
BMW collecting vehicle data in EU for safety upgrades; firm shares OEM data privacy policies research

BMW has added detail on its expansion of driver assistance technologies and active safety systems, available on the new X3 and i3, X5, and 7 Series, as well as subsequent new models and model updates.
Since April 2026, the BMW Group has been collecting image data from real-world traffic situations via European Union customer vehicles. The OEM says the images, along with extensive virtual testing using simulations and physical validation with its fleet of development vehicles, can “provide significant added value for the continuous improvement and further development of driver-assistance systems.”
A BMW press release notes that it only uses image data from customers’ vehicles who have consented, and collection is carried out in compliance with all data protection regulations.
“Thanks to BMW software updates, customers and road users will benefit from over-the-air system improvements that can be implemented in the future using the image data collected from real-world traffic situations,” the release states.
Compliance with applicable data protection regulations is a top priority throughout the entire data collection and use process. The BMW Group provides information on this topic on a new website featuring the relevant privacy notices.
BMW says data collection for further development of its vehicle driver assistance functions focuses exclusively on specific traffic situations in which the systems can be particularly beneficial.
“These include, for example, collisions prevented by assistance systems during lane changes on the highway, the activation of the emergency braking assistant, heavy manual braking, or a sudden evasive maneuver by the driver,” the release states. “Only sensor and image data that is relevant to understanding the situation and further optimizing driver assistance systems is specifically collected. This includes images of the vehicle’s surroundings captured by the exterior cameras, data from the environmental sensors, and driving dynamics information such as speed, direction of travel, or steering angle.”
It adds that event-based video data may be collected from vehicles, limited to a maximum of 120 seconds per event, in unaltered form beginning in mid-September.
“The BMW Group has implemented ‘privacy-by-design’ measures for data processing,” the release states. “Before the data is used, the vehicle identification number is deleted immediately after transmission to the BMW IT backend, so that it is no longer possible to link the data to a specific vehicle. Under no circumstances do BMW systems identify individual road users. Unaltered image data is used to further develop driver assistance systems and semi-automated driving functions through machine learning.
“If authorized BMW employees need to access individual recordings for development purposes, faces or license plates of other road users contained in the image data are obscured prior to playback to the extent technically possible. The handling of data collected for this purpose is carried out in compliance with all applicable data protection requirements.”
In 2023, BMW took issue with customer data privacy and security accusations made in Mozilla Foundation research findings. Based on those findings, Mozilla said vehicles were the worst threat to data privacy that consumers faced.
According to Mozilla at the time, OEMs can collect sexual activity, immigration status, race, facial expression, weight, health, and genetic data, as well as where customers drive.
In response to the report’s release three years ago, BMW said it takes data privacy and security “very seriously.”
The brands evaluated were Mercedes-Benz, Nissan, BMW, Ford, Toyota, Tesla, Kia, Subaru, Chrysler, GMC, Cadillac, Dacia, Jeep, Lincoln, Acura, Fiat, Volkswagen, Dodge, Buick, Lexus, Honda, Audi, Chevrolet, Renault and Hyundai.
Mozilla determined Nissan was the worst offender, while BMW was considered one of the best.
The report stated that while customers may be able to opt out, doing so could mean losing full functionality of connected services — if they work at all without data use consent, according to Mozilla. Sometimes personally identifiable information (PII) can be deleted, but not every state in the U.S. gives consumers that right.
New findings from research firm All About Cookies show that the average car privacy policy requires college freshman-level education to understand.
BMW’s privacy policy has 11,111 words and would take about an hour to read, according to All About Cookies. It found that the policy is at a college freshman reading level.
“Despite being middle-of-the-road in terms of word count, the complexity of language in Tesla’s privacy policy makes it the hardest to read of any manufacturer, requiring the same level of comprehension as topics discussed in a 400-level college textbook (16th grade),” the report states.
It also found that some of what manufacturers collect has nothing to do with driving.
“Nissan claims exclusive rights to the carbon credits your EV charging generates,” the report states. “Kia’s policy lists citizenship status among the sensitive data it collects. Ford logs what you’re listening to, down to the title, artist, and genre.”
And Ford publishes the longest single privacy document of any major brand, at 18,588 words, according to the report. It states that Kia runs the longest overall, splitting more than 25,000 words across two separate policies.
The report also covers how OEMs collect data and who they share it with.
“While car companies send driver data to other branches of their parent company, such as dealerships and financing and insurance departments, they also send data to third-party companies and services,” the report states. “These typically include insurance companies, advertising and marketing networks, law enforcement, and data and analytics companies.”
It notes that in January, the FTC banned GM and OnStar from sharing this kind of data with outside consumer reporting agencies for five years and required them to get explicit permission to collect and share driver data for the next 20 years.
GM faces several lawsuits in relation to data collection and sharing that the report states could cost it millions in damages.
The topic of private personal information (PPI), another term for PII, on vehicles was discussed in July at a Collision Industry Conference (CIC) meeting.
According to Andrea Amico, Privacy4Cars founder and CEO, 90% of vehicles go to a salvage auction with PII accessible.
“Cars have become the third personal computing device that consumers use every day,” he said.
However, vehicles typically lack encryption or hidden controls compared to phones or computers, he added.
Amico said vehicles can collect personal data through cameras, microphones, GPS, and synced phones. He said data collected by vehicles includes call logs, garage codes, biometrics, contacts, and passwords.
Images
Featured image: The new BMW iX3 50 xDrive – Automated Driving with the BMW Highway/Motorway-Assistant (Provided by BMW Group)
