EV Technology

EV Telematics and Data Privacy in India: Compliance Guide

Navigating DPDP Act Requirements for Connected Electric Two and Three-Wheelers

Manju Verma 27 November 2026 14 min read
Telematics Data Privacy DPDP Act Connected Vehicles EV Compliance

Introduction

India's electric two and three-wheeler market has undergone a remarkable transformation. From bustling urban delivery fleets to last-mile connectivity solutions, connected EVs now form the backbone of sustainable mobility across Indian cities. But with connectivity comes data—vast streams of location trails, battery diagnostics, riding patterns, and usage logs that flow from every telematics-enabled vehicle.

For EV manufacturers, fleet operators, and technology providers, this data represents enormous value: enabling predictive maintenance, optimising fleet efficiency, improving battery life, and enhancing rider safety. Yet it also represents significant regulatory responsibility under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the accompanying DPDP Rules, 2025.

The DPDP Act has fundamentally shifted how automotive businesses must approach data. As one industry analysis noted, automakers must now treat personal data as a regulated asset—rethinking systems so that consent, transparency, and data minimisation are embedded from the first line of code 10. This guide provides a practical, compliance-focused framework specifically for the Indian 2W and 3W EV ecosystem.

Why Telematics Matters for Indian EVs

Telematics units in modern electric scooters, bikes, and three-wheelers are far more than GPS trackers. They serve as the digital nervous system of the vehicle, collecting data from the Battery Management System (BMS), motor controller, onboard sensors, and connectivity modules.

  • Fleet efficiency: Real-time tracking, route optimisation, and utilisation analytics for commercial 3W fleets
  • Battery health: State of Charge (SoC), State of Health (SoH), cell balancing data, and thermal management logs
  • Predictive maintenance: Early fault detection in motor, controller, and charging systems
  • Rider safety: Accident detection, harsh braking alerts, and geofencing capabilities
  • OTA updates: Remote firmware upgrades for BMS, controllers, and infotainment systems
  • Charging behaviour: Session data, energy consumption patterns, and charging infrastructure utilisation

For fleet operators managing dozens or hundreds of electric three-wheelers, telematics is not optional—it is essential for unit economics. For individual EV owners, connected features like remote battery monitoring and navigation enhance the ownership experience. But each data point generated carries privacy implications under Indian law.

The DPDP Act Framework for EV Data

The DPDP Act applies to any entity processing digital personal data within India. For the EV ecosystem, this covers a wide range of stakeholders:

  • EV manufacturers (OEMs) and their telematics suppliers
  • Fleet operators and logistics companies
  • Mobility-as-a-Service platforms and vehicle subscription services
  • Dealers and authorised service centres accessing vehicle diagnostics
  • Charging network operators processing charging session data

Under the Act, EV manufacturers and fleet platforms typically qualify as Data Fiduciaries—entities that determine what data is collected, how it is processed, and with whom it is shared 4. Third-party cloud providers, telematics vendors, and analytics firms usually act as Data Processors. However, primary accountability for compliance remains with the fiduciary.

Large OEMs, EV platforms, and ride-hailing companies with significant telematics operations may be notified as Significant Data Fiduciaries (SDFs), subjecting them to enhanced obligations including Data Protection Impact Assessments and periodic audits 6.

What Data is Collected by 2W and 3W EVs

Understanding the data categories collected by telematics units is the first step toward compliance. For Indian electric two and three-wheelers, typical data streams include:

Data Category Examples Privacy Risk Level
Location Data GPS coordinates, travel routes, frequent destinations High
Riding Behaviour Speed, acceleration, braking patterns, cornering High
Battery Diagnostics SoC, SoH, cell voltages, temperature logs Medium
Charging Behaviour Charging sessions, location of charging, duration Medium
Vehicle Identifiers VIN, registration number, ECU IDs Low-Medium
Usage Patterns Time of use, trip frequency, duration Medium
Mobile App Data Account info, preferences, notification settings Varies

Location data deserves special attention. As legal analysis has emphasised, location data can reveal an individual's home and workplace, daily routines, and even religious, medical, or political inferences. Continuous tracking significantly heightens the risk of harm, making regulators particularly sensitive to misuse or over-collection 4.

Consent Requirements Under DPDP

The DPDP Act sets a high bar for consent. It must be free, informed, specific, unambiguous, and capable of withdrawal. Generic disclosures buried in user manuals or lengthy terms of service are unlikely to meet statutory standards 6.

For EV manufacturers, this means consent mechanisms must be purpose-specific. Collecting location data for navigation does not automatically permit using that same data for insurance scoring or targeted advertising. Each distinct purpose requires fresh, explicit consent.

