Every modern car is a sensor on wheels. It logs mileage, charging cycles, fault codes, tyre pressure, location, braking events and dozens of other signals, then streams much of it back to the manufacturer. For years that telematics stream flowed almost entirely one way, into the OEM's cloud, where independent garages, used-car buyers and software builders could not reach it. The EU Data Act is the first regulation to change that default, and connected car data access is now a legal right rather than a commercial favour the manufacturer may or may not grant.
This article walks through the in-vehicle data access regime the Data Act creates: what counts as connected car data, who can ask for it, how third parties such as repairers and app developers get a share, and where OEM gatekeeping is being narrowed. It is a starting point for dealers, independent repairers and developers who want to understand the new rules before deciding what to build or buy on top of them. It is not legal advice, and the practical detail will keep evolving as guidance and sector rules land.
What counts as connected car data
"Connected car data" is a loose phrase, and the Data Act is more precise than everyday usage. The regime centres on data generated by the use of a connected product and its related services. For a vehicle that includes telematics and event data such as:
- Odometer readings, trip logs and usage patterns.
- Battery state of health, charging cycles and energy consumption for EVs.
- Diagnostic trouble codes and component wear signals.
- Driving events the vehicle records, such as harsh braking or fault triggers.
- Location and movement data where the vehicle captures it.
What the Act is generally not designed to hand over is the manufacturer's heavily processed, inferred or enriched output, the proprietary models and analytics an OEM builds on top of the raw stream. The line between raw, readily available data and proprietary derived data is one of the most contested parts of the regime, and it is exactly where disputes are likely to concentrate.
Who can access the data: the user comes first
The pivotal concept in the Data Act is the user. The user is the person or business that owns, leases or rents the connected product, and they hold the primary access right. For a car, the user is typically the registered owner, the leasing customer or a long-term fleet operator, not the manufacturer and not the dealer who sold it.
The user has two core entitlements:
- Direct access. The user can obtain the data the vehicle generates, including in real time where the product is built to allow it, in many cases without paying the manufacturer for it.
- Sharing on request. The user can instruct the manufacturer or data holder to share that data with a third party the user chooses.
This matters because it shifts the centre of gravity. Under the old model, the OEM decided who saw the data. Under the Data Act, the user decides, and the data holder is obliged to facilitate that decision within the limits the Act sets.
Where the dealer sits
A dealer is not automatically the user. If you sell a car, the buyer becomes the user and inherits the access rights. If you operate a demo fleet or courtesy cars, your dealership may be the user for those vehicles. The practical takeaway for dealers is that access to a customer's connected car data normally runs through the customer's consent, not through your relationship with the OEM.
How third parties get access
Most of the commercial value in this regime sits with third parties: independent repairers, valuation and inventory tools, insurers, charging networks and app developers. They do not have a standalone right to in-vehicle data. They get it because a user asks the data holder to share it with them.
The mechanics matter:
- The user authorises sharing with a named third party.
- The data holder must make the data available to that third party, on fair, reasonable and non-discriminatory terms.
- The third party may only use the data for the purposes agreed with the user, and faces restrictions on onward sharing and on building directly competing products from it.
| Party | What they can access | How they get it | Key limit |
|---|---|---|---|
| User (owner, lessee, fleet) | Data the vehicle generates in use | Direct request to the data holder | Personal data and security rules still apply |
| Independent repairer | The user's vehicle data relevant to the job | User authorises sharing | Use limited to the agreed purpose |
| App or tool developer | Data for users who opt in | User consent, FRAND terms from the holder | No onward resale or competing-product abuse |
| OEM (data holder) | The full stream by default | Built-in technical access | Cannot unfairly refuse or block lawful sharing |
OEM gatekeeping: narrowed, not removed
It would be a mistake to read the Data Act as the end of OEM control. The manufacturer still designs the vehicle, runs the telematics back end and remains the technical gatekeeper of the stream. What the Act does is constrain how that gatekeeping can be exercised.
Three constraints stand out:
- No unfair refusal. A data holder cannot simply decline to share data the user is entitled to, nor make access deliberately impractical.
- FRAND terms for third parties. Where a third party receives data, the terms must be fair, reasonable and non-discriminatory, which limits the ability to price independents out.
- Anti-lock-in expectations. The broader thrust of EU data policy is to reduce dependence on a single provider and keep markets contestable.
There are genuine carve-outs. Manufacturers can invoke safety, security and trade-secret protections, and the boundary of those exceptions is where most of the early friction is likely to land. A security justification can be legitimate, or it can be a convenient way to keep a competitor out. Expect that line to be tested.
For the strategic picture of why control of this layer matters competitively, see EU data sovereignty as a competitive advantage, and for the wider regulatory context, the EU Data Act and the automotive industry.
What it means in practice for dealers, repairers and developers
The regime is still settling, so the sensible posture is to prepare rather than to assume everything works smoothly tomorrow. A few concrete implications:
- Independent repairers gain a clearer route to the diagnostic and service data they need, provided the customer authorises it. That weakens the historic tie between servicing and the franchised network, though access quality is likely to vary by manufacturer.
- Dealers should think about consent flows. If you want to use a customer's connected car data, for valuation, service reminders or trade-in appraisal, build the permission step into the customer relationship rather than assuming OEM access.
- Developers get a legal hook to build on vehicle data without negotiating bespoke deals with every OEM. But you are building on FRAND terms you do not fully control yet, so design for variability in availability and format.
Where VehIQ fits
VehIQ does not sit between you and the manufacturer's data stream, and it makes no claim to unlock OEM telematics. What it is designed to do is make whatever vehicle data you legitimately hold genuinely usable.
VehIQ is being built as an API-first, EU-sovereign data layer for the automotive industry, starting with the dealer management system. The design principles map directly onto the problems this regime creates: canonical vehicle data with field-level lineage, so every value can be traced to its source; AI valuations that show their sources and a confidence interval rather than a single black-box figure; and inventory intelligence such as days-to-sell and margin-at-risk built on data the customer owns in open formats. As connected car data access widens under the Data Act, the constraint shifts from getting the data to trusting it. VehIQ is pre-seed and still being built, but that is the gap it is aimed at: turning new data rights into decisions you can stand behind.