ADAS & Autonomous Vehicle International
  • News
    • A-L
      • ADAS
      • AI & Sensor Fusion
      • Business
      • Connectivity
      • Cybersecurity
      • Expo
      • HMI
      • Last-mile delivery
      • Legislation & Standards
      • Localization/GNSS
    • M-Z
      • Mapping
      • Off-Highway
      • Robo-Taxis
      • Sensors
      • Shared Mobility
      • Safety
      • Simulation
      • Testing
      • Trucks
      • V2X
  • Features
  • Online Magazines
    • January 2025
    • September 2024
    • April 2024
    • January 2024
    • Subscribe
  • Opinion
  • Videos
  • Supplier Spotlight
  • Events
LinkedIn Facebook Twitter
  • Automotive Interiors
  • Automotive Testing
  • Automotive Powertrain
  • Professional Motorsport
  • Tire Technology
  • Media Pack
    • 2026 Media Pack
    • 2025 Media Pack
LinkedIn Facebook
Subscribe
ADAS & Autonomous Vehicle International
  • News
      • ADAS
      • AI & Sensor Fusion
      • Business
      • Connectivity
      • Cybersecurity
      • Expo
      • HMI
      • Last-mile delivery
      • Legislation & Standards
      • Localization/GNSS
      • Mapping
      • Off-Highway
      • Robo-Taxis
      • Sensors
      • Shared Mobility
      • Safety
      • Simulation
      • Testing
      • Trucks
      • V2X
  • Features
  • Online Magazines
    1. April 2025
    2. January 2025
    3. September 2024
    4. April 2024
    5. January 2024
    6. Subscribe
    Featured
    April 15, 2025

    In this Issue – April 2025

    Online Magazines By Web Team
    Recent

    In this Issue – April 2025

    April 15, 2025

    In this Issue – January 2025

    November 29, 2024

    In this Issue – September 2024

    July 23, 2024
  • Opinion
  • Videos
  • Supplier Spotlight
  • Events
  • Awards
    • About
    • 2025 winners
    • Judges
  • Webinars
LinkedIn Facebook
Subscribe
ADAS & Autonomous Vehicle International
Features

AVs, biometrics, and consumer privacy

Dan SymondsBy Dan SymondsAugust 16, 20195 Mins Read
Share
LinkedIn Twitter Facebook Email

Paul Keller, Jeewon Serrato and Sue Ross from law firm Norton Rose Fulbright discuss the potential implications of the California Consumer Privacy Act for AV developers and self-driving taxi services

AVs use many technologies inside the vehicle that collect biometric data to improve the travel experience. These technologies include fingerprint readers, facial scanners, iris scans, voice recognition, and gesture recognition.

Organizations that collect or process such information will have a duty under privacy and data protection laws globally to keep that data private and secure. In the USA, in addition to biometric-specific state laws, such as the Illinois Biometric Information Privacy Act, California has recently passed a comprehensive privacy law. The California Consumer Privacy Act (CCPA), which goes into effect on January 1, 2020, will regulate how biometrics are collected and handled. Given how other states are considering CCPA-like laws, the impact of these new laws and regulations should be closely examined.

Expanded definitions of personal information and sale
Under the CCPA, the definition of ‘personal information’ includes biometric information, audio, electronic, visual, thermal, or olfactory information, geolocation data, and even inferences drawn from other personal data to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, and abilities.    

Biometric information under CCPA includes, but is not limited to: imagery of the iris, retina, fingerprint, face, hand, palm, vein patterns, and voice recordings, from which an identifier template, such as a faceprint, a minutiae template, or a voiceprint, can be extracted, and keystroke patterns or rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain identifying information.

CCPA has separate sets of requirements for organizations that ‘collect’ personal information and those that ‘sell’. The definition of a ‘sale’ of data under CCPA, however, is much more expansive than is traditionally understood. A sale under CCPA includes: selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means a consumer’s personal information to a third party for monetary or other valuable consideration.

Opt-out requirement
CCPA requires that companies enable California residents to opt out of the sale of personal information by providing a “clear and conspicuous link on the business’s Internet home page, titled ‘Do Not Sell My Personal Information’”. If an AV manufacturer collected the personal information, it may now be required to alert its third-party partners or service providers that the consumer has opted out of the sale of the consumer’s personal information.