Consent is no longer a pop-up; it is the new fuel that powers every layer of the automotive data engine. The traditional automotive workflow, built on implicit assumptions and broad authorisations, is fundamentally incompatible with India's new privacy architecture.

Practical implementation requires consent layers built into the Human-Machine Interface (HMI)—whether through the vehicle's display console or the companion mobile app. Customers must be able to easily understand what they are sharing and revoke consent as simply as they granted it.

Purpose Limitation and Function Creep

One of the most significant compliance risks for EV businesses is function creep—the gradual repurposing of data collected for one purpose to serve another. Telematics data collected for vehicle diagnostics and safety may be tempting to repurpose for:

  • Insurance risk scoring based on riding behaviour
  • Targeted advertising to EV owners
  • Cross-selling of accessories, services, or financing
  • Sharing with third-party data brokers or analytics firms

Under the DPDP Act, each of these secondary uses requires fresh, explicit consent. Sharing driver behaviour data with insurers, financiers, or advertisers without clear consent exposes companies to enforcement risk, even where such practices are commercially attractive 6.

For fleet operators, the distinction between vehicle data and personal data is equally important. While fleet vehicles are business assets, the riders operating them are individuals whose personal data—location trails, riding patterns, break times—must be protected. Consent from the fleet company does not automatically cover individual rider data.

Data Retention and Deletion Obligations

The DPDP Act introduces a storage limitation principle: personal data must be deleted once its purpose is fulfilled. However, this creates a tension with other legal obligations. As one analysis of the DPDP regime noted, privacy and preservation must now coexist, not compete 2.

For EV businesses, this means developing a nuanced retention policy that balances:

  • DPDP storage limitation: Delete personal data when purpose is served
  • Statutory retention: Tax, warranty, and product liability laws may require longer retention
  • Evidentiary needs: Potential warranty disputes or accident investigations
  • AIS-156 requirements: BMS data logging for battery traceability and safety analysis

A practical approach involves data classification—categorising telematics data by retention requirement and applying differential policies. Anonymised or aggregated battery performance data, for instance, may be retained indefinitely for product improvement, while personally identifiable location data should be deleted on a shorter schedule.

Cross-Border Data Transfer Challenges

India's DPDP framework follows a negative list model for cross-border data transfers: data flows are permitted until a country is blacklisted. This creates operational uncertainty for global EV manufacturers and telematics providers using foreign cloud infrastructure or analytics platforms.

If a destination country is suddenly added to the restricted list, OEMs may be forced to rapidly re-architect global data routes. Connected vehicles constantly push data to global servers, foreign telematics partners, and parent-company systems—making this a significant compliance checkpoint 10.

Practical mitigation strategies include building dual-cloud architectures with mirrored data centres in India, maintaining fallback workflows for instant suspension of foreign transfers, and negotiating contracts with global vendors that ensure data does not transit through prohibited geographies.

Cybersecurity Standards: AIS-189 and AIS-190

Data privacy compliance must be underpinned by robust cybersecurity. India has developed automotive-specific standards aligned with global frameworks:

  • AIS-189: Establishes a Cyber Security Management System (CSMS) for OEMs, requiring identification, assessment, and mitigation of cyber risks across the vehicle lifecycle. Applicable to vehicles with ECUs handling critical functions, including select L7 two-wheelers 7
  • AIS-190: Focuses on Software Update Management System (SUMS), mandating cryptographic signing of firmware, rollback mechanisms, and audit logs for OTA updates 7

These standards mandate hardware-level security such as Hardware Security Modules (HSMs), Trusted Execution Environments (TEEs), and Secure Elements for secure key storage, encrypted communications, and tamper-resistant OTA authentication 7.

The urgency of these measures was underscored by CERT-In's 2026 report of cybersecurity vulnerabilities in low-cost e-rickshaw BMS units, where default or absent authentication credentials allowed unauthorised individuals to connect via publicly available mobile applications and potentially disable a moving vehicle 1. This incident illustrates why privacy and security must be addressed together.

Privacy-by-Design for EV Manufacturers

The DPDP Act pushes automakers toward a privacy-by-design architecture where data protection is not an afterthought but a foundational engineering principle 10. For 2W and 3W EV manufacturers, this translates into concrete design decisions:

  1. Data minimisation: Design telematics units to collect only functional data rather than broad datasets. If a sensor can perform its function without transmitting personal data, make that the default.
  2. Edge processing: Perform anonymisation at the vehicle level before transmitting data to cloud systems. Aggregate riding behaviour data locally, sending only statistical summaries rather than individual trip details.
  3. Granular consent architecture: Build consent management into the HMI, allowing users to toggle individual data sharing purposes without disabling core vehicle functions.
  4. Separation of data streams: Isolate entertainment/infotainment data from telemetry and diagnostics data, ensuring granular consent for each function.
  5. Retention automation: Implement automated deletion schedules based on data classification, with audit logging to demonstrate compliance.
  6. Encryption by default: Encrypt all in-transit and at-rest telematics data, with secure key management using hardware security modules.

