Most dealers first heard the phrase gdpr vs eu data act when a manufacturer portal, a workshop system, or a connected-car feature flagged a new consent screen or data-sharing clause. The two regulations get mentioned in the same breath, so it is easy to assume they cover the same ground. They do not. GDPR is about protecting personal data - information that identifies a human being. The EU Data Act is about who gets access to the data a connected product generates while it runs. A modern car produces both kinds at once, which is exactly why the two regimes overlap on your forecourt and why confusing them creates real compliance and commercial risk.

This article draws the boundary clearly: where GDPR ends, where the Data Act begins, and where they sit on top of each other for the same vehicle. It is written for dealer principals and compliance leads who need a working mental model rather than a legal treatise. The short version is that you can be fully GDPR-compliant and still be on the wrong side of the Data Act, and vice versa, because they answer two different questions about the same car.

Two regulations, two different questions

The cleanest way to keep these straight is to remember what each one is actually trying to fix.

GDPR (the General Data Protection Regulation, in force since 2018) exists to protect individuals. Its scope is personal data: any information relating to an identified or identifiable natural person. If you can tie a piece of data back to a human - a name, an email, a number plate linked to a registered keeper, a location history - GDPR rules apply. It tells you what lawful basis you need, how long you can keep data, what rights the person has, and what happens when something leaks.

The EU Data Act (which became applicable from September 2025) exists to unlock data from connected products and related services. Its scope is the data generated by the use of a product - the readings, logs, events and signals a connected device produces. Much of this is non-personal machine data: tyre pressure, battery state of health, fault codes, mileage, charging cycles. The Data Act is concerned with a different question entirely: not "is this person protected", but "who is allowed to get this data, and can they share it with someone else".

Key point
GDPR asks is this about a person, and are they protected. The Data Act asks who can access the data this product generates, and who can they pass it to. Same car, two separate questions.

Why a connected car triggers both

A connected vehicle is the textbook case for overlap. Picture the data streaming off one car on your lot or in a customer's hands:

  • Battery state of health, fault codes, mileage - machine data. On its own, not personal. Squarely Data Act territory.
  • GPS location trail, driving behaviour tied to a logged-in profile, a paired phone's contacts - these identify or relate to a person. GDPR territory.
  • A maintenance event log that records who was driving and where - both at once.

The vehicle does not separate these neatly. They flow through the same telematics unit and often the same export. That is why you cannot treat "vehicle data" as a single category with a single rulebook. We unpack the ownership side of this in more depth in who owns vehicle data in Europe.

The boundary, side by side

DimensionGDPREU Data Act
Core subjectPersonal data (identifies a person)Data generated by a connected product or related service
Primary goalProtect individuals and their rightsEnable fair access to and sharing of data
Who it empowersThe data subject (the individual)The user of the product (owner, lessee, fleet operator)
Typical vehicle exampleDriver identity, location history, contactsBattery health, fault codes, usage and sensor logs
Key right for your customerAccess, rectification, erasure, portabilityAccess to product data and right to share it with a third party
When it bites a dealerWhenever you process customer personal dataWhen you request or receive product data on a user's behalf

The watch-out hiding in this table: a single export from one vehicle can land in several rows at once. A battery-health report (Data Act) that includes a logged driver profile and a location stamp (GDPR) is one file governed by two regimes. Compliance is not "pick the right regulation" - it is "satisfy both where they overlap".

What changes for a dealership in practice

For a dealer principal or compliance lead, the practical shift is less about new paperwork and more about new access. The Data Act is designed to make it easier for the user of a vehicle to get the data it produces and to direct it to a service provider of their choice - which can be your dealership, your workshop, or a valuation and inventory tool you rely on.

That cuts two ways.

The opportunity. Historically, much connected-vehicle data sat behind a manufacturer's gate. The Data Act is intended to loosen that gate so the user can authorise sharing. For a dealer, richer access to genuine usage and condition data can mean better-grounded appraisals, more accurate reconditioning decisions, and fewer surprises at trade-in. The honest, source-backed approach to that data is the whole point of vehicle history checks in Europe.

The obligation. The moment that data identifies a person - and connected-vehicle data very often does - GDPR rides along. You still need a lawful basis to process it, a retention limit, and a clear answer if the customer asks what you hold and asks you to delete it. The Data Act does not switch GDPR off; it sits alongside it.

Watch out
Receiving data lawfully under the Data Act does not make you GDPR-compliant. If a Data-Act share includes personal data, you still need a GDPR lawful basis to hold and use it. Two green lights are required, not one.

A simple test before you handle vehicle data

When a new data flow appears - a portal feed, a telematics export, a third-party integration - ask three questions in order:

  1. Is any of this data about an identifiable person? If yes, GDPR applies to that portion. Confirm your lawful basis and retention.
  2. Was this data generated by the use of a connected product? If yes, the Data Act governs who may access and share it. Confirm the user authorised the share.
  3. Does the same dataset answer yes to both? Then both regimes apply together - protect it under GDPR and respect the access rules under the Data Act.

This is deliberately boring, and that is the point. A repeatable test beats trying to remember which regulation a given field belongs to.

Where the confusion usually comes from

Three recurring mix-ups are worth naming, because they cause most of the wasted effort.

"The Data Act replaces GDPR for cars." It does not. They are complementary. GDPR is the protection layer for anything personal; the Data Act is the access layer for product-generated data. Neither overrides the other.

"If data is non-personal, I have no obligations." Non-personal machine data is outside GDPR, but the Data Act still governs who can access and share it, and under what terms. "Not personal" does not mean "no rules".

"Consent under GDPR is the same as authorisation under the Data Act." They are different mechanisms. GDPR consent (where consent is the lawful basis) is about lawful processing of personal data. Data Act authorisation is about a user directing product data to a recipient. You can need both for the same flow.

This is also why the cross-border picture matters: the same vehicle's data may move between countries with the same EU rules but different local practice. We cover that in cross-border vehicle data in Europe, and the wider regulatory context in the EU Data Act and the automotive industry.

Where VehIQ fits

VehIQ is being built as an EU-sovereign, API-first data layer for the automotive industry, starting with the dealer management system. The reason the gdpr vs eu data act boundary matters to that design is simple: a data platform for European dealers has to treat both regimes as first-class, not as an afterthought.

That shapes three deliberate choices. First, field-level lineage - every value carries where it came from, so a dealer can tell at a glance whether a field is personal data, product-generated data, or both, which is the exact question both regulations turn on. Second, valuations that show their sources and a confidence interval rather than a single black-box number, so the data behind an appraisal is traceable rather than opaque. Third, open formats the customer owns, so authorised data access translates into data the dealer actually controls. VehIQ is pre-seed and these are design commitments rather than deployed results, but the regulatory shift toward user-directed access is precisely the world this layer is meant to operate in - running alongside your existing systems rather than replacing them.