
Key points
The boss of one of Australia's leading car makers has called on policymakers to introduce a consistent national approach to how customer data is collected from connected cars.
Lexus Australia boss Jack Hobbs told Open Road that data privacy should carry a similar level of importance to vehicle safety, and that more needs to be done to educate and protect car buyers as connected vehicles become increasingly common in Australian showrooms.
A connected car is a vehicle that can communicate with the internet, its manufacturer and other devices to deliver features such as remote vehicle controls, navigation, emergency assistance, vehicle diagnostics and infotainment services.
But these technologies can also capture a significant amount of personal information, including location and route history, in-cabin activity, and even images and audio.
Unlike Europe, Australia is yet to develop a comprehensive approach to vehicle data and privacy, and Hobbs believes there is a case for a more consistent national framework.
"It's a little bit like safety. The broad answer is yes," Hobbs said when asked whether Australia needs a consistent policy covering vehicle data.
“Like I said, it's like looking after their physical safety. That's how important it is. So there should be more education, should be more transparency, I think.”

Hobbs said Lexus would comply with any Australian government regulations but suggested there was value in looking to Europe, where vehicle safety and emissions standards have often provided a benchmark for Australia.
"I think it does make sense," he said.
Hobbs' comments echo the recommendations of a major new report released today by the NRMA examining the risks associated with connected vehicles and cyber security.
The report, titled ‘Secure and Connected Vehicles: Stronger data, privacy & cyber rules in Australia’ was developed in partnership with leading cyber security, data and transport infrastructure resilience experts and calls for stronger privacy protections, nationally consistent cyber security standards and greater consumer control over vehicle data.
The report warns that connected vehicles can collect highly sensitive information about drivers and passengers, while current Australian arrangements can limit consumers' practical ability to access, control or share their own vehicle data.
The NRMA is calling for consumers to have clear rights to access, control and securely share their vehicle data with third parties of their choice, as well as the ability to refuse unnecessary collection or on-selling of personal information.
The report also highlights the cyber security risks associated with connected EV charging infrastructure, which increasingly relies on connected systems for payments, software updates, smart charging and electricity demand management.

Lexus believes it’s important that customers understand what information their vehicle collects and why.
Lexus experts told Open Road that connected services are not simply switched on as default when a customer takes delivery of a new vehicle.
“All the connected services, when you pick up the car, are off,” one Lexus expert said. “There's no data going out of the car, except for the safety services. So, SOS or automatic collision activation.”
According to Lexus, safety services such as emergency assistance operate separately, with data generated when a specific trigger occurs, such as a crash or the driver pressing an emergency button.
Customers who want to activate other connected services must do so through the Lexus app, where they are shown what data is required for each service.
“If you want to activate the rest of connected services, you need to opt in,” the Lexus expert confirmed.
Lexus experts also described different levels of consent for different features, meaning customers can activate some connected services while opting out of specific functions.
The company says it only collects information required to provide the relevant service and does not collect data with the intention of selling it to another company.
That doesn't mean Lexus rules out sharing data with third parties in the future. A Lexus expert told us any such use would require customer consent.
"If you're studying some use cases that will have to share the data with another company, let's say, an insurance company, it would be because the customer consent to provide or to access a service that joins us, Toyota, with their insurance provider," he said.
Lexus is owned by its parent company, Toyota, and Hobbs says the same approach applies to both Lexus and Toyota customers.
One of the biggest questions facing owners of connected vehicles is who actually controls the information captured by their car.
When asked who owns the data, a Lexus expert told Open Road: "The customer always has control."
According to Lexus, customers can contact the call centre to opt out of connected services and request the removal of data associated with them.
The company says it has processes in place to remove customer data and has been working to make its policies and explanations more transparent.
Lexus also says it attempts to retain as much data onshore in Australia as possible, although some applications used for connected services send data to North America or Japan.
NRMA Chief Membership Officer Victoria Doidge said consumers should have a clear choice over non-essential data collection.
"Connected vehicle technologies are delivering important safety, convenience and mobility benefits to Australians. However, Australian customers must have the enforceable right to refuse or withdraw consent for non-essential, unclear or excessive collection of identifiable personal data at point of sale or subsequently," Doidge said.
"That decision must not deny them access to core vehicle functions, safety features or warranty entitlements. Consumers should also have clear rights to access, control and securely share their vehicle data with third parties of their choice."

Lexus says its approach is based on giving customers control over which connected services they use and what data they consent to share.
The company says the onboarding process through the Lexus app explains the different packages and features available, including what data is collected for each service.
“Sometimes people don't really understand, maybe fully, what they're getting into,” said Hobbs. “So in our customer interactions, we've got to try and make sure that they do understand what their options are and where they can opt in, where they can opt out.”
Lexus also believes dealers have an important role to play in explaining connected services at the point of sale.
"A car these days is so much more complicated," Hobbs said. "The handover process is going to take some time, and it's going to be important."
The company says its dealers are encouraged to explain connected services during the onboarding process, including what data is collected, why it is required and how customers can control their consent.

The amount and sensitivity of data generated by connected vehicles also creates a cyber security concern.
A modern connected car can potentially build up a detailed picture of where a vehicle travels and even where its owner lives, works and spends time.
When asked whether Lexus had considered scenarios involving a cyber attack that could expose GPS information, phone data or recordings, Hobbs acknowledged the risk.
"It's definitely a risk that we take very seriously," he said.
The NRMA firmly believes more needs to be done to manage data risks, with Victoria Doidge saying Australia's existing framework needs to catch up with the rapidly changing technology.
"Australia's privacy, consumer and cyber security framework is not designed for the scale and sensitivity of real-time vehicle data," she said.
"Where legitimate data collection supports safety research, planning and policy, it must be properly anonymised, aggregated and governed."