Quick Answer
Automotive companies collect personal data through connected vehicles, dealership CRMs, service records, and telematics systems. Under the DPDP Act 2023, vehicle data linked to an identifiable individual is personal data — requiring consent, privacy notices, and data retention limits. OEMs and dealers must review their data collection practices across the customer lifecycle from lead generation to after-sales service.
Quick AnswerAutomotive companies must obtain explicit consent for telematics and location tracking, limit data sharing with insurance and advertising partners, and implement vehicle-data deletion workflows on ownership transfer.
DPDP Compliance Checklist
- Map all connected-vehicle data: telematics, GPS, driver behaviour, diagnostics
- Obtain explicit in-vehicle consent for location and driving pattern collection
- Restrict sharing telematics data with insurance companies to opt-in basis only
- Implement data deletion on vehicle resale — clear all personal data from infotainment systems
- Review dealer CRM: ensure sales lead data has valid consent for follow-up
- Train dealership staff on customer data handling and DSAR processing
- Audit third-party fleet management software for DPDP compliance
- Publish privacy notice in owner's manual and digital touchpoints
- Implement 72-hour breach notification SOP for customer data incidents
- Conduct annual DPDP assessment covering OEM + dealer + partner ecosystem
Download Full Compliance Guide (Free)
Get the complete sector-specific checklist, risk areas, and 30-day action plan — delivered to your inbox.
Frequently Asked Questions
Is location data from vehicles considered personal data?+
Yes. GPS and telematics data linked to a vehicle owner is personal data under DPDP. Collection requires explicit consent and clear disclosure of purpose.
Who is the data fiduciary for connected vehicles?+
The OEM is the primary data fiduciary for vehicle-generated data. Dealers act as data processors when handling customer leads and service records.
What happens to vehicle data when a car is sold?+
DPDP requires that personal data of the previous owner be deleted before vehicle handover. OEMs should build automated data-wipe flows into vehicle transfer processes.
Every Sunday
The Sunday DPDP Brief
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.