Your driving data – private or public property?
This story first appeared in the May issue of EVtalk – CLICK HERE to download the magazine FREE

Whether drivers are aware of it or not, vehicles in our fleet are becoming connected to the internet at an increasing rate.
New vehicles are equipped with a growing number of sensors which, combined with the onboard computer’s AI, sift through an amazing amount of data. The stated intentions of connected vehicles are good; for instance, the ability to share traffic and road conditions.
There are, however, other potential uses. Like the monetisation of your search activity or Facebook data, data on your location, behaviour, and driving habits can be monetised. Like this Facebook data, data generated and collected in the real world should be part of the privacy debate.
It has been estimated that a single connected car will collect over 25GB of data per hour. In New Zealand, the average adult spends almost five hours a week in a vehicle.
This would mean a connected car would likely collect over six terabytes of data per person over a year. If New Zealand’s fleet of four million vehicles were fully connected, this could amount to over 25 exabytes of data collected per year (1 exabyte (EB) = 1,000 petabytes (PB) = 1 million terabytes (TB) = 1 billion gigabytes (GB)).
We are assured that this data collection will lead to a better and safer driving experience.

The data, we are told, will be used by the cars themselves to advise us on better routes and parking, but can also be provided to civil planners to identify high-risk or inefficient roads.
It is very likely, however, that another objective is to collect data on consumer behaviours and preferences that could be sold to outside vendors for marketing purposes. This would look very much like what we expect from Google and Facebook today.
In my role as a policy analyst for the imported vehicles sector, I have been part of debates on this very topic – the importance of privacy to the general public.
It seems to some that the success of these internet giants in collecting and monetising our data proves the decreasing importance of privacy and illustrates the true potential of selling the fruits of our data back to us.
Car manufacturers and other analytics companies are betting that if they can position the solution right, offering discounts and coupons on a foundation of safety-related features, not only will the public happily sign their data away, the government will eventually mandate it.
Third parties interested in this data will include the obvious, such as insurance companies, panelbeaters, gas stations, city planners, restaurants, shopping centres and more.
As illustrated by the Facebook and the Cambridge Analytica fiasco, the potential to sell data to third parties is the greatest opportunity – and the greatest risk. Once that data is in the marketplace, who it goes to and why is no longer within our control.
While the risk today might be nominal, as AI evolves and proliferates, potential uses of that data are open to the imagination – and data available today will be archived forever.
Trunk sensor data could be used to see when and where people are buying goods, providing a metric for consumer sentiment. RFID chips on goods, which make shopping more convenient, can add detail to the nature of these goods.
Changes in driving behaviour can be used to inform creditors of a loss of job; on a wider scale, this could be used to predict a financial downturn. A broken-down vehicle could lead to pre-emptive loan offers. The options for collection and potential insights are endless – not all benign.
Companies and governments are being quick to point out that we have a choice to opt out of data sharing.
Unfortunately, it will be likely that drivers will not understand what they’re signing away. Of course, this is assuming that the manufacturers are not simply able to convince the government of the necessity of gathering the data, on the grounds of “safety” or “intellectual property”.
The data collected by a car about itself will be impossible to divorce from user behaviour; the two are innately intertwined. Allowing, or even mandating, the collection of one is allowing the other.
New Zealand’s new Privacy Bill is currently under discussion. It will replace the previous legislation. Public submissions are welcome until May 24, 2018.
I encourage anyone who is interested in this topic to read the proposed bill and make a submission.


Join the conversation