Connected Vehicle IP and Data Checklist: Data Rights, Supplier Terms, Feature Licensing, Telematics Privacy, and Aftermarket Access
By Casey Scott McKay ·
This checklist builds a connected vehicle IP and data position in the order that makes the later steps possible. Phase one splits vehicle data into diagnostic, journey, and occupant categories, because a single undifferentiated category cannot carry the different consents, retention rules, and access obligations each attracts. Phase two isolates the one category with an express statutory owner, the event data recorder window. The middle phases rebuild the connected services terms, set the telematics and parts access position before a legislature sets it, and work through supplier IP allocation, autonomy development terms, standard essential patent exposure, and escrow. The closing phases cover fleet and remarketing failures, cybersecurity and support life, litigation readiness, brand and model naming, and the registers and gates that keep the programme current.
IP and Technology > Information Technology | Checklist | Published 17 January 2026 - Updated 6 July 2026 | Casey Scott McKay - marksy.us
Summary. This checklist builds a connected vehicle IP and data position in the order that makes the later steps possible. Phase one splits vehicle data into diagnostic, journey, and occupant categories, because a single undifferentiated category cannot carry the different consents, retention rules, and access obligations each attracts. Phase two isolates the one category with an express statutory owner, the event data recorder window. The middle phases rebuild the connected services terms, set the telematics and parts access position before a legislature sets it, and work through supplier IP allocation, autonomy development terms, standard essential patent exposure, and escrow. The closing phases cover fleet and remarketing failures, cybersecurity and support life, litigation readiness, brand and model naming, and the registers and gates that keep the programme current.
Keywords: connected vehicle checklist · data category inventory · event data recorder policy · connected services terms · household driver problem · subscription feature disclosure · over the air update governance · supplier IP register · tooling ownership · escrow release conditions · standard essential patent indemnity cap · design filings on visible parts · parts authentication policy · telematics access programme · fleet monitoring notice · remarketing data deletion · log retention policy · subpoena response · open source bill of materials · model name clearance
How to use this checklist
| Field | Detail | |---|---| | Who runs it | Product counsel with connected services, privacy, purchasing, aftersales, and engineering | | When | Before a connected feature launches; on each platform programme; annually thereafter | | Time required | Six to eight weeks for a first pass across one platform | | Gates | Data inventory complete; terms rewritten by category; supplier terms executed before production | | Output | A data inventory, rewritten services terms, four registers, and an access policy | | Companion documents | Advising an Automotive or Mobility Business and The Car That Reports Back |
The matter. A vehicle manufacturer is launching a platform with over-the-air updates, three subscription features including one that unlocks installed hardware, a driver assistance system developed jointly with a tier-one supplier trained on fleet-collected imagery, and a usage-based insurance partnership. Its connected services terms were drafted six years ago for a navigation service and refer throughout to "vehicle data". Engineering has enabled four telemetry streams for debugging that no policy mentions. Aftersales gives diagnostic tools to independent repairers in some regions and not others, informally. Two states have telematics access bills pending. A used vehicle was recently delivered to a customer with the previous owner's account still paired. Nobody can produce an open source bill of materials for the head unit.
Phase 1. Split the data into three categories
-
[ ] Build the inventory from production telemetry, not from documentation. Why. Engineering enables streams for debugging and forgets them; a query against production data finds streams no policy mentions. Trap. An inventory assembled by asking each team what it collects.
-
[ ] Category one: diagnostic data. Fault codes, component wear, software versions, calibration state. Why. Largely impersonal, subject to emissions access requirements under the Clean Air Act and 40 C.F.R. § 86.1806, and the subject of the repair access fight. Trap. Bundling calibration state with journey data because they travel in the same message.
-
[ ] Category two: journey data. Location, speed, route, duration, driving events. Why. Precise geolocation is sensitive data under most state comprehensive privacy statutes, attracting consent or opt-out rights and assessment duties. Trap. Treating aggregated route data as impersonal when it is trivially re-identifiable.
