CNIL Issues GDPR Guidance on Connected Vehicle and Geolocation Data
The French Data Protection Authority (CNIL) published detailed guidance on June 30, 2026, addressing the processing of personal data generated by connected vehicles, with a special focus on geolocation data. This guidance is crucial for automotive manufacturers, suppliers, and mobility companies operating within the European Union. It offers clear instructions on managing EU privacy and data protection laws related to vehicle data, helping organizations navigate the complex regulatory environment.
This comprehensive 60-page document covers the automotive digital ecosystem by identifying the roles of various stakeholders and the sources of location data, such as in-vehicle sensors, telematics devices, mobile applications, and data aggregators. It highlights common real-world scenarios where location data is used, including fleet management, roadside assistance, fraud prevention, and product development. The CNIL provides practical recommendations to ensure that organizations balance innovation with compliance, processing location data in line with the General Data Protection Regulation (GDPR).
Key recommendations from the CNIL include assessing when connected vehicle data qualifies as personal data, especially when individuals can be identified through vehicle identification numbers (VIN), registration documents, or user profiles in infotainment systems. Organizations should also consider the application of EU ePrivacy rules, particularly regarding user consent for accessing or storing information on connected vehicle systems. The guidance emphasizes the importance of clearly defining processing purposes, identifying the roles and responsibilities of stakeholders, and establishing appropriate legal bases for data processing activities, such as contract performance or legal obligations.
Furthermore, the CNIL stresses the need for data minimization, storage limitation, and transparency by providing clear privacy information through sales or rental agreements, service contracts, and vehicle interfaces. It also encourages facilitating data subject rights, such as access and erasure, and implementing strong cybersecurity measures, including encryption and access controls. The guidance addresses complex data-sharing arrangements in automotive supply chains and highlights the importance of complying with international vehicle cybersecurity standards. This document is an essential resource for automotive businesses aiming to strengthen their data protection programs and prepare for regulatory scrutiny in the European market.