“ANNEX XVII ACCESS TO VEHICLE OBD AND VEHICLE REPAIR AND MAINTENANCE INFORMATION
1.INTRODUCTION
1.1.This Annex lays down technical requirements for the accessibility of vehicle OBD and vehicle repair and maintenance information.
2.REQUIREMENTS
2.1.Vehicle OBD and vehicle repair and maintenance information available through websites shall follow the common standard referred to in Article 6(1) of Regulation (EC) No 595/2009. Until this standard is adopted, manufacturers shall provide vehicle OBD and vehicle repair and maintenance information in a standardised manner which is non-discriminatory compared to the provisions given or access granted to authorised dealers and repairers.
Those requiring the right to duplicate or republish the information shall negotiate directly with the manufacturer concerned. Information for training material shall also be available, but may be presented through other media than websites.
Information on all parts of the vehicle, with which the vehicle, as identified by the vehicle identification number (VIN) and any additional criteria such as wheelbase, engine output, trim level or options, is equipped by the vehicle manufacturer and which can be replaced by spare parts offered by the vehicle manufacturer to its authorised repairers or dealers or third parties by means of reference to original equipment (OE) parts number, shall be made available in a database which is easily accessible to independent operators.
This database shall comprise the VIN, OE parts numbers, OE naming of the parts, validity attributes (valid-from and valid-to dates), fitting attributes and, where applicable, structuring characteristics.
The information on the database shall be regularly updated. The updates shall include in particular all modifications to individual vehicles after their production if this information is available to authorised dealers.
2.2.Access to vehicle security features used by authorised dealers and repair shops shall be made available to independent operators under protection of security technology in accordance with the following requirements:
data shall be exchanged ensuring confidentiality, integrity and protection against replay;
the standard https//ssl-tls (RFC4346) shall be used;
security certificates in accordance with ISO 20828 shall be used for mutual authentication of independent operators and manufacturers;
the independent operator’s private key shall be protected by secure hardware.
The Forum on Access to Vehicle Information referred to in Article 2h shall specify the parameters for fulfilling these requirements in accordance with the state of the art. The independent operator shall be approved and authorised for this purpose on the basis of documents demonstrating that he pursues a legitimate business activity and has not been convicted of any criminal activity.