The CNIL publishes its recommendations on the use of connected vehicle location data

The National Commission on Informatics and Liberty (CNIL) has published a recommendation regulating the use of location data from connected vehicles by professionals.
This document, intended for manufacturers, fleet managers, telematics providers, and data aggregators, aims to strengthen legal security and transparency for the use of vehicles by individuals, excluding company cars. It specifies the application conditions of Article 82 of the Data Protection Act, making user consent mandatory for the processing of location data, except when such data are essential for a service explicitly requested. The recommendation also provides clarifications on the exercise of rights, notably the right of access, in a context where the same vehicle may be used by multiple persons. It addresses common purposes such as assistance, fleet management, theft prevention, and service improvement, recalling the basic principles of the GDPR.

Developed following a public consultation conducted in March 2025, the final version of the recommendation has been enhanced. It now recommends the use of authenticated profile systems to facilitate the management of choices and the exercise of rights by different users of a vehicle. The CNIL specifies that consent is not required to collect location data aimed at preventing a breach of trust, such as the non-return of a rental vehicle. Finally, the document suggests allowing users to remotely disconnect their personal account and proposes best practices to limit access to residual data left by a previous user.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire