Toyota Australia says highly sensitive connected-car data is encrypted and never leaves the vehicle
Toyota Australia has moved to reassure customers about connected-car privacy, claiming highly sensitive data is encrypted inside the vehicle and never transmitted, as the industry awaits the outcome of regulator inquiries and faces renewed calls for purpose-built vehicle data laws.
Automatically researched, written and checked using AI. Verify details against the sources.
Toyota's assurance on in-car data
Toyota Australia has confirmed that highly sensitive customer data is encrypted and never transmitted from its vehicles, following recent calls for greater government regulation of information generated by connected cars, CarExpert reports. Speaking at a business update at Toyota's Port Melbourne headquarters, vice president of sales, marketing and franchise operations John Pappas told the publication the company is extremely diligent in handling data, with customer privacy a priority. 1
“Our data systems are hosted in secure data centres, the majority of which are located in Australia, with some data also processed and stored in secure Toyota-managed environments in North America and Singapore,” Mr Pappas told CarExpert. Asked whether a Toyota could be hacked, he declined to comment on other brands but said: “Any highly sensitive data is fully encrypted inside the car, is never transmitted.” He likened the company's approach to data protection to its approach to physical vehicle safety, describing it internally as “hardware equals software”. 1
A million connected Toyotas and what still leaves the car
Toyota told CarExpert there are now more than one million connected Toyotas on Australian roads, after Toyota Connected Services launched in November 2020. Almost every model across the current passenger and commercial range offers the service, with exceptions including the LandCruiser 70 Series, GR86 and Tundra. 1
Some data does leave the vehicle in defined circumstances. CarExpert notes that SOS Emergency Call, included free by Toyota for the life of the relevant mobile network and part of ANCAP's 2026 assessment protocols, can transmit information required to provide emergency assistance, and Toyota says the service has been used more than 10,000 times in Australia. Stolen Vehicle Tracking data may similarly be provided to police; the publication notes models including the RAV4, HiLux and LandCruiser 300 Series have been among targets during a rise in vehicle thefts, including in Victoria where thefts have reached two-decade highs. 1
Toyota also updated its Connected Services Privacy Policy in March 2026. CarExpert reports the current policy states that, outside specified circumstances, Toyota does not share information about a customer's use of Connected Services with anyone else unless asked, and that personal information collected through the service is not used for direct marketing. 1
Regulatory scrutiny without findings
Toyota is currently the subject of an ongoing investigation by the Office of the Australian Information Commissioner, which is also investigating Hyundai over connected-vehicle privacy, CarExpert reports. The regulator has not publicly detailed either investigation or announced any findings of wrongdoing by either brand. It began preliminary inquiries into connected-car privacy in February 2024, but the vehicle brands involved were not made public until 2026. 1
An industry ahead of Australian law
Earlier reporting by GoAuto in August 2026 found the federal government and intelligence agencies had yet to engage with the automotive industry on connected-vehicle data security, despite ASIO deputy director general Lisa Alonso Love warning politicians at a senate estimates hearing to exercise caution when travelling in vehicles equipped with connected services. Polestar Australia managing director Scott Maynard told GoAuto his company had never been approached by government on cybersecurity, while BYD Australia public relations director Paul Ellis said the industry was applying elements of the Australian Privacy Act from 1988 that “almost certainly did not foresee a scenario with connected vehicles almost 40 years on”. 2
Cybersecurity figures suggested the ASIO warning was grounded in more than theory. Tony Ridley, chief security and risk advisor at EMA Global and author of research on vehicle security vulnerabilities, told GoAuto that “the deputy director general (of ASIO) doesn’t speculate; she speaks to evidence and verifiable facts”, arguing such public warnings are typically issued after an occurrence rather than in speculation about what might happen. 2