-
[ ] Category three: occupant data. Voice, cabin sensing, seat occupancy, and anything ingested from a paired phone. Why. The most sensitive category, generated largely by people who never contracted with anyone, and the subject of wiretap claims under the Wiretap Act and state analogues. Trap. Assuming the head unit's copy of a paired phone's messages belongs to the vehicle owner.
-
[ ] Record per stream: what, where stored, retention, internal access, external recipients, legal basis. Why. Every later step depends on this table. Trap. Recording the intended design rather than the deployed behaviour.
-
[ ] List every third-party recipient and the contract governing it. Analytics providers, mapping partners, insurers, dealer systems. Why. These are usually framework agreements with no data terms at all. Trap. Assuming a vendor agreement covers a data feed that postdates it.
-
[ ] [Gate] The inventory is complete when every stream is in exactly one category and nothing is described as "vehicle data". Why. Undifferentiated language cannot support differentiated consent. Trap. Signing off an inventory with a residual "other" bucket.
Phase 2. Handle the regulated category separately
-
[ ] Identify the event data recorder window precisely. Why. 49 C.F.R. Part 563 prescribes what is captured, for how long, and in what format, and requires retrieval with commercially available tools. Trap. Conflating the regulated crash window with the continuous telemetry stream.
-
[ ] Apply the Driver Privacy Act rules to that window only. Why. It gives the owner or lessee an express claim to recorder data, retrievable by others only with consent, court order, anonymised safety research, or defined emergency circumstances. Trap. Extending the statute to telematics it does not cover, or ignoring it for the data it does.
-
[ ] Write a retrieval policy. Who may request, what process is required, what is logged, what the customer is told. Why. Requests arrive from police, insurers, litigants, and the customer, and an ad hoc response creates inconsistency that is later characterised as bias. Trap. Handling requests through the engineering team.
-
[ ] Separate recorder retrieval from telematics production in the subpoena response policy. Why. They have different legal bases and different notice obligations. Trap. A single legal process template for both.
Phase 3. Rewrite the connected services terms
-
[ ] Name the three categories in the terms. Why. Differentiated consent requires differentiated description. Trap. A glossary definition of "vehicle data" that lists everything.
-
[ ] State purposes per category, separating service delivery, product improvement, marketing, and third-party disclosure. Why. Third-party disclosure is where enforcement begins and burying it in a general list is the usual failure. Trap. A purposes clause drafted to preserve maximum flexibility, which reads as concealment.
-
[ ] Define owner, lessee, primary driver, and occasional driver as distinct roles. Why. They have different reasonable expectations and different rights. Trap. Terms that assume one person.
-
[ ] Solve the household problem with engineering, not drafting. Driver profiles, in-vehicle notice, and a way for a non-signing driver to decline. Why. Most data subjects never agreed to anything, and no term fixes that. Trap. A longer consent flow shown only to the purchaser.
-
[ ] Address transfer on sale explicitly. What is deleted, what persists, what the next owner inherits, how the prior account is unlinked. Why. This is the most common live incident in the sector. Trap. A deletion process available on request rather than executed at trade-in.
-
[ ] Separate feature activation from data enrolment. Why. Bundling means a customer who declines data sharing loses functionality they paid for. Trap. A single acceptance screen covering both.
-
[ ] Move material disclosures into the signed purchase documents. Why. Vehicle purchase is one of the few consumer transactions with a signed paper document, and it is routinely wasted. Trap. Relying on a click-through at first ignition.
Phase 4. Set the access positions before someone sets them for you
-
[ ] Decide what independent repairers may access, through what interface, with what authentication. Why. Telematics access legislation is pending in multiple states and contracts will govern in the interim. Trap. An informal, region-by-region practice that cannot be described consistently.
-
[ ] Document the security rationale contemporaneously. Why. A cybersecurity justification is credible when the analysis predates the commercial dispute. Trap. A rationale whose boundary coincides exactly with service revenue.
-
[ ] Keep the diagnostic and journey categories apart in any access platform. Why. Repair access concerns diagnostics; handing over journey data solves a competition problem by creating a privacy one. Trap. A single data feed offered as "the repair interface".
-
[ ] Publish a parts and tools access policy. Why. It is cheaper than the legislative alternative and removes the strongest argument against you. Trap. An internal position paper never published.
