Provisions on the Administration of Automotive Data Security of the PRC (Trial) — Full English Translation (2021)

Jointly issued by the Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security and the Ministry of Transport on August 16, 2021

Effective: October 1, 2021


Article 1 — These Provisions are formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China and other laws and administrative regulations, for the purposes of strengthening the security management of automotive data, protecting the lawful rights and interests of individuals and organizations, and safeguarding national security and public interests.

Article 2 — These Provisions apply to the collection, storage, use, processing, transmission, provision and disclosure of automotive data carried out within the territory of the People’s Republic of China.

Article 3 — For the purposes of these Provisions:

(1) “automotive data” means the data, including personal information and important data, generated or collected in the course of the design, production, sale, use, operation and maintenance of automobiles;

(2) “automotive data processing” means the collection, storage, use, processing, transmission, provision and disclosure of automotive data;

(3) “automotive data processor” means an organization that carries out automotive data processing activities, including automobile manufacturers, component and software suppliers, distributors, repair and maintenance institutions and travel service enterprises;

(4) “personal information” and “sensitive personal information” have the meanings given to them by the Personal Information Protection Law of the People’s Republic of China; and

(5) “important data” means the following data collected, generated or otherwise obtained by an automotive data processor: data on the flow of people and vehicles within military administrative areas, national defense science and technology industrial entities and other areas involving national security; data on the flow of people and vehicles within important sensitive areas such as Party and state organs and units of key importance; geographic information, traffic flow and other data that may reflect the state of key areas; audio and video data of areas outside the vehicle collected on a large scale; and other data that may endanger national security, public interests, or the lawful rights and interests of individuals or organizations.

Article 4 — An automotive data processor shall process automotive data in a lawful, justified and necessary manner, and shall process personal information in accordance with the principles of honesty, openness and transparency, and shall not process personal information in an excessive or unreasonable manner.

Article 5 — An automotive data processor shall adhere to the principles of minimum necessity and purpose limitation in processing automotive data, and shall not collect data that is unrelated to the functions of the automobile or the services provided.

Article 6 — An automotive data processor shall not collect personal information inside the vehicle unless it is genuinely necessary, and shall not collect personal information by default. Where personal information inside the vehicle may be collected, the processor shall provide the user with the option to choose not to provide such personal information, and shall not refuse to provide basic functions of the automobile solely on the ground that the user declines to provide personal information.

Article 7 — Where an automotive data processor collects personal information, it shall inform the individual of the matters prescribed by law, such as the name and contact details of the processor, the purpose and method of processing, the categories of personal information, the retention period, and the manner of exercising rights, and shall obtain the consent of the individual or satisfy other conditions prescribed by law.

Article 8 — An automotive data processor processing sensitive personal information shall obtain the separate consent of the individual and shall inform the individual of the necessity of processing the sensitive personal information and the impact on the individual’s rights and interests. Sensitive personal information generated in automotive data processing includes precise location information, driving trajectories, audio and video data inside and outside the vehicle, and biometric information.

Article 9 — Important data shall be stored within the territory of the People’s Republic of China in accordance with the law.

Article 10 — Where an automotive data processor provides important data outside the territory of the People’s Republic of China, it shall first conduct a security assessment. Where the important data is to be provided abroad, the processor shall apply to the Cyberspace Administration of China and the other relevant competent authorities for a security assessment, and shall not provide such data abroad without approval.

Article 11 — Where an automotive data processor provides personal information outside the territory of the People’s Republic of China, it shall comply with the relevant provisions of laws and administrative regulations governing the cross-border provision of personal information.

Article 12 — An automotive data processor shall process personal information such as location information and audio and video data inside and outside the vehicle in accordance with the principle of minimum necessity, and shall, where technically feasible, carry out processing such as anonymization and de-identification within the vehicle or the terminal device.

Article 13 — An automotive data processor shall provide individuals with convenient channels for accessing, copying, correcting and deleting their personal information, and shall respond to requests made by individuals to exercise their rights in a timely manner.

Article 14 — Where location information or audio and video data outside the vehicle collected by an automotive data processor is no longer necessary for the stated purpose, the processor shall anonymize it or delete it within a reasonable period.

Article 15 — An automotive data processor shall take appropriate technical and organizational measures to ensure the security of automotive data, prevent automotive data from being leaked, destroyed, lost, tampered with, illegally obtained or illegally used, and shall establish a sound automotive data security management system.

Article 16 — An automotive data processor shall designate a person responsible for data security, establish and improve internal data security management rules and operating procedures, and conduct data security education and training for relevant personnel.

Article 17 — Where an automotive data security incident occurs, the automotive data processor shall immediately take remedial measures, and shall promptly notify the users concerned and report to the relevant competent authorities in accordance with the relevant provisions.

Article 18 — An automotive data processor shall, in accordance with the requirements of the relevant competent authorities, identify the important data it processes and report such data to the Cyberspace Administration of China and the other relevant competent authorities, and shall carry out a security assessment of its processing of important data.

Article 19 — An automotive data processor shall cooperate with the supervision and inspection conducted by the Cyberspace Administration of China and the other relevant competent authorities in accordance with the law, and shall provide relevant materials and explanations truthfully.

Article 20 — An automotive data processor shall establish a channel for receiving complaints and reports concerning automotive data security, and shall handle complaints and reports in a timely manner.

Article 21 — Where a violation of these Provisions occurs, the Cyberspace Administration of China and the other relevant competent authorities shall impose penalties in accordance with the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law and other relevant laws and administrative regulations.

Article 22 — These Provisions shall come into force on October 1, 2021.

← Back to the China Laws Directory⬇ Download Full Text as PDF

Free PDF download of the complete article.

Wechat

WhatsApp

WhatsApp

WhatsApp
[email protected]
+86 18565453956