DPDP Act for Automotive Companies: Connected Cars, Telematics and Dealer Data
Date Published

Connected vehicles process continuous streams of location, driving behaviour, account, diagnostic, voice and camera data. When these streams relate to an identifiable driver, owner, passenger or employee, they can constitute personal data under India's Digital Personal Data Protection Act, 2023.
The exposure extends far beyond the vehicle. Personal data moves through biometric attendance systems on the factory floor, test-drive forms in the showroom, financing and insurance referrals, dealership-management systems, service records, companion apps and EV-charging networks. Most of the operational provisions relevant to these activities become enforceable on 13 May 2027, under the DPDP Act and its Rules.
This guide explains how automotive companies should assign Data Fiduciary and Data Processor roles, distinguish core vehicle functions from optional data uses, manage dealer and partner ecosystems, and address a frequently overlooked event: the transfer of a connected vehicle to a new owner. The obligation throughout is to maintain evidence of the applicable purpose, notice, consent and controls, because where consent is relied upon, the burden sits with the Data Fiduciary to prove compliant notice and consent.

How Does the DPDP Act Apply to Automotive Companies?
The DPDP Act applies wherever an automotive company processes personal data of identifiable individuals in India, across the vehicle, the showroom, the factory and the partner network. It does not require consent on every data flow. It requires the correct purpose and legal basis for each one, transparent notice, and evidence that controls were applied.
The automobile sector has spent a decade turning the car into a software platform, and the data generated around that platform now has to be governed with the same discipline the industry applies to product safety and cybersecurity. The rest of this guide maps that obligation flow by flow.
Who Is the Data Fiduciary Across the Automotive Data Ecosystem?
The correct starting point is not the name of the organisation but the function it performs. The statutory test is who determines the purpose and means of processing. An OEM will commonly act as the Data Fiduciary for connected services and manufacturer-controlled telematics. A dealership may act as an independent Data Fiduciary for its own sales and service activities, or as a Data Processor where it processes personal data solely on the OEM's documented instructions.
A telematics provider processing data only to deliver an OEM-defined service may be a Data Processor. The same provider may become a separate Data Fiduciary where it independently develops driver scores, analytics products or services for insurers.
The same organisation may therefore hold different roles for different processing activities. OEMs, dealers, mobility platforms and technology vendors should map these roles purpose by purpose and document them contractually, without assuming that contractual labels alone determine the statutory position. Contracts can record role allocation, but they cannot override what the parties actually do.
When Do Connected Vehicles Need User Consent?
Not every connected-car function runs on consent. Connected-car processing should be mapped purpose by purpose. Data necessary to deliver a connected service requested by the user may be assessed under Section 7(a), while other processing may be required for safety, security or compliance with applicable law. Optional personalisation, behavioural profiling, targeted marketing and sharing with insurers or other commercial partners will commonly require separate, specific consent unless another lawful basis can be clearly established.
The notice should explain the personal data involved, the specified purpose, the available rights and the mechanism for withdrawing consent where consent is the basis. The user must have the option to access the notice or consent request in English or any language specified in the Eighth Schedule; the law does not require every interface to display all 22 languages simultaneously. Understanding the different types of consent under DPDP helps map which flows genuinely need it.
Telematics is where these questions concentrate. Location trails reveal home, workplace, and habits. Driving-behaviour data can feed insurance pricing. Voice assistants capture in-cabin audio, and driver-monitoring cameras built for ADAS record faces. Each stream needs its own purpose and basis, and the mechanism to manage purpose-linked connected-car consent where consent applies. Companion apps add a second layer: SDKs and trackers inside the app collect device and behavioural data that needs its own consent surface.

Can Driving Data Be Shared With Insurers?
Not automatically. Driving data collected for a vehicle-safety feature should not be repurposed for insurance pricing without a fresh basis. The insurance use must be separately disclosed and supported by a valid purpose and legal basis, which will commonly involve specific consent from the relevant driver.
The US Federal Trade Commission's action against General Motors and OnStar provides a useful international warning. The regulator alleged that consumers were not clearly informed that precise geolocation and driving-behaviour data would be collected and sold to third parties. The FTC finalised its order in January 2026, reinforcing the regulatory risk of treating connected-service enrolment as permission for unrelated downstream data use. It is a comparable international risk pattern rather than a prediction of how the Indian Board will enforce the Act.
