China Data Localisation Update: New Mandates Reshape Automotive and Financial Data Flows
China’s data localisation regime tightened significantly in March 2025, with new enforcement mandates specifically targeting the automotive and financial services sectors — requiring companies to store and process over 85% of operational data categories within mainland China servers. The updates, issued jointly by the Cyberspace Administration of China (中国网信办, Zhōngguó Wǎngxìn Bàn, CAC) and the People’s Bank of China (中国人民银行, Zhōngguó Rénmín Yínháng, PBOC), introduce stricter classification rules, real-time reporting obligations, and penalties that can reach ¥50 million (≈ $6.9 million) for non-compliant data controllers handling more than 1 million user records.
The new mandates build on the existing Data Security Law (2021) and Personal Information Protection Law (2021), but now force sector-specific compliance timelines. Automotive companies face a 6-month window to relocate vehicle telemetry and geolocation data to local data centres, while financial institutions have 12 months to migrate core customer transaction and credit assessment data. This marks a clear escalation from the 2022–2023 pilot regimes, when selective exemptions were available for foreign-invested enterprises (外商独资企业, WFOE, wàishāng dúzī qǐyè) under the Beijing and Shanghai FTZ data export negative lists.
Why the Crackdown Accelerated
China’s data localisation agenda is not new, but the automotive and financial sectors have become enforcement priorities due to their volume of sensitive personal data and national security implications. In 2024, CAC recorded 347 data breach incidents in these two sectors alone, a 38% increase year-on-year. The updated mandates directly respond to concerns that foreign-connected vehicle fleets and cross-border financial algorithms could leak personally identifiable information (PII) or trade-sensitive commercial intelligence.
For automakers — both domestic and foreign — the most impactful change is the requirement that all vehicle-generated data, including real-time GPS trajectories, driver behaviour logs, and in-car biometrics, must be stored and processed within China. Previously, some foreign OEMs had been transferring aggregated, anonymised driving data to parent R&D centres in Europe, the US, or Japan for product improvement. Under the new rules, any export of such data requires a formal security assessment approval from CAC, which can take 90 to 180 days and must be reapplied for every two years. The penalty for unauthorised cross-border transfer of automotive telematics data: up to ¥20 million for the first violation, with potential suspension of manufacturing licences for repeat offenders.
The financial sector faces parallel pressure. Banks, insurers, and fintech platforms must now classify their data into three tiers (Basic, Important, Core) based on the Data Classification and Grading Guidelines (数据分类分级指南, shùjù fēnlèi fēnjí zhǐnán, DCGG) issued by PBOC in December 2024. Core data — covering customer identities, transaction histories over ¥50,000, and credit scoring models — cannot leave China under any circumstance. Important data — such as aggregated loan portfolios and insurance claim statistics — may be transferred only after passing a CAC security assessment and obtaining explicit individual consent from each data subject. Non-compliant financial institutions face fines of up to 5% of annual revenue (vs. 2% under the 2021 framework) and potential revocation of their cross-border business licences.
How the Automotive and Financial Mandates Compare
The table below summarises the key requirements across both sectors to help foreign executives compare their compliance obligations at a glance.
| Requirement | Automotive Sector (CAC + MIIT) | Financial Sector (PBOC + CAC) |
|---|---|---|
| Data classification tiers | 3 tiers: General, Important, Core | 3 tiers: Basic, Important, Core |
| Local storage mandate effective | September 2025 (6-month window) | March 2026 (12-month window) |
| Cross-border transfer route | CAC security assessment only | CAC security assessment + individual consent |
| Max penalty (first violation) | ¥20 million + potential licence suspension | 5% annual revenue + cross-border licence revocation |
| Reporting frequency to regulator | Quarterly automated telemetry reports | Monthly manual + automated reports |
| Exemptions for small entities | Under 10,000 vehicles / 100,000 records | Under 500,000 customer records |
| Third-party data processor audit | Required annually (by CAC-accredited firm) | Required bi-annually (by PBOC-approved agency) |
While the table shows clear differences, the overarching trend is the same: China is closing loopholes that previously allowed foreign companies to use contractual language (e.g., Standard Contractual Clauses, SCCs) or certification schemes to bypass full local storage. As of the March 2025 update, SCCs alone are no longer sufficient for automotive telematics or financial core data — only a CAC security assessment provides legal coverage for cross-border data transfer in these sectors.
Implementation Gaps and Pitfalls That Trip Up Foreign Companies
Many foreign-invested enterprises (FIE) have already invested in local server infrastructure and appointed local data protection officers (DPOs), but three specific pitfalls are emerging as the March 2025 deadline nears.
For foreign executives evaluating China market entry or scaling existing operations, the data localisation update represents a significant operational cost inflection point. The good news is that compliance can be structured efficiently if you start with a clear decision framework tailored to your data profile.
Decision Framework: Which Compliance Route Fits Your Business
The following decision guide helps foreign firms quickly determine which localisation path applies based on their sector and data volume.
- If your company is an automotive OEM or large-tier-1 supplier handling telematics data from more than 10,000 vehicles or 100,000 user records: choose the full local storage + CAC security assessment route; apply for the assessment immediately to secure a slot before the September 2025 deadline.
- If your company operates in financial services with core customer data (identities, high-value transactions, credit scores) exceeding 500,000 records: choose the PBOC tier-classification-first approach — classify your data, isolate core data on China-based servers, and only then begin the CAC security assessment for important data. Do not attempt a single “one-size-fits-all” protocol; the PBOC and CAC have different reporting formats.
- If your company is a small fintech or automotive parts supplier with under 50,000 customer records or under 1,000 vehicle data points: choose the simplified SCC-based route for non-core data only, but prepare a full localisation plan in case your data volume exceeds the threshold within 12 months.
This framework saves time by avoiding unnecessary full-security assessments for small-scale operators while ensuring large data controllers do not underestimate the regulatory burden. In both sectors, the cost of non-compliance — reputational damage plus fines that can exceed ¥20 million — far outweighs the investment in local infrastructure and compliance staff.
Next Steps for Foreign Companies
- Conduct a Data Classification Gap Analysis. Before choosing any compliance route, map all data flows in your China operations against the new DCGG and automotive classification guidelines. Use our China Data Classification Assessment Template to document categories, volumes, and current storage locations.
- Apply for a CAC Security Assessment – Early. The CAC has limited assessment capacity, and slots fill quickly. Initiate your application at least 4 months before your compliance deadline. Review the step-by-step process in our CAC Security Assessment Application Guide.
- Implement Automated Real-Time Reporting. Both sectors now require regular reporting — quarterly for automotive, monthly for financials. Deploy a data governance platform that can generate regulator-ready reports automatically. See our recommended vendors and integration checklists in Data Governance Platforms for China Compliance.
— China Gateway 360 —
Remote China market entry support, built around execution.
