Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who is accountable for GDPR compliance when an…
Governance, Ownership & Risk

Who is accountable for GDPR compliance when an OEM controls vehicle data shared with service providers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

When an OEM determines the purpose and means of processing vehicle data, it acts as a data controller and carries direct accountability for compliance. That role includes implementing appropriate security measures, managing privacy obligations, and coordinating responsibilities with processors such as service providers. Shared data flows do not remove the OEM’s core duty to govern personal data properly.

Who bears responsibility when vehicle data moves from an OEM to service providers?

The accountability question is usually resolved by the role the OEM plays in deciding why vehicle data is collected and how it is used. If the OEM determines the purpose and means of processing, it remains the controller, even when processors or service providers handle parts of the flow. That means the OEM cannot outsource compliance simply by outsourcing operations.

Why controller status matters more than the data-sharing chain

Controller status determines who must be able to justify the processing, document lawful bases, keep notices aligned with actual use, and ensure security measures match the sensitivity of the data. In a vehicle ecosystem, that often means the OEM owns the privacy design, the governance model, and the accountability trail, while service providers act under instructions and contract terms.

Shared processing does not dilute the core rule: the entity deciding the processing remains accountable for the outcome. In practice, the OEM must still verify that each downstream party is limited to the processing scope it was given and that contractual controls reflect the real data flow, not just the commercial relationship.

What the OEM must govern in mixed OEM and provider processing

The most important work is not naming parties, but proving control over the full processing chain. That includes data minimisation, retention limits, access restriction, security of processing, and clear allocation of duties where a provider handles hosting, analytics, telematics support, customer service, or fleet operations. The contractual layer should match the operational layer, or accountability becomes difficult to defend.

For teams mapping the control environment, the useful question is whether the OEM can evidence that each service provider is acting within a defined purpose and that the OEM still oversees the lifecycle of the data. NHIMG’s Identity Security Regulatory Map is a practical reference for linking governance duties to compliance obligations, and the Identity Data Privacy and Consent Guide is useful where shared data flows depend on lawful collection, consent handling, and retention discipline.

How responsibility should be split without losing accountability

Processors can carry operational duties, but they do not replace the controller’s accountability for the overall compliance posture. The OEM should treat every service provider as part of its governed processing environment, with instructions, auditability, and exit expectations built into the relationship from the start. If the provider can change how data is used without OEM approval, the operating model is already misaligned.

At the governance boundary, it helps to distinguish who makes decisions from who executes them. NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives is useful for understanding how auditability and governance expectations apply when access and processing responsibilities are distributed across systems and parties.

Risk and Threat Considerations

The main risk is false delegation, where an OEM assumes a service provider has absorbed privacy and security obligations that still sit with the controller. That creates exposure in notice accuracy, retention, access control, breach handling, and vendor oversight, especially when vehicle data is enriched, combined, or reused beyond the original purpose.

Failure mechanism: The OEM loses practical visibility into downstream use, or approves a provider arrangement that exceeds the stated purpose, which weakens lawful processing, security governance, and accountability evidence.

Impact: The result can be compliance failure, contractual dispute, uncontrolled data sharing, and regulatory scrutiny because the organisation responsible for deciding the processing cannot show that it controlled the processing chain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

GDPR and ISO/IEC 27001:2022 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
GDPRArt. 5 — Principles relating to processing of personal dataThe question turns on controller accountability and lawful processing of vehicle personal data.
Art. 24 — Responsibility of the controllerDirectly addresses who remains accountable when processing is outsourced to service providers.
Art. 28 — ProcessorCovers processor instructions and contractual controls for service providers handling OEM data.
Recommendation — Apply Art. 5 to evidence lawful, purpose-limited processing across the OEM and provider chain. Assign controller ownership and maintain records proving oversight of each processor relationship. Use Art. 28 terms to constrain provider processing, audit rights, and subprocessor use.
ISO/IEC 27001:2022A.5.15 — Access controlAccess restriction is central to governing who can reach shared vehicle data.
A.5.19 — Information security in supplier relationshipsService providers are suppliers whose security obligations must be governed contractually.
A.5.34 — Privacy and protection of PIIShared vehicle data may include personal data that requires explicit privacy governance.
Recommendation — Define and enforce access rules for every party handling vehicle-data sets. Set security requirements and oversight for every provider processing OEM data. Embed privacy obligations into processing design, retention, and disclosure controls.

Practitioner Guidance

What to verify: Confirm that the OEM can show controller decisions, provider instructions, retention limits, and security obligations for every material vehicle-data flow. If those artefacts do not line up with the actual architecture, the compliance position is weaker than the contract language suggests.

Decision rule: If the OEM chooses the purpose or means of processing, treat it as accountable for compliance even where the provider runs the platform or performs the service. Only the execution can be delegated; the governing responsibility cannot.

Practitioner takeaway: Shared processing changes the operating model, not the locus of accountability, so the OEM must be able to demonstrate control over purpose, scope, and downstream use.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org