-
[ ] Write the access commitments into supply, service, and dealer agreements. Why. Retrofitting a mandated interface across a dealer network is far harder than drafting for it. Trap. Treating access as an aftersales operating decision.
Phase 5. Discipline the subscription feature model
-
[ ] Disclose at the point of sale, in the purchase documentation. What hardware is installed, what is active, what requires payment. Why. The exposure is deception under 15 U.S.C. § 45 and state analogues, not licensing. Trap. Disclosure in the connected services terms only.
-
[ ] State what transfers on resale. Why. Silence favours nobody and will be resolved against the drafter. Trap. An unstated assumption that subscriptions are personal.
-
[ ] Do not remove or degrade a delivered feature by update. Why. It is a warranty and consumer protection matter before it is a licensing one. Trap. A silent capability reduction shipped with a security patch.
-
[ ] Keep a defensible pricing rationale. Why. A feature genuinely dependent on hardware, connectivity, support, or liability exposure is a different proposition from one that costs nothing to enable. Trap. Internal documents describing the model purely as margin capture.
-
[ ] Govern over-the-air updates. Notice, changelog, rollback capability, and a legal review gate for any change that alters functionality. Why. The same channel that patches can degrade. Trap. An update pipeline with engineering approval only.
Phase 6. Fix the supplier IP terms
-
[ ] Build a supplier IP register keyed to modules. Executed terms, tooling ownership, escrow status, open source disclosure, support life. Why. Diligence, recalls, and enforcement all run off this table. Trap. A contract repository organised by counterparty rather than by part.
-
[ ] Settle tooling ownership in writing. Title, location, marking, maintenance, access on notice, return on termination, prohibition on use for others, and possession rights on insolvency. Why. Payment does not transfer title, and a supplier holding an unowned tool holds the production line. Trap. A purchase order for tooling with no title clause.
-
[ ] Schedule background before work starts. Why. Unscheduled background becomes contested background at exactly the moment the platform is refreshed. Trap. A definition of background broad enough to swallow the foreground.
-
[ ] Limit the licence back by field and duration. Why. Unlimited cross-licences are how a supplier ships your platform to a competitor. Trap. A reciprocal clause that looks balanced and is not.
-
[ ] Allocate improvements to the party whose background they build on, with a licence back where otherwise unusable. Why. Silence resolves in favour of whoever holds the source. Trap. An improvements clause that assigns everything to the manufacturer and is therefore never honoured.
-
[ ] Require delivery of what is needed to rebuild, not only to run. Why. A manufacturer holding only binaries cannot patch an abandoned module. Trap. Accepting a delivery without attempting a build.
-
[ ] Set objective escrow release conditions. Insolvency, cessation of supply, sustained failure to remediate a defect. Why. "Material breach" can be argued into by any commercial dispute. Trap. Escrow deposits never verified.
-
[ ] Flow down open source, third-party licence, export, and security obligations, with an audit right. Why. These arise at tiers you never contract with. Trap. Flow-down clauses with no verification mechanism.
-
[ ] [Gate] Test the programme by asking one tier-one for a module's open source bill of materials and timing the response. Why. That number measures the programme more accurately than any warranty. Trap. Accepting a warranty in place of an artefact.
Phase 7. Structure the autonomy development agreement
-
[ ] Split the deliverable into four assets. Training data, model architecture, trained weights, improvements and derived models. Why. A single "foreground IP" clause cannot allocate four things that behave differently. Trap. A development agreement drafted from a mechanical component template.
-
[ ] Address training data provenance. Faces, licence plates, private property, and the terms under which the fleet collected it. Why. It determines whether the data can lawfully be used to train and to license. Trap. Fleet collection authorised for one purpose and used for another.
-
[ ] State whether the supplier may use manufacturer-derived data to improve products for others. Why. In the absence of language, it will. Trap. Assuming confidentiality obligations answer a data-use question.
-
[ ] Negotiate the weights hardest. Why. They are the manufacturer's data applied to the supplier's architecture and they are the asset that performs. Trap. Conceding weights in exchange for ownership of a report.
