Share This Article
19 makers of cars and trucks sold in the US committed to preserve the privacy of their customers in the view of the massive amount of personal data that are going to be processed through connected car.ย
I have already reviewed privacy issues affecting connected car in this post and more recently I reported in this post about the findings on legal issues affecting connected car from the Connected Automobiles conference. ย But the relevance of such issues has been now acknowledged by the Alliance of Automobile Manufacturers, the Association of Global Automakers, and their members that adopted the ‘Consumer Privacy Protection Principles‘.
The companies that are signatories of these principles include Chrysler, Ford, General Motors, Volkswagen, Toyota which reppresent over 91% of US sales of vehicles.
Principles for connected car manufactures
The principles adopted can be summarized as follows:
- Transparency: owners and registered users shall be provided with ready access to clear and meaningful notices about theย collection, use and sharing of their information;
- Choice: owners and registered users shall be provided with certain choices regarding the collection, use and sharing of their information;
- Respect for Context: information shall be collected and shared in ways that are consistent with the context in which it was collected taking account of the likely impact on owners and registered users;
- Data Minimization, De-Identification & Retention: information shall be collected only as needed for legitimate business purposes and shall be retained no longer than they determine necessary for legitimate business purposes;
- Data Security: reasonableย measures have to be implemented to protect information against loss and unauthorizedย access or use.
The reaction in Europe
The above principles sound quite familiar to European data protection experts and indeed are in line with what previously discussed. ย In particular the need to provide information about the mechanics of processing of personal data collected and to provide a free choice to users on the processing of their data is a fundamental principle of EU privacy law. ย Likewise the compliance with security measures in the processing and storage of data that has to be limited to what necessary to achieve the purposes of the processing notified to users is a consolidated milestone of EU data protection law.
The major difference between the US and Europe for connected car is however that the breach of similar principles in Europe will lead to fines under the new EU Privacy Regulation will be equal to 5% of the global turnover of the breach entity.
We will see how such principles will be implemented by connected car makersย and thisย is among the issues that will be discussed at our webinar on connected car to which you can registeredย HERE.
@GiulioCoraggio