Consent in a vehicle also has a design problem showrooms and apps do not: multiple people drive one car. Consent given by the registered owner does not automatically authorise consent-based processing of personal data relating to other identifiable adult drivers or passengers. Automotive privacy design should therefore account for shared and rented vehicles through separate driver profiles, guest modes, visible indicators for active microphones or cameras, and accessible settings for optional data collection. For safety-critical or legally required processing, the manufacturer should document the applicable basis and minimise the data collected rather than presenting the feature as an optional consent choice.
How Does the DPDP Act Apply to Dealerships?
For most customers, the dealership is where their data enters the ecosystem: enquiry forms, test-drive licences, KYC for financing, insurance proposals, exchange valuations, and years of service records inside the dealership-management system. Dealer networks are also where compliance is hardest to standardise, because thousands of independently owned outlets run their own CRMs, WhatsApp groups and spreadsheets alongside the OEM's systems.
Three practices need immediate attention. Test-drive data collected for a drive should not default into a marketing pipeline; that second purpose needs its own notice and consent. When a dealership shares a customer's details with a bank, insurer or financing marketplace, the recipient will generally act as a separate Data Fiduciary for its own processing; the referral should be transparently presented as a separate purpose, the customer told which organisation will receive the data, and separate consent obtained where the sharing is not already supported by a valid specified purpose or applicable legitimate use. Financing consent can be integrated within the booking journey, provided it is clearly distinguishable and purpose-specific rather than bundled.
On network-wide programmes, a dealer may process data on the OEM's behalf, making dealer practices part of the OEM's processor-governance responsibility. For independently managed sales, local marketing or service activities, the dealer may instead be a separate Data Fiduciary. OEMs should avoid applying one role to the entire dealer relationship. Franchise and dealer agreements should document permitted purposes, processor instructions where applicable, security controls, sub-processing, retention, rights handling and breach escalation, reflecting the actual operating model rather than assigning every obligation to the other party. The final Rules expressly require suitable security provisions in contracts between a Data Fiduciary and Data Processor where applicable, so it helps to govern dealer and technology-provider risk systematically.
Do Manufacturers Need Consent for Employee Data?
Section 7(i) permits processing for purposes of employment and for specified purposes related to protecting the employer from loss or liability. Attendance, payroll, access control and workforce administration may therefore rely on employment legitimate use where the processing is genuinely necessary and proportionate to that purpose.
This does not mean every form of biometric or shop-floor monitoring is automatically permitted. Manufacturers should still assess whether less intrusive data would achieve the purpose, restrict access, establish defined retention periods and communicate the processing transparently to employees. Reliance on consent may in any case be difficult to defend where employees have no meaningful choice.
Separate analysis is required for productivity surveillance, emotion or fatigue analysis, wellness programmes, R&D studies involving employees, and datasets created to train driver-monitoring or ADAS systems. Where these activities fall outside the employment purpose, the organisation should identify another lawful basis, conduct a privacy-risk assessment and use anonymised or minimised data where feasible. Visitor CCTV, contractor records and outsourced-worker data should not be automatically placed under the employee provision; each should be mapped according to the relationship, purpose and actual processing involved.
How Should EV-Charging Data Be Governed?
EV charging creates a new chain of potential Data Fiduciaries and Data Processors, including charge-point operators, e-mobility service providers, OEM apps, roaming platforms and payment providers. Each party's role should be mapped by purpose.
Processing necessary to locate a charger, initiate a session, authenticate the user, process payment and provide a receipt may be assessed as part of the service requested by the user. Separate consent may be required for unrelated location profiling, cross-service behavioural analysis, targeted offers or sharing charging histories with additional commercial partners. Interoperability programmes should design purpose controls and role allocation into their data exchanges, rather than treating every transfer as either automatically permitted or automatically consent-based. For a sector building charging infrastructure at speed, designing these controls in now is far cheaper than retrofitting them, which starts with the ability to discover personal data across dealer and OEM systems and the charging estate.
What Happens to Personal Data When a Vehicle Is Resold?
