Nařízení Komise v přenesené pravomoci (EU) 2026/699 ze dne 23. března 2026, kterým se mění nařízení Evropského parlamentu a Rady (EU) 2018/858, pokud jde o standardizovaný přístup k informacím palubního diagnostického systému vozidla a k informacím o opravách a údržbě vozidla a požadavky a postupy pro bezpečný přístup k informacím palubního diagnostického systému

Identifier:
32026R0699
Status:
effective
Text language:
en

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, amending Regulations (EC) No 715/2007 and (EC) No 595/2009 and repealing Directive 2007/46/ECOJ L 151, 14.6.2018, p. 1 , ELI: http://data.europa.eu/eli/reg/2018/858/oj. , and in particular Article 61(11) thereof,

Annex X to Regulation (EU) 2018/858 is amended in accordance with the Annex to this Regulation.

OJ L 151, 14.6.2018, p. 1 , ELI: http://data.europa.eu/eli/reg/2018/858/oj.

(1) Regulation (EU) 2018/858 requires vehicle manufacturers to provide to independent operators unrestricted, standardised and non-discriminatory access to vehicle on-board diagnostics (OBD) information, diagnostic and other equipment, tools including the complete references, and available downloads, of the applicable software and vehicle repair and maintenance information.

(2) Article 4(5), point (d), of Regulation (EU) 2019/2144 of the European Parliament and of the CouncilRegulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users, amending Regulation (EU) 2018/858 of the European Parliament and of the Council and repealing Regulations (EC) No 78/2009, (EC) No 79/2009 and (EC) No 661/2009 of the European Parliament and of the Council and Commission Regulations (EC) No 631/2009, (EU) No 406/2010, (EU) No 672/2010, (EU) No 1003/2010, (EU) No 1005/2010, (EU) No 1008/2010, (EU) No 1009/2010, (EU) No 19/2011, (EU) No 109/2011, (EU) No 458/2011, (EU) No 65/2012, (EU) No 130/2012, (EU) No 347/2012, (EU) No 351/2012, (EU) No 1230/2012 and (EU) 2015/166 (OJ L 325, 16.12.2019, p. 1 , ELI: http://data.europa.eu/eli/reg/2019/2144/oj). (the Union cybersecurity rules) provides that the manufacturers are to comply with the applicable requirements on the protection of vehicles against cyberattacks. Technical requirements and testing procedures adopted to that effect reference the requirements of UN Regulation No 155UN Regulation No 155 – Uniform provisions concerning the approval of vehicles with regards to cybersecurity and cybersecurity management system [2021/387] (OJ L 82, 9.3.2021, p. 30 , ELI: http://data.europa.eu/eli/reg/2021/387/oj). .

(3) Pursuant to UN Regulation No 155, the technical requirements and testing procedures provided therein are, however, without prejudice to the Union legislation governing the access by authorised parties to the vehicle, its data, functions and resources, and conditions of such access:

(4) Regulation (EU) 2018/858 precludes a vehicle manufacturer from making access by independent operators to vehicle repair and maintenance information and to OBD information, including write access to that information, subject to conditions other than those laid down therein, such as those motivated by cybersecurity.

(5) The Union legal framework governing cybersecurity measures to be applied on access to vehicle OBD information is not complete. The Union cybersecurity rules require the manufacturers to protect vehicles against cyberattacks but limit the effect of the technical requirements specifying the applicable measures as regards access to vehicle data. On the other hand, rules on access to vehicle OBD information do not sufficiently take cybersecurity into account. As a result, vehicle manufacturers face important legal constraints preventing them from applying effective measures protecting the vehicle from cyberattacks related to access to vehicle OBD information.

(6) It is therefore necessary to ensure that car manufacturers are allowed to apply effective and proportionate cybersecurity measures while providing access to OBD information.

(7) The increase of cybersecurity threats and the related adoption of the Union rules requiring the vehicle manufacturers to protect vehicles against cyberattacks constitute technical and regulatory developments justifying such amendments to Annex X.

(8) In order to permit the manufacturers to address those threats while maintaining effective access of independent operators to vehicle OBD information, the Regulation (EU) 2018/858 should contain the conditions and procedures that vehicle manufacturers are allowed to apply to ensure secure access to OBD information by independent operators.

(9) Depending on the nature and the consequences of the access sought, vehicle manufacturers should be allowed to require the manufacturers of diagnostic tools used for access to OBD information to authenticate the tool and the independent operator seeking access or its employee and to ensure traceability by recording and storing the relevant information on such access. They should also be allowed, in specific cases, to require connection to the vehicle manufacturer’s server.

(10) To protect the equal conditions for competition, the information on the independent operators seeking access to the vehicle OBD information should be pseudonymised.

