- Regulation (EU) 2018/858 and UN R155 and R156 on cybersecurity and software updates
- Regulation (EU) 2016/679 — GDPR, Article 27
- Regulation (EU) 2023/2854 — Data Act for vehicle data
- Regulation (EU) 2024/1689 — AI Act for driving automation
Who has to appoint one
Suppliers outside the Union providing connected vehicle services or software to EU users. Vehicle cybersecurity and software update management are type approval requirements under UN R155 and R156, which apply to the manufacturer but cascade to suppliers contractually.
Thresholds and exemptions
Type approval requirements apply to new vehicle types and, since July 2024, to all new vehicles registered in the Union.
What must appear on the label
Not physical for software. The vehicle carries its type approval marking, and the privacy notice names the Article 27 representative and explains what vehicle-generated data is processed.
Marketplace fields
Vehicle manufacturers impose cybersecurity management system requirements on suppliers as a condition of doing business, because their own type approval depends on the supply chain.
Documentation you must hold
Cybersecurity management system and software update management system documentation cascaded from the manufacturer, Article 30 records covering location, driving behaviour and biometric data from driver monitoring, the Article 27 designation, and Data Act arrangements for user access to vehicle data.
Standards and testing
Cybersecurity testing under the R155 framework, over-the-air update validation, and for driver monitoring systems accuracy testing and, under the AI Act, the requirements applicable to safety components.
Language requirements
User-facing information in the language of the vehicle's market.
When it applies
Type approval requirements have applied to all new vehicles since July 2024. Data Act access provisions from September 2025.
How long records are kept
Vehicle data only as long as necessary, with location and driving behaviour histories a recurring point of criticism when retained indefinitely.
What happens if you do not comply
Loss of type approval for the vehicle, which is existential for the manufacturer and cascades contractually to suppliers, plus GDPR fines for the data processing.
Who enforces it
Type approval authorities, data protection authorities, and market surveillance for the Data Act.
Where the boundary lies
Vehicle data belongs to a contested space: the Data Act gives users rights to data generated by use of the vehicle, while manufacturers control the technical access. Driver monitoring cameras process biometric data inside the cabin, which requires careful basis analysis.
Questions we are asked
- Does the AI Act apply to driver assistance?
- Systems that are safety components of vehicles follow the automotive framework, with the AI Act applying from August 2027 for products under Annex I legislation.
- Who owns vehicle-generated data?
- The Data Act gives users the right to access and share data generated by their use of a connected product, which includes vehicles, subject to defined conditions.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom