How to Comply with China’s EV Data Security Regulations: 2026 Guide

Date:

Share post:

How to Comply with China’s EV Data Security Regulations: 2026 Guide

Last Updated: July 2026 | Category: EV Data Compliance | Reading Time: 13 min

Modern electric vehicles are, for all practical purposes, data centres on wheels. A single EV can generate terabytes of data per day — from GPS location history and driving behaviour to biometric information from in-cabin cameras, battery telemetry, and personal preferences synced from the owner’s smartphone. In China, this data is subject to one of the world’s most comprehensive and stringent data security regulatory frameworks.

For foreign EV manufacturers operating in China, compliance with data security regulations is not optional — it is a legal and operational prerequisite. Non-compliance can result in fines of up to 50 million RMB (approximately $7 million), suspension of operations, mandatory data deletion, and even criminal liability for senior executives. This guide provides a comprehensive overview of China’s EV data security regulatory framework as it stands in 2026, with actionable steps for achieving and maintaining compliance.

1. The Regulatory Landscape Overview

China’s data security framework for vehicles is built on three foundational laws, supplemented by sector-specific regulations:

Law / Regulation Effective Scope
Cybersecurity Law of the PRC (CSL) June 2017 Network security, data localization, critical information infrastructure
Data Security Law of the PRC (DSL) September 2021 Data classification, cross-border data transfer, data processing obligations
Personal Information Protection Law (PIPL) November 2021 Personal data processing, consent, rights of data subjects
Automotive Data Security Management Regulations (Draft / Formal) October 2021 (Trial) / 2022 (Formal) Vehicle-specific data collection, storage, and transmission rules
GB/T 40861-2021 (Automotive Cybersecurity) January 2023 Cybersecurity management for vehicle development and production
MIIT Guidelines on Data Security for Intelligent Connected Vehicles 2022-ongoing Data security for connected and autonomous vehicles

Together, these laws and regulations create a compliance framework that touches every aspect of how an EV collects, stores, processes, and transmits data within China.

2. Key Data Categories and Classification

Under China’s Automotive Data Security Management Regulations (ADSMR), vehicle data is classified into several categories with different compliance requirements:

Category A: Personal Information

Data that can identify an individual driver or passenger, including name, phone number, driver’s license information, payment accounts, and facial recognition data from in-cabin cameras. Personal information is subject to PIPL requirements, including explicit consent, purpose limitation, and the right to deletion.

Category B: Sensitive Personal Information

A subset of personal information that could cause harm if disclosed. For EVs, this includes precise location tracking data (GPS traces), audio/video recordings from interior cameras, biometric data used for driver authentication, and driving behaviour profiles. Processing sensitive personal information requires separate explicit consent and a necessity justification.

Category C: Important Data

Data that could affect national security, public interests, or critical infrastructure. For the automotive sector, important data includes:

  • Geographic information maps of sensitive areas (military zones, government facilities)
  • Operational data from vehicles used by government or military entities
  • Aggregate traffic flow data at a level that could reveal sensitive patterns
  • Raw battery and powertrain telemetry from large fleets

Important data is subject to the most stringent controls under the DSL, including mandatory data localization and government security assessments for any cross-border transfer.

3. Core Compliance Requirements for EV Manufacturers

3.1 Data Localization

China’s data localization requirements are among the strictest globally. Under the ADSMR and the CSL, the following rules apply:

  • In-vehicle data: Data collected by vehicle sensors, cameras, radars, and telematics control units must be stored and processed within China. Raw data collected within China may not be transferred abroad.
  • Data centres: Cloud infrastructure used for vehicle data processing must be physically located in mainland China. Many foreign automakers (Tesla, BMW, Volkswagen) have established local data centres in partnership with Chinese cloud providers like Alibaba Cloud, Huawei Cloud, or Baidu AI Cloud.
  • Cross-border transfer restrictions: Transferring data outside China requires passing a security assessment by the Cyberspace Administration of China (CAC) for important data, or entering into a Standard Contract for personal information transfers.

Key Development (2025-2026): China has been tightening enforcement of data localization rules for connected vehicles. In 2025, multiple foreign OEMs were instructed to migrate data processing from offshore to onshore servers within a 6-month compliance window. MIIT and the CAC now conduct regular audits of connected vehicle data flows.

