When Codes Takes the Wheels India’s Legal Opportunity in the Age of Connected Mobility

Prerna Kapoor
Author

The next major automobile recall may not begin with smoke arising from an engine or a mechanical error or fault. It may begin with a malicious line of code crossing a national border, entering thousands of vehicles through a compromised software update and turning connectivity into vulnerability. At that moment, the familiar boundaries between a defective product, a data breach, a cyberattack and road safety event will collapse. The possibility captures the predominant regulatory **challenge** confronting the automobile sector across globe. The modern vehicles is no longer merely a mechanical machine regulated at a factory gate. It is a cyber physical legal object: part product, part software platform, part data ecosystem and part continuing services. Its safety not only depends upon strength, crash test and components but also on algorithms, cloud infrastructure, telecommunication networks and suppliers that are located across several jurisdictions.
For India, this **transformation** carries marked distinctiveness. The country has automotive manufacturing scale, a deep software-service base and an ambition to Make India a Global Manufacturing Hub. The decisive question is whether India will treat data and cybersecurity rules as costs imposed from abroad or use them to move from cost-efficient manufacturing to trusted mobility.
A connected vehicle may record location, driving behaviour, diagnostics, battery performance, charging history, voice command and interactions with other mobile applications. Such data can enable predictive maintenance, safer fleets and better vehicle designs. It can also reveal intimate patterns of an individual’s life. The law should answer the simplistic question, “Who owns the data?” Data is not always governed like a physical property. Hence the sharper question can be who determines its purpose and means of processing, whether it identifies an individual, who permits its collection and when it must be erased.
In India, the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 provide the principal **framework** where vehicle information constitutes digital personal data. An OEM, fleet operator, insurer or connected-service provider may become a Data Fiduciary when it determines why and how such data is processed. This brings duties relating to notice, consent or another permitted use, security safeguards, breach response and the rights of Data Principals.
Compliance cannot be reduced to a dense clause in a purchase agreement. The driver may not be the owner who accepted the original terms; a passenger may never see the dashboard notice and a used-car purchaser may inherit the previous owner’s stored information. Privacy must therefore be engineered across the vehicle’s lifecycle. Data necessary for safety or warranty administration must be distinguished from data collected for profiling, advertising or monetisation.
India’s Information Technology Act, 2000 and the 2022 Directions issued by CERT-In under section 70B form a general cybersecurity layer. Specified incidents must be reported to CERT-In within six hours, alongside obligations relating to logs and regulatory cooperation. An automotive company must therefore decide quickly whether an anomaly is an engineering fault, a reportable cyber incident or both. The sector-specific **framework** is also evolving. AIS-189 addresses vehicle cybersecurity and cybersecurity-management systems, while AIS-190 concerns software updates and software-update-management systems. A June 2026 draft amendment to the Central Motor Vehicles Rules proposed their phased application. Its draft status must be stated accurately, but its direction is unmistakable: regulation is moving away from a single pre-sale test and toward continuous institutional responsibility. The Consumer Protection Act, 2019 adds another dimension. Its product-liability provisions can reach manufacturers and in appropriate circumstances, sellers and service providers where a defective product or deficient service causes harm. In a software-defined vehicle, failure to correct a known vulnerability, warn users or securely deliver an update may become relevant to the standard of reasonable care.
Responsibility is complicated by the supply chain. An OEM rarely writes every line of code embedded in a vehicle, yet consumers and regulators will look first to the brand on the bonnet. Supplier contracts must therefore address secure development, software provenance, vulnerability disclosure, audit rights, incident cooperation and long-term support. Indemnities cannot replace technical capacity or continuing oversight.
Export **Opportunity** and the extraterritorial vehicle
For Indian exporters, cybersecurity is becoming a form of digital homologation. UNECE Regulation No. 155 requires a cybersecurity-management **approach**, while Regulation No. 156 addresses software updates and their management. In jurisdictions applying these rules, a mechanically sound vehicle may still fail to obtain or retain market access if the manufacturer cannot demonstrate governance, risk assessment and lifecycle documentation. International standards such as ISO/SAE 21434 on automotive cybersecurity engineering and ISO 24089 on software updates are not statutes. Nevertheless, they may influence contracts, regulatory expectations and judicial assessments of due diligence. Their legal importance lies not in formal compulsion alone, but in their ability to shape the content of reasonable conduct.
The European Union illustrates the density of the emerging regime. The General Data Protection Regulation governs personal data, the EU Data Act gives users greater control over data generated by connected products and facilitates access by authorised third parties and the revised Product Liability Directive expressly brings software and cybersecurity vulnerabilities into the assessment of product defectiveness. The law thus demands two things that can appear contradictory: manufacturers must prevent unauthorised access while avoiding unjustified control over data that users are entitled to obtain or share.
Other markets create different pressures. The United States has adopted connected-vehicle supply-chain restrictions concerning specified software and hardware linked to China or Russia. China, meanwhile, applies its Personal Information Protection Law, Data Security Law, Cybersecurity Law and automotive-data measures. An Indian exporter must know not only what its vehicle collects, but where the data travels, which entity can access it and who developed each critical digital component. A vehicle may leave India physically while remaining legally connected to several jurisdictions.
A legal architecture for trusted mobility
India should respond through coordinated legal design rather than fragmented compliance.
First, the Government should align the DPDP **framework**, CERT-In directions, motor-vehicle regulation and consumer law through a coherent automotive data and cybersecurity policy. Clear institutional responsibility among MeitY, MoRTH, CERT-In and testing agencies would reduce regulatory overlap.
Second, OEMs should make privacy and cybersecurity design requirements, not post-production audits. Every connected function should be supported by data mapping, risk assessment and a software bill of materials. Safety, cyber and privacy teams should operate through a unified incident-response structure.
Third, lifecycle duties require greater legal clarity. Consumers should know the minimum period of security support, the consequences of declining a critical update and the procedure for vulnerability disclosure, recalls and end-of-support vehicles. The power to alter a vehicle remotely must carry a corresponding duty to test, secure and document the alteration.
Fourth, smaller suppliers must not become casualties of compliance. **Model** contractual clauses, shared laboratories, skills programmes and affordable certification can help them satisfy global expectations. The resilience of an exported vehicle is ultimately limited by the weakest participant in its software supply chain. Finally, Indian exporters should build one high global baseline, supplemented by jurisdiction-specific modules. Compliance evidence data maps, update histories, supplier audits and incident records should be treated with the same seriousness as a crash-test certificate.
The automobile of the future will not be judged only when it leaves the assembly line. It will be judged every time it collects data, receives an update or crosses a digital border. “Made in India” must therefore come to signify more than manufacturing efficiency. It must signify lawful data use, resilient code and accountability over time. Cybersecurity law is not merely a restraint on India’s automotive ambition; properly understood, it is the bridge from “Make in India” to “Trust in India.”





