Your car knows where you live, where you go, when you leave and who you phone on the way. Some of them listen. Some of them watch. In Australia, what happens to all that car data is governed by a law written in 1988, back when a car phone was a brick in a briefcase.
The Australian Electric Vehicle Association has put a set of proposals to the Federal Government this week asking for that to change. AEVA is the oldest electro-mobility group in the world, and not a body given to unfounded shouting. Their submission says the rules covering car data have fallen so far behind the machinery that owners have almost no protection worth the name.
By 2035 the association expects 95% of new vehicles sold here to be internet-connected. Close to 70 brands now sell cars in Australia, and their head offices are in 12 different countries. Every one of those cars with a SIM card in it is a data terminal you drive. Every one of those 12 jurisdictions has its own view about what a company may do with what it collects, and none of them is here.
This is not just an electric car story, whatever the name on the letterhead has access to data. Any modern vehicle with an embedded SIM or a telematics unit can send car data somewhere else, and almost all of them now have one.
What Your Car Really Knows
Start with location, because it is the one people underestimate. A month of trip records shows more than where you drove. It shows where you sleep and where you work. It shows which school you pull up outside at 3pm, which medical centre you visited twice in a fortnight, and whose house you park at overnight. None of that has to be recorded anywhere as a fact about you. It falls out of the timestamps.
But wait, there’s more. Synced phone contacts and call logs, texts pulled across when you paired the handset, voice recordings from the assistant. And as if that wasn’t enough, the cabin cameras watch the driver’s eyes, and in some models the passengers too. Seat sensors, braking behaviour, acceleration, speed against the posted limit are all gathered.
Mozilla tested 25 car brands against its privacy standards and every single one failed, which made cars the worst product category the foundation had ever reviewed. It found 84% of brands share or sell personal data. It found 92% give drivers little or no control over it. Exactly two, Renault and Dacia, offer owners the right to have their car data deleted, and both are European, where the law obliges them.
The list of what some policies claim the right to collect goes well past driving. Mozilla found brands reserving the right to record sexual activity, immigration status, health data and what it politely called genetic information. Whether any of them do it is quite beside the point. They wrote themselves the permission and you agreed to it, in a document you did not read, on a screen in a dealership, while somebody waited for you to sign. they know that nobody has the time to read the fine print so that’s where they hide the bad stuff.
Above: 2026 GAC M8 Luxury Master Super Hybrid review – Why Legacy Brands Can’t Match It
GACM8, #GACM8PHEV, #GAC, #M8PHEV, #PHEV, #PlugInHybrid, #PeopleMover, #MPV, #KiaCarnival, #LexusLM, #LDVMifa9, #Zeekr009, #SevenSeater, #FamilyCar, #CarReview, #Australia, #GayCarBoys

Help Support Gay Car Boys Subscribe to our Youtube Channel by SMASHING THE BUTTON ABOVE
ABOVE: Connected cars and the data they collect
The Money Is in Selling It
If that reads as theoretical, the American version is not. Carmakers were caught passing driving behaviour to the data broker LexisNexis, which turned it into risk scores and sold those to insurers. Drivers found their premiums climbing and had no idea why. The sharing had been buried in the sign-up for a connected services app, or switched on by a salesperson demonstrating the features.
A hard brake on a wet road is not a moral failing. Presented to an insurer as a score, stripped of the truck that cut in front of you, it becomes one. The driver never sees the reasoning and cannot argue with it.
That trade already exists here in a smaller way, through insurance apps people opt into knowingly. The difference with car data is that the collection happens whether or not you opted in, and the vehicle keeps doing it long after the novelty of the app wears off.
The Second-Hand Problem Nobody Mentions
There is a version of this that catches people who never bought a connected car at all. Every trade-in carries its history with it. Paired phones, contact lists, garage door codes, saved addresses and the previous owner’s account, all still sitting in the infotainment. Dealers are not obliged to wipe any of it and plenty do not. The next owner inherits somebody’s life along with the car.
Company cars and novated leases raise a different question again. When a fleet manager can pull car data showing where a vehicle went and how it was driven, that is workplace surveillance that comes through the glovebox rather than through an enterprise agreement. Nobody has settled what an employer may look at, because the law never imagined the vehicle as the machine filing the report. A job may depend on the employee agreeing to it.
Stolen Cars Made easy
In 2024 four security researchers found a flaw in Kia’s dealer portal that let them locate, unlock and start millions of cars built from 2013 onwards. The only thing they needed was the number plate. Start to finish it took about 30 seconds, and it worked whether or not the owner had ever paid for a connected subscription.
The same flaw handed over the owner’s name, phone number, email address and home address. It also let the researchers add themselves as a second user on someone else’s car without the owner being told. Kia fixed it, and the researchers were the good sort. How many of the other 69 brands have a portal nobody has looked at that hard.
Cars now ship on the assumption of permanent connectivity and a decade of software support, which means a decade of somebody remembering to patch them. The United Nations has written rules for exactly this, R155 for cyber security and R156 for software updates. They have been mandatory across Europe since 2024. Australia has proposed adopting them, and AEVA’s point is that proposed is not binding. Today compliance here rests on corporate goodwill which rarely ends well.
Why Car Data Law Is Not Ready
The instrument in question is the Privacy Act 1988, propped up by a voluntary code from the Federal Chamber of Automotive Industries. Voluntary is the word that should make everyone feel uneasy. A code nobody can be fined for breaking is a statement of intent, not a protection.
