跳到主要内容
ZHAOXUN

MIIT and Seven Agencies Issue the 2026 Auto Data Export Security Guidelines

Eight agencies led by MIIT issued the Guidelines to implement the Data Security Law, ease auto data export, and propose a Chinese approach to automotive data governance.

On January 30, 2026, MIIT together with the Cyberspace Administration, NDRC and five other agencies issued the "Automotive Data Export Security Guidelines (2026 Edition)" (released February 3), implementing national decisions on cross-border data flows and the Data Security Law — raising facilitation for automotive data export while building a virtuous cycle of high-quality development and high-level security.

Core content in four parts: first, general provisions — scope (personal information and important data across vehicle design and production; processors including OEMs and parts suppliers), definitions of export behavior (e.g. transmitting data abroad or making it retrievable from overseas), and three management tracks (security assessment, standard contracts / certification, and nine exemption categories such as emergency avoidance and free-trade-zone negative-list data); second, important-data determination with detailed rules across five scenarios including R&D design (BOMs, test data), manufacturing (process lists, control code) and driving automation (algorithms, training data); third, export procedures covering data identification and assessment / contract / certification steps; fourth, security requirements across governance, technical protection (e.g. encrypted transmission), log retention (no less than 3 years) and incident response.

The document also clarifies that exemptions carry conditions (e.g. vulnerability-remediation data must be reported first), filings do not require raw data, and important-data rules will be dynamically adjusted — with future rollout via training, data filing and enterprise capability building.

← Back to Newsroom