Most dealers first heard the phrase gdpr vs eu data act when a manufacturer portal, a workshop system, or a connected-car feature flagged a new consent screen or data-sharing clause. The two regulations get mentioned in the same breath, so it is easy to assume they cover the same ground. They do not. GDPR is about protecting personal data - information that identifies a human being. The EU Data Act is about who gets access to the data a connected product generates while it runs. A modern car produces both kinds at once, which is exactly why the two regimes overlap on your forecourt and why confusing them creates real compliance and commercial risk.
This article draws the boundary clearly: where GDPR ends, where the Data Act begins, and where they sit on top of each other for the same vehicle. It is written for dealer principals and compliance leads who need a working mental model rather than a legal treatise. The short version is that you can be fully GDPR-compliant and still be on the wrong side of the Data Act, and vice versa, because they answer two different questions about the same car.
Two regulations, two different questions
The cleanest way to keep these straight is to remember what each one is actually trying to fix.
GDPR (the General Data Protection Regulation, in force since 2018) exists to protect individuals. Its scope is personal data: any information relating to an identified or identifiable natural person. If you can tie a piece of data back to a human - a name, an email, a number plate linked to a registered keeper, a location history - GDPR rules apply. It tells you what lawful basis you need, how long you can keep data, what rights the person has, and what happens when something leaks.
The EU Data Act (which became applicable from September 2025) exists to unlock data from connected products and related services. Its scope is the data generated by the use of a product - the readings, logs, events and signals a connected device produces. Much of this is non-personal machine data: tyre pressure, battery state of health, fault codes, mileage, charging cycles. The Data Act is concerned with a different question entirely: not "is this person protected", but "who is allowed to get this data, and can they share it with someone else".
Why a connected car triggers both
A connected vehicle is the textbook case for overlap. Picture the data streaming off one car on your lot or in a customer's hands:
- Battery state of health, fault codes, mileage - machine data. On its own, not personal. Squarely Data Act territory.
- GPS location trail, driving behaviour tied to a logged-in profile, a paired phone's contacts - these identify or relate to a person. GDPR territory.
- A maintenance event log that records who was driving and where - both at once.
The vehicle does not separate these neatly. They flow through the same telematics unit and often the same export. That is why you cannot treat "vehicle data" as a single category with a single rulebook. We unpack the ownership side of this in more depth in who owns vehicle data in Europe.
The boundary, side by side
| Dimension | GDPR | EU Data Act |
|---|---|---|
| Core subject | Personal data (identifies a person) | Data generated by a connected product or related service |
| Primary goal | Protect individuals and their rights | Enable fair access to and sharing of data |
| Who it empowers | The data subject (the individual) | The user of the product (owner, lessee, fleet operator) |
| Typical vehicle example | Driver identity, location history, contacts | Battery health, fault codes, usage and sensor logs |
| Key right for your customer | Access, rectification, erasure, portability | Access to product data and right to share it with a third party |
| When it bites a dealer | Whenever you process customer personal data | When you request or receive product data on a user's behalf |
The watch-out hiding in this table: a single export from one vehicle can land in several rows at once. A battery-health report (Data Act) that includes a logged driver profile and a location stamp (GDPR) is one file governed by two regimes. Compliance is not "pick the right regulation" - it is "satisfy both where they overlap".
What changes for a dealership in practice
For a dealer principal or compliance lead, the practical shift is less about new paperwork and more about new access. The Data Act is designed to make it easier for the user of a vehicle to get the data it produces and to direct it to a service provider of their choice - which can be your dealership, your workshop, or a valuation and inventory tool you rely on.
That cuts two ways.
The opportunity. Historically, much connected-vehicle data sat behind a manufacturer's gate. The Data Act is intended to loosen that gate so the user can authorise sharing. For a dealer, richer access to genuine usage and condition data can mean better-grounded appraisals, more accurate reconditioning decisions, and fewer surprises at trade-in. The honest, source-backed approach to that data is the whole point of vehicle history checks in Europe.
The obligation. The moment that data identifies a person - and connected-vehicle data very often does - GDPR rides along. You still need a lawful basis to process it, a retention limit, and a clear answer if the customer asks what you hold and asks you to delete it. The Data Act does not switch GDPR off; it sits alongside it.
A simple test before you handle vehicle data
When a new data flow appears - a portal feed, a telematics export, a third-party integration - ask three questions in order:
- Is any of this data about an identifiable person? If yes, GDPR applies to that portion. Confirm your lawful basis and retention.
- Was this data generated by the use of a connected product? If yes, the Data Act governs who may access and share it. Confirm the user authorised the share.
- Does the same dataset answer yes to both? Then both regimes apply together - protect it under GDPR and respect the access rules under the Data Act.
This is deliberately boring, and that is the point. A repeatable test beats trying to remember which regulation a given field belongs to.
Where the confusion usually comes from
Three recurring mix-ups are worth naming, because they cause most of the wasted effort.
"The Data Act replaces GDPR for cars." It does not. They are complementary. GDPR is the protection layer for anything personal; the Data Act is the access layer for product-generated data. Neither overrides the other.
"If data is non-personal, I have no obligations." Non-personal machine data is outside GDPR, but the Data Act still governs who can access and share it, and under what terms. "Not personal" does not mean "no rules".
"Consent under GDPR is the same as authorisation under the Data Act." They are different mechanisms. GDPR consent (where consent is the lawful basis) is about lawful processing of personal data. Data Act authorisation is about a user directing product data to a recipient. You can need both for the same flow.
This is also why the cross-border picture matters: the same vehicle's data may move between countries with the same EU rules but different local practice. We cover that in cross-border vehicle data in Europe, and the wider regulatory context in the EU Data Act and the automotive industry.
Where VehIQ fits
VehIQ is being built as an EU-sovereign, API-first data layer for the automotive industry, starting with the dealer management system. The reason the gdpr vs eu data act boundary matters to that design is simple: a data platform for European dealers has to treat both regimes as first-class, not as an afterthought.
That shapes three deliberate choices. First, field-level lineage - every value carries where it came from, so a dealer can tell at a glance whether a field is personal data, product-generated data, or both, which is the exact question both regulations turn on. Second, valuations that show their sources and a confidence interval rather than a single black-box number, so the data behind an appraisal is traceable rather than opaque. Third, open formats the customer owns, so authorised data access translates into data the dealer actually controls. VehIQ is pre-seed and these are design commitments rather than deployed results, but the regulatory shift toward user-directed access is precisely the world this layer is meant to operate in - running alongside your existing systems rather than replacing them.