drawing on elements of Europe’s General Data Protection Regulation (GDPR) and China’s automotive data security framework in a bid to establish mandatory national standards for internet-connected vehicles, as summarised below:

  • Mandate local data processing for sensitive information, with Australian storage where cloud transmission is required.
  • Require data collection to default to ‘off’ with motorists opting in before manufacturers harvest personal information.
  • Give owners the right to view and permanently erase vehicle data before selling or transferring ownership.
  • Guarantee independent repairers access to vehicle data under Australia’s right-to-repair framework.
  • Make UNECE R155 and R156 cybersecurity standards mandatory, replacing today’s voluntary compliance.
  • Adopt technology-neutral legislation applying to all connected vehicles, regardless of brand or country of origin.

By Matt Brogan and Neil Dowling

Sovereign Insurance
Manheim
Manheim
Gumtree
MotorOne
VACC
Gumtree
Impel
AutoGrab
Indiqator
PitcherPartners
AdTorque Edge
PitcherPartners
Indiqator
VACC
AdTorque Edge
ConnectedVehicles
MotorOne
AutoGrab
Impel
Gumtree
Schmick