Problem statement (privacy & compliance)
Connected cars behave like networked IoT devices: embedded SIMs continuously interact with mobile networks, making it technically possible to track vehicles, correlate VINs with IMEI/IMSI identifiers and reconstruct driving histories. At the same time, drivers expect strong privacy protection and strict limitation of surveillance, as highlighted by civil‑society concerns about function creep from lifesaving systems like eCall into broad vehicle tracking. Automotive OEMs therefore face a dual challenge: they must be able to support legitimate investigations and cross‑border requests, while minimizing data exposure, enforcing purpose limitation and ensuring full transparency and auditability.
ETSI TR 103 854 in automotive
ETSI TR 103 854 defines a reference model and interface for requests from law enforcement agencies (LEAs) to organizations that hold vehicle‑related data, called Response Processing Systems (RPS). It describes concrete use cases such as VIN‑to‑IMEI, IMEI‑to‑VIN, VIN‑to‑IMSI, VIN‑to‑location and VIN‑to‑vehicle‑data, plus recommendations for HTTPS‑based, schema‑driven request/response exchanges in XML or JSON. The report also introduces data categories (identification, location, routing, driving behavior, component status, customer details and more) and stresses clarity, efficiency, auditability, security and privacy in every disclosure workflow.

