Your customer’s name, address, Social Security number, driver’s license number, and even biometric data like fingerprints or facial images can be part of the data collected in today’s connected vehicles.
It’s all considered personally identifiable information (PII) and is often shared with third parties, such as insurers, software suppliers, vehicle history services and trading partners. Sensitive information is then stored in vehicles and/or the cloud, making it susceptible to cyberattacks and data breaches.
While the Federal Trade Commission provides guidelines for businesses to protect personal information, and some regulations offer control over the data businesses collect — such as the EU’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act of 2018 (CCPA) — most consumers are unaware of the risks. Meanwhile, collision repair facilities are facing the challenge of safeguarding this data.
This is becoming increasingly important for the collision repair industry to understand and address with the introduction of connected autonomous vehicles (CAVs). CAVs are next-generation vehicles that combine self-driving capabilities with communication/connectivity.
“The integration of connected autonomous vehicles (CAVs) has significantly enhanced driving convenience, but it has also raised serious privacy concerns, particularly regarding the personal identifiable information (PII) stored on infotainment systems,” according to an article in the Journal of Sensor and Actuator Networks written by Jason Carlton, who recently received a master’s degree in information systems and technology, and Hafiz Malik, professor of electrical and computer engineering and associate dean for graduate, education and research in the Electrical Engineering Department at the University of Michigan-Dearborn, in Michigan.
The article, “Safeguarding Personal Identifiable Information (PII) after Smartphone Pairing with a Connected Vehicle,” outlines the challenges of removing PII from rental vehicles and highlights studies examining rental vehicle users’ awareness of PII.
In one study, the authors rented three vehicles from different providers and learned that the PII had not been removed from previous renters.
In another study, 83.3 percent of the 120 respondents indicated they highly value personal information, but the majority didn’t know they needed to delete PII after using the vehicle.
“This lack of awareness further exacerbates the risks associated with PII leakage,” Carlton and Malik commented in their article.
Through their research, the authors recognized and highlighted the challenges of protecting the PII that intelligent transportation systems collect, store and process.
What Repairers Should Know About Protecting Customer PII
Laur says once a repair facility accesses vehicle data, it assumes responsibility for protecting any personal information tied to that vehicle.Brandon Laur, president of CCi Global Technologies, said that data ownership and customer privacy remain among the most complex and important topics facing the collision industry today.
“Protecting a customer’s personally identifiable information (PII) is not optional — it is a fundamental responsibility shared across the entire collision repair ecosystem,” he emphasized. “The sensitivity and potential impact of PII exposure place a clear duty on repair facilities and their technology partners to ensure information is handled with the highest level of care and integrity.
To help address these concerns, Laur recommended that collision repair facilities actively vet who has access to customer data within their systems, particularly when evaluating Software as a Service (SaaS) solutions and third-party data integrations. This includes understanding which providers are connected via data pumps, what data is being collected, how it is processed, and whether it is stored, shared, or monetized in any way. Reviewing terms and conditions, data usage policies, and security standards should standard practice for any technology decision, according to Laur.
Pete Tagliapietra, managing director of DataTouch, advised collision repair facilities to be aware of the information privacy laws that may be in effect in the state(s) they operate in.
“Each state that has enacted a law varies,” Tagliapietra explained. He pointed out the potential legal liability that shops face when they inadvertently or intentionally share customer information with supply chain products and services.
“It is well established that the PII included on estimates is being aggregated and sold to third-party entities,” he commented.
In light of these concerns, Laur said that transparency is critical. “Not all organizations operate with the same level of openness, and as economic pressures increase — particularly in tighter revenue environments — there is a heightened risk of ethically questionable data practices,” he shared.
Laur said that selling or leveraging customer data to offset shortfalls is not only irresponsible, but it also undermines trust across the industry.
“As an industry, we must hold ourselves and our partners accountable to higher standards,” he pointed out. “By demanding transparency, enforcing strong data governance, and choosing partners who prioritize ethical data stewardship, we collectively protect consumers, reinforce trust, and ensure the long-term health and credibility of the collision repair industry. This shared commitment is essential to sustaining progressive growth and safeguarding our industry’s future.”
Who Owns the Data?
Tagliapietra says vehicle owners retain ownership of personal data, even when repairers access it during estimates and repairs.When it comes to who owns the data, Tagliapietra said that copyright law is clear: the creator of the information output owns it.
“As such, the shop owns the estimate data, but the named vehicle owner owns the PII,” he said. “The fact that the shop used third-party resources is not a factor as long as the third party that was a part of the output is identified.”
Tagliapietra noted that the estimating system is always identified within the body of the estimate.
Laur pointed out that there are numerous agreements, integrations, and data-sharing relationships across the collision repair ecosystem. “In some cases, these agreements can appear to contradict one another, creating uncertainty around ownership and responsibility,” he explained.
At a foundational level, CCi contends that PII belongs to the vehicle owner, while data generated by the collision center — such as operational, repair, and workflow data — belongs to the collision center. At the same time, Laur said that insurers rightfully own policy-related information, and OEMs may also have legitimate rights to certain data, particularly in scenarios involving leased vehicles or vehicles being returned to a dealer for resale.
“These overlapping interests highlight the need for greater clarity and alignment across all stakeholders,” noted Laur. “There is a meaningful opportunity for the industry to come together to establish clearer standards and definitions around data ownership, access, and usage.”
He mentioned that trusted organizations, such as CIECA, along with other industry groups, are well-positioned to help lead these conversations and create frameworks that all parties can align with.
“Until broader standards are defined, collision centers play a critical role as stewards of customer data,” said Laur. This includes safeguarding PII and proactively engaging SaaS partners and data providers to clearly define how PII is handled, protected, and governed within their platforms.
“Asking the right questions, demanding transparency, and holding partners to clearly articulated standards are essential steps in protecting customers, building trust, and strengthening the industry,” he advised.
Developing a Privacy & Data Security Plan
Barry says shops should limit data access to only what is necessary for a transaction, rather than sharing or storing data broadly.Paul Barry, the executive director of the Collision Industry Electronic Commerce Association (CIECA), agreed that information and data privacy are of vital concern to all segments of the industry, particularly as they relate to the PII of both businesses and consumers.
To the extent possible, the organization is committed to developing standards that support the concepts of data segregation and segmentation, enabling member companies that implement CIECA standards to share only the data necessary to complete the defined transaction.
Barry noted that CIECA strongly supports all its member companies’ efforts to develop and implement comprehensive information privacy and data security plans. According to CIECA’s position on information privacy, a comprehensive information program consists of three main components:
- Data Security Plan: The physical and logical protection against unauthorized access to systems and networks.
- Data Privacy Plan: Internal policies and procedures designed to protect how data is used and shared.
- Data Segregation/Segmentation: The segmentation of information and data to limit what type of data may be shared outside the organization.
“It is incumbent upon every organization to ensure they have a data security plan and a data privacy plan in place, which includes data sharing agreements that ensure PII is not being misused or shared inappropriately,” said Barry.
Stacey Phillips Ronak