Connected vehicle data

Connected vehicle data in the UK

What a UK company can actually get from a connected vehicle, who supplies it, and the rules that apply. The short answer is that Great Britain has no statutory vehicle-data access right equivalent to the EU's, and the gap is filled by competition law and by manufacturers' own terms.

What connected vehicle data is

Connected vehicle data is information generated by a vehicle in use and transmitted off the vehicle, rather than read from a port by a technician standing next to it. Three sources get conflated, and they behave differently.

Manufacturer-authorised data comes from the vehicle's built-in modem to the manufacturer's servers, and reaches a third party through an interface the manufacturer controls. Aftermarket telematics comes from hardware installed in the vehicle, usually in the OBD port or hard-wired, and reports to the supplier of that hardware. Phone and app data is derived from a driver's handset and never touches the vehicle's own systems.

The distinction matters because each carries different coverage, different signals and, most importantly for this page, a different legal basis for access. Manufacturer-authorised data is the only one of the three where the question "am I allowed to have this?" is answered by regulation rather than by a purchase decision.

What a UK company can actually get

There is no single statute in Great Britain that gives a vehicle's user a right to the data their vehicle generates. Access rests on two other things: a competition-law instrument that penalises restricting it, and whatever the manufacturer's own terms provide.

The competition-law route is the Competition Act 1998 (Motor Vehicle Agreements Block Exemption) (No. 2) Order 2023, in force from 1 June 2023 and expiring on 31 May 2029. Article 6 treats as an excluded restriction any restriction on independent operators accessing information, tools or training, and its definition of vehicle information covers "data which is generated by a part or system of a motor vehicle, and any information which is required for the purposes of interpreting that data".

This is not a data-access right. It is a block exemption: it removes protection from agreements that restrict access, which is a different legal mechanism with different remedies. An operator denied data under the EU regime can assert a statutory entitlement. An operator denied data in Great Britain is in the territory of competition law.

Separately, assimilated Article 61 of Regulation 2018/858 still requires manufacturers to provide "unrestricted, standardised and non-discriminatory access" to on-board diagnostic information and repair and maintenance information. That obligation survived in GB law and remains the strongest access provision on the statute book here.

The EU Data Act and why it does not reach UK-registered vehicles

The EU Data Act (Regulation (EU) 2023/2854) has applied since 12 September 2025 and gives users of connected products a right of access to the data those products generate. Its scope provision, Article 1(3), is keyed to the Union: it covers manufacturers of connected products placed on the market in the Union, users in the Union, and data recipients in the Union.

The Regulation is not assimilated UK law. A search of legislation.gov.uk for Regulation 2023/2854 returns no result, because it was made after the end of the transition period and was never brought across.

This does not mean UK-domiciled companies can ignore it. The scope provision applies irrespective of where a company is established, so a UK group placing vehicles on the EU market, or serving users in the EU, may well be within scope. What it means is narrower and more specific: a UK user of a UK-registered vehicle cannot rely on the Data Act to compel access to their own vehicle's data.

Nor is there a domestic equivalent in force. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, but it creates enabling powers for smart data schemes rather than a scheme itself. The Department for Transport's work on transport smart data was still described as an exploratory project as of June 2026, and the multi-sector call for evidence closes on 1 October 2026. No vehicle data access scheme has been made in law.

What this looks like in practice: BMW CarData

BMW publishes terms for a UK CarData service that lets a customer view their vehicle's telematics data and release it to third parties. The terms current at the time of writing are dated May 2026. They open by stating that BMW (UK) Limited, of Farnborough, offers the service "to comply with its obligations under the Regulation (EU) 2023/2854 ('Data Act')", and Section 2 provides that "the Customer is therefore considered a user within the meaning of Article 2 (12) Data Act".

The Data Act does not apply to a UK-registered vehicle. The access is nonetheless offered, on the manufacturer's terms, using the EU Regulation's own framework and vocabulary throughout. The same document imports other EU instruments as well, including the GDPR, the Trade Secrets Directive, the Digital Markets Act and the Data Governance Act.

