EU Data Act Transparency Notice

(Regulation (EU) 2023/2854 – “Data Act”)

Effective date of applicability: 12 September 2025

Who we are: ZF Digital Solutions International B.V. and its subsidiaries (“ZF DSI”, “we”, “us”), part of ZF Group, provide connected fleet management solutions for trucks, trailers, vans, cars, and related services to fleets and transport operators (“the User”).

Purpose of this Notice.

The Data Act grants users of connected products and related services—such as fleet operators—rights to access and share data generated by those products. It also sets obligations for manufacturers, data holders and cloud providers. This Notice explains what data our connected products generate, how users can access and share it, the conditions that apply, and how we protect data and trade secrets.

1) What is a “connected product” and a “related service” at ZF?

  • Connected products are ZF telematics devices installed in trucks, trailers, vans, and cars. These retrofit devices (e.g., telematics control units, gateway hubs, smart sensors) obtain, generate, or collect data about their use or environment and can communicate that data via mobile networks, physical connectors, or on-device access. A vehicle (or trailer, van, or car) becomes a connected product once the telematics unit is activated in the fleet portal.
  • Related services are digital services necessary for the product to function fully or that affect its functions or operation (e.g., fleet monitoring dashboards, over-the-air configuration, remote diagnostics, predictive maintenance, driver coaching). A related service involves two-way data exchange with the connected product.

2) Which ZF products does this Notice cover?

All EU marketed ZF DSI–enabled connected products (trucks, vans, cars, trailers, retrofit telematics units and smart sensors) for which the telematics module has been activated by the user (fleet account holder).

3) What types of data can the connected product generate?

Depending on configuration, software and service package, the following categories may be generated:

  1. Interaction data (user actions): e.g., Tachograph data, driving and resting times, switch/button states.
  2. Usage/condition data (vehicle/trailer state): e.g., ECU data, VIN, odometer, speed, LIN Sensor, Reefer data, fuel/energy consumption, battery SoC, TPMS, Braking System Data, axle loads, CAN bus data, door/lock status, driver assistance system status, EBS/ABS events, alarms.
  3. Diagnostics data: e.g., DTCs, firmware/software versions, calibration state, sensor health, and Communication Unit Health Data.
  4. Environmental/context data: e.g., GPS/GNSS location, heading, motion sensor, ambient/internal temperatures, proximity/radar readings, road/traffic context captured by vehicle sensors where applicable.

Important scope notes under the Data Act:

  • In scope: “raw” or raw but usable data generated through the use of the product or related service (including relevant metadata).
  • Out of scope: derived or highly enriched data resulting from significant additional processing (e.g., proprietary analytics models, long-term aggregated insights).
  • Content from wider infrastructure (e.g., highway sensors) is excluded unless the user has rights over those sensors.

Formats: ZF provides thoughtfully designed HTTPS REST API endpoints for integration using JSON for request and response exchange.

Estimated volume/frequency: Data frequency ranges from event-based/periodic (seconds/minutes) to near real-time streaming while connected. Payloads vary by configuration (powertrain, sensor suite, service options).

4) Is the product capable of generating data continuously and in real time?

Yes. When the telematics unit is active and connectivity is available, the product can generate and transmit data continuously and in near real time. Some data may be buffered for later transmission where coverage is unavailable (e.g., roaming/out of coverage).

5) Who is the “user” and who is the “data holder”?

  • The user is the natural or legal person who owns, leases or rents the connected product or receives the related service (e.g., the fleet company or vehicle owner).
  • The data holder is the party responsible for using and making available the product/related service data—typically the manufacturer or service provider operating the telematics platform (ZF DSI/ZF Group entities, depending on contract).

6) What are your Data Act rights as a user?

