Governing industry data well is not bureaucracy - it is what keeps the data worth contributing to. The usage rules in a data sharing programme need to be written down, repeated often and enforced by protocol rather than opinion. When participants understand where internal use ends and public disclosure begins, trust holds, participation continues and the shared picture stays useful for everyone. The rules exist to protect the programme, and with it every participant's access to the data.
Most participants in a data sharing programme know instinctively that they should not misuse the figures they receive. Far fewer know exactly where the line sits. A product manager drops a market share percentage into a press release. A multi-brand dealer passes data to a brand it does not report for. Each is a well-meaning person who has just put the whole programme at risk. This is the heart of trust and governance in competitive data sharing: when trust breaks down, participation drops and the data loses its value. In this post, we explore the most common ways participants cross the line, and how good governance keeps a programme safe.
The two ways well-meaning participants cross the line
The two misuses we see most often are promotional use and access-boundary breaches.
The first is a visibility problem. A participant posts a strong result and the instinct is to broadcast it - declaring a number one position at an industry event, or advertising market share. Most programme rules prohibit this, and a market share claim that references the programme breaks the rules even when the position is genuinely true.
The second is structural. A dealer that represents several brands may hold data because it participates with one of them, then assume that holding the data confers the right to share it more widely. It does not. The permission usually extends only to internal use, plus supplying the data up to the OEM or parent company for which the dealer submits its own sales - not the other brands it represents. The dealer becomes the route by which controlled data escapes into uncontrolled hands. In one case we are aware of, a dealer shared figures with an OEM that was not authorised to receive them. It was resolved quickly and amicably through education, once the source of the leak was identified.
Where internal use ends and public disclosure begins
This is one of the hardest lines for people to hold, because the same data point can be fine in one context and prohibited in another.
Inside the relationship between an OEM and its dealer, the data can be used for accountability. An OEM can tell a dealer "your market share is fifteen percent, but the national average is eighteen, so you are below the market," or "you are the top dealer in the country." That is exactly what benchmarking dealer performance is for, and the programme permits it.
The same number becomes a breach the moment it is published or used to market a position. So when we guide a new participant, the principle is simple: internal use only. For an OEM, "internal" includes its dealer network. For a dealer, it includes sharing up to the parent company it reports for. Beyond that, the association owns the detail. PowerStats supplies the guardrails; how granular the wording becomes is for each association to define and communicate to its members, because every association's structure differs. We do not impose a standard template.
A code of conduct only works if it is written down and repeated
A rule that lives only in someone's memory is not a rule. Three preventative actions matter:
- Document the condition in the Code of Conduct or Code of Ethics, so it is a must-adhere item rather than an assumption.
- Table it regularly, so it stays live rather than dormant.
- Communicate the main messages via all comms. Automatically!
Without active reinforcement, a code of conduct becomes a one-time signature that is then forgotten, and a breach can run for months before anyone notices.
The most efficient way to keep the rules live is to attach them to something the meeting already does. Best practice for an industry association meeting is for the chair to read out an anti-competition statement at the start - a reminder that pricing, supply plans, volumes and any forward-looking discussion are off the table. Adding the key data usage points to that statement is a thirty to forty-five second bolt-on, not a fresh lecture. These meetings usually happen once a year, so the burden is small, and the reminder lands with the seriousness of the antitrust warning it sits beside. Once a year is frequent enough to stick without becoming background noise.
Enforcement should follow protocol, not opinion
A Code of Conduct with no documented incident-response process leaves an association improvising - an off-the-record word, a verbal warning, no formal authority. Without defined rules, there is little it can actually say or do. The fix is to define both the rules and the consequences in advance, so enforcement does not depend on who discovers the breach or how they feel about it.
Where the process is well defined, it should lead with education, then a formal written warning, and only then, as a last resort, exclusion. Two points matter here:
- First, exclusion should never be decided by consensus. A board or statistics committee has no place forming subjective opinions on who should be removed, because that hands veto power to the very competitors who gain most from removing a rival. The criteria must be objective and applied by protocol.
- Second, the delivery should still be human. Difficult news is best given in person, or by phone or video call, then confirmed in writing so there is a paper trail. The rules can be cold and clear while the conversation stays warm.
These programmes run on trust, and you do not want to lose a participant over a poorly worded email.
Transparency after a breach does more to protect trust than silence ever could. When something goes wrong, the association takes the lead in a clear memo to all members at the same time: what happened, how it was contained, and what has changed to prevent a recurrence. Handled this way, a breach can strengthen a programme's credibility, because it shows the governance is real and working. We have never seen this kind of incident cause a loss of trust where the communication was prompt, clear and transparent.
One illustration shows why the rules have to be airtight. Years ago, a participant in a monthly programme was permitted to report quarterly to suit its business. It then exploited the arrangement by declaring zero sales for the opening months of each quarter, which tricked the system into releasing everyone else's monthly figures while it disclosed nothing real - handing itself a head start on the market. Because this breached our terms of use, we recommended suspension rather than education, and the member was expelled. The lesson endured: we no longer allow reporting exceptions of this kind, even when every member agrees to them. Watertight governance is what made it possible to act.