3.2 In-Vehicle Data Collection Rules

The ADSMR places strict limits on what data can be collected by vehicles operating in China:

  • Default-off collection: All non-essential data collection must be disabled by default. The driver must actively opt in for features like video recording, voice assistant collection, and driving behaviour analysis.
  • “Minimum necessary” principle: Data collected must be limited to what is strictly necessary for the specific function being performed. Collecting extra data “just in case” is a violation.
  • Storage duration limits: Personal and sensitive data must be deleted when the purpose of collection is fulfilled. For example, location data used for navigation should not be retained indefinitely.
  • In-vehicle processing priority: To the extent possible, data processing should occur within the vehicle’s onboard computing systems rather than being transmitted to the cloud.

3.3 User Consent and Transparency

The PIPL requires that EV manufacturers provide clear, specific, and informed consent mechanisms:

  • Privacy notices must be available in Chinese and prominently displayed in the vehicle’s infotainment system. They must specify exactly what data is collected, for what purpose, how long it is retained, and who it is shared with.
  • Granular consent must be obtained for each category of data collection. A single “Agree All” button is not compliant — users must be able to consent to navigation data collection while declining in-cabin video recording.
  • Right to withdrawal: Users must be able to withdraw consent at any time, and the vehicle must stop collecting the relevant data immediately upon withdrawal.
  • Right to deletion: Users have the right to request deletion of their personal data. Manufacturers must process such requests within 15 working days.

3.4 Cybersecurity Management System (CSMS)

Based on GB/T 40861-2021 and aligned with UN R155/R156 principles adapted to China’s context, EV manufacturers must establish and maintain a Cybersecurity Management System that covers:

  • Risk assessment: Cybersecurity risks must be identified and assessed throughout the vehicle lifecycle, from design to decommissioning.
  • Secure development: Cybersecurity must be integrated into the vehicle development process (secure by design).
  • Incident response: A documented cyber incident response plan is required, including reporting obligations to MIIT and the CAC within 24 hours of a significant incident.
  • Supply chain security: Tier 1 and Tier 2 suppliers must demonstrate compliance with cybersecurity requirements, and manufacturers must maintain a software bill of materials (SBOM) for all vehicle software components.
  • Software update management: As of 2025, a Software Update Management System (SUMS) is mandatory for any OTA-capable vehicle, with requirements mirroring UN R156.

4. Data Security Assessment and Certification

Data Security Impact Assessment (DSIA)

Before launching a new EV model in China, manufacturers must conduct a Data Security Impact Assessment covering:

  • What data the vehicle collects and processes
  • Risk analysis for each data processing activity
  • Mitigation measures implemented
  • Assessment of whether data processing complies with applicable laws

The DSIA must be documented and kept available for regulatory inspection. For high-risk processing activities (such as in-cabin video for driver monitoring), the DSIA must be submitted to the relevant regulatory authority.

Personal Information Protection Impact Assessment (PIPIA)

Under Article 55 of PIPL, personal information processors must conduct a PIPIA before engaging in activities that involve sensitive personal information, automated decision-making, or cross-border data transfer. For EVs, a PIPIA is required before activating connected services, driver monitoring, or any biometric authentication features.

Cybersecurity Level Protection (Dengbao / 等保)

China’s classified protection of cybersecurity regime (MLPS 2.0) applies to connected vehicle service platforms. Most OEM cloud platforms for connected EVs require at least Level 3 Dengbao certification, which involves:

  • Technical assessment of network security controls
  • On-site inspection by a Dengbao assessment agency
  • Registration with the local Public Security Bureau
  • Annual re-assessment

5. Cross-Border Data Transfer Mechanisms

For foreign EV manufacturers that need to transfer data out of China (e.g., for global R&D, incident analysis, or fleet management), several legal mechanisms exist:

Mechanism When to Use Requirements
CAC Security Assessment Important data or large volumes of personal information (1M+ individuals) Government-led assessment, 45-90 business days, requires data disclosure
Standard Contract for PI Export Personal information under 1M individuals, non-sensitive Filing with CAC, contractual protections, PI impact assessment
Certification by CAC-Accredited Body Alternative to Standard Contract Third-party certification of data protection practices, annual renewal

Important Note: As of 2026, the CAC has been tightening approval for cross-border data transfers by automotive companies. Applications that were routinely approved in 2023-2024 are now receiving additional scrutiny, particularly regarding the transfer of vehicle telemetry data and connected service usage data. Budget for 3-6 months of processing time for security assessment applications.

6. Practical Implementation Steps for Foreign Automakers

Step 1: Map Your Data Flows

Begin by creating a comprehensive data flow map covering every type of data your vehicles collect, process, store, and transmit. This should include:

  • All vehicle sensors and their data output
  • Connected services and their data usage
  • Cloud infrastructure (both in China and abroad)
  • Third-party data sharing (navigation providers, charging network operators, insurance partners)
  • Data retention and deletion schedules

Step 2: Classify Your Data

Implement a data classification system aligned with Chinese regulatory categories (Personal Information, Sensitive Personal Information, Important Data). Train your engineering teams to classify data at the architectural design stage, not as an afterthought.

