A new legal briefing from Norton Rose Fulbright maps how connected-car data is becoming a regulated asset in Europe and Australia, where regulators are moving toward UN cyber security rules for vehicles.
Australia has no design rule covering vehicle cyber security or software updates. During 2026 it consulted on adopting UN Regulation No 155 on cyber security and UN Regulation No 156 on software updates as Australian Design Rules, the briefing notes. Adoption would make cyber security management a type-approval requirement for every new vehicle sold there.
The briefing also charts the data-access fight. Modern cars generate real-time location, driving behavior, voice and biometric data spread across automakers, Tier 1 suppliers and tech platforms. The EU Data Act grants users access rights to data from connected products, with guidance putting raw and pre-processed data in scope but excluding proprietary analytics. EU data protection authorities generally treat vehicle data as personal data under the GDPR, and the European Mobility Data Space is being built to create a common market for it.
Australia is extending existing frameworks rather than writing a new statute. Treasury’s February review of the Motor Vehicle Service and Repair Information Sharing Scheme found it broadly working; consultations now cover electronic logbooks and data aggregators. The Consumer Data Right could be extended to automotive by designation, following the UK’s Smart Data model. The Albanese government also confirmed July 20 it would consult on more privacy reforms, and the auto industry’s voluntary data code remains unenforceable under the Privacy Act.
The bottom line for carmakers: overlapping EU and Australian regimes place vehicle data at the intersection of privacy law, competition rules and cyber security mandates, so compliance with one framework no longer guarantees compliance with the others.