EU Data Act Mandates Open Access to Vehicle Diagnostic Systems for Independent Shops
New European Union Data Act provisions, as reported by the Competition and Consumer Protection Commission, mandate "access by design" for connected products.
Aldous Moorland·updated September 11, 2026

The framework enables vehicle owners to export operational and diagnostic data directly to independent repair and maintenance providers, dismantling the proprietary barriers that have long shielded OEM service channels. For European and Asian import platforms with deep network integration, this recalibrates the diagnostic baseline at the OBD-II port.
What the rule actually opens
The regulation compels manufacturers to expose the same operational and diagnostic telemetry their dealer networks consume. Where a gateway module previously filtered request IDs, a standardized export channel now allows a third-party scan tool to read fault codes, live data streams, and service interval records directly from the vehicle. Manufacturer software locks that previously rejected aftermarket tools at the CAN bus handshake are now subject to regulatory challenge. The hardware remains unchanged. The data layer is what shifts.
Cyber Resilience Act enters the equation
Article 14 of the EU Cyber Resilience Act took effect alongside these provisions, according to Taylor Wessing. Diagnostic tools, aftermarket software, and charging infrastructure now fall under strict vulnerability disclosure and cybersecurity obligations. Any shop connecting third-party hardware to a modern vehicle network must verify that its tooling meets the new compliance baseline. Non-compliant diagnostic suites risk regulatory action in EU jurisdictions, regardless of where the tool was manufactured.
Baseline parameters to verify
Independent shops servicing EU-spec imports should confirm three gates before treating the rule as operational. First, the scan tool must read OEM-grade telemetry, not just generic OBD-II PIDs, without requiring a paid manufacturer subscription. Second, the tool's firmware must carry documented CRA Article 14 compliance, including an active vulnerability reporting channel. Third, the data export channel must accept standard formats compatible with existing shop management systems. If any of these three conditions fail, the access the regulation promises has not yet reached the bay floor.