-
[ ] Allocate simulation environments and scenario libraries expressly. Why. They are expensive, reusable, part copyrightable and part secret, and almost never mentioned. Trap. Discovering at programme end that the scenario library belongs to the supplier.
-
[ ] Say who owns the validation evidence. Why. The test campaign supporting a safety case is worth more than the model in a dispute. Trap. Validation treated as a service deliverable rather than an asset.
Phase 8. Manage standard essential patent exposure
-
[ ] Build a declared-essential exposure inventory by module. Why. A demand should be assessable in days. Trap. Discovering the exposure when the letter arrives.
-
[ ] Cap or carve out standard essential patent indemnities in supplier agreements. Why. An uncapped module supplier may be indemnifying against a royalty computed on the price of a vehicle. Trap. A general IP indemnity with no standards carve-out.
-
[ ] Decide the licensing posture: pool, direct licences, or both. Why. Continental Automotive Systems v. Avanci was decided on standing and left component-level licensing unsettled, so vehicle-level licensing remains the working norm. Trap. Treating licensing as a procurement clause rather than a programme with owners.
-
[ ] Model the foreign rate-setting risk. Why. Global rates set elsewhere are pressed on the same parties here, and anti-suit and anti-anti-suit injunctions are routine. Trap. A domestic-only view of a global licensing dispute.
-
[ ] Assess essentiality rather than accepting declarations. Why. Declared-essential portfolios contain a large proportion of patents that are not essential. Trap. Paying a portfolio rate without sampling.
Phase 9. Set the aftermarket position
-
[ ] File design patents on visible parts. Panels, lamps, grilles, mirrors, bumpers. Why. 35 U.S.C. § 171 with 35 U.S.C. § 289 total-profit remedies, and United States law has no must-match exception. Trap. Filing volume without distinctiveness after LKQ Corp. v. GM Global Technology Operations made incremental designs easier to challenge.
-
[ ] Understand the limits of the doctrinal position on authentication. Why. Impression Products v. Lexmark International exhausts patent rights on sale, Aro Manufacturing v. Convertible Top Replacement permits replacement of worn components, and 17 U.S.C. § 1201 exemptions permit repair circumvention. Trap. Briefing the board that the parts lock rests on intellectual property when it rests on tool control.
-
[ ] Separate the safety case from the commercial case in every internal document. Why. Where they coincide exactly, regulators notice. Trap. A single memo doing both jobs.
-
[ ] Concentrate enforcement on counterfeits. Why. 15 U.S.C. § 1114 claims with recordation and seizure produce the best return per unit of effort. Trap. Spending the enforcement budget on lawful competition.
-
[ ] Handle gray imports with trademark, not patent. Why. Material-difference theories under 15 U.S.C. § 1125 and customs recordation remain effective where specifications genuinely differ. Trap. A patent theory foreclosed by exhaustion.
Phase 10. Fleet, leasing, and remarketing
-
[ ] Write a monitoring policy before any fleet telematics deployment. Why. Fleet telematics is employee monitoring, several states require notice, and out-of-hours location tracking is where claims concentrate. Trap. Deploying under the consumer privacy policy.
-
[ ] Say in the lease documentation who accesses what, and when it is purged. Why. The lessee contracts, the lessor owns, and the data persists after the lease ends. Trap. Lease terms silent on connected services entirely.
-
[ ] Make deletion part of reconditioning, with evidence that it ran. Why. A used vehicle delivered with the prior owner's account paired is a recurring and entirely avoidable incident. Trap. A deletion process available on request.
-
[ ] Handle shared mobility with in-vehicle notice and per-trip profile deletion. Why. Dozens of drivers per vehicle, none of whom read anything. Trap. Relying on the fleet operator's terms to reach the driver.
-
[ ] Keep compelled regulatory streams separate from commercial analytics. Why. Hours of service and inspection data have a different legal character. Trap. A single telematics platform mixing both.
Phase 11. Security, support life, and updates
-
[ ] Contract for support across the vehicle's service life. Why. Vehicles last two decades; software support windows do not. Trap. A five-year support term on a twenty-year product.