In the same GoAuto report, Toyota's John Pappas was quoted describing the company's connected systems as designed with “privacy-first engineering principles”, ensuring only data required for core safety services is activated by default, with sensitive information such as facial biometric markers or in-cabin video encrypted and never transmitted. Other brands set out their own arrangements: Mazda says data from its China-built 6e and CX-6e stays on a Singapore server while other models send data to Japan, and Polestar says no customer data passes through or is held in China. 2
Independent research points to a broader problem
The scale of data sharing in the wider connected-vehicle ecosystem was highlighted by a peer-reviewed study from researchers at Northeastern University conducted in partnership with Consumer Reports, reported by TechCrunch. Researchers tested 21 late-model vehicles from 17 automakers – including GM brands, Ford, Lucid, Rivian, Tesla and Toyota – plus 30 companion mobile apps, and found 19 of the 21 vehicles sent data to at least one third party. Seven of the 30 apps gave sensitive data such as VINs, emails, phone numbers and precise location to companies associated with tracking and advertising. 3
According to TechCrunch's report of the study, data was shared with tech companies including Adobe, Google, Microsoft, Meta, Snap and Yahoo, and pairing a companion app to a vehicle roughly doubled exposure to advertising and tracking companies. The findings were shared with the manufacturers, and the researchers said all but Honda shifted blame elsewhere; Honda instead ordered its vendor Amplitude to delete geolocation data it had received. 3
Closer to home, CarExpert reports that BYD changed its privacy policy after the ABC's Four Corners investigation aired on September 21, 2026, with the program reporting that the revised policy removed previous references to 16 countries to which customer data could be sent. BYD launched an investigation into the program's findings and subsequently said it would implement software changes, “thereby eliminating the access path identified during the investigation”. Canberra-based Fortify Labs, which carried out the vehicle ‘attacks’ for Four Corners, suggested introducing a cyber-security star rating to allow customers to compare the level of protection offered by different brands. 1
AI evidence finder
Ask about this article
Ask a question to find relevant published passages and source links. AI selects evidence; the passages remain exactly as published.
Behind this report
Sources & context
Cited source mix
3 cited pages across 3 websites
- News publisher 2
- Role not assessed 1
Website breakdown
- CarExpertcarexpert.com.au1 page
- GoAutogoauto.com.au1 page
- techcrunch.com1 page
1 cited page with an undocumented publisher role. Websites may share ownership or repeat the same reporting.
Saved research extracts
3 / 3 cited pages with saved extracts
0 shortened at our text limit · 0 without a saved-extract record
Extracts retrieved 9 Oct 2026.
Extracts can omit page content. These counts do not verify claims or measure independent reporting. Political leaning and reliability are not rated.
- Toyota Australia says sensitive connected-car data "never transmitted"News publisherSource extract saved
Why these labels?Toyota Australia says sensitive connected-car data "never transmitted"
Who produced it
Publishes automotive news and reviews and operates a car-buying service connecting buyers with dealers. Identity reference ↗
How this report uses it
Cited in 7 paragraphs: Toyota's assurance on in-car data; A million connected Toyotas and what still leaves the car; Regulatory scrutiny without findings; Independent research points to a broader problem.
This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.
Evidence record
Text retrieved 9 Oct 2026. The retained extract did not reach our text limit. Extraction can still omit page content.
- Feds not engaging OEMs on cybersecurityNews publisherSource extract saved
Why these labels?Feds not engaging OEMs on cybersecurity
Who produced it
GoAutoMedia publishes automotive industry and consumer news, vehicle reviews and model information. Identity reference ↗
How this report uses it
Cited in 3 paragraphs: An industry ahead of Australian law.
This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.
Evidence record
Text retrieved 9 Oct 2026. The retained extract did not reach our text limit. Extraction can still omit page content.
- Your car and its mobile app are probably handing over all ...Role not assessedSource extract saved
Why these labels?Your car and its mobile app are probably handing over all ...
Who produced it
We have not documented this publisher’s role. An unassigned label is not a negative rating.
How this report uses it
Cited in 2 paragraphs: Independent research points to a broader problem.
This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.
Evidence record
Text retrieved 9 Oct 2026. The retained extract did not reach our text limit. Extraction can still omit page content.