
Connected Vehicles and IoT Regulation
Regulatory compliance for connected mobility, telematics and IoT deployments
Telecoms, data protection and product security regulation for IoT and connected vehicle deployments
Trigger situation
A vehicle manufacturer or fleet operator is deploying connected vehicle technology that uses cellular connectivity (eCall, V2X, telematics, over-the-air updates). An IoT platform provider is offering connectivity services that may fall within the scope of UK telecoms regulation. A smart city or smart building developer is deploying sensor networks that use licensed or unlicensed spectrum. A PE investor is assessing a connected devices business and needs to understand the regulatory overlay.
Why it matters now
Four regimes apply at once to a connected vehicle or IoT deployment: UK telecoms regulation, UK data protection law, product safety law (including the Product Security and Telecommunications Infrastructure Act 2022), and cyber security regulation (including the Network and Information Systems Regulations 2018, SI 2018/506). An operator whose device or platform is an electronic communications network or service under the Communications Act 2003 must comply with the full range of telecoms obligations, including the General Conditions, the Telecommunications (Security) Act 2021 security requirements, and, where a technical capability notice is given under section 253 of the Investigatory Powers Act 2016, an obligation to maintain an interception capability. The Communications Act 2003 draws no distinction between a telecoms company and a technology company or software platform. The test is what the network or service does.
Connected vehicles use cellular connectivity to transmit telematics data, to receive over-the-air updates, and (increasingly) to enable vehicle-to-everything (V2X) communication. The eCall system (emergency call on crash) is now mandatory in the EU and retained EU law applies in the UK. eCall uses the cellular network, which means vehicle manufacturers and eCall service providers must comply with telecoms law. eCall also carries its own requirements under Regulation (EU) 2015/758, which has effect in the UK as assimilated law, amended by the Road Vehicles and Non-Road Mobile Machinery (Type-Approval) (Amendment and Transitional Provisions) (EU Exit) Regulations 2022 (SI 2022/1273) and applying to GB type-approval of category M1 and N1 vehicles. This regime specifies technical and operational requirements for eCall that go beyond standard telecoms obligations.
A manufacturer, importer or distributor of a connected device must meet the minimum cybersecurity requirements in Part 1 of the PSTI Act 2022. Those duties fall on it whether or not it is also a telecoms operator. A vehicle manufacturer deploying connected vehicles is subject to the PSTI Act regardless of whether it is also a telecoms provider. The Secretary of State enforces Part 1, in practice through the Office for Product Safety and Standards, by compliance, stop and recall notices and by a monetary penalty under section 36 of the PSTI Act 2022, with an appeal to the First-tier Tribunal under section 41. Part 1 creates no offence of non-compliance by a manufacturer, importer or distributor.
A business that settles its regulatory position before launch avoids rebuilding the product to meet obligations it finds after deployment.
Common failure points
A business that transmits signals over its own network operates an electronic communications network, whatever it calls itself. Under section 32(1) of the Communications Act 2003, an electronic communications network is a transmission system for the conveyance, by the use of electrical, magnetic or electro-magnetic energy, of signals of any description, together with the apparatus, software, stored data and other resources used with it for conveying those signals. The definition is broad and technologically neutral. It encompasses private networks that transmit data over wireless spectrum, even if the network operator has no intention of providing a public service. A manufacturing facility that deploys IoT sensors communicating over a private 5G network is operating an electronic communications network whether or not it describes itself as a telecoms company.
A business operating an electronic communications network must comply with the General Conditions, which Ofcom sets under section 45 of the Communications Act 2003 and gives effect to by notification under section 48. These include obligations relating to network functioning and access (GC A1), number portability and switching (GC B), consumer protection and contract transparency (GC C), and emergency call access (General Condition A3). Cooperation with lawful interception is not a General Condition: it arises under the Investigatory Powers Act 2016, including any technical capability notice given under section 253 of that Act. The obligations apply from the moment the network carries traffic, whether or not the operator has the capacity to handle emergency calls or lawful intercept requests.
The PSTI Act and telecoms regulation are separate regimes that apply together, not as alternatives. Part 1 of the PSTI Act 2022 applies to a “relevant connectable product” as defined in section 4 of that Act. A manufacturer must implement security measures appropriate to the risk of the device being compromised or misused. Schedule 1 to the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 (SI 2023/1007) imposes three requirements on manufacturers: passwords must be unique per product or defined by the user, and must not be based on incremental counters, on publicly available information or otherwise be guessable; a point of contact for reporting security issues must be published; and the defined support period for security updates must be published. A device manufacturer that is also a telecoms provider must comply with both the General Conditions and the PSTI Act. These regimes have different actors (all General Conditions obligations fall on the network provider, but PSTI Act obligations fall on the manufacturer or distributor) and different compliance timetables.
