Connected vehicle owners in Australia now have concrete reasons to ask what their cars collect and who can access it. An ABC Four Corners investigation reported that BYD revised its Australian privacy policy after receiving questions from the program, uploading the new version 76 minutes before sending it to the Four Corners team. A separate controlled cybersecurity test demonstrated that a specialist could remotely access several systems on a moving BYD Shark 6 via a mobile network.
The BYD privacy policy update removed explicit references to “China” and “surveillance” from the Australian consumer terms. ABC reported that the revised document was uploaded just 76 minutes before the company sent it to the Four Corners team.
In the cybersecurity test, Fortify Labs co-founder Dan Hreszczuk accessed a BYD Shark 6 while it was travelling at 30 km/h. He remotely activated the headlights, wipers, windscreen spray, and speakers. He also accessed the vehicle’s infotainment system and gained real-time tracking and live cabin microphone access. The available reporting does not establish that the test enabled remote control of steering or braking.
BYD is challenging Toyota for the position of Australia’s top-selling car brand. The Shark 6 is a plug-in hybrid ute positioned against petrol-powered commercial vehicles in the fleet and tradie market.
Owners of connected smart vehicles now face a practical trade-off between digital convenience and personal security. While the test did not demonstrate remote control of driving functions, secondary controls and location data were accessible. The revised policy removed the explicit reference to China while retaining provisions allowing personal data to be transferred overseas.
What Changed in BYD's Australian Privacy Terms
BYD’s revised Australian policy still contains provisions allowing telemetry data transfers to overseas affiliates and operational cloud providers. The removal of “China” from the third-party processing list altered the document’s wording but retained the transfer provisions.
Australia’s BYD vehicles collect vehicle usage data, driving behaviour, geolocation, infotainment activity, and diagnostics. That data profile is standard across most connected vehicles today, but the combination of the policy change and the remote access demonstration has pushed it into sharper focus for Australian buyers. For anyone considering or currently owning a connected EV in Australia, the relevant questions are the same as for any connected device: what is collected, where it goes, and how access is controlled. A broader overview of what Australian connected vehicle regulations currently require is available in .
ABC also reported that Lockheed Martin used a third company to ship F-35 components that were meant to be flown to the United States, as a separate illustration of logistics-chain oversight issues involving Australian-origin equipment. The BYD investigation is distinct but sits alongside a broader public debate about data sovereignty in Australian consumer technology.
Can a BYD car be hacked remotely while driving?
Controlled cybersecurity testing showed Fortify Labs co-founder Dan Hreszczuk could remotely access several functions on a moving BYD Shark 6—including headlights, wipers, speakers, and infotainment—while tracking the vehicle and accessing its cabin microphone via a mobile network. The available reporting does not show that the test enabled remote control of steering or braking.
BYD has not publicly confirmed what technical changes, if any, will follow the privacy policy revision. Australia’s federal government is reviewing smart vehicle cybersecurity standards, with a parliamentary process examining connected vehicle security requirements. Check back as that review progresses.