-
[ ] Require vulnerability disclosure and patch service levels from suppliers, with escalation and step-in rights. Why. A supplier that cannot remediate leaves the manufacturer with the safety exposure. Trap. Security addressed only in an information security annex about the supplier's own systems.
-
[ ] Publish and honour a coordinated disclosure policy. Why. Researchers will find vulnerabilities; the response to the first one determines what the next twenty do. Trap. A legal threat as the first response.
-
[ ] Treat a safety-relevant vulnerability as a potential defect. Why. The recall framework applies, and the analysis should start there rather than in the security team. Trap. A vulnerability triaged solely on exploitability.
-
[ ] Maintain the update governance record. What changed, when, why, and what functionality was affected. Why. It is the evidence in any consumer or regulatory challenge to an update. Trap. Release notes written for engineers only.
Phase 12. Litigation and evidence readiness
-
[ ] Write the log retention policy in advance and follow it. Why. Deleting on schedule is defensible; deleting after notice is not. Trap. Retention decided by storage cost.
-
[ ] Require legal process for both recorder data and telematics, with customer notice where permitted. Why. Consistency is the defence against a claim of selective production. Trap. Informal cooperation with one requester type.
-
[ ] Anticipate infotainment forensics. Why. Head units hold messages, contacts, and location for every phone paired, including those of people unconnected to the litigation. Trap. Assuming owner consent reaches data the owner did not create.
-
[ ] Set chain of custody standards for extractions. Tool version, hash values, vehicle state, whether the extraction altered the source. Why. The practice is closer to mobile forensics than to document discovery. Trap. An engineer performing an extraction with no protocol.
-
[ ] Preserve vehicles under claim. Why. A vehicle repaired, sold, or scrapped after notice takes its data with it, and spoliation follows. Trap. Normal disposal processes continuing after a claim is notified.
Phase 13. Brand, model names, and design disclosure
-
[ ] Clear model names globally, years ahead. Why. Names are announced long before launch and a conflict found late is expensive. Trap. Clearing in the home market only.
-
[ ] Clear and file feature and technology names. Why. Driver assistance and infotainment names acquire enormous recognition and are routinely launched unprotected. Trap. Treating them as engineering designations.
-
[ ] Review technology names for what they claim. Why. A name implying autonomy the system does not deliver is a consumer protection and safety problem at once. Trap. Marketing naming a driver assistance feature without safety or legal review.
-
[ ] Plan concept vehicle naming. Why. Concepts generate coverage and are frequently abandoned, leaving unprotected names or dead applications. Trap. Intent-to-use filings maintained indefinitely for cancelled programmes.
-
[ ] Clear revived heritage nameplates. Why. A name unused for decades may be abandoned under 15 U.S.C. § 1127 with a third party now using it. Trap. Nostalgia treated as a clearance opinion.
-
[ ] File designs before motor show or regulatory disclosure. Why. Foreign rights depend on absolute novelty, and a global model's design value is mostly foreign. Trap. A design filing calendar not synchronised with the reveal calendar.
Phase 14. Working the example matter
-
[ ] Query production telemetry before reading a single policy. Why. Four debugging streams nobody documented are the reported facts, and the real number is usually higher. Each one needs a purpose, a retention period, a recipient list, and a decision to keep or disable. Trap. Asking engineering to list what it collects, which produces the intended design rather than the deployed behaviour.
-
[ ] Rewrite the six-year-old navigation terms from scratch. Why. Terms drafted for a navigation service and referring throughout to "vehicle data" cannot support an autonomy data pipeline, three subscription features, and an insurance partnership. Amendment will not fix a structure built on one undifferentiated category. Trap. Bolting an addendum onto terms whose defined terms are the problem.
-
[ ] Unbundle the hardware-unlock feature immediately. Why. A feature that unlocks installed hardware is the highest-exposure item in the launch, and the exposure is disclosure, not licensing. Move the disclosure into the signed purchase documents and state what transfers on resale. Trap. Launching with the disclosure in the connected services acceptance flow.
-
[ ] Paper the insurance partnership as separate, explicit, revocable consent. Why. Data collected by the manufacturer for stated safety and service purposes, and supplied to an insurer for pricing, is the fact pattern regulators have pursued under 15 U.S.C. § 45. Trap. Consent obtained in the same flow as connected services enrolment.