Opt-in requirement for minors
CCPA has special requirements for minors, requiring opt-in consent for those aged 13 to 16, and requiring parental consent for minors under 13, if the business has “actual knowledge” that the personal information that is being ‘sold’ is of a minor. If AV manufacturers have “actual knowledge” that minors could be passengers, they will need to consider how to obtain the required consent before they ‘sell’ the personal information to third parties.

Notice requirement for resale
The CCPA prohibits businesses who ‘bought’ personal information from reselling the information unless the consumer has received explicit notice and is provided an opportunity to exercise the right to opt out. For example, if the consumer riding in an AV downloads a third-party app and the app had collected certain personal information directly from the consumer but also combined it with other data, then before it shares the information it has collected with any third parties (e.g. the AV manufacturer), the app must provide explicit notice of the data transfer to the consumer and offer the consumer an opportunity to opt-out.

Enforcement and litigation
The CCPA will be enforced by the California Attorney General. A violation can result in fines up to US$2,500 for each violation or US$7,500 for each intentional violation. There is no maximum cap.

A private right of action is available if personal information is subject to “an unauthorized access and exfiltration, theft or disclosure as a result of the business’s violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information”. Consumers must show that one of the following data elements were included in the breach: (a) name in combination with either the social security number, driver’s license number or other California identification cards number, financial account number with password, medical information or health insurance information; or (b) a username or email address in combination with a password or security question and answer that would permit access to an online account.  There is no ‘actual harm’ requirement. Consumers can seek damages between US$100 US$750 per consumer per incident or actual damages, whichever is greater.

For any organization collecting or processing personal information, such as biometrics, a privacy risk assessment is needed to analyze the impact of new and emerging laws such as the CCPA.

About the authors:
Paul Keller is a partner in Norton Rose Fulbright’s New York office; Jeewon Serrato is the global law firm’s US head of data protection, privacy and cybersecurity; and Sue Ross is a senior counsel, also based in New York.

For more on privacy and cybersecurity in connected and autonomous vehicles, check out the ADAS & AV Legal Issues & Liabilities Congress in Novi, Michigan, on October 22 and 23. The conference will feature a panel discussion and a presentation on the Collection, Use, and Sharing of Vehicle Data, as well as the various other legal issues, implications and liabilities arising from ADAS and future autonomous vehicles. Visit www.adaslegal-issuesandliabilities.com for more information.

Share. Twitter LinkedIn Facebook Email
Previous ArticleUber ATG joins SAE’s Automated Vehicle Safety Consortium
Next Article TriEye short-wave infrared sensors secure investment from Porsche

Related Posts

Features

ASAM shares updates on its positioning for SDV, AI and open-source at Technical Seminar

April 14, 20259 Mins Read
Safety

The potential impact of ADAS on hospital admissions and healthcare expenditures

March 27, 202511 Mins Read
Features

SPONSORED ARTICLE: Material solutions for vehicle domain controllers

February 27, 20254 Mins Read
Latest News

WeRide collaborates with RTA and Uber to launch pilot operations

June 16, 2025

Aurrigo founder David Keene receives MBE for the decarbonization of airports

June 13, 2025

WATCH NOW: Driving performance, efficiency and reliability – material solutions for vehicle domain controllers

June 13, 2025
FREE WEEKLY E-NEWSLETTER

Receive breaking stories and features in your inbox each week, for free


Enter your email address:


Our Social Channels
  • Facebook
  • LinkedIn
Getting in Touch
  • Free Weekly E-Newsletters
  • Meet the Editors
  • Contact Us
  • Media Pack
    • 2026 Media Pack
    • 2025 Media Pack
RELATED UKI TOPICS
  • Automotive Interiors
  • Automotive Testing
  • Automotive Powertrain
  • Professional Motorsport
  • Tire Technology
  • Media Pack
    • 2026 Media Pack
    • 2025 Media Pack
© 2025 UKi Media & Events a division of UKIP Media & Events Ltd
  • Terms and Conditions
  • Privacy Policy
  • Cookie Policy
  • Notice & Takedown Policy
  • Site FAQs

Type above and press Enter to search. Press Esc to cancel.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.

CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.

Functional

Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.

Advertisement

Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.

Others

Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.

SAVE & ACCEPT