A connected-vehicle resale should be treated as both an ownership event and a data-lifecycle event. The former owner's account, paired devices, contacts, saved destinations, access credentials and optional connected-service permissions should be removed or de-linked from the vehicle.
However, the sale does not automatically require the erasure of every historical record. The OEM or service provider may need to retain limited information for warranty, product safety, fraud prevention, dispute management or compliance with applicable law. The Act requires erasure when consent is withdrawn or the specified purpose is no longer being served, unless retention is necessary under law, and the final Rules additionally require certain personal data, associated traffic data and processing logs to be retained for at least one year for specified purposes, unless another law requires longer. Such records should be purpose-tagged, access-controlled and no longer associated with active services for the previous owner unless continued processing is justified.
The new owner should receive a fresh notice and provide consent for optional connected services. Dealers handling exchanges and used-car transactions should include account deprovisioning, device disconnection and verification of the in-vehicle reset in the ownership-transfer checklist, so they can operationalise vehicle-owner data rights consistently.

Could Automotive Companies Become Significant Data Fiduciaries?
Large OEMs, mobility platforms and nationwide automotive groups may be assessed for Significant Data Fiduciary designation, because the statutory criteria include data volume, sensitivity and risk to Data Principals. However, the additional SDF obligations apply only after an organisation or class of organisations is formally notified by the Central Government. Volume and sensitivity alone do not make an automotive company an SDF.
Once notified, an SDF must appoint an India-based Data Protection Officer and undertake a Data Protection Impact Assessment and audit once every 12 months. It must also exercise due diligence to verify that technical measures, including algorithmic software used in processing personal data, are not likely to pose a risk to Data Principal rights. This requirement can become relevant to ADAS, driver-scoring, personalisation, dynamic-pricing and finance integrations where algorithmic systems are used to host, modify, transmit, store, share or otherwise process personal data.
What Are the Automotive Data-Breach Reporting Requirements?
A compromise involving telematics, connected-service accounts or dealership systems may trigger several parallel processes. Under the DPDP Rules, affected Data Principals must be informed without delay, the Board must receive an initial intimation without delay, and a detailed report must follow within 72 hours unless the Board permits additional time.
Where the event also falls within a category covered by the CERT-In Directions, a six-hour CERT-In reporting obligation may run in parallel. Not every personal-data breach is automatically a reportable CERT-In incident, so automotive organisations should integrate privacy, cybersecurity, dealer and vendor escalation workflows rather than treating breach response as a single 72-hour filing. Structured incident management under DPDP is what keeps those parallel clocks coordinated.
Separate contraventions may attract maximum penalties of up to ₹250 crore for failure to maintain reasonable security safeguards and up to ₹200 crore for failure to meet breach-notification obligations, subject to the Board's findings and penalty determination.
DPDP Compliance Checklist for Automotive Companies
Although the DPDP Act does not establish a standalone provision titled "privacy by design," its requirements around specified purpose, data necessity, security safeguards, consent evidence, rights and erasure make privacy-by-design practices a practical implementation approach. In sequence:
- Discover personal data across telematics, DMS, CRM, mobile apps, charging systems, HR platforms and R&D datasets.
- Map each activity to a specific purpose and legal basis.
- Assign OEM, dealer, platform and vendor roles flow by flow.
- Separate core vehicle functions from optional analytics, marketing and insurance uses.
- Design driver, guest and passenger-facing controls.
- Establish rights, withdrawal and grievance workflows.
- Create a connected-vehicle ownership-transfer process.
- Define retention by record and purpose.
- Update dealer and processor contracts.
- Integrate DPDP, CERT-In and product-safety incident response.
- Maintain evidence of notice, consent, processing, retention and escalation.
A general DPDP compliance checklist sequences the generic programme; the steps above mark where automotive diverges.
How Privy Supports DPDP Readiness for Automotive Companies

Privy by IDfy helps automotive organisations operationalise privacy controls across connected vehicles, dealerships, mobile applications, employee systems and partner networks.
Its Consent Governance Platform can manage purpose-linked notices, consent, withdrawal and evidence across test drives, marketing journeys, companion apps and optional telematics services. Data Compass can discover and classify personal data across dealership-management systems, CRMs, OEM clouds, endpoints and charging platforms. Privacy assessment, third-party risk and incident-management workflows can help automotive companies review high-risk data use, oversee dealers and technology providers, and coordinate breach response across complex partner ecosystems.
