On 3 September 2026, Uber and Wayve began London's first commercial robotaxi service. According to The Next Web, fewer than 20 Ford Mustang Mach-E cars are running, Transport for London approved up to 15 for a one-year trial, and a licensed driver is in every car and legally responsible throughout each journey. Riders are matched through the Uber app.
The launch is small. The data questions it raises are not. Every one of these cars carries cameras and sensors that record streets, pedestrians, other drivers and passengers. Who governs that data, and what it may be used for, will decide whether the UK's autonomous vehicle regime is trusted and whether it stays attractive to builders like Wayve.
The case for tougher rules
The strongest argument for stricter, AV-specific data rules is this. A robotaxi is a mobile surveillance platform. Its cameras capture bystanders who never agreed to anything, and its cabin can capture passengers who chose a ride, not a recording. The Information Commissioner's Office (ICO) has already said that in-vehicle recording affects everyone in and around the car. Its guidance on surveillance in vehicles expects a data protection impact assessment (DPIA) that addresses the rights of both drivers and passengers, and it says operators should safeguard "licenced drivers, passengers and other members of the public". Critics can fairly add that guidance is not law, and that a company holding training data has a commercial incentive to keep more than it needs.
What already applies
The gap is smaller than that argument suggests. UK GDPR applies whenever footage or telemetry relates to an identifiable person, and the ICO's guidance sets out concrete expectations: clear signage or notices, a DPIA, necessity and proportionality, and audio switched off by default and used only "in exceptional circumstances". Those are specific, testable duties on an operator like Uber.
The ICO's Tech Horizons 2025 chapter on connected transport names the right problems. Connected vehicles collect "increasing volumes of information". Sensors gather data with limited ability for users to opt out. In shared vehicles, transparency is hard because there are several occupants and small displays. The ICO's answer is privacy by design and early engagement with regulators, not a ban or a new statute. That is the right instinct.
The AV Act's role is safety data
The Automated Vehicles Act 2024 does a different job from data protection. Its data provisions serve safety. The government's response on the automated passenger services (APS) permitting scheme, published on 23 April 2026 alongside the Automated Vehicles (Permits for Automated Passenger Services) Regulations 2026, says the services will be independently assessed, monitored and enforced. It also records one change after consultation: the statutory instrument was widened "to enable wider non-safety-related information to be shared with emergency responders".
That sentence shows how a data regime can drift. Sharing information that helps a fire crew handle a crashed vehicle is easy to defend. Once the category is "wider non-safety-related information", the limits matter. The government response does not spell out retention periods or how UK GDPR constrains those flows, and I could not find those details in it. Regulators should publish them.
Why the Uber and Wayve launch is a useful test
The current pilot is the least risky setting for these questions. As The Next Web reports, TfL licensed the cars as private hire vehicles, not as automated vehicles. The companies do not yet hold an APS permit from the Driver and Vehicle Standards Agency, which driverless operation requires. A human is legally responsible for every trip. So the data flowing today is mostly training and validation data collected under existing private hire and data protection rules.
That is a reason to settle the data rules now, before permits for driverless service arrive. There are three practical points:
- Purpose separation. Data kept to investigate an incident, data used to improve the driving model, and data shared with emergency services are different purposes. Each needs its own legal basis and retention limit under UK GDPR.
- Bystander minimisation. Training pipelines should blur faces and number plates where the model does not need them. That is cheap for a software company and answers the ICO's "no more than they need" concern.
- Passenger clarity. Riders who book through the Uber app should see plain notices about any in-cabin recording before the trip, not after it.
A proportionate path
The UK has an advantage over rivals. Waymo already runs fully driverless in 14 American cities, according to The Next Web, and London is a generation behind. The way to catch up is not a stricter data regime than competitors face. It is a clearer one. A separate AV privacy statute would duplicate UK GDPR, add compliance cost for start-ups like Wayve, and take years to pass.
The better course has three parts. First, the ICO should publish AV-specific guidance covering training data, incident data and in-cabin recording, building on its existing surveillance guidance. Second, the permitting authority should require applicants to file a DPIA as part of any APS application. Third, the government should say in the APS scheme how emergency-responder data sharing is limited and how long the data is kept.
This keeps the public's trust without slowing deployment. Wayve's supervised cars are a small, well-lit trial. If the rules are settled before the safety drivers leave, the UK can have safe robotaxis and a defensible answer on data, and it will not need to trade one for the other.