Australia’s largest motoring club wants connected cars treated as the data-collecting devices they are. The NRMA’s 29-page policy paper, built with cybersecurity firm Irdeto and other partners, maps the legal gaps that leave vehicle data largely unprotected. It landed the same week Lexus Australia’s chief executive called for national rules on what cars collect.
The paper found the gaps start with the law itself. Australia regulates smart doorbells more strictly than the data streams of connected cars: surveillance statutes don’t treat vehicles as surveillance devices, privacy notices skip the passengers and pedestrians exterior cameras record, and the smart-device security rules passed in 2024 were drafted to leave road vehicles out.
Regulation is thinner than in Europe. Charge point operators count as essential or important entities under the EU’s NIS2, while Australia’s SOCI Act leaves EV charging networks out of critical infrastructure. The voluntary industry code running since July 2021 offers principles with no enforcement teeth.
Lexus Australia boss Jack Hobbs told the NRMA’s Open Road magazine that vehicle data deserves the same weight as physical safety and called Europe a sensible template. The company says connected services ship switched off except SOS and automatic collision notification, with opt-in consent per feature. The telematics control unit stays registered to a cellular network regardless, and consent only gates which data streams publish.
The survey numbers explain the urgency. Ninety-five percent of NRMA members flagged remote hacking or unconsented data sale as a top concern, and 70 percent said they were unwilling or unlikely to buy from a brand that trades in their information. Australia’s privacy regulator has formal investigations into vehicle suppliers underway, the paper notes. It also calls for owner-authorized data access so independent repair shops are not strangled by well-meaning drafting.