Look to China and Europe for privacy examples in smart cars, EV lobby group tells government | Region Canberra

Look to China and Europe for privacy examples in smart cars, EV lobby group tells government | Region Canberra

The Australian Electric Vehicle Association says Australia can learn from China and Europe about regulating privacy in internet cars. Photo: Thomas Lucraft.

Growing privacy concerns over internet-enabled cars have sparked a call for the Federal Government to look to the countries making the vehicles for examples of how to manage the issue.

That approach offers a far better solution than fearing the intentions of countries of origin regarding data-connected vehicles and privacy, claims the Australian Electric Vehicle Association (AEVA), the world’s longest-running EV society.

Projections are that up to 95 per cent of all new vehicles sold in Australia by 2035 will be internet-enabled. That figure includes electric vehicles.

Without government intervention, consumer protection and national security risks will likely escalate as these vehicles flood into the country.

The threat extends to any modern vehicle, not just EVs, equipped with an internal SIM card or telematics system capable of transmitting data to external locations.

It is an issue playing out in one of the most competitive markets worldwide, where nearly 70 brands sold in Australia trace their headquarters to 12 overseas jurisdictions.

AEVA is urging the government to integrate key traits from Europe’s “highly effective” General Data Protection Regulation and China’s “world-leading” Automobile Data Security mandates.

Europe ties vehicle cybersecurity and software-update security to market access to United Nations standards, which prohibit transferring personal data outside of a vehicle.

China’s approach mandates in-vehicle processing, a default non-collection principle, a precision limitation principle for cameras and radar, and a desensitisation principle.

AEVA’s submission to government is that much can be learned and adopted from these legal frameworks.

“Consumers nationwide continue to be let down by insufficient data privacy legislation,” AEVA national president James Pickering said.

“Instead of instigating fear and distrust in the connected vehicles we drive, policymakers have the power to make effective changes to protect drivers and consumer choice.

“We are great believers in compliance over country-of-origin and will continue our discussions with government to support consumer choice and protection, while also maintaining national security.”

The lobby group is calling on the Federal Government to enact tighter data laws to protect connected-car owners.

“Compared with some other countries, Australia’s current framework remains underdeveloped,” its submission states.

“It does not yet provide a dedicated, mandatory vehicle-specific regime for cybersecurity and software-update management, and automotive data governance still depends largely on general privacy obligations and voluntary industry commitments rather than enforceable rules.

“This matters because modern vehicles are increasingly networked, software-defined systems whose malfunction, compromise or manipulation can have immediate real-world safety consequences and may also create avenues for disruption by malicious state or non-state actors.”

AEVA’s recommendations include integrating the best of the legal approaches being implemented in Europe and China.

These include:

  • Local data processing: To protect consumer privacy and national security, vehicles should keep your most sensitive information inside the vehicle
  • Data defaults to “off”: Meaning a car company can’t track you unless you explicitly choose to let them, and
  • Superior hacking protection: Legally binding rules that force car manufacturers to meet strict international vehicle security measures (such as the United Nations UNECE standards R155 & R156).

At present, internet-connected vehicle owners in Australia are reliant on the Privacy Act 1988, supplemented by voluntary standards set out by the Federal Chamber of Automotive Industries. AEVA says this Act is outdated for today’s requirements.

In a recent Senate Estimates hearing, ASIO deputy director-general Lisa Alonso Love warned Australia’s public servants not to discuss sensitive government information if they are travelling in internet-connected cars, over fears of electronic eavesdropping and the risk of espionage.

“In relation to any vehicle, whether it’s connected or not, we would suggest that Members of Parliament or public servants do not have conversations that contain sensitive or classified information,” she said.

“Obviously, a connected car may have other vectors to gather that information, but those conversations should only ever happen in places that are set up for classified conversations.

“And we would say that people should be conscious of the things that they are discussing in vehicles, knowing that people may be able to get that information.”