The revision history makes the position sharper. The previous version of these terms, dated September 2025, provided at Section 15 that "the sole place of jurisdiction ... will be Munich, Germany" and that "German law will apply". The May 2026 version replaces both, giving jurisdiction and governing law as the United Kingdom. The rights framework was left as it was. A deliberate revision pass changed which country's law governs the contract and kept the EU Data Act as the basis of the service.

Two further provisions define the shape of what a UK customer holds. BMW will notify customers of changes to the terms at least six weeks before they take effect, and the right to use CarData ends when the underlying ConnectedDrive contract expires or is terminated.

Alongside this, BMW's technical documentation points the other way. The CarData integration guide, version 1.6 and dated 30 July 2026, lists four prerequisites for retrieving vehicle data, one of which is that "your vehicle is assigned to a supported market (EU)". The United Kingdom is not named in that guide. BMW (UK) Limited publishes UK terms for the same service and operates a UK customer portal. Note that the prerequisite keys to the market the vehicle is assigned to, not to where the customer is based.

That is the practical shape of the gap. An EU user holds this access as a statutory right. A UK user holds functionally similar access as a contractual term, offered voluntarily, amendable on notice, ending with a service contract, and resting on eligibility criteria that do not name their country. Whether that distinction ever matters depends on whether a manufacturer changes its mind, which is precisely the risk a statute removes.

Type approval: R155, R156 and the Great Britain timing gap

Two UNECE regulations govern vehicle cybersecurity and software updates. UN Regulation No. 155 requires a certified cybersecurity management system, and UN Regulation No. 156 requires a software update management system. Both entered into force on 22 January 2021.

Neither regulation contains a mandate date of its own. The texts set no deadline for new types or for all new vehicles. Those dates come from each contracting party's domestic law, which is the mechanism that produced a gap between Great Britain and the EU.

The EU mandated both through Delegated Regulation (EU) 2022/2236, applying from 6 July 2022. Great Britain mandated them through the Road Vehicles (Type-Approval) (Amendment) (No. 3) Regulations 2025, made on 20 October 2025 and in force from 13 November 2025. GB type approval will be refused for new types not meeting the requirements from 1 June 2026, with registration prohibitions following on 1 June 2027 and 1 June 2028.

The Explanatory Memorandum to that instrument records that before it was made, the GB type-approval scheme had no requirements for cyber security or software updating at all. It also states that the instrument ensures the GB scheme is aligned with the EU, which is worth noting: on type approval the direction of travel is convergence, not divergence. The United Kingdom is a contracting party to the 1958 Agreement in its own right and already accepts vehicles approved to these regulations.

One distinction matters throughout this section. Northern Ireland operates the EU type-approval scheme under the Windsor Framework, so the rules described here are Great Britain's, not the United Kingdom's as a whole.

Vehicle data and UK GDPR

Vehicle-generated data is personal data when it relates to an identified or identifiable individual, which in practice turns on whether it is linked to a driver, an account or a vehicle identifier that can be traced to a person. There is no general answer that holds for all vehicle data, and the Information Commissioner's Office has not published a position stating one.

In fact the ICO has published no statutory guidance specific to connected vehicles. The closest material is the connected transport chapter of its Tech Horizons report 2025, published on 20 February 2025. That document is horizon scanning rather than guidance, and it should not be read as a statement of the regulator's enforcement position. It does note that organisations should take care to identify the correct lawful basis, and it flags that where information is stored on or accessed from terminal equipment, regulation 6 of PECR must be considered before UK GDPR.

One structural point is often missed. Article 70 of the GDPR, which establishes the European Data Protection Board and its tasks, was omitted from UK law on 31 December 2020. The EDPB's Guidelines 01/2020 on processing personal data in the context of connected vehicles were adopted in final form on 9 March 2021, after that date, and have no binding status in the United Kingdom. They remain directly relevant to the same organisations' EU-facing processing.

