Release Date: 2021-08-16
Effective Date: 2021-10-01
Source: Cyberspace Administration of China
Original Title: 汽车数据安全管理若干规定(试行)
Order No. 7
Cyberspace Administration of China
National Development and Reform Commission of the People’s Republic of China
Ministry of Industry and Information Technology of the People’s Republic of China
Ministry of Public Security of the People’s Republic of China
Ministry of Transport of the People’s Republic of China
The Several Provisions on Automotive Data Security Management (for Trial Implementation), adopted at the 10th office affairs meeting of the Cyberspace Administration of China in 2021 on July 5, 2021, and approved by the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security and the Ministry of Transport, are hereby promulgated and shall enter into force on October 1, 2021.
Zhuang Rongwen, Director of the Cyberspace Administration of China
He Lifeng, Chairman of the National Development and Reform Commission
Xiao Yaqing, Minister of Industry and Information Technology
Zhao Kezhi, Minister of Public Security
Li Xiaopeng, Minister of Transport
August 16, 2021
Article 1 These Provisions are formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China and other laws and administrative regulations to regulate automotive data processing activities, protect the lawful rights and interests of individuals and organisations, safeguard national security and public interests, and promote the reasonable development and use of automotive data.
Article 2 Automotive data processing activities and the supervision and administration of their security within the territory of the People’s Republic of China shall comply with the requirements of relevant laws, administrative regulations and these Provisions.
Article 3 For the purposes of these Provisions, automotive data includes personal information data and important data involved in automotive design, manufacture, sale, use, operation and maintenance, among other activities.
Automotive data processing includes the collection, storage, use, processing, transmission, provision and disclosure of automotive data, among other activities.
Automotive data processors are organisations that conduct automotive data processing activities, including automobile manufacturers, component and software suppliers, dealers, repair service providers and mobility service providers.
Personal information means all kinds of information recorded electronically or by other means relating to identified or identifiable individuals, such as vehicle owners, drivers, passengers and persons outside vehicles, excluding information that has been anonymised.
Sensitive personal information means personal information that, once leaked or illegally used, may subject vehicle owners, drivers, passengers, persons outside vehicles or other individuals to discrimination or seriously endanger their personal safety or the security of their property. Such information includes vehicle movement trajectories, audio, video, images and biometric characteristics.
Important data means data that, if tampered with, destroyed, leaked, or illegally obtained or used, may endanger national security, public interests, or the lawful rights and interests of individuals or organisations, including:
(I) geographical information, flows of people, vehicle traffic flows and other data concerning important sensitive areas, such as military administrative areas, entities engaged in national defence science, technology and industry, and Party and government organs at or above the county level;
(II) data reflecting economic activity, such as vehicle traffic flows and logistics;
(III) operational data of automotive charging networks;
(IV) video and image data captured outside vehicles that contain facial information, licence plate information or similar information;
(V) personal information relating to more than 100,000 individuals; and
(VI) other data identified by the national cyberspace authority and relevant departments of the State Council, including those responsible for development and reform, industry and information technology, public security and transport, as potentially endangering national security, public interests, or the lawful rights and interests of individuals or organisations.
Article 4 The processing of automotive data by automotive data processors shall be lawful, legitimate, specific and clearly defined, and directly related to activities such as automotive design, manufacture, sale, use, operation and maintenance.
Article 5 Those conducting automotive data processing activities through information networks such as the Internet shall implement the cybersecurity multi-level protection system and other relevant systems, strengthen automotive data protection, and fulfil data security obligations in accordance with the law.
Article 6 The State encourages the lawful, reasonable and effective use of automotive data and advocates that automotive data processors adhere to the following principles when conducting automotive data processing activities:
(I) The principle of in-vehicle processing: data is not provided outside the vehicle unless truly necessary;
(II) The principle of no collection by default: unless the driver chooses otherwise, the default setting for each drive is that no data is collected;
(III) The principle of appropriate precision and scope: the coverage and resolution of cameras, radar and other devices are determined according to the data precision requirements of the functions and services provided; and
(IV) The principle of data desensitisation: anonymisation, de-identification and other such processing are applied wherever possible.
Article 7 When processing personal information, automotive data processors shall inform individuals of the following matters in a prominent manner through user manuals, in-vehicle display panels, voice notifications, applications related to vehicle use, or other means:
(I) the categories of personal information processed, including vehicle movement trajectories, driving habits, audio, video, images and biometric characteristics;
(II) the specific circumstances in which each category of personal information is collected, and the methods and channels for stopping collection;
(III) the purposes, uses and methods of processing each category of personal information;
(IV) the storage locations and retention periods for personal information, or the rules for determining those locations and periods;
(V) the methods and channels for accessing and copying their personal information, deleting personal information within the vehicle, and requesting the deletion of personal information that has already been provided outside the vehicle;
(VI) the name and contact details of the contact person responsible for user rights and interests; and
(VII) other matters that laws and administrative regulations require to be notified.
Article 8 Automotive data processors shall obtain individuals’ consent to process their personal information or meet other conditions provided for by laws and administrative regulations.
Where personal information concerning individuals outside a vehicle is collected for the purpose of ensuring driving safety and their consent cannot be obtained, such information shall be anonymised if it is provided outside the vehicle. This includes deleting images that could identify natural persons or converting faces and similar identifying features in images into outlines.
Article 9 When processing sensitive personal information, automotive data processors shall satisfy the following requirements or other requirements prescribed by laws, administrative regulations, mandatory national standards and the like:
(I) the processing shall have a purpose that directly serves individuals, such as improving driving safety, intelligent driving or navigation;
(II) individuals shall be informed of the necessity of the processing and its impact on them in a prominent manner through user manuals, in-vehicle display panels, voice notifications, applications related to vehicle use, or other means;
(III) individuals’ separate consent shall be obtained, and individuals may independently determine the period for which their consent is valid;
(IV) provided that driving safety is ensured, the collection status shall be indicated in an appropriate manner, and individuals shall be provided with convenient means to stop collection; and
(V) where an individual requests deletion, the automotive data processor shall delete the information within ten working days.
Automotive data processors may collect biometric information, such as fingerprints, voiceprints, facial characteristics and heart rhythms, only for the purpose of improving driving safety and where there is sufficient necessity for the collection.
Article 10 Automotive data processors conducting important data processing activities shall carry out risk assessments in accordance with relevant provisions and submit risk assessment reports to the cyberspace authorities and other relevant departments of the province, autonomous region or municipality directly under the Central Government.
The risk assessment report shall include the categories, quantity and scope of the important data processed, its storage locations and retention periods, the methods of use, details of the data processing activities and whether the data is provided to third parties, the data security risks faced and the measures taken to address them, among other matters.
Article 11 Important data shall be stored within the territory of the People’s Republic of China in accordance with the law. Where it is truly necessary to provide such data overseas for business purposes, a security assessment organised by the national cyberspace authority in conjunction with relevant departments of the State Council shall be passed. The security management of cross-border transfers of data involving personal information that is not classified as important data shall be governed by the relevant provisions of laws and administrative regulations.
Where international treaties or agreements concluded or acceded to by China contain different provisions, those treaties or agreements shall apply, except for provisions to which China has declared reservations.
Article 12 When providing important data overseas, automotive data processors shall not exceed the purpose, scope, methods, data categories, volume or other parameters specified in the security assessment for the cross-border transfer.
The national cyberspace authority, together with relevant departments of the State Council, shall verify the matters prescribed in the preceding paragraph through spot checks and other means. Automotive data processors shall cooperate and present relevant information in readable or other convenient forms.
Article 13 Automotive data processors conducting important data processing activities shall, before December 15 each year, submit the following annual information on automotive data security management to the cyberspace authorities and other relevant departments of the province, autonomous region or municipality directly under the Central Government:
(I) the names and contact details of the person responsible for automotive data security management and the contact person responsible for user rights and interests;
(II) the categories and volume of automotive data processed, and the purposes and necessity of the processing;
(III) the security protection and management measures for automotive data, including storage locations and retention periods;
(IV) details of the provision of automotive data to third parties within China;
(V) automotive data security incidents and how they were handled;
(VI) user complaints relating to automotive data and how they were handled; and
(VII) other information on automotive data security management specified by the national cyberspace authority in conjunction with relevant departments of the State Council, including those responsible for industry and information technology, public security and transport.
Article 14 In addition to reporting as required under Article 13 of these Provisions, automotive data processors providing important data overseas shall report the following supplementary information:
(I) basic information about the recipients;
(II) the categories and volume of automotive data transferred overseas, and the purposes and necessity of the transfers;
(III) the locations, retention periods, scope and methods of storing automotive data overseas;
(IV) user complaints concerning the provision of automotive data overseas and how they were handled; and
(V) other information required to be reported concerning the provision of automotive data overseas, as specified by the national cyberspace authority in conjunction with relevant departments of the State Council, including those responsible for industry and information technology, public security and transport.
Article 15 The national cyberspace authority and relevant departments of the State Council, including those responsible for development and reform, industry and information technology, public security and transport, shall, within their respective responsibilities and in light of the data processing activities, conduct data security assessments of automotive data processors. Automotive data processors shall cooperate.
Institutions and personnel participating in security assessments shall not disclose automotive data processors’ trade secrets or unpublished information learned during the assessments, nor use information learned during the assessments for purposes other than the assessments.
Article 16 The State shall strengthen the development of network platforms for intelligent (connected) vehicles, provide services for the network access, operation and security assurance of intelligent (connected) vehicles, and work with automotive data processors to strengthen the security protection of intelligent (connected) vehicle networks and automotive data.
Article 17 When conducting automotive data processing activities, automotive data processors shall establish channels for complaints and reports, provide convenient access to those channels, and promptly handle user complaints and reports.
Where automotive data processing activities cause harm to users’ lawful rights and interests or public interests, the automotive data processor shall bear the corresponding liability in accordance with the law.
Article 18 Automotive data processors that violate these Provisions shall be penalised by relevant authorities at or above the provincial level, including those responsible for cyberspace affairs, industry and information technology, public security and transport, in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China and other laws and administrative regulations. Where a violation constitutes a crime, criminal liability shall be pursued in accordance with the law.
Article 19 These Provisions shall enter into force on October 1, 2021.
