Compliance

CAC Data Export Assessment Checklist for Automotive Companies (2026)

πŸ“… September 8, 2026 ⏱️ 11 min read βœ… Reviewed July 2026

Connected vehicles generate the most regulated data category in China. Between the CAC's automotive data rules, PIPL, and the 2024 cross-border data flow provisions, an export that looks routine β€” telemetry to your global engineering center, mapping updates, fleet analytics β€” can trigger a CAC security assessment. This checklist walks automotive companies through the 2026 decision process.

Step 1: Inventory and Classify Your Data

Before any threshold analysis, map every data flow out of China. For automotive businesses the categories that matter are:

Data TypeTypical ExamplesDefault Sensitivity
Out-of-vehicle data (camera/radar)Street imagery, surroundings recordingsOften "important data" β€” sensitive areas are the trigger
Location & trajectoryGPS tracks, geofenced areas, fleet movementPotentially important data at scale; PI when linked to individuals
In-cabin personal informationDriver identity, biometrics, voice, cabin videoPersonal information; biometric = sensitive PI
Vehicle operation dataBattery, charging network, autonomous-driving logsMay be important data in aggregate
Map/navigation dataHD map collection, surveying dataHeavily regulated β€” separate surveying & mapping rules apply
Automotive-specific trap: out-of-vehicle data collected in or near sensitive zones (military areas, key infrastructure) is a core "important data" trigger. Chinese authorities have publicly penalized foreign automakers over this exact category. Assume camera data is restricted until classified otherwise.

Step 2: Determine Your Export Path

Run each data flow through the decision chain (mirrors our Data Export Self-Checker):

  • CAC Security Assessment β€” required if: you are a CIIO transferring any data abroad; the flow contains important data; or personal information volumes exceed the statutory cumulative thresholds since January 1.
  • SCC Filing or Certification β€” the middle path for personal information below assessment thresholds (and sensitive PI under the small-volume threshold): file standard contractual clauses with the provincial CAC or pursue personal information protection certification.
  • Exemptions β€” limited categories exist (e.g. transfers necessary for cross-border transport/aviation safety, contract necessity with de minimis volumes, de-identified statistical data). Automotive operational flows rarely fit cleanly β€” document any exemption claim carefully.

Step 3: If Assessment Is Required β€” the Checklist

  1. PIPIA first. Complete a Personal Information Protection Impact Assessment and keep it on file β‰₯ 3 years β€” it is required for all cross-border paths and feeds the application.
  2. Self-assessment report. The CAC assessment application requires a detailed self-assessment: data types, volumes, fields, recipient country's legal environment, and contractual safeguards.
  3. File via provincial CAC. The operator submits to the provincial cyberspace administration, which forwards to the national CAC.
  4. Respond to supplementation. Budget at least one round of follow-up questions. Incomplete data-flow descriptions are the top rejection driver.
  5. Result validity. Assessment results have a limited validity period and must be renewed; material changes to the flow require re-application.

Step 4: The Localization Alternative

Most major automakers now default to local storage with selective export: keep Chinese vehicle data on Chinese servers, and only push genuinely necessary data (usually de-identified engineering data or consented personal information) through assessed channels. This "China cloud" model β€” pioneered by Tesla's Shanghai data center β€” is the pragmatic 2026 baseline. Costs: domestic cloud contracts, separate Chinese engineering environments, and a data governance team that can evidence separation.

Step 5: Ongoing Compliance

  • Annual review of the data inventory and classification (regulators update catalogs).
  • Consent management for in-cabin personal information (separate, specific consent for cross-border transfer).
  • Contracts with overseas recipients covering PIPL Article 38 obligations.
  • Monitor FTZ "free flow" pilot lists β€” Shanghai and other pilots maintain negative lists where certain data flows are eased; automotive "important data" remains restricted everywhere.

Quick Self-Check

Answer seven questions β€” CIIO status, important data, volumes, sensitivity β€” and get your required path with the Data Export Self-Checker. For the broader legal framework, read our Data Cross-Border Transfer Guide and the step-by-step SCC Filing Steps 2026.

Informational only β€” verify with official sources; not legal advice.

Frequently Asked Questions

What counts as "important data" for automotive companies in China?
Under CAC guidance, important data in the automotive context includes data outside protected geographic areas involving military zones or sensitive infrastructure, data on vehicle traffic flow, charging network operation, out-of-vehicle (camera/radar) data reflecting sensitive areas, and data on personnel activity that could affect national security. The 2021 CAC automotive data provisions and subsequent catalog updates define the categories.
Do all cross-border transfers of automotive data need CAC security assessment?
Not all β€” but most transfers that matter do. Personal information can qualify for SCC filing or certification below statutory thresholds, but "important data" transfers always require a CAC security assessment. CIIOs need assessment for any cross-border transfer. The 2024 Provisions on Promoting and Regulating Cross-Border Data Flows also created limited exemption categories.
How long does a CAC security assessment take?
The statutory timeline is 45 business days from complete acceptance, but real-world timelines run 3-6 months including pre-acceptance preparation, provincial CAC forwarding, and possible supplementation requests. Plan well ahead of any product launch that depends on data flows.
Can Tesla-style localized storage satisfy compliance without any transfer?
Localized storage with no cross-border transfer removes the export-control trigger entirely. That is why most major automakers (including foreign brands) store Chinese vehicle data domestically and only export genuinely needed, de-identified or consented data through assessed channels.

Related Guides

Found this useful?

Stay Informed

Weekly Policy Briefing

Get a curated digest of the latest Chinese policy changes, investment insights, and regulatory updates β€” delivered every Monday morning. Choose what matters to you.

Customize your briefing

Industries

Cities / Regions

Frequency

No spam. Unsubscribe anytime. Update your preferences anytime.