China Tightens Connected Vehicle Data Rules With Mandatory Local Sensor Scrubbing
The Ministry of Industry and Information Technology requires automakers to sanitize autonomous driving telemetry and high-definition mapping data inside mainland data centers before export.
China's Ministry of Industry and Information Technology, in coordination with the Cyberspace Administration of China, has issued updated security guidelines requiring automakers to scrub, anonymize, and store all sensory and telemetry data generated by connected vehicles within mainland borders before requesting export approval.
The directive updates the 2021 Provisions on the Management of Automotive Data Security, creating specific operational thresholds for foreign and domestic automakers operating Level 2 and Level 3 automated driving fleets. Under the updated framework, any vehicle data containing high-precision geographic coordinates, exterior video feeds, point-cloud streams from light detection and ranging (LiDAR) sensors, or voice recordings from vehicle cabins must undergo automated algorithmic sanitization at local facilities before cross-border transmission is considered.
Automakers operating in China face strict structural boundaries regarding how automated driving systems collect and process real-world road data. The rules mandate that all raw exterior imagery capturing human faces and license plates must be blurred directly at the vehicle edge or within secured onshore server installations. Furthermore, sensory data collected within a 500-meter perimeter of government compounds, military installations, telecommunications hubs, and strategic industrial infrastructure cannot leave the mainland under any operational circumstance, even in obfuscated formats.
The policy directly affects international manufacturers that rely on centralized global cloud infrastructure to train neural networks and machine learning models for autonomous navigation. Companies such as Tesla, Volkswagen Group, BMW, and Mercedes-Benz must bifurcate their software engineering workflows, establishing dedicated computational clusters inside China to ingest, process, and train regional perception algorithms. Tesla, which operates a localized data center in Shanghai to comply with domestic storage laws, cannot transfer raw Chinese corner-case driving scenarios to its supercomputing clusters in North America without undergoing formal security reviews conducted by provincial cyberspace administrations.
Volkswagen Group, operating through its software division CARIAD and its local automated driving venture with Horizon Robotics, is similarly adapting its data ingestion architecture. The joint venture must verify that all training iterations of its regional automated driving software run on servers physically located in China. Autonomous driving systems developed by domestic manufacturers, including Baidu's Apollo platform, Huawei Technologies' intelligent automotive unit, XPeng, and NIO, have already completed alignment with the domestic data boundary requirements by routing fleet data into certified domestic cloud nodes in Guiyang, Shanghai, and Inner Mongolia.
For global Tier 1 component and software suppliers, the guidelines impose hardware-level and firmware-level constraints. Sensor manufacturers such as Hesai Technology, RoboSense, Bosch, and Mobileye must ensure that perception chips and processing controllers support standardized encryption and deterministic data logging that interface directly with state-approved audit systems. Compute platforms supplied by Nvidia and Qualcomm must be configured to prevent unmonitored diagnostic logging through over-the-air cellular modems when vehicles operate on Chinese public roads.
The updated guidelines also define clear technical criteria for what constitutes high-precision mapping data. Trajectory traces collected by connected vehicles that achieve absolute positional accuracy higher than one meter, or relative spatial accuracy higher than 0.2 meters, fall under state surveying and mapping regulations. Foreign automakers cannot independently gather or process such spatial data without partnering with a licensed Chinese mapping enterprise, such as NavInfo, AutoNavi, or Baidu Maps, which assume legal liability for geographic data integrity and onshore retention.
To obtain cross-border data transfer clearance for technical debugging, incident investigations, or fleet warranty assessments, automakers must submit quantitative risk evaluation filings to the Cyberspace Administration of China. These filings require a full cryptographic inventory of data packets, structural definitions of data schemas, designated foreign recipient server addresses, and independent third-party audit reports confirming that no unmasked geographical or personal data is present in the payload. Processing periods for outbound data transfer licenses range between 45 and 60 business days.
The Ministry of Industry and Information Technology confirmed that compliance with the sensor data guidelines forms an explicit prerequisite for vehicle model homologation in the national New Energy Vehicle Catalogue and the Catalogue of Motor Vehicle Manufacturers and Products. Vehicles that fail technical audits will not receive production approval or vehicle sales permits. The ministry also retains the authority to suspend over-the-air software update privileges for non-compliant fleets and levy administrative penalties under the Data Security Law and the Personal Information Protection Law.
Provincial communications administrations and automotive testing agencies will begin joint compliance audits across vehicle assembly plants and enterprise cloud facilities on Nov. 15, 2026. Automakers holding active testing permits for advanced driver assistance systems must complete initial self-assessments and submit technical compliance reports to the national vehicle data supervision platform by Oct. 31, 2026.
Impact map
How this development propagates across the region and out to global buyers.
| Event | Korea | China | Japan | Global impact |
|---|---|---|---|---|
| Connected car data export rule | tier 1 suppliers adapt firmware | sovereign compute mandatory | automakers isolate software branches | global ai training loops split |
In this story
- Companies
- TeslaVolkswagen GroupBMWMercedes-BenzBaiduHuawei Technologies
- Tickers
- TSLAVOW3.DEBMW.DEMBG.DE9888.HK
- Exposed
- Hesai TechnologyRoboSenseNvidiaMobileyeHorizon RoboticsNavInfo
- Policy
- Economic SecurityExport ControlsData Governance
- Impact
- ComplianceCapexSupply ChainCost Structure
This briefing carries no linked sources: it was written from our desks' working knowledge of the sector rather than from documents retrieved for this piece. East Asia Brief publishes no citation it cannot link. Our English text is produced with AI assistance under human editorial review. See our methodology and AI policy. Spotted an error? Tell us.