-
[ ] Fix the autonomy agreement before production intent. Why. A system trained on fleet-collected imagery raises training data provenance, weights ownership, and whether the supplier may use manufacturer-derived data for its other customers. All three are cheaper to settle now than after the model is in vehicles. Trap. A development agreement that assigns "all foreground IP" and says nothing about data.
-
[ ] Formalise the diagnostic tool position across regions. Why. Informal, inconsistent provision to independent repairers is indefensible in the two states with pending telematics bills and is a discrimination argument everywhere else. Publish one policy and apply it. Trap. Regional aftersales teams setting terms independently.
-
[ ] Treat the remarketing incident as a process failure, not a one-off. Why. A used vehicle delivered with the prior owner's account paired means deletion is not part of reconditioning. Add it, and require evidence that it ran. Trap. Handling it as a customer service complaint.
-
[ ] Demand the head unit's open source bill of materials and time the response. Why. Inability to produce it means the flow-down clauses are unverified across the most complex module in the vehicle. Trap. Accepting a warranty of compliance in place of the artefact.
-
[ ] [Gate] Do not launch the platform until the inventory, the rewritten terms, the unbundled feature disclosure, and the tool access policy are in place. Why. Each is materially harder to fix after vehicles are in customers' hands. Trap. A launch date treated as immovable and a compliance plan treated as negotiable.
Phase 15. Patent portfolio alignment
-
[ ] Map filings to platform architecture rather than to engineering department. Why. Departmental portfolios produce three groups filing around one problem and nobody claiming the integration. Trap. Reporting filings by cost centre.
-
[ ] Prioritise interface claims. The message a controller sends, the state a module reports, the handover between automated and manual control. Why. They are hardest to design around and easiest to detect. Trap. Filing on internal algorithms nobody can observe.
-
[ ] Ask at drafting how infringement would be proved. Why. A claim covering unobservable internal behaviour is expensive decoration. Trap. Detectability treated as a litigation problem rather than a drafting one.
-
[ ] Watch the standards trajectory in charging and connectivity. Why. Today's proprietary filing becomes tomorrow's declared-essential patent with licensing obligations attached. Trap. A portfolio strategy that ignores the standards calendar.
-
[ ] Draft software claims to physical effect. Why. Vehicle control claims tied to concrete actuation fare better on eligibility than abstractly framed data processing. Trap. Specification language written for a software product.
-
[ ] Run freedom to operate on the software stack. Perception, planning, mapping, connectivity. Why. These are densely patented by parties that do not make vehicles. Trap. Relying on a supplier's representation instead of a clearance exercise.
Phase 16. Trade secrets in a sector that shares everything
-
[ ] Identify what is genuinely secret. Calibration maps, control strategies, battery chemistry and pack design, process parameters, validation data. Why. Everything else is patented, published, or visible on a teardown. Trap. Controls applied uniformly and therefore applied nowhere effectively.
-
[ ] Assume systematic teardowns. Why. Competitors buy and disassemble vehicles; benchmarking services publish detailed analyses. Trap. Treating a visible design choice as confidential.
-
[ ] Test the programme against 18 U.S.C. § 1839. Why. Reasonable measures are an element of any Defend Trade Secrets Act claim. Trap. A supplier-facing programme with no access segregation.
-
[ ] Include the 18 U.S.C. § 1833 notice in agreements. Why. Omission forfeits exemplary damages and fees. Trap. Notice in the handbook only.
-
[ ] Invest in exit forensics and documented onboarding rather than in covenants. Why. Engineer mobility is constant and covenant enforceability varies sharply by state. Trap. A restrictive covenant strategy in a state that will not enforce it.
-
[ ] Build a confidentiality architecture into joint ventures. Why. Shared platform, battery, and charging arrangements require disclosure to entities partly owned by competitors. Trap. Confidentiality terms drafted after the equity terms are agreed.
Phase 17. Charging, energy, and battery data
-
[ ] Treat charging session data as journey data. Why. Where the vehicle charged, when, and how often is location history under another name, and it flows to network operators, payment processors, and utilities. Trap. Classifying it as transactional payment data.