Step 3: Establish In-China Infrastructure

Set up data centres and cloud infrastructure within mainland China. Most foreign OEMs use a combination of Alibaba Cloud for connected vehicle services and on-premise servers for sensitive data processing. Ensure that data residency is enforced at the infrastructure level.

Step 4: Implement Privacy-by-Design

Redesign your vehicle software architecture to incorporate China’s specific requirements:

  • Default-off for non-essential data collection
  • Granular consent management in the infotainment system
  • In-vehicle processing where possible
  • Real-time data deletion capabilities

Step 5: Engage Regulatory Consultants

China’s data security regulations are complex and frequently updated. Engage Chinese data security law firms and regulatory consultants who specialize in the automotive sector. They provide invaluable guidance on interpretation, enforcement trends, and compliance strategy.

Step 6: Conduct Pre-Launch Audits

Before launching any new model or connected service, conduct a comprehensive data security audit covering:

  • Regulatory compliance (DSIA, PIPIA)
  • Technical security assessment (penetration testing, vulnerability scanning)
  • Dengbao certification status
  • Cross-border data transfer compliance
  • Supplier security compliance

7. Enforcement and Penalties

China’s data security regulators have demonstrated a willingness to enforce aggressively. Key enforcement trends as of 2026 include:

  • MIIT spot checks: MIIT conducts unannounced data security spot checks on connected vehicle service platforms. In 2025, 12% of spot checks resulted in corrective action orders.
  • CAC cross-border data audits: The CAC has increased audits of automotive companies’ cross-border data flows. Several foreign OEMs received compliance notices requiring data migration to China within specified deadlines.
  • Consumer complaints: Chinese consumers have become increasingly privacy-aware. Data privacy complaints filed through the 12315 consumer hotline can trigger regulatory investigations.
Violation Maximum Penalty Under CSL/DSL/PIPL
Illegal collection of personal information Up to 50 million RMB or 5% of annual revenue
Cross-border data transfer without approval Up to 50 million RMB; suspension of relevant business
Failure to conduct DSIA or PIPIA Warning and corrective order; up to 1 million RMB
Failure to obtain user consent Up to 50 million RMB; suspension of app or service
Data security incident with harm to individuals Up to 50 million RMB; potential criminal liability

8. Emerging Trends for 2026-2027

Autonomous Vehicle Data Regulation: As China accelerates deployment of Level 3 and Level 4 autonomous vehicles, new data regulations specific to autonomous driving data collection and storage are expected. Key areas include mandatory recording of autonomous driving system operational data (similar to an event data recorder for ADS) and restrictions on transmitting high-definition map data abroad.

AI Data Governance: With the proliferation of AI-powered features in vehicles (voice assistants, driver monitoring, personalized recommendations), new AI data governance requirements under China’s Generative AI regulations may apply to in-vehicle AI systems. This includes transparency about AI data processing and user rights regarding AI-driven decisions.

Data Anonymization Standards: China is developing automotive-specific data anonymization standards. Properly anonymized data may be exempt from certain PIPL requirements, but the bar for “effective anonymization” will be set high and likely diverge from European standards.

Interoperability with Charging Data: As China’s EV charging network expands, new requirements for sharing vehicle and charging data between OEMs, charging operators, and grid operators may emerge. This creates both compliance challenges and opportunities for data-driven services.

Conclusion

China’s EV data security regulatory framework is complex, evolving, and strictly enforced. For foreign EV manufacturers, compliance requires a significant, ongoing investment in data governance infrastructure, legal expertise, and technical implementation. The key to success is treating data security compliance not as a one-time regulatory hurdle but as a continuous operational requirement woven into the fabric of product development, manufacturing, and after-sales service.

Leading automakers in China treat data compliance as a competitive advantage rather than a burden. Companies that invest early and comprehensively in data security build trust with Chinese consumers, avoid costly enforcement actions, and are better positioned to adapt to the inevitable tightening of regulations. As China moves toward fuller autonomy in vehicles and deeper integration of AI, the data security demands will only grow — making early investment in a robust compliance infrastructure the wisest strategic choice.


Disclaimer: This guide is for informational purposes and does not constitute legal advice. Regulatory requirements are subject to change. Always consult with qualified legal and data security professionals for your specific situation.

Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's