Hubs: EV & battery · Data privacy · Transfer roadmap · AI guide (ADAS / cabin AI).
Data types that drive compliance design
- Personal information — drivers, passengers, phone pairings, biometrics, voice
- Vehicle / operations data — location trajectories, video, diagnostics (may be important data in some contexts)
- Maps / geospatial — elevated sensitivity; specialised mapping rules may apply
- R&D fleets — test vehicles still generate regulated data
Core workstreams
- Data inventory by ECU/feature and storage location
- Classification: PI vs important data vs other
- Onshore processing defaults for high-risk sets
- Outbound pathway design if global clouds are required
- Security assessment / filing themes where triggered
- Supplier contracts for telematics and cabin AI vendors
- Incident response for breaches and unsafe software updates
OEM / supplier checklist
- [ ] Feature-level data map (what leaves the car, where it goes)
- [ ] China privacy notice and in-vehicle UX consents
- [ ] Cross-border transfer status for each global system
- [ ] Cabin AI / recording features reviewed under AI + privacy rules
- [ ] Tier-1 data processing agreements updated
- [ ] Export-control interface for ADAS hardware (tracker)
Counsel
General information only—not cybersecurity certification advice. Automotive data rules are technical and evolving. Last reviewed: August 2026 · China Legal Portal Editorial