-
[ ] Paper vehicle-to-grid participation as a data licence. Why. Battery state and availability shared with a regulated utility is a second data relationship with its own retention and access rules. Trap. Accepting the utility's technical interface specification as the contract.
-
[ ] Decide deliberately who receives battery health data. Why. It determines residual value, warranty exposure, second-life value, and whether independent battery service is viable, so every party in the chain wants it. Trap. Retaining it by default until the market or a regulator forces disclosure on worse terms.
-
[ ] Raise battery passport and material traceability requirements with cell suppliers early. Why. Composition and provenance disclosure obligations intersect awkwardly with supplier confidentiality. Trap. Discovering the conflict when the obligation takes effect.
-
[ ] Manage charging network branding as a trademark licence. Why. Networks are operated by third parties with the quality control and termination issues of a dealer network and none of the franchise statute protections. Trap. A co-branding arrangement with no quality control provisions.
-
[ ] Track connector and protocol standardisation. Why. Declared-essential patents and licensing dynamics follow standardisation, and the standards are still consolidating. Trap. Assuming a proprietary interface will remain proprietary.
Phase 18. Registers, gates, and reporting
-
[ ] Maintain four registers. The data inventory; the supplier IP register keyed to modules; the declared-essential exposure inventory; the design filing register mapped to visible parts. Why. Every question in this checklist is a query against one of them. Trap. Registers owned by four functions with no shared identifiers.
-
[ ] Place a legal gate at four points. Before a new data stream is enabled; before a feature is offered on subscription; before a module enters production under new supplier terms; before a part family is released to the aftermarket. Why. These are the four moments where an irreversible commitment is made. Trap. Gates that can be waived by the programme manager.
-
[ ] Report four measures. Proportion of streams with stated purpose and retention; proportion of production modules with executed terms and escrow; time to answer a standard essential patent demand; number of visible parts with design coverage. Why. These are the measures that predict incidents. Trap. Reporting contracts reviewed and filings made.
-
[ ] Refresh annually. State privacy statutes, telematics legislation, circumvention exemption cycles, and design case law all move on separate clocks. Why. A policy written once will be wrong within two years. Trap. An annual review that checks the policy exists rather than whether it is still correct.
Phase 19. Documents this checklist should produce
-
[ ] A three-category data inventory, built from production systems, with purpose, retention, internal access, external recipients, and legal basis per stream. Why. It is the foundation of every other output. Trap. An inventory that describes the architecture rather than the traffic.
-
[ ] Rewritten connected services terms organised by category, with purposes stated per category, roles defined, transfer on sale addressed, and feature activation separated from data enrolment. Why. The old terms cannot be amended into this shape. Trap. An addendum.
-
[ ] A published parts and tools access policy with a documented security rationale and a narrow, justified safety-critical carve-out. Why. It is cheaper than the legislative alternative. Trap. An internal position never published.
-
[ ] A supplier IP register keyed to modules, with executed terms, tooling title, escrow status, open source disclosure, and support life. Why. Recalls, diligence, and enforcement all query it. Trap. A contract repository keyed to counterparties.
-
[ ] Retention, subpoena response, and update governance policies, written before they are needed and followed. Why. Consistency is the defence in every evidentiary dispute. Trap. Policies drafted during the first incident.
Phase 20. A note on sequencing
-
[ ] Do the inventory before anything else, and do not let it slip. Why. Every other item on this list is a query against it, and a programme that starts with contract drafting will draft against the wrong facts. Trap. Beginning with the terms because they are the visible artefact.
-
[ ] Fix the highest-exposure item next, not the easiest. Why. Undocumented streams flowing to third parties, and features that unlock paid-for hardware, are the two items that generate enforcement. Trap. Starting with the design filings because that work is familiar.
-
[ ] Treat the access policy as a strategic decision made once, not as a series of regional operational choices. Why. Inconsistency is itself the finding. Trap. Delegating it to aftersales.