Together, these capabilities help automotive organisations move from policy-level compliance to an auditable operating model across the customer and vehicle lifecycle.

Conclusion
The automotive industry has spent the past decade transforming vehicles into connected digital platforms. The DPDP Act requires the sector to govern the personal data generated around those platforms with the same discipline it applies to product safety, engineering quality and cybersecurity.
The priority is not to place consent on every data flow. It is to identify the correct purpose and legal basis, separate essential functions from optional data use, clarify accountability across OEMs and dealers, and retain evidence of how each decision was implemented. Automotive companies that complete this mapping before May 2027 will be better positioned to launch connected services, charging ecosystems and data-led business models without repeatedly rebuilding their privacy architecture.
Build an auditable DPDP operating model across connected vehicles, dealerships and mobility ecosystems. Request a Privy walkthrough (link to a demo form or button rather than exposing an individual email address in the article body).
FAQ's
Is a car's telematics data personal data under the DPDP Act?
Yes, where the information relates to an identifiable driver, owner, passenger or account holder. Location trails, driving behaviour, voice recordings, driver-monitoring images and vehicle identifiers linked to a person may constitute personal data. Truly anonymised fleet statistics may fall outside the Act, but coded or pseudonymised data that can still be linked to an individual should continue to be treated as personal data.
Who is the Data Fiduciary for connected-car data: the OEM or the dealer?
It depends on who determines the purpose and means of each processing activity. An OEM will commonly be the Data Fiduciary for manufacturer-controlled telematics, while a dealership may be a separate Data Fiduciary for its own sales or service activities. A dealer or technology provider may instead be a Data Processor where it acts solely on another organisation's instructions.
Do manufacturers need employee consent for biometric attendance?
Employee consent may not be required where biometric attendance or access control is genuinely necessary for an employment or workplace-security purpose covered by Section 7(i). However, the employer must still assess necessity, minimise the data, implement security safeguards and establish retention limits. More intrusive monitoring or processing unrelated to employment requires a separate legal-basis analysis.
What happens to personal data when a car is resold?
The former owner's account, paired devices, contacts, saved destinations and optional connected-service permissions should be removed or de-linked. Limited records may still be retained where required for warranty, safety, dispute resolution or compliance with law. The new owner should receive a fresh notice and independently activate optional connected services.
Will automotive companies be Significant Data Fiduciaries?
Large automotive companies may be candidates for SDF designation, because the government may consider factors such as data volume, sensitivity and risk to individuals. However, SDF obligations apply only after the organisation or relevant class of organisations is formally notified. Building DPIA, audit, DPO and algorithmic due-diligence capabilities in advance can nevertheless reduce future implementation pressure.
Can an OEM share driving-behaviour data with an insurer?
Not automatically. If driving data was collected for vehicle diagnostics or safety, sharing it for insurance pricing is a separate purpose. The OEM must transparently disclose the use and establish an appropriate legal basis, which will commonly require specific consent from the relevant driver.
Does the buyer's consent cover every person who drives the car?
No. A vehicle owner generally cannot provide consent on behalf of unrelated adult drivers or passengers. Shared vehicles should support separate driver profiles, guest modes and accessible controls for optional personal-data processing.
Do connected-car safety features require consent?
Not in every case. The correct basis depends on the feature, the data involved and why it is being processed. Safety-critical, legally required and user-requested functions should be distinguished from optional analytics, personalisation, marketing and third-party sharing.
Are dealers Data Processors of the OEM?
Sometimes, but not always. A dealer may process data on the OEM's instructions for one programme while acting as an independent Data Fiduciary for its own marketing, service or local customer-management activities.
Does the DPDP Act require all vehicle data to be stored in India?
The current framework does not impose blanket localisation on all connected-vehicle data. Transfers remain subject to government restrictions, and specified personal data processed by an SDF may be subjected to localisation requirements.
.png&w=3840&q=75)
How Indian e-commerce operators meet DPDPA obligations in 2026: consent notices, dark patterns, data principal rights, breach rules & data discovery.