Who supplies connected vehicle data in the UK

The supplier landscape has consolidated sharply. Otonomo, for several years the most visible independent vehicle-data marketplace, merged into Urgent.ly Inc. in an all-stock transaction that closed in October 2023, and its shares were delisted that December. Any description of it as an independent listed data platform is out of date.

The remaining routes are the manufacturers' own programmes and a small number of aggregators that hold contracts with them. The table below shows which manufacturers are named in each aggregator's published material.

How to read this table. A "named" cell means the manufacturer appears in that provider's official published API specification or coverage material. It does not mean the data is available to a UK company, or for a UK-registered vehicle. Provider API specifications contain no country or region scoping at all, which is why the UK column is almost entirely unpublished. That column is the point of the table, not a defect in it.

ManufacturerSmartcarHigh MobilityCarusoManufacturer directUK availability stated?
BMW and MININamedNamedNamedYesNot published
Mercedes-BenzNamedNamedNamedYesNot published
Volkswagen GroupNamedNamedNamedPortal onlyNot published
StellantisNamedNamedNamedYes, ex-PSA brandsNot published
FordNamedNamedNamedNot publishedNot published
Toyota and LexusNot listedNamedNamedPortal onlyNot published
Renault and DaciaNamedNamedNamedNot publishedNot published
HyundaiNamedNamedNot publishedPortal onlyNot published
KiaNamedNamedNamedYesYes, UK-specific terms
Volvo CarsNamedNamedNamedYesNot published

Last verified: 4 August 2026. Sources are each provider's own published specifications and each manufacturer's own developer or data-access material. Cells reading "not published" mean no public statement was found either way, which is itself informative. "Portal only" means the manufacturer operates an EU Data Act consent portal for vehicle owners rather than a programmatic interface for third parties, and those portals are scoped to the EU by construction.

Two caveats apply to every row. Being named at brand level never implies coverage of every model or model year, because providers qualify availability by model year, trim, firmware and active subscription. And the aggregator route is not the same as the manufacturer route: a brand may be reachable through one and not the other.

Manufacturer-direct programmes also diverge in how they are offered. Mercedes-Benz and Kia both state that a signed framework agreement is a prerequisite. Stellantis describes access as available only on request. Volvo Cars publishes a free tier. Where a manufacturer runs only an EU Data Act consent portal, that is a route for the vehicle's owner rather than a commercial data feed.

Why the manufacturer's own channel is rarely enough for a fleet

A manufacturer's customer-facing data channel is built for a person checking their own car, and its published limits show it. BMW's CarData integration guide, version 1.6 dated 30 July 2026, sets a rate limit of 50 API requests per day per user, resetting at midnight UTC. Data can be retrieved only by the primary user registered against a given vehicle identification number. Streaming is capped at one connection per user account at a time. Access tokens last an hour and refresh tokens a fortnight.

Those constraints are entirely reasonable for an owner. They do not scale to a fleet. Fifty requests a day is a handful of calls per vehicle across even a small fleet, one stream per account does not cover a depot, and primary-user-only retrieval assumes the person requesting the data is the individual registered to the car, which is frequently not how a company fleet is set up. The guide itself recommends the streaming route rather than polling where higher frequency is needed.

This is the practical reason aggregators exist, and why the question of who may register as a third party matters more to a fleet than the customer-side terms do. It is also the part of the picture that is least documented: no provider publishes country-level eligibility, and the terms governing third-party registration with BMW were not publicly readable at the time of writing. That cell in the table above reads "not published" for exactly that reason.

Frequently asked questions

What is connected vehicle data?

Connected vehicle data is information generated by a vehicle in use and transmitted off the vehicle over its built-in connection, rather than read from a diagnostic port. It covers manufacturer-authorised feeds, aftermarket telematics hardware and phone-derived data. The three differ in coverage, in the signals available, and in the legal basis on which a third party may access them.

Does the EU Data Act apply to UK vehicles?

