← IoT Privacy Database

Jaguar Land Rover InControl / Pivi Pro

Jaguar Land Rover · Connected Car

✓ Reviewed

5.0Surveillance
Index
Policy — what its policy permitsF
Evidence — what research provesC

Jaguar and Land Rover's InControl and Pivi Pro systems link the vehicle to a cloud account that collects precise location, trip and driving data, voice input and vehicle diagnostics for remote lock/locate, SOS and stolen-vehicle tracking, tied to your identity. JLR's policy permits sharing with partners for marketing. The dominant documented concern is the manufacturer's security posture: JLR suffered a catastrophic 2025 ransomware attack that halted global production for weeks and leaked internal data, though its handling of consumer telematics specifically remains largely unstudied.

Why this rating

Policy permits marketing sharing with partners (sells-data, broker-disclosure) and collects precise location and voice via InControl/Pivi Pro (sensitive-collection), with vague partner language (policy-vagueness). Evidence: JLR suffered a 2025 cyberattack that halted global production for about five weeks with an estimated ~1.9bn GBP economic impact, assessed by the independent Cyber Monitoring Centre as among Britain's most damaging cyber incidents; the cited assessment names no attacker and does not establish what data was exposed, and JLR's own driver-telematics practices remain unstudied, so the evidence axis is capped.

What it is

Manufacturer
Jaguar Land Rover
Category
Connected Car
Model years
2019-present
Market status
Current
Companion app
InControl Remote / Land Rover Remote / Jaguar Remote

The evidence 1

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Breach report · Cyber Monitoring Centre · 2025-10

    An independent body assessed the 2025 JLR cyberattack, which halted global production for weeks with an estimated ~1.9B GBP economic impact, as among Britain's most damaging cyber incidents; the HELLCAT group leaked source code and employee/partner data.

    Why it matters here: A severe operational-security failure at the maker of InControl/Pivi Pro; the cited assessment concerns the production-halting attack's scale and economic impact and does not establish exposure of driver telematics, so it bears only indirectly on consumer privacy.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database