Compliance Checklist for Fleet Operators

Fleet operators of electric two and three-wheelers face unique compliance challenges. They process both vehicle data (as business assets) and rider data (as personal data). The following checklist provides a practical framework:

Compliance Area Action Required Priority
Data Mapping Document all telematics data flows, including what is collected, where it is stored, and who has access High
Consent Framework Implement rider consent for location tracking, behaviour monitoring, and any secondary use of rider data High
Purpose Limitation Define and document the specific purposes for which rider data is collected; ensure no undisclosed repurposing High
Retention Policy Establish differentiated retention periods for vehicle data vs. personal rider data Medium
Vendor Agreements Ensure all telematics vendors and cloud providers have DPDP-compliant data processing agreements High
Breach Response Develop 72-hour breach notification workflow as required under DPDP Rules and CERT-In guidelines High
Consent Manager Deploy consent manager integration as mandated under DPDP Rule 4 Medium
Privacy Impact Assessment Conduct DPIAs for all telematics features involving personal data Medium

Practical Implementation Steps

Moving from compliance awareness to operational readiness requires a phased approach. For EV businesses at any stage of telematics deployment, the following roadmap provides actionable guidance:

  1. Phase 1 – Discovery (Weeks 1-4): Conduct a comprehensive data inventory. Identify every telematics data point generated by your 2W/3W fleet or product. Map data flows from vehicle to backend, noting all storage locations and third-party access points.
  2. Phase 2 – Gap Assessment (Weeks 5-8): Compare current practices against DPDP requirements. Identify gaps in consent mechanisms, retention policies, cross-border transfers, and security controls. Prioritise high-risk gaps involving location and behavioural data.
  3. Phase 3 – Technical Remediation (Weeks 9-16): Implement privacy-by-design changes. Deploy consent management systems, configure data minimisation at the telematics unit level, establish retention automation, and encrypt all data in transit and at rest.
  4. Phase 4 – Policy and Documentation (Weeks 12-20): Draft privacy notices, consent forms, retention schedules, and breach response protocols. Execute DPDP-compliant data processing agreements with all vendors.
  5. Phase 5 – Training and Audit (Ongoing): Train engineering, product, and operations teams on DPDP obligations. Establish audit procedures to verify compliance and identify emerging risks.

Conclusion

India's electric two and three-wheeler revolution is creating unprecedented opportunities for sustainable mobility. Telematics-enabled connectivity enhances safety, efficiency, and user experience. But connectivity without privacy is not sustainable.

The DPDP Act is not merely a compliance burden—it is an opportunity for the Indian EV industry to build trust with customers, differentiate on privacy, and establish global best practices. As SIAM leadership has emphasised, innovation must be done within the limits of customer data privacy and security 3. The organisations that thrive will be those that treat privacy as a product feature, not a legal checkbox.

For EV manufacturers, fleet operators, and technology providers, the path forward is clear: embed privacy-by-design from the first line of code, implement robust cybersecurity aligned with AIS-189 and AIS-190, and build consent architectures that respect the Indian rider's right to control their personal data.

Data privacy in connected EVs is not about restricting innovation—it is about building the trust infrastructure that allows sustainable mobility to scale responsibly. The 2W and 3W segment, which carries millions of Indians daily, deserves the highest standards of data protection.

Manju Verma
Manju Verma

Manju Verma

Founder EVXpertz, EV Technologist & Engineering Leader

Manju Verma is an engineering leader and EV technology enthusiast focused on building scalable platforms, AI-driven diagnostics, and next-generation electric mobility solutions.

Frequently Asked Questions

AIS-189 establishes Cyber Security Management System (CSMS) requirements for OEMs, applicable to vehicles with ECUs handling critical functions, including select L7 two-wheelers. AIS-190 mandates Software Update Management System (SUMS) requirements for OTA-capable vehicles, including cryptographic signing, rollback mechanisms, and audit logs.
The DPDP Act's storage limitation principle requires deletion once the purpose is fulfilled. However, other laws (tax, warranty, product liability) may mandate longer retention. AIS-156 also requires BMS data logging for battery traceability. The practical approach is data classification with differential retention policies—shorter for personally identifiable location data, longer for anonymised battery performance data.
Back to all articles