The EU Data Act's scope provision is keyed to the Union: manufacturers placing connected products on the Union market, users in the Union, and data recipients in the Union. It is not assimilated UK law. A UK user of a UK-registered vehicle therefore cannot rely on it to compel access. It can still apply to a UK-domiciled company that places vehicles on the EU market or serves users there, because the scope provision applies irrespective of place of establishment.

Is there a UK equivalent to the EU Data Act?

Not in force. The Data (Use and Access) Act 2025 creates enabling powers for smart data schemes rather than a scheme itself, and no vehicle or transport scheme has been made in law under it. The Department for Transport's transport smart data work was still an exploratory project as of June 2026, with a multi-sector call for evidence closing on 1 October 2026.

Do UK BMW drivers get EU Data Act rights?

Not by law. BMW's UK CarData terms dated May 2026 state that BMW (UK) Limited offers the service "to comply with its obligations under the Regulation (EU) 2023/2854 ('Data Act')" and treat the customer as a user within the meaning of Article 2(12) of that Regulation. Because the Data Act is not UK law, that access is a contractual term rather than a statutory right. The previous version of those terms was governed by German law; the May 2026 revision changed the governing law to the United Kingdom and kept the Data Act framework. BMW may change the terms on six weeks' notice, and access ends with the underlying ConnectedDrive contract.

What are UNECE R155 and R156?

UN Regulation No. 155 requires a certified cybersecurity management system for vehicle types, and UN Regulation No. 156 requires a software update management system. Both entered into force on 22 January 2021. Neither contains a mandate date of its own; the dates on which they bite come from each contracting party's domestic law.

When do R155 and R156 apply in Great Britain?

GB type approval will be refused for new vehicle types not meeting R155 and R156 from 1 June 2026, under the Road Vehicles (Type-Approval) (Amendment) (No. 3) Regulations 2025. Registration prohibitions follow on 1 June 2027 and 1 June 2028. The EU applied the same regulations from 6 July 2022. Northern Ireland operates the EU scheme under the Windsor Framework, so these GB dates do not describe the whole United Kingdom.

Is vehicle data personal data under UK GDPR?

It depends on whether the data relates to an identified or identifiable individual, which usually turns on linkage to a driver, an account or a traceable vehicle identifier. There is no general answer covering all vehicle data, and the ICO has not published a position stating one. Where information is stored on or accessed from terminal equipment, regulation 6 of PECR may be engaged before UK GDPR is reached.

Do EDPB connected-vehicle guidelines apply in the UK?

They have no binding status in the UK. Article 70 of the GDPR, which establishes the European Data Protection Board, was omitted from UK law on 31 December 2020, and the EDPB's Guidelines 01/2020 on connected vehicles were adopted in final form in March 2021. They remain directly relevant to the same organisation's EU-facing processing.

Which providers have the broadest manufacturer coverage?

On published material, High Mobility and Caruso name the widest range of manufacturers, and Smartcar names all of the ten largest in Europe except Toyota. Being named is not the same as being available: provider specifications carry no country scoping, so none of them publishes whether a given manufacturer is reachable for a UK-registered vehicle.

Can I get connected vehicle data without installing hardware?

Yes, where the vehicle has a factory-fitted connection and the manufacturer or an aggregator offers an interface to it. That route avoids installation and warranty questions entirely, but coverage is limited to vehicles the manufacturer supports, and access depends on the consent and contractual arrangements described above. Aftermarket hardware remains the route that works regardless of make, model year or manufacturer participation.

Sources and method

Regulatory statements on this page cite primary sources: the UNECE regulation texts, EUR-Lex for EU instruments, legislation.gov.uk for UK and assimilated law, and the ICO's own publications. Provider coverage is taken from each provider's published API specifications and coverage pages rather than from third-party listings. Where no public statement could be found, the page says "not published" rather than inferring an answer.

This page describes regulation as published. It is not legal advice, and it does not tell you what your organisation should do. Anyone relying on the position described here for a commercial or compliance decision should take their own advice on their own facts.

Orbis IO works with OEM-authorised vehicle data for UK fleets.

Talk to us →