Good governance is about discipline, not size
Good governance tends to correlate with resources. Larger industry bodies often represent high-value industries with significant membership income, which lets them employ professional, legally trained staff - a managing director, or a technical director who owns the data programme and runs it with discipline. Where those people exist, programmes typically run well.
But smallness is not the problem; the absence of anyone driving it is. A small association can run a sound programme when a proactive, experienced volunteer - a president with a clear vision - sets the direction, secures member buy-in and briefs the provider, while an impartial vendor runs the project day to day. The volunteer provides governance direction precisely because their own participation creates a conflict of interest that bars them from running it. For that reason, we would never tell a smaller association it is not ready for a data programme. We work with what is there.
Even so, we are honest about the limits of our role. As a neutral third party, PowerStats can advise best practice but cannot mandate it. If an association chooses not to adopt an internal-use clause, all we can do is explain that it is best practice and let them decide. A whole category of misuse can go undetected simply because nobody defined it as a breach, or because nobody is looking. We do not know what we do not know - which is exactly why defined rules matter.
Protecting against reverse-engineering without withholding data
The instinct to prevent reverse-engineering by sharing less is usually the wrong one. Education, governance and defined processes are the better answer.
Take an open-reporting programme. Rather than disclosing data at postcode level, which would be too granular geographically, the programme reports by confidential sales zones or PMAs that are unique to each participant. Because those zones are not standardised across the group, they are far harder to reverse-engineer. The choice of geographic unit is a deliberate governance decision tied to the reporting model, not a blanket restriction on detail.
Even then, good faith matters. Sales zones shift as territories and sales teams change. In theory a participant could download a data set under the old zones, then again under the new ones, and compare the two to derive areas smaller than the threshold allows. The practical fix is a standard request form for any zone change whose first condition is an explicit commitment not to reverse-engineer the data. Without that agreement, the change is not actioned. Strong contracts and a clear Code of Conduct still rely on good ethics underneath them, which is why the architecture that enforces the rules matters as much as the rules themselves. You can read how that works on our data and security page.
On competition law specifically, the risk is real but rarely imminent. Our research highlights that antitrust attention concentrates on forward-looking, collusive information - price fixing and future production planning - rather than historical sales data, though historical data can sometimes be perceived as live. The point is structural vigilance: every data provider should understand what drives competition regulators such as the New Zealand Commerce Commission, and make sure the spirit, not just the letter, of a programme meets those guidelines. PowerStats' own position is that well-run data sharing increases competition, because better intelligence on real consumer demand lets participants build products the market actually wants.
Key takeaways
- The rules in a data sharing programme exist to protect trust and every participant's continued access to the shared data.
- Data is for internal use only: an OEM benchmarking its dealers privately is fine, but publishing or advertising the same figure is a breach.
- A Code of Conduct only works when it is documented and repeated, ideally bolted onto the anti-competition statement read at each meeting and included with all comms.
- Enforcement should follow objective protocol, never consensus, so competitors cannot use exclusion as a power play.
- Transparency after a breach protects trust: a clear, simultaneous memo shows the governance is real and working.
- Sound governance depends on discipline and someone driving it, not on the size of the association.
Frequently asked questions
Can an OEM tell a dealer they are the worst performer in their territory?
Generally yes, when it stays internal. An OEM benchmarking its own dealer network is a private accountability conversation the programme permits, and it is one of the main reasons OEMs value the data. The same figure must not be published, shared outside the relationship or used to market a position. This answer may be guided further by your association's rules.
Can we advertise our market share if it comes from an industry data programme?
Generally, no. Market share claims that reference the programme are prohibited in external communications, even when the position is genuinely true. The data is for internal use, and using it promotionally - in advertising or at an industry event - is one of the most common breaches. This answer may be guided further by your association's rules.
How often should an association remind members of the data usage rules?
At least once a year is usually enough in person, and as regular as possible via comms. The most efficient approach is to add the key points to the anti-competition statement the chair already reads at the start of each meeting. It takes thirty to forty-five seconds and keeps the rules live without becoming background noise.
What happens when a participant breaches the rules?
It depends on having a documented incident-response process. Best practice leads with education, then a formal written warning, and only exclusion as a last resort. Decisions should follow objective criteria rather than a committee vote, so enforcement stays consistent and cannot be turned into a power play.
Talk to us about governing your data programme
Governing industry data well is not about adding bureaucracy; it is about protecting the trust that makes the data worth sharing. Write the rules down, keep them live and enforce them by protocol - and a programme becomes more credible every time it is tested. To see how we build trust and governance in competitive data sharing into every programme, contact PowerStats to talk through running or reviewing your industry data programme.



