LATESTNews

Are your EV’s cameras, microphones and location data spying on you? Calls for tougher Australian laws as electric car sales boom

Australia’s booming EV market is creating a new data privacy and national security challenge as increasingly sophisticated electric cars collect everything from location and driving patterns to voice recordings, cabin camera footage and biometric information.

Now the Australian Electric Vehicle Association (AEVA) is calling on the Federal Government to introduce tough new laws governing what happens to that data, including requirements for sensitive information to be processed within the vehicle and personal vehicle data to be stored in Australia by default.

The consumer EV advocacy group also wants optional data collection switched off unless owners actively opt in, greater protection against vehicle hacking and tougher controls over information transmitted overseas.

The push comes as Australia experiences rapid EV growth and an unprecedented influx of new electric cars, many from China, fitted with increasingly sophisticated cameras, microphones, driver-monitoring systems, smartphone connectivity and permanently connected telematics.

But while concerns about Chinese-made connected cars and where their data ends up have become part of the wider debate over cybersecurity and national security, AEVA argues Australia should regulate the technology rather than target vehicles based on where they were built.

Its proposed rules would apply equally to Chinese, European, American, Japanese, Korean and other manufacturers selling connected vehicles here.

“From Europe to USA, to China and the rest of Asia, we are lucky to welcome such an incredible range of electric cars to our shores,” said AEVA national president James Pickering.

“We are great believers in compliance over country-of-origin and will continue our discussions with government to support consumer choice and protection, while also maintaining national security.”

While EVs are at the forefront of the issue because of the sophisticated connected technology many carry, AEVA stresses the potential risks apply to any vehicle with a SIM card, telematics unit or other system capable of transmitting information externally.

AEVA says 95 per cent of all new vehicles sold in Australia by 2035 are expected to be internet-enabled.

At present, connected vehicles in Australia are covered primarily by the Privacy Act 1988 and Australian Privacy Principles, supplemented by voluntary industry standards including the Federal Chamber of Automotive Industries’ data privacy code.

AEVA argues that framework has not kept pace with modern EVs and other software-defined cars and wants mandatory vehicle-specific requirements covering privacy, cybersecurity, data storage and software updates.

Among the most significant proposals is a requirement for sensitive information to be processed within the vehicle wherever practical instead of routinely uploaded to manufacturer cloud systems.

That would include raw information gathered by cabin cameras and microphones as well as voice recordings, biometric information and detailed location data.

Personal data generated by vehicles in Australia should also be stored in Australia by default, with overseas transfers restricted to situations where they are necessary, proportionate, clearly disclosed and limited to the minimum information required.

AEVA also wants non-essential data collection switched off by default, with owners able to see what information is collected, why it is collected, where it is stored and who receives it.

Owners should be able to delete personal information, including contacts and location history, before selling their EV.

2025 Sony Honda Afeela sedan dashboard.
2025 Sony Honda Afeela sedan dashboard.

National security is another key element of the proposal.

Modern EVs can carry multiple exterior cameras and other sensors while recording location and vehicle information, potentially collecting data around defence facilities, sensitive government sites, strategic transport routes, charging networks and other critical infrastructure.

AEVA wants the Federal Government to assess those risks and establish protections for sensitive information.

Interestingly, one country AEVA believes Australia can learn from is China.

China introduced automotive data rules in 2021 that include principles favouring processing information within the vehicle, non-collection by default and anonymising or de-identifying information before transmission.

Its rules also identify movement information, audio, video, images and biometric information as sensitive personal data, while important automotive data is required to be stored domestically and undergo security assessment before being transferred offshore.

AEVA does not advocate adopting China’s broader state-security model, but argues some of its protections make sense for Australian consumers.

Europe is another influence, with AEVA calling for Australia to mandate UNECE R155 and R156 international standards governing vehicle cybersecurity and software-update management.

These would require car-makers to establish certified cybersecurity and software-update systems and processes for dealing with vulnerabilities, security incidents and secure updates throughout a vehicle’s life.

AEVA also wants safety-critical systems including braking and steering technically separated from infotainment, apps and cloud-connected functions.

But the association doesn’t simply want to prevent EV data leaving the car.

It wants owners to control who can access vehicle-generated information, including independent repairers, charging and energy companies, insurers and other authorised third parties, rather than data being trapped inside manufacturer-controlled “walled gardens”.

For EV owners that could be particularly significant, with vehicle data potentially used for battery health monitoring, charging optimisation and vehicle-to-grid (V2G) energy services.

Leave a Reply

Your email address will not be published. Required fields are marked *