That code deserves a closer look while we are here. Industry wrote it, it binds nobody, there is no penalty for ignoring it and no regulator polices it. Compare that with Europe, where mishandling car data can cost a percentage of global turnover, or China, where the rules on what may leave the country are strict enough that carmakers rebuilt their systems to comply.
The Act has improved somewhat this year. A VIN and telematics records now count as personal information when they can be tied to a person. Collection also has to be fair and reasonable, even where you technically consented. From December, companies using personal information to make automated decisions have to disclose it, which falls squarely on anybody pricing insurance off driving behaviour.
What none of it does is tell a carmaker where car data must be stored, or what has to stay inside the vehicle. Nor does it say collection should be off until you switch it on. That is the gap AEVA is pointing at.
The Regulator Is Already Looking
This is not hypothetical. In February the Privacy Commissioner, Carly Kind, told a Senate committee that her office has two active investigations into car manufacturers, examining whether they collect excessive personal information and what they then do with it. Two more makers had preliminary examinations, and in January the office ran a compliance sweep in which car dealerships were one of six sectors selected.
Kind would not name the two under investigation. Asked directly by a senator whether they were Chinese state-owned companies, she would say only that they were based in Asia, so make of that what you will. This tells you that the regulator does not believe the current arrangements are working.
It Is Not a Chinese Car Problem
The politics will try to make it one, and the facts do not support it. The brands Mozilla failed were mostly the familiar ones such as Ford, Volkswagen, Toyota, Honda, Nissan, BMW, and Mercedes-Benz. The insurance scandal in the United States involved General Motors and Honda, not a newcomer. Every carmaker selling a connected vehicle is collecting, and the ones with the longest history here have had the longest time to write themselves generous terms.
James Pickering, AEVA’s national president, puts it as compliance over country-of-origin. The answer is a standard every brand has to meet, not a blacklist. A rule that says car data stays onshore, defaults are off and security is audited applies equally to a Chinese newcomer and a German incumbent. A rule aimed at one country protects nobody from the rest.
What AEVA Is Asking For
Three things, all lifted from rules that already work elsewhere. First, local processing. Voice recordings, face scans, cabin camera footage and precise routes should be handled inside the vehicle rather than uploaded. Whatever car data does leave should be stored here rather than shipped offshore.
Second, collection off by default. Nothing optional is gathered unless you turn it on, you can see exactly what is held, and you can wipe it completely before you sell. AEVA adds a practical rider, that owners should be able to share their own vehicle data with an independent mechanic instead of being funnelled back to a dealership.
Third, binding security. Make R155 and R156 legal requirements rather than aspirations, so that braking and steering are walled off from the entertainment screen, and security updates keep coming for the life of the car.
What You Can Do Before Any of That Happens
Not much, but start by going into your vehicle settings and the phone app and turn off every data sharing option you find, particularly anything described as improving products and services. Decline the offer to sync contacts and messages when you pair a phone, because a hands-free call does not need your address book.
Read the connected services agreement before you accept it at handover. If the salesperson can’t tell you what leaves the car and where it goes, take that as an answer. Before you sell or return a vehicle, factory reset the infotainment, remove paired phones and delete the car from your account. A used car with your home address still in it is somebody else’s car now.
What Should Bother You
Ten years ago this was a story about companies knowing slightly too much. he difference is what happens to the information after it leaves. Broker markets buy it and merge it. Breaches spill it. Pattern-matching tools infer from ordinary trip records the facts nobody ever asked you for.
Inference is what changed the arithmetic. A list of trips is dull. A model run across that list produces conclusions you never volunteered, and it does not have to be right to be used. Regular stops at a fertility clinic. A pattern of nights away from the registered address. A commute that stops for six weeks. Insurers, employers, landlords and lenders all make decisions on thinner material than that.
Nobody consents to a conclusion. You consent to a collection, if you consent to anything at all. The conclusion gets drawn years later, by a company you have never heard of, using car data that has changed hands twice since you sold the vehicle.
The car is the most detailed sensor most people own, and the one they think about least. It travels with you, it knows the address, and it never forgets a Tuesday. AEVA is asking for the rules to catch up while this is still a policy question rather than the next national data breach. That seems a reasonable ask.
What a Connected Car Can Collect
| Collected | What it reveals |
|---|---|
| Location history | Home, work, school, medical visits, overnight stays |
| Trip timing | Daily routine, absences, when the house is empty |
| Driving behaviour | Braking, acceleration, speed against the limit, used for risk scores |
| Synced phone data | Contacts, call logs, messages, sometimes calendar |
| Voice capture | Assistant commands, in some cars cabin conversation |
| Cabin cameras | Driver attention, face data, passengers |
| Charging and fuel stops | Where you stop and how often, plus payment links |
| Vehicle identifiers | VIN, now personal information under Australian law |
The Rules, Here and Elsewhere
| Measure | Australia | Europe | China |
|---|---|---|---|
| Main instrument | Privacy Act 1988 | GDPR | Automobile Data Security rules |
| Industry code | FCAI, voluntary | Binding | Binding |
| Data must stay onshore | No | Transfers restricted | Yes |
| Right to deletion | Limited | Yes | Yes |
| UN rules R155 and R156 | Proposed | Mandatory since 2024 | Equivalent regime |
More Technology Stories
- GAC M8 Luxury PHEV Review, The Van That Killed the Carnival
- Audi Q9 Is the Biggest Audi Ever at 5.31 Metres Long
- OttoSafe Cam Wireless CarPlay And Dash Cam Review a Clever Upgrade

Help Support Gay Car Boys Subscribe to our Youtube Channel by SMASHING THE BUTTON ABOVE
Leave a Reply