(11) In order to enable vehicle manufacturers to manage dependencies, as required under the applicable vehicle cybersecurity rules, they should be allowed to verify that the diagnostic tools and their manufacturers comply with relevant cybersecurity standards and security implementations.

(12) In case of cybersecurity incidents, serious abuse or incidents involving the vehicle manufacture’s liability, vehicle manufacturers should be able to obtain information on specific cases of access and to temporarily suspend, as appropriate and under the control of the approval authority, access of a tool, and independent operator or its employee.

(13) Vehicle manufacturers should provide all necessary technical information to the manufacturers of generic diagnostic tools sufficiently in advance of a vehicle being placed on the market to allow those tool manufacturers to provide adequate service to independent repair operators.

(14) In addition to the conditions and procedures for secure access to OBD information, this Regulation should further facilitate access to vehicle OBD information and repair and maintenance information (RMI), taking into account the technical progress.

(15) The catalogue of information to be made available by vehicle manufacturers should be clarified and updated, notably taking into account the needs related to repair and maintenance of vehicle batteries and new driver assistance systems.

(16) Whenever vehicle manufacturers, for the purpose of accessing vehicle OBD information, diagnostics, repair and maintenance, monitoring and inspection, enable access to the in-vehicle data stream by other mean than using the serial data port on the standardised connector, the same access and information should be available under non-discriminatory conditions to all independent operators.

(17) Recognising the role of data publishers in facilitating the vehicle repair and maintenance, the information sharing requirements of the vehicle manufacturers should be further clarified.

(18) In order to enable independent repairers to reprogram vehicle control units in the same conditions as those available to vehicle manufacturers and authorised repairers, it is necessary to set out additional requirements for manufacturers to make specific software or information available to independent diagnostic tool manufacturers.

(19) However, complying with these requirements requires the vehicle manufacturers to implement important preparatory measures, therefore the application of these requirements should be deferred to provide for an appropriate lead-time.

(20) This Regulation applies without prejudice to Regulation (EU) 2016/679 of the European Parliament and of the CouncilRegulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1 , ELI: http://data.europa.eu/eli/reg/2016/679/oj). and Directive 2002/58/EC of the European Parliament and of the CouncilDirective 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37 , ELI: http://data.europa.eu/eli/dir/2002/58/oj). . In particular, the obligations of manufacturers as regards providing access to vehicle OBD information to independent operators under this Regulation are without prejudice to the rights of data subjects and the obligations of vehicle manufacturers, manufacturers of diagnostic tools and independent operators under those acts.

(21) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the CouncilRegulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39 , ELI: http://data.europa.eu/eli/reg/2018/1725/oj). and delivered an opinion on 20 February 2026 https://www.edps.europa.eu/data-protection/our-work/our-work-by-type/opinions_en. .

(22) Regulation (EU) 2018/858 should therefore be amended accordingly,

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union .

Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users, amending Regulation (EU) 2018/858 of the European Parliament and of the Council and repealing Regulations (EC) No 78/2009, (EC) No 79/2009 and (EC) No 661/2009 of the European Parliament and of the Council and Commission Regulations (EC) No 631/2009, (EU) No 406/2010, (EU) No 672/2010, (EU) No 1003/2010, (EU) No 1005/2010, (EU) No 1008/2010, (EU) No 1009/2010, (EU) No 19/2011, (EU) No 109/2011, (EU) No 458/2011, (EU) No 65/2012, (EU) No 130/2012, (EU) No 347/2012, (EU) No 351/2012, (EU) No 1230/2012 and (EU) 2015/166 (OJ L 325, 16.12.2019, p. 1 , ELI: http://data.europa.eu/eli/reg/2019/2144/oj).

Article 1 Article 1

Article 2 Article 2

UN Regulation No 155 – Uniform provisions concerning the approval of vehicles with regards to cybersecurity and cybersecurity management system [2021/387] (OJ L 82, 9.3.2021, p. 30 , ELI: http://data.europa.eu/eli/reg/2021/387/oj).

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1 , ELI: http://data.europa.eu/eli/reg/2016/679/oj).

Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37 , ELI: http://data.europa.eu/eli/dir/2002/58/oj).

Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39 , ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

https://www.edps.europa.eu/data-protection/our-work/our-work-by-type/opinions_en.

HAS ADOPTED THIS REGULATION:

Nařízení Komise v přenesené pravomoci (EU) 2026/699 ze dne 23. března 2026, kterým se mění nařízení Evropského parlamentu a Rady (EU) 2018/858, pokud jde o standardizovaný přístup k informacím palubního diagnostického systému vozidla a k informacím o opravách a údržbě vozidla a požadavky a postupy pro bezpečný přístup k informacím palubního diagnostického systému — LexHub