
- As new cars have flooded the market, data privacy laws have not kept up.
- Australia is being urged to adopt similar vehicle cybersecurity laws to Europe.
- As it stands, data collected by new cars in Australia is stored overseas.
Australia’s new car market is relatively small, with just 1.24 million vehicles sold across 2025, yet it remains extraordinarily competitive, home to almost 70 different brands all fighting for their slice of the sales. That kind of density puts a lot of hardware, and a lot of software, into Australian driveways every year.
But as the nation’s car market has diversified, it appears the government has forgotten to protect the sensitive data that so many new cars collect. Now, the Australian Electric Vehicle Association (AEVA) is calling for action, noting the country does not have dedicated, vehicle-specific policies for cybersecurity and software-update management, as many other nations do.
Review: China’s 2026 GAC Aion UT Is A Budget EV That Doesn’t Feel Cheap
New vehicles are more connected than ever, particularly EVs, routinely collecting not only location data but also uploading voice recordings and images from in-car cameras to manufacturer cloud storage systems, often overseas. Of the almost 70 car brands in Australia, they come from just 12 overseas countries, and these nations could be collecting driving data from locals and doing with it as they please.
Australia Needs To Follow Europe

The AEVA is calling on the Australian government to adopt a connected-vehicle cybersecurity framework similar to Europe. This would require manufacturers to maintain a certified cyber security management system, a software update management system, and “clear lifecycle processes for vulnerability management, incident response and secure software updates.
At present, the only legal framework helping protect local data is the 1988 Privacy Act’s Australian Privacy Principals, which requires open and transparent handling of personal information. This, alongside with voluntary standards from the Federal Chamber of Automotive Industries (FCAI) is all that’s used.
What Should Be Done?

The AEVA wants in-car data to be processed in the vehicle by default and that data collected is stored in Australia by default. There should also be strict limits on overseas data feeds from Australian vehicles to overseas manufacturers, and locals should have the rights to access, delete, and manage vehicle data.
Even China is doing a better job than Australia. Its 2021 automobile data provisions prioritizes in-vehicle processing of data and a default non-collection principle. Important data also needs to be stored domestically and is subjected to security assessment before it can be transferred abroad.
“A well-designed Australian regime can support innovation, enable safe software-defined vehicles, and still require privacy-protective defaults, local processing, strong cybersecurity and meaningful user control,” the AEVA noted. “It should also ensure that consumers and consumer-authorised third parties are not locked out of legitimate access to vehicle data, functions and resources by manufacturer-controlled digital gatekeeping.”

Â