A modern car is a data factory. It records how it is driven, how its battery behaves, when its parts wear, where it goes and how it performs. For years, almost all of that data flowed to one place - the manufacturer - and stopped there. If a dealer, an independent workshop or the driver wanted access, they asked, and often the answer was no, or "through our system, on our terms."
The EU Data Act changes the default. It is one of the most consequential pieces of regulation the European automotive industry has faced in years, and yet it is widely misunderstood as a privacy law or a generic data-governance rulebook. It is neither. At its core, the Data Act is about who gets to use the data that connected products generate. For an industry where the product is increasingly a computer on wheels, that question is foundational.
This is a plain-language guide to what the Data Act means for vehicle data, written for the people who will actually have to live with it: dealers, workshop owners, and the compliance leads trying to translate a regulation into a decision.
The one idea behind the Data Act
Strip away the legal language and the Data Act rests on a simple principle: the people who generate data through using a connected product should be able to access it and to share it with others they choose.
For a car, the "user" is the person or business that owns or leases and operates the vehicle. The "data holder" is whoever controls the data the vehicle produces, typically the manufacturer. The Data Act establishes that the user has rights over that data - to access it, and to direct that it be shared with a third party, such as an independent workshop or a service provider.
That is the shift. Data that was effectively private to the manufacturer becomes data the user can reach and redirect. It moves control toward the edge - toward owners, drivers and the businesses serving them - and away from whoever happened to be holding the pipe.
What counts as vehicle data here
It helps to be concrete about the kind of data in play, because "vehicle data" is a broad phrase.
The Data Act is concerned primarily with data generated by the use of the product. For a car, that includes things like:
- Operational and diagnostic data: fault codes, component wear indicators, service needs.
- Battery and powertrain data: state of health, charging behaviour, efficiency.
- Usage data: mileage, driving patterns, how systems are actually used.
It is worth being clear about the boundaries. The Data Act is not a privacy regulation, and it does not override data-protection law. Where vehicle data is personal data - which much usage and location data is - the existing rules on consent and lawful processing still apply on top. The Data Act answers a different question: assuming the data can lawfully be used, who is allowed to get at it and share it. The two regimes sit side by side, and compliance means satisfying both.
What changes in practice
For most people in the trade, the regulation matters not as legal theory but as a set of practical shifts.
Independent access becomes a right, not a favour
The most direct effect is on the aftermarket. Today, independent workshops and service providers often depend on the manufacturer's goodwill or proprietary tools to get the diagnostic and operational data they need. The Data Act reframes that access as something the user can grant, by directing their data to the provider of their choice. A workshop that is not part of a manufacturer's authorised network can, in principle, get the data it needs to do the job - because the customer has the right to send it there.
This is a meaningful change to competitive dynamics. Servicing, repair, parts, valuation, insurance and fleet management all run on vehicle data. When access stops being controlled by a single gatekeeper, the field opens to anyone who can do something useful with the data.
Data portability becomes an expectation
The Act pushes toward data being available in usable, interoperable forms, and toward switching between service providers being practical rather than punishing. For a dealer or fleet operator, that means the data a vehicle produces becomes less locked to one vendor's ecosystem and more like an asset you can move and reuse. Lock-in built on "we hold your data" gets weaker.
Closed ecosystems lose their grip
For years, the strategic logic for some manufacturers was to make their data and their tools a closed loop: to use the car's data flow as a way to keep servicing, parts and software revenue inside the network. The Data Act directly challenges that logic. It does not abolish manufacturer ecosystems, but it removes the ability to keep others out simply by controlling the data. The advantage shifts from owning the pipe to being genuinely better at the service.
Why this favours open, interoperable players
Here is the part the trade should pay attention to, because it is strategic rather than procedural.
Regulation rarely changes who wins on its own. But it changes which strategies are viable. When data is locked, the closed ecosystem is the dominant play, because controlling the data controls the customer. When the user gains the right to access and redirect their data, that play stops working, and a different one becomes viable: open systems that interoperate, that can ingest data from many vehicles and many sources, and that compete on what they do with it rather than on whether they can keep rivals out.
The Data Act tilts the ground toward players who are built to be open - to take vehicle data in standard forms, combine it, add value and hand it onward. It tilts away from those whose advantage rested on being the only door. For dealers, this is broadly good news: more competition among the providers serving you, less dependence on a single manufacturer's system, and more ability to choose tools on merit.
It also raises a real obligation. If your business holds data others have a right to - and many in the chain do - you need to be able to provide it in a usable form, with a record of what was shared and on what basis. Compliance is not only about claiming your access rights; it is about being able to honour others'.
A practical checklist for dealers and compliance leads
You do not need to become a lawyer, but a few questions are worth asking now.
- Know what data your vehicles and systems generate, and where it sits. You cannot manage access rights to data you have not mapped.
- Understand which data you hold versus which you depend on. Your obligations differ depending on whether you are the data holder or the user.
- Check your contracts. Existing agreements with manufacturers and software vendors may contain terms that the Data Act now constrains, particularly around data access and switching.
- Mind the overlap with data protection. Where vehicle data is personal data, the privacy rules still apply. Build for both regimes, not one.
- Favour interoperability when choosing tools. Systems built around open, standard data formats will age far better under this regulation than closed ones.
- Keep records of data sharing. Being able to show what was shared, with whom, and on what legal basis will matter.
A closing thought
The Data Act is best read not as a compliance chore but as a signal of direction. Europe has decided that the data a connected product generates should not belong, by default, to whoever controls the pipe. For automotive, that decision quietly redraws the competitive map in favour of openness and interoperability.
This is the world VehIQ is built for: canonical vehicle data with clear lineage, open formats, and access designed to be shared rather than hoarded. We did not build it to comply with the Data Act. We built it because we think the Act describes where the industry was always going to end up - and being ready for that is simply good engineering.