A five-year-old rule reaches its final phase
Since 7 July 2026, every newly registered car and van in the EU must carry an Advanced Driver Distraction Warning (ADDW) system — an infrared camera aimed at the driver's face, tracking gaze direction, blink rate and head position to detect when attention has drifted from the road (European Commission, "Safer cars, safer roads: new rules take effect"). It is the last major tranche of Regulation (EU) 2019/2144, the General Safety Regulation, which already required a related driver drowsiness and attention warning system on all newly type-approved vehicles from July 2022 and all new registrations from July 2024 (InterRegs). The mandate has landed exactly as billed: a camera pointed at the driver's face is now standard equipment on the European car fleet, and it has reignited a GDPR and "mission creep" debate that the regulation's drafters tried to design around rather than legislate away.
The case for watching the driver
The safety argument is not manufactured. The European Commission's own road safety observatory estimates driver fatigue contributes to somewhere between roughly 10% of crashes by conservative police-report counts and up to 20% of crashes on motorways under naturalistic and in-depth crash studies (European Road Safety Observatory). The EU recorded roughly 19,400 road deaths in 2025 — a 3% improvement on 2024, but still far off the pace needed to hit the bloc's target of halving deaths and serious injuries by 2030 against a 2019 baseline (European Commission, Mobility and Transport). Distraction and drowsiness are among the few crash causes a vehicle-side sensor can plausibly catch before impact, rather than after. A regulator staring at that toll and reaching for the one sensor package proven to intervene in real time is not acting on a whim.
A closed loop, by design
What critics of the mandate often skip is that the GSR's implementing rules were written with the privacy objection in mind. ADDW and its drowsiness-detection predecessor are required to run as a closed loop: infrared illumination invisible to the eye, processing that happens entirely on-device, no transmission to any external server, no biometric identification of the driver, and immediate deletion of the frame once a distraction score is computed (Forbes). That is not an incidental feature — it tracks almost exactly what the European Data Protection Board recommended in its Guidelines 1/2020 on connected vehicles, which pushed manufacturers toward local, on-board processing of biometric signals like gaze and eye movement precisely because keeping the data inside the vehicle avoids the higher-risk profile of cloud processing and materially reduces the odds the system ever needs Article 9 GDPR-level special-category handling in the first place (EDPB, Guidelines 1/2020). In other words: the automaker didn't stumble into a privacy-conscious architecture. Data protection regulators told them, years in advance, exactly what a defensible design looked like, and the GSR's technical annexes largely match it.
Where the law is actually doing the work
The uncomfortable part for privacy advocates is that none of this closed-loop design is written into the General Safety Regulation as an ADDW-specific legal guarantee with its own enforcement teeth. The behavioral constraint — no retention, no third-party access, immediate deletion — sits in the regulation's technical requirements, while the deeper legal backstop against repurposing that data is ordinary GDPR: Article 9's special-category protections for biometric data used to identify a person, and the EDPB's expectation that any processing beyond the safety mandate would need its own lawful basis and, in most cases, a full Data Protection Impact Assessment. That is a real backstop, but it is a general-purpose one, bolted onto a car-safety rule rather than purpose-built for it. The safety regulation didn't need to reinvent data protection law — GDPR already covers biometric processing — but it also means the durability of the closed-loop promise rests on GDPR enforcement discipline continuing to apply as vigorously to dashboards as it does to smartphones.
The real risk is downstream, not in the sensor
That's also why "mission creep" is the right frame and the wrong target. The camera itself, as mandated, is proportionate: it responds to a documented, quantifiable safety problem, and its default architecture is about as privacy-protective as an always-on driver-facing sensor can be. The risk sits one layer down — in whether insurers angling for usage-based pricing, fleet operators wanting behavioral scoring, or a future Commission delegated act looking to extend ADDW into intervention (steering or braking) will find the hardware already installed and the software change comparatively cheap. None of that requires defeating the current rule. It requires that any such expansion go through the same EDPB-guided, DPIA-anchored scrutiny that shaped the original design — not quietly ride on infrastructure Europeans have already accepted for a narrower purpose.
Regulators got the hard part right by treating privacy as a design constraint from the start rather than an afterthought bolted on post-launch. The obligation now runs the other way: keep every future use of that camera on the same leash, and say so before, not after, the software update ships.