Outcome. A data inventory in which every stream sits in exactly one category with a stated purpose and retention period; connected services terms that describe those categories and separate feature activation from data enrolment; a published access policy; supplier IP, escrow, design filing, and declared-essential registers that can be queried in a day; and retention, subpoena, and update governance policies written before they are needed.
The five things people get wrong
One. Treating "vehicle data" as one thing. Diagnostic, journey, and occupant data attract different consents, different retention rules, different access obligations, and different litigation exposure. A policy written for one produces absurd results applied to another, and a consent flow that covers all three covers none of them properly.
Two. Asking who owns the data. Nobody does. Facts are not property, Feist Publications v. Rural Telephone Service forecloses the copyright workaround, and the only express statutory owner in the vehicle is the owner of the event data recorder window. The operative question is who can reach it and what did the person it describes agree to.
Three. Believing the parts lock is an intellectual property position. It is a tool-control position. Exhaustion, repair doctrine, and the circumvention exemptions all run against the manufacturer, and briefing the board otherwise leads to a strategy that collapses the moment it is tested or legislated.
Four. Bundling feature activation with data enrolment. It means a customer who declines data sharing loses functionality they paid for. That is the single fact pattern regulators in this sector have pursued most consistently, and unbundling costs nothing.
Five. Discovering the undocumented telemetry streams after the incident. Engineering enables streams for debugging and they persist for years, flowing to third parties under agreements that never contemplated them. This is, in almost every programme, the largest single exposure, and it is found by querying production systems rather than by asking anyone.
Key Authorities at a Glance
| Authority | Proposition | |---|---| | 15 U.S.C. § 45 | Unfair or deceptive practices | | 15 U.S.C. § 1114 | Registered mark infringement | | 15 U.S.C. § 1116 | Injunctions and seizure | | 15 U.S.C. § 1125 | False designation; material differences | | 15 U.S.C. § 1127 | Abandonment | | 17 U.S.C. § 102 | Facts not copyrightable | | 17 U.S.C. § 117 | Maintenance and repair copies | | 17 U.S.C. § 1201 | Circumvention and exemptions | | 18 U.S.C. § 1836 | DTSA civil action | | 18 U.S.C. § 1839 | Trade secret definition | | 18 U.S.C. § 2510 | Wiretap definitions | | 18 U.S.C. § 2511 | Interception | | 35 U.S.C. § 171 | Design patents | | 35 U.S.C. § 271 | Infringement | | 35 U.S.C. § 289 | Total profit remedy | | 42 U.S.C. § 7521 | Emission standards; diagnostics | | 40 C.F.R. § 86.1806 | On-board diagnostics | | 49 C.F.R. § 563 | Event data recorders | | Feist Publications v. Rural Telephone Service | Facts not copyrightable | | Riley v. California | Devices qualitatively different | | Carpenter v. United States | Comprehensive location records | | Spokeo v. Robins | Concrete injury | | TransUnion v. Ramirez | Concrete harm in data cases | | Van Buren v. United States | Authorised access | | Impression Products v. Lexmark International | Exhaustion on sale | | Aro Manufacturing v. Convertible Top Replacement | Permissible repair | | Samsung Electronics v. Apple | Article of manufacture | | KSR International v. Teleflex | Flexible obviousness | | Chamberlain Group v. Skylink Technologies | Circumvention nexus | | MDY Industries v. Blizzard Entertainment | Independent section 1201 right | | LKQ Corp. v. GM Global Technology Operations | Design obviousness | | Continental Automotive Systems v. Avanci | Component-level licensing | | hiQ Labs v. LinkedIn | Public data access | | Driver Privacy Act | Recorder data ownership | | Telematics access legislation | Wireless diagnostic access | | Vehicle cybersecurity management | Security as market access |
Related Documents
Articles
Guides
- Advising an Automotive or Mobility Business
- Navigating Section 1201
- Structuring a Joint Development Agreement
Checklists
Toolkits
- Automotive, Mobility, and Connected Vehicle IP Toolkit
- Standard Essential Patents and FRAND Toolkit
- Anticircumvention and Repair Toolkit
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Connected vehicle positions depend on the contracts in place, the applicable state statutes, and a regulatory landscape that is changing quickly. Marksy is not a law firm.