  • Direct access by design: Product and related service data, including necessary metadata, are easily, securely, and free of charge directly accessible by default in a structured, commonly used, machine-readable format.
  • Right to obtain data without undue delay: Upon request, we provide readily available data without delay via portal download, API access, or secure transfer.
  • Right to share data with third parties: You may instruct us to transmit your data to a third party (e.g., workshop, insurer, TMS provider), and we will implement your instruction under Data Act conditions.
  • Fair terms; protection of trade secrets: Access is provided on fair, reasonable, and non-discriminatory (FRAND) terms where applicable, with safeguards for trade secrets and security.
  • Cloud-switching rights: If you use ZF data processing services bundled with cloud hosting, facilitated switching and anti-lock-in protections apply.

7) How can you exercise these rights with ZF?

  • Self-service access: Export and API access through the ZF fleet portal (documentation available to customers).
  • Directed sharing: Within the portal, you can authorize third-party access via scoped API tokens, timebound links, or submit a ticket to arrange secure data delivery to a designated recipient.
  • Authentication & authorization: We use role-based controls and strong authentication to ensure only authorized users or recipients access the specified data. (These steps align with the Data Act’s “access by design” principle.)
  • Third-parties: If you are a third party and need access to certain ZF customer data (the user), please contact the relevant user directly to request access.

8) What conditions apply when we share data with your designated third-party?

Third parties receiving data at your request must:
  • Enter into a formal contract defining the scope, purpose, security, confidentiality, termination, and deletion terms.
  • Use the data only for the specified purpose.
  • Delete or return the data when the purpose ends.
  • Not attempt to derive competing products using trade-secret-protected information or to circumvent security measures.
  • Comply with GDPR where personal data is involved.
  • We may deny or limit sharing to protect trade secrets, security, IP, safety or cybersecurity where required.

9) Personal data: How does the Data Act interact with the GDPR?

If data can identify a person (e.g., driver ID, precise location linked to a driver), the GDPR applies in full and prevails in case of conflict. Supervisory authorities designated under the GDPR remain competent. ZF acts as a Data Processor, and you must ensure an appropriate legal basis. We support data subject rights and apply privacy‑by‑design principles.

Your existing Data Processing Terms continue to apply and can be found via the following link: Data Processing Agreement.

10) Compensation and fees

Direct user access to readily available product/related service data is free of charge, except for reasonable costs related to bespoke, excessive or repeated requests beyond standard interfaces. FRAND conditions and reasonable compensation apply when required by EU law.

11) Security, trade secrets and intellectual property

We implement technical and organizational measures (encryption, API security, access logging, etc.). When enabling access or third-party sharing, we pseudonymize or redact data where feasible and may require NDAs or equivalent safeguards to protect trade secrets and IP. Requests may be refused or tailored where disclosure would endanger cybersecurity, safety or trade secrets. An overview of our technical and organizational measures can be found in Appendix 1 of our Data Processing Agreement.

12) Unlawful governmental access (non EU)

ZF applies safeguards to prevent unlawful governmental access to EU‑stored personal and non‑personal data by third‑country authorities, including challenge and transparency mechanisms.

13) Public sector access in cases of “exceptional need”

We may be required to provide data to public sector bodies or EU institutions where an exceptional need exists (e.g., a public emergency). Such requests must meet formal requirements and include safeguards. We will notify users where legally permitted.

14) Interoperability and standards

We support commonly used, machine‑readable formats to enable lawful access, transfer and use across services and data spaces. APIs and export formats evolve to meet interoperability and cloud‑switching requirements.

15) Timelines & legacy products

  • The Data Act applies from 12 September 2025.
  • The Commission’s FAQs clarify how certain rights apply prospectively to data generated after applicability, with clarifications updated in 2025 for connected products and related services (e.g., the definition of “readily available” data and examples for cameras and vehicles).

16) Dispute resolution

We aim to resolve access/sharing issues quickly through our customer support. The Data Act provides for out‑of‑court dispute settlement and competent national authorities. Details will be provided upon request.

17) How this Notice relates to other ZF terms

This Notice supplements (and does not replace) our ZF Terms and Conditions for the Supply of Telematics and Internet of Things Services, Data Processing Agreement and portal/service specific terms. GDPR‑based terms prevail where personal data is involved.

18) Contact

For questions related to Data Act, Security or Privacy, please contact legaldcs.cvcs@zf.com.

SCALAR

0