The DRIVER Act would require motor vehicle manufacturers to give vehicle owners secure, real-time access to motor vehicle data generated by their vehicles, and to allow owners joint control over that data at no additional cost beyond the vehicle purchase price. The bill says owners must be able to access data through onboard ports and wireless transmission where available, use the data for any lawful purpose, authorize third-party access, and do so without paying decryption or licensing fees. It also requires access in a way that supports deletion of user data stored in the vehicle and that complies with voluntary automotive cybersecurity standards.
The bill also limits how manufacturers and certain fleet owners may sell “covered data,” requiring clear and conspicuous opt-out opportunities for owners and, in some cases, drivers. It prohibits knowing sales of motor vehicle data to specified foreign adversary countries, including China, Russia, Iran, North Korea, and Venezuela, while listing numerous exceptions for safety, diagnostics, recalls, cybersecurity, warranty work, emergency response, investigations, and other operational uses. The bill defines covered data broadly to include personal data tied to biometric identifiers, precise geolocation, and driver behavior, and it excludes deidentified, pseudonymous, aggregate, or publicly available information.
If enacted, the bill would create a federal access-and-control framework for vehicle-generated data and would make violations enforceable by the Federal Trade Commission as unfair or deceptive acts or practices. It would also preempt state and local laws that relate to the bill’s vehicle-data access requirements, limiting states’ ability to impose different or additional rules in this area. The measure would affect automakers, fleet owners, data processors, and third-party service providers that rely on vehicle data, while preserving certain manufacturer business information and operational exceptions.
No committee transcript or vote record is available, so there is no recorded floor or committee sentiment to summarize. Based on the bill text, the measure appears designed to appeal to vehicle owners and aftermarket service providers by expanding data access and limiting manufacturer control, while also addressing privacy, cybersecurity, and national security concerns. The introduction by multiple House members and referral to the Energy and Commerce Committee indicate the bill is in an early stage of consideration.
The main points of contention are likely to be the scope of owner access, the extent of federal preemption, and how much control manufacturers retain over vehicle data and cybersecurity protections. Automakers may object to mandatory real-time access, joint control, and limits on their ability to monetize or restrict data, while privacy advocates may focus on whether the bill’s exceptions are broad enough to protect consumers. Fleet owners and employers may also scrutinize the driver opt-out rules and the carveout for commercial or governmental fleet vehicles, especially where driver behavior data could be used for profiling or harmful decisions.