Deploying a connected device over a licensed spectrum band brings the device within the scope of the Wireless Telegraphy Act 2006 and the spectrum licensing regime; it does not take the device outside telecoms regulation. A device that uses cellular spectrum does come within the spectrum licensing regime and the operator must hold a spectrum license. Whether the operator is also subject to the General Conditions is a separate question, answered by whether it provides an electronic communications network or service within section 32 of the Communications Act 2003 and by the application provision of each Condition. Holding a spectrum licence neither creates nor removes that liability.
Connected devices carry data protection implications that telecoms compliance alone does not address. Connected devices typically transmit personal data (telematics data, location data, usage patterns). This data is subject to UK GDPR and the Data Protection Act 2018. Whether the device operator, the manufacturer or a platform provider is a controller, joint controller or processor is fact-sensitive: it turns on who determines the purposes and essential means of each processing operation. But the UK GDPR and the Data Protection Act 2018 operate independently of telecoms regulation. A provider can be in full compliance with telecoms law but in breach of data protection law. The two regimes require separate compliance planning.
How the analysis runs
A connected vehicle or IoT deployment engages telecoms law, product safety law, data protection law and cyber security regulation together, and the obligations under each have to be identified before launch.
The first question is whether the device or platform is an electronic communications network or service, and it is answered on what the device or platform does. The points that decide it are whether the device transmits signals, whether it is open to public use or closed, and whether it carries user data or only diagnostic data. The statutory definitions have to be applied to the particular business model. The answer is often not obvious, and it depends on Ofcom’s published guidance and its decisions on scope.
Not every General Condition applies to every provider. Some conditions apply only to “public” providers or to providers serving “end-users”. Some conditions apply only to providers with significant market power. The demanding obligations are emergency call access under General Condition A3 and, separately from the General Conditions, interception capability under the Investigatory Powers Act 2016 and any technical capability notice given under section 253 of that Act. A provider needs the technical and operational capacity to meet them before it carries traffic.
A device transmitting on a licensed band brings its operator within the licensing regime in the Wireless Telegraphy Act 2006, which Ofcom administers. If a device manufacturer is deploying devices that transmit on licensed spectrum bands, the manufacturer may need a spectrum license. Which class of licence is required, and on what conditions, depends on the band and on how the device is deployed.
PSTI Act compliance is settled in product development, not after launch. The PSTI Act is principles-based; it does not prescribe specific technical standards. Instead, it requires that manufacturers implement security measures “appropriate to the risk” of IoT devices being compromised. What is appropriate depends on the device and on its risk profile, and the manufacturer records that judgement as it makes it. The Office for Product Safety and Standards enforces the Act and can issue compliance notices and seek undertakings, so the record has to stand up when it is asked for.
Telecoms compliance does not answer the data protection question. A connected device transmits personal data, and the controller must comply with the UK GDPR and the Data Protection Act 2018 as well as with telecoms law. This is particularly important for connected vehicles, which generate detailed telematics and location data about identifiable individuals.
A connected vehicle using cellular connectivity may carry further obligations on eCall, on V2X communication and on over-the-air security updates. A manufacturer builds those into product design and into its operational processes.
Enforcement risk follows the business model: an operator that cannot meet the General Conditions it is subject to, and a manufacturer that cannot show how it met the PSTI Act requirements, are the two exposures to plan for.
When to instruct
You should instruct Bratby Law before deploying a connected device or IoT platform that uses cellular or radio connectivity. Taking advice before deployment lets you build compliance into the product rather than retrofit it. You should instruct if you are a device manufacturer deploying connected devices and want to understand your obligations under both the PSTI Act and telecoms regulation. You should instruct if you are an investor assessing a connected device business and want to understand the regulatory risk profile. You should not instruct for routine questions about whether your product meets industry standards unless those standards have regulatory significance.
How Bratby Law helps
The questions this page covers are whether a device or platform is an electronic communications network or service, which General Conditions then apply, whether the deployment needs a spectrum licence, what the PSTI Act requires of the manufacturer, and how data protection compliance is built into product design alongside them.
Discuss your matter
Frequently asked questions
When is a device manufacturer subject to UK telecoms regulation?
A device manufacturer is subject to UK telecoms regulation if the device operates or enables the operation of an electronic communications network or service. Under section 32(1) of the Communications Act 2003, an electronic communications network is a transmission system for the conveyance, by the use of electrical, magnetic or electro-magnetic energy, of signals of any description, together with the apparatus, software, stored data and other resources used with it for conveying those signals. The definition is technology-neutral and applies to any system that transmits signals, including private networks. A device manufacturer that deploys a network of IoT sensors communicating over cellular or radio spectrum is operating an electronic communications network and is subject to telecoms regulation.
What are the General Conditions and what obligations do they impose?
The General Conditions are set by Ofcom under sections 45 to 64 of the Communications Act 2003 and are the baseline regulatory obligations applicable to all providers of electronic communications networks and services. They cover network functioning and access (GC A1), number portability and switching (GC B), consumer protection, contract transparency and complaints handling (GC C), emergency call access (GC A3), and security obligations. Not all General Conditions apply equally to all providers; some apply only to public networks or to providers with significant market power. An IoT or connected device provider should obtain advice on which conditions apply to their specific business model and service category.
What is the Product Security and Telecommunications Infrastructure Act 2022 and how does it apply to IoT devices?
Part 1 of the PSTI Act 2022 requires manufacturers, importers and distributors of relevant connectable products to comply with the security requirements made under section 1. Section 7 defines manufacturer, importer and distributor, and section 4 defines “relevant connectable product”. The requirements are principles-based: manufacturers must implement security measures that are appropriate to the level of risk posed by IoT devices being compromised. The Office for Product Safety and Standards enforces the PSTI Act. The PSTI Act applies independently of telecoms regulation; a device manufacturer can be compliant with telecoms law but in breach of the PSTI Act, or vice versa.
Is an IoT service provider subject to lawful intercept obligations?
Interception capability is not a General Condition and Ofcom does not enforce it. Interception is governed by the Investigatory Powers Act 2016. Under section 253 of that Act the Secretary of State may give a telecommunications operator a technical capability notice, approved by a Judicial Commissioner, imposing the applicable obligations specified in regulations and requiring the operator to take the steps specified in the notice, so that it has the capability to give assistance in relation to a warrant issued under Part 2, 5 or 6 or an authorisation or notice given under Part 3. An IoT service provider that is a telecommunications operator may be given such a notice; absent one, it carries no standing interception capability duty.
What is eCall and what are the regulatory obligations?
eCall is the European emergency call system, which is mandatory in new vehicles sold in the EU and retained EU law in the UK. eCall automatically transmits location data and basic vehicle information to emergency services when the vehicle is in a crash. eCall uses the cellular network, which means vehicle manufacturers and eCall service providers must comply with the eCall Regulation (retained EU law) and also with general telecoms regulation. The eCall Regulation specifies technical and operational requirements, including requirements for security, resilience and data protection. An eCall service provider must comply with both the eCall Regulation and the General Conditions of the Communications Act 2003.
Can a connected device use unlicensed spectrum without a spectrum licence?
There is no telecoms licence to hold. Sections 5 to 8 of the Telecommunications Act 1984, which required a licence to run a telecommunication system, were repealed by the Communications Act 2003 with effect from 25 July 2003, and providing an electronic communications network or service now requires no individual authorisation. Spectrum is a separate question: most unlicensed spectrum, such as the ISM bands used by WiFi and Bluetooth, is exempted from the licensing requirement in the Wireless Telegraphy Act 2006 but remains subject to the technical conditions Ofcom sets. Whether the General Conditions apply is a third question, answered by whether the operator provides an electronic communications network or service within section 32 of the Communications Act 2003, and then by the application provision of each Condition.
What is the relationship between UK telecoms regulation and UK GDPR for connected devices?
UK telecoms regulation and UK GDPR are separate regimes that apply independently. A connected device transmits personal data, and the party that determines the purposes and essential means of that processing, often the device operator, is a controller under UK GDPR. The operator must comply with the General Conditions under telecoms law and also comply with UK GDPR. The two regimes have different actors, different obligations and different enforcement mechanisms. A provider that is compliant with telecoms law can still breach UK GDPR if it does not implement adequate data protection safeguards. Similarly, a provider that is GDPR-compliant can still breach telecoms law if it fails to implement the General Conditions.
Advice on connected vehicle and IoT regulation
Related telecoms regulation pages
The telecoms regulation and data protection pages cover the wider framework. See also:
Am I regulated?
Ofcom General conditions of entitlement
SMP regulation and market reviews
Numbering
Code Powers and access to land
Spectrum
Lawful intercept and the Investigatory Powers Act 2016
Telecoms Security
Ofcom Licence Fees
Ofcom: Advice for Operators, Investors and Platforms
Interconnection regulation
Complaints and investigations
EU Digital Networks Act
