EV charging data ownership: who owns charger and session data?
There is no universal owner of EV charging data. Hardware ownership, database control, contractual access and drivers’ personal-data rights are separate questions.
Who owns EV charger and session data?
There is no single universal owner of EV charging data. The answer depends on the data type, the parties’ contracts and applicable law. Owning the physical charger does not automatically give a site host unrestricted rights to every customer, payment or roaming record.
It is more useful to separate four questions: who controls the charger, who holds the database, who may access and reuse each dataset, and whose personal data appears in it.
What data a charging service creates
Operational data can include charger identity, connectivity, firmware, configuration, status, alarms, error codes and remote actions. Session data can include timestamps, connector, energy, meter values, authorisation token, stop reason and tariff result. Customer and payment systems may add names, account details, receipts and support history.
Some fields are not personal on their own but become personal data when linked to an identifiable driver, employee, vehicle or location pattern. Aggregation or pseudonymisation can reduce risk, but pseudonymised data can still be personal data if it can be reconnected to a person.
Controller and processor roles matter more than ownership
Under the EU General Data Protection Regulation, a controller determines why and how personal data is processed; a processor handles it on the controller’s behalf. A CPO, employer, fleet, eMSP, CPMS provider or energy service may take either role, and some services involve separate or joint controllers.
Drivers have rights over their personal data, including access and, where the legal conditions apply, portability. That is not the same as owning the entire operational database. Exact duties vary by role, purpose and jurisdiction.
What the CPMS contract should specify
A CPMS agreement should define:
- which party controls operational, session, customer and derived data;
- who can view, export, correct and delete each dataset;
- available APIs, formats, rate limits and export fees;
- retention periods, storage locations and subprocessors;
- permitted analytics, benchmarking and model training;
- security controls, audit logs and incident responsibilities; and
- what is returned or deleted when the service ends.
A promise that “you own your data” is incomplete unless the contract explains access, usability and exit. Raw OCPP messages, normalised sessions, tariff calculations and aggregated reports may all have different terms.
How roaming and other partners affect access
A public session may involve a CPO, eMSP, roaming hub, payment provider, site host and support contractor. OCPI can exchange tokens, sessions and charge detail records between participating platforms. Each recipient still needs a defined purpose, lawful basis, retention rule and security responsibility for personal data.
Operators should minimise shared identifiers and give drivers clear information about the parties involved. Commercial settlement needs enough evidence to reconcile a session, but not every partner needs every raw diagnostic or customer field.
What amina’s architecture changes
The amina CSMS integration guide documents a direct charger-to-CSMS connection without a proprietary amina cloud in that communication path. The connectivity documentation also states that the CPO receives control of the factory eSIM and cellular traffic when the products leave the factory.
That architecture can reduce dependency on an intermediary for charger communications. It does not by itself decide who controls driver accounts, session databases, payments, roaming records or energy-service data. Those boundaries still depend on the selected CPMS, connected services and contracts.
Check data exit before choosing a platform
Before signing, request a sample export and test whether charger identities, sessions, meter records, users, tariffs, audit history and roaming references can be moved. Confirm who controls OCPP credentials and certificates, how long an export takes, and how deletion is evidenced after migration.
Data portability is both a compliance question and an operating requirement. A network should be able to investigate past sessions and continue service without rebuilding its history by hand.