VINs Ruled to be Personal Data by EU Court

26th March 2024

The European Court of Justice has ruled in a recent case that Vehicle Identification Numbers (VINs) count as personal data under EU GDPR. 

Article 4(1) of the GDPR states that “‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.

ECJ Finds that a VIN Can Be Considered Personal Data

In the case of Gesamtverband Autoteile-Handel eV v Scania CV AB (aka case C-319-22),  the ECJ found that a VIN can be personal data if it is linked to a particular natural person. Scania gives access to information about its vehicles to authorised dealers and mechanics, including repair and maintenance information. This is provided on a website where one can search for a specific vehicle via the model, engine, year of manufacture, or the VIN. 

What is a VIN?

A VIN, or vehicle identification number, is unique to every vehicle and is inscribed on the chassis of the vehicle. This information is not shared with all independent operators, just those who are going to be undertaking the actual repair of the vehicle. Scania asserts that the EU GDPR would prohibit the disclosure of VINs to independent operators as they have no legal basis for processing this data.

Case Background

The Gesamtverband Autoteile-Handel eV or GAH is a Germany-based association of auto parts traders, which represents the professional interests of the industry. They claim that Scania should be sharing the vehicle information described above with more independent operators as per the Market Surveillance Legislation (EU) 2019/1020 and Article 61 of Regulation 2018/858, which states that:

“Manufacturers shall provide to independent operators unrestricted, standardised and non-discriminatory access to vehicle OBD information, diagnostic and other equipment, tools including the complete references, and available downloads, of the applicable software and vehicle repair and maintenance information.”

The case was originally heard by the Regional Court in Cologne, who then referred it to the ECJ for clarification of how the law should be applied. The ECJ ruled that while the VIN is intended to identify a vehicle rather than a person, the registration certificate also contains the name and address of whomever holds said certificate. This means that if these aforementioned independent operators have the VIN, they also have access to personal data about the vehicle’s owner or driver. If the vehicle is registered to a company, then the VIN does not in itself constitute personal data.

Similar ECJ Rulings

The ECJ ruled in a similar case (Patrick Breyer v. Bundesrepublik Deutschland – Case C-582/14) that an IP address can be considered personal data if the internet service provider has additional data that could identify the website user, and if such identification is legally and practically possible. 

So basically, a VIN can indeed constitute personal data, although not in every case. It is therefore important to apply nuance to each case to find out how the data protection laws should be applied.

Looking ahead to the Data Protection and Digital Information Bill

Clause 1 of the proposed DP & DI Bill proposes a change to the definition of personal data. Information being processed will only be deemed to be information relating to an identifiable individual:-

(i) where the individual is identifiable by the controller or processor by reasonable means at the time of processing; or

(ii) where the controller or processor knows, or ought reasonably to know, that another person will, or is likely to, obtain the information as a result of the processing and the individual will be, or is likely to be, identifiable by that person by reasonable means at the time of processing.

This will mean that IP addresses and VINs may not be considered personal data in the UK, but will remain so if we are dealing with individuals located within the EU.

Read more about this case at Cordery Compliance.

 

Author: Paul Adams LLB (HONS)

Paul is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details