Home/ Insights/ Europe Just Passed a Law That Its Own Car Industry Wasn't B…
Europe Just Passed a Law That Its Own Car Industry Wasn't Built to Follow
Automotive & Mobility · Marqstats Research

Europe Just Passed a Law That Its Own Car Industry Wasn't Built to Follow

One law says third parties get fair access to your car's data. Most cars were built to send that data somewhere else first: straight to the manufacturer.

13 min read 1,358 words Automotive & Mobility

A new EU law mandates open vehicle data access. Most cars weren't built for it.

In brief:

  • The EU Data Act mandates fair, real-time third-party access to connected vehicle data, enforceable since September 2025.
  • Most European automakers built the Extended Vehicle (ExVe) model, which routes all telemetry through the manufacturer's own cloud servers first.
  • Industry coalitions AFCAR and CLEPA argue this architecture undermines the law's intent across more than 50 million connected vehicles.

Regulation (EU) 2023/2854, the EU Data Act, sets out a specific right: owners and operators of connected products, including vehicles, can access, use and transfer the data those products generate, and can direct that data to authorized third parties under fair, reasonable and non-discriminatory terms. For cars specifically, that third party might be an independent repair shop, a competing insurance provider, or a software developer building a fleet-management app. The regulation applies broadly across connected products, not just vehicles, but automotive telemetry is one of its most closely watched applications given how much of a modern car's value depends on data generated during ordinary use.

Europe Just Passed a Law That Its Own Car Industry Wasn't Built to Follow — exhibit 1

The problem is that the law describes a right of access without specifying exactly how that access has to work technically. And the technical model most European automakers already had in place, built years before this law existed, works in a way that makes the law's real-time promise difficult to deliver in practice.

Sep 2025EU Data Act enforcement begins
Sep 2026Harder design obligation takes effect
50M+Connected vehicles across Europe affected

What the Extended Vehicle model actually does

In the Extended Vehicle architecture, a car's sensors and onboard systems send data to a Telematics Control Unit, which transmits it over a cellular connection directly to the automaker's own cloud infrastructure. If a third party, say, an independent repair shop, wants that data, they can't get it from the car. They have to query the automaker's back-end server through a web API - and the automaker controls exactly what that API returns, how often it updates, and how much it costs.

This isn't a workaround or a loophole. It's the architecture automakers deliberately built, and it predates the Data Act by years. The model made sense from a manufacturer's perspective: centralized data under manufacturer control, one system to secure, one point of commercial control over who gets access to what.

The law wants real-time access. The architecture was built to put the manufacturer in the middle of every request.

— Marqstats Analyst Team

Why independent repairers say this defeats the law's purpose

The Alliance for the Freedom of Car Repair in Europe and the European Association of Automotive Suppliers, known as AFCAR and CLEPA, have been the most vocal critics of the Extended Vehicle model specifically in the context of Data Act compliance. Their argument is straightforward: routing every data request through a manufacturer-controlled server introduces latency that a manufacturer's own internal systems don't experience, imposes commercial fees that vary by manufacturer with no standardized rate, restricts access to in-vehicle human-machine interfaces that would let a third-party app interact with the car directly, and limits the kind of real-time safety or maintenance application that needs immediate data rather than data delayed by a manufacturer's API response time.

In a 2024 policy paper, CLEPA specifically argued that more than 50 million connected cars across Europe remain under this kind of proprietary manufacturer control, meaning the Data Act's legal right of access exists on paper for a huge fleet that, in technical practice, still routes through the exact chokepoint the law was arguably meant to open up.

Why automakers say the alternative is genuinely dangerous

Automakers don't dispute that the Extended Vehicle model routes data through their own servers. Their defense is that doing anything else creates real safety risk. Under UNECE Regulations R155 and R156, cybersecurity rules built into EU vehicle type-approval requirements, manufacturers are legally responsible for maintaining a certified Cybersecurity Management System across the vehicle's entire lifecycle. Opening direct third-party access to a car's internal CAN bus or Ethernet network, the argument goes, creates a genuine vulnerability vector - potentially reaching systems that control steering, braking or powertrain function, not just diagnostic data.

The counter-argument: is this a genuine safety concern or a convenient justification?

It's worth taking both sides of this seriously rather than assuming one is acting in bad faith. The cybersecurity concern is not manufactured - vehicle systems genuinely do need protection from unauthorized bus access, and R155 compliance is a real, audited legal obligation, not a voluntary preference. At the same time, it's also true that the current architecture happens to give manufacturers exclusive commercial control over data monetization, and that alignment between a stated safety justification and a convenient business outcome is exactly the kind of overlap that invites scrutiny. The honest position is that both things can be true simultaneously: the cybersecurity risk is real, and the current architecture also serves manufacturers' commercial interests, and resolving which concern should take precedence is precisely the unresolved policy question this market now depends on.

The EU Data Act's mandate for real-time, fair third-party vehicle data access and the Extended Vehicle architecture most European automakers already built are not naturally compatible - one demands direct, low-latency access while the other channels everything through manufacturer-controlled infrastructure. Whether this gets resolved through automaker-built compliant API gateways, new sector-specific legislation mandating a different technical model, or continued reliance on cybersecurity justifications to limit access, is likely the single most consequential open question for this market's growth trajectory through 2034.

What this means for repairers, developers and automakers

  • Independent repairers and fleet software developers should plan around the actual API terms automakers publish under Data Act compliance, rather than assuming the law alone guarantees frictionless real-time access.
  • Automakers should treat FRAND-compliant API gateway development as an immediate operational priority given the September 2026 design-obligation deadline, not an optional compliance layer.
  • Policymakers evaluating whether additional sector-specific vehicle data legislation is needed should weigh AFCAR and CLEPA's architecture-level objections specifically, not just the general principle of data access rights.

Two deadlines, not one, and why the gap between them matters

It's worth being precise about the actual compliance timeline here, since it is more staggered than a single enforcement date suggests. Most of the Data Act's obligations, including the basic data access and sharing requirements, became applicable from 12 September 2025. But a separate, harder requirement, the design obligation that requires new connected products to actually be built to allow direct user access to data, does not apply until 12 September 2026. And certain obligations affecting contracts concluded before September 2025 extend even further, to September 2027.

Europe Just Passed a Law That Its Own Car Industry Wasn't Built to Follow — exhibit 2

This staggered timeline gives automakers a real transition window rather than a single hard cutover, and it is likely deliberate: retrofitting compliant data-sharing architecture into an existing vehicle fleet and existing back-end infrastructure is a genuinely large engineering undertaking, and the European Commission's own September 2025 automotive-specific guidance, clarifying exactly which data categories must be shared, suggests regulators recognized that ambiguity about scope was itself slowing compliance efforts before the guidance existed.

What a compliant alternative architecture might actually look like

The market's own technical analysis identifies a third possible architecture beyond the current Extended Vehicle model and a fully open third-party model: on-board application sandboxing, where authorized third-party software runs directly within the vehicle's own compute environment, isolated through memory partitioning and safety certification, rather than routing data out to any external server at all, OEM or third-party. This approach could theoretically satisfy both sides of the current dispute simultaneously - genuine real-time, low-latency data access for authorized applications, without requiring raw telemetry to leave the vehicle's own secured compute environment in the first place. The technical complexity and certification cost of this approach is substantial, which is likely why it remains a scenario-level possibility in current market analysis rather than an architecture already deployed at scale.

The full market picture

Marqstats' complete Europe automotive data management market analysis, including the full regulatory landscape and a three-scenario forecast through 2034, is available in the linked report below.

Related reportEurope Automotive Data Management Market Size, Share & Forecast 2026 – 2034Automotive and Mobility
Marqstats
Marqstats Research
Market Intelligence & Advisory · marqstats.com
Automotive & Mobility Market Research Marqstats Intelligence
Back to insights