Most privacy laws regulate what you do with data. China's automotive law regulates where the chip has to be.
In brief:
- China's Several Provisions on the Management of Automobile Data Security establish an in-vehicle processing principle and a default non-collection doctrine.
- Raw vehicle telemetry, cabin audio and biometric identifiers must be processed inside the vehicle by default, not offloaded to cloud servers.
- Any cross-border transfer of important data requires formal government cybersecurity assessment and approval.
Compare the way most privacy regulation works with the way China's automotive data law works, and the difference is architectural, not procedural. The California Consumer Privacy Act, the EU's GDPR, and similar frameworks generally govern consent, disclosure and downstream use: a company can collect data if it discloses what it's doing and gets appropriate consent, and the data can generally move wherever the company's infrastructure lives, subject to those consent rules. Data can generally move freely between the automaker's global systems once appropriate legal bases exist.

China's framework, jointly issued by the Cyberspace Administration of China, the Ministry of Industry and Information Technology, the National Development and Reform Commission, and the Ministry of Public Security, does something categorically different. It specifies where computation must physically occur, independent of consent or disclosure.
The two doctrines, and what they actually require
The in-vehicle processing principle requires that raw vehicle telemetry, cabin acoustic signals, video monitoring streams and biometric identifiers undergo computational processing inside the vehicle cabin by default. Automated offloading to central enterprise clouds is prohibited unless a specific functional necessity is established and justified. This is a genuinely different regulatory lever than a consent requirement - it doesn't ask whether the automaker has permission to send data to the cloud, it starts from the position that the data shouldn't leave the vehicle at all unless there's a specific, defensible reason.
The default non-collection doctrine works alongside it: external perceptual sensors, including high-definition cameras and LiDAR units, must default to a non-recording state unless actively engaged by vehicle occupants to deliver a specific navigation or safety function. Again, this isn't a rule about what happens to data once collected - it's a rule about whether the sensor is even allowed to be capturing data in the first place, absