DPDP compliance for automobile and automotive companies

DPDP compliance for automobile and automotive companies
Automotive

DPDP compliance for automobile and automotive companies

Modern vehicles collect real-time location, driving behaviour, and biometric data. Here is what DPDP requires from OEMs, dealerships, and fleet operators.

Quick Answer: Automotive companies — OEMs, dealerships, fleet operators, and telematics providers — process a growing volume of personal data through connected vehicles, test drive records, service histories, and digital customer journeys. Connected vehicle data includes real-time GPS location, driving behaviour analytics, in-vehicle biometric data (facial recognition for driver fatigue detection), and home/workplace location inference from journey patterns — much of which is sensitive. Consent is required before activating connected features that collect personal data. Dealerships processing customer finance and test drive records need DPDP-compliant privacy notices. Enforcement begins May 2027.

What personal data do automotive companies collect under DPDP?

OEMs and dealerships collect: customer registration data, test drive records (identity, driving licence), purchase and finance data, vehicle service history, telematics data from connected vehicles (GPS location, speed, acceleration, braking patterns), in-car infotainment usage, voice assistant recordings, and data from driver monitoring systems (eye tracking, fatigue detection). Fleet operators additionally hold driver assignment records, commercial trip data, and driver performance scores. Several of these — location, biometric, financial — are sensitive or high-risk.

Does connected vehicle data require consent under DPDP?

Connected vehicle features that collect personal data — real-time GPS, driving behaviour analytics, driver monitoring — require explicit consent from the vehicle owner and/or driver before activation. OEMs should implement a connected services consent screen during vehicle setup: a specific, clear choice about which data collection features are enabled. Factory-on connected features that activate without consent are a significant DPDP risk. Provide genuine opt-out options for each feature with no degradation of non-connected vehicle functionality.

How does in-car voice assistant data work under DPDP?

Voice assistants in vehicles record voice commands — which are personal data — and may also capture background conversation. Voice recordings must be disclosed in the privacy notice, stored securely, retained for a defined period, and not used for advertising profiling without explicit consent. If voice data is processed by a third-party AI vendor (Amazon Alexa Auto, Google Assistant), that vendor is a Data Processor requiring a DPA. Do not train AI models on in-car voice recordings without clear user consent.

What DPDP obligations arise from vehicle location data?

GPS location data reveals an individual's home address, workplace, frequented locations, and movement patterns. This is sensitive in the same way as any real-time location data. OEMs must: disclose location data collection in the privacy notice; allow owners to disable location tracking (without disabling safety features like emergency call systems); restrict who can access location data (roadside assistance, fleet managers, law enforcement on court order); and delete historical location data on a schedule. Do not share location data with third parties — insurers, advertisers — without explicit consent.

How does DPDP apply to dealership CRM and finance data?

Dealership CRM systems hold test drive records, purchase enquiries, customer contact histories, and finance application data. Finance applications involve sensitive financial data (income, liabilities, credit history) that requires explicit consent and appropriate security. Third-party finance companies processing the application are Data Processors requiring DPAs. Test drive data — driving licence details, insurance information, test route record — should be retained only for the period needed to manage the dealership's test drive liability and then deleted.

What are DPDP obligations for automotive fleet operators?

Fleet operators using telematics to manage commercial vehicles process driver personal data — GPS routes, speed behaviour, idling time, harsh braking events. Drivers must be informed of what is tracked (typically in employment contracts and a fleet privacy notice) and the data must be proportionate to the management purpose. Using telematics data to make employment decisions about individual drivers — disciplinary action, bonus, dismissal — makes it high-stakes processing requiring clear policy and a mechanism for drivers to access and contest their data.

Frequently asked questions

Can automotive companies sell connected vehicle data to insurers?

Selling telematics and location data from connected vehicles to insurers (for usage-based insurance pricing) requires explicit vehicle owner consent specifically covering data sale to named or named categories of insurers. This is a commercially sensitive consent that many owners would decline if properly informed. Implement this as an explicit opt-in separate from the general connected services consent, and do not make connected features conditional on data sale consent.

Does DPDP apply to pre-owned vehicle buyer data?

Yes. Dealerships processing pre-owned buyer and seller data — identity, vehicle service history linked to previous owners — are Data Fiduciaries for that data. Previous owner data in a used vehicle's service history should be anonymised before sharing with the new buyer. Do not share previous owner personal data (name, contact, address) with the buyer — they need the vehicle's service record, not the previous owner's identity.

Are automotive OEMs likely to face SDF designation?

Large OEMs processing connected vehicle data for millions of Indian vehicles at scale — particularly if they process location, biometric, or driving behaviour data — are potential SDF candidates given the volume and sensitivity of the data and the potential harm from breach or misuse. OEMs should prepare for SDF by building DPO-ready governance, commissioning DPIAs on connected vehicle data flows, and implementing consent management systems at vehicle onboarding.

Assess your automotive DPDP compliance

Niti Bharat's DPDP Readiness Assessment covers automotive OEMs, dealerships, and fleet operators — connected vehicle consent, telematics data, voice assistant DPAs, and location data governance.

Start Automotive DPDP Assessment
Previous Post Next Post

Get Free DPDP Checklist