Who owns EV charger and session data?

There is no universal owner of EV charging data. The answer depends on the data, the contracts and applicable law. Owning the charger does not automatically give a site host unrestricted rights to every customer, payment or roaming record.

Separate four questions: who controls the charger, who holds the database, who may access and reuse each dataset, and whose personal data appears in it.

What data a charging service creates

Operational data can include charger identity, connectivity, firmware, settings, status, alarms, errors and remote actions. Session data may include times, connector, energy, meter values, authorisation token, stop reason and tariff result. Customer and payment systems can add names, accounts, receipts and support history.

Some fields become personal data when linked to an identifiable driver, employee, vehicle or location pattern. Aggregation or pseudonymisation can reduce risk, but pseudonymised data remains personal data when it can be linked back to a person.

Controller and processor roles matter more than ownership

Under the EU General Data Protection Regulation, a controller decides why and how personal data is processed; a processor handles it on the controller’s behalf. A CPO, employer, fleet, eMSP, CPMS provider or energy service may take either role. Some arrangements involve separate or joint controllers.

Drivers have rights over their personal data, including access and, where Article 20 conditions apply, portability. That is not ownership of the whole operational database. Duties depend on role, purpose and jurisdiction.

What the CPMS contract should specify

A CPMS agreement should define:

  • which party controls operational, session, customer and derived data;
  • who can view, export, correct and delete each dataset;
  • APIs, formats, rate limits and export fees;
  • retention, storage locations and subprocessors;
  • permitted analytics, benchmarking and model training;
  • security controls, audit logs and incident duties; and
  • what is returned or deleted when the service ends.

“You own your data” is incomplete unless the contract explains access, usability and exit. Raw OCPP messages, normalised sessions, tariff calculations and aggregated reports may carry different terms.

How roaming and other partners affect access

A public session may involve a CPO, eMSP, roaming hub, payment provider, site host and support contractor. OCPI can exchange tokens, sessions and charge detail records between platforms. Each recipient still needs a defined purpose, lawful basis, retention rule and security responsibility for personal data.

Share only the identifiers required and tell drivers which parties are involved. Commercial settlement needs enough evidence to reconcile a session; it does not give every partner a reason to receive every diagnostic or customer field.

What amina’s architecture changes

The amina CSMS integration guide documents a direct charger-to-CSMS connection without a proprietary amina cloud in that path. The connectivity documentation says the CPO receives ownership of the factory eSIM and control of cellular traffic when products leave the factory.

That can remove one intermediary from charger communications. It does not decide who controls driver accounts, session databases, payments, roaming records or energy-service data. Those boundaries still come from the chosen CPMS, connected services and contracts.

Check data exit before choosing a platform

Request a sample export before signing. Test whether charger identities, sessions, meter records, users, tariffs, audit history and roaming references can move. Confirm who controls OCPP credentials and certificates, how long export takes and how deletion is evidenced after migration.

Data portability is both a compliance question and an operating requirement. The network should be able to investigate old sessions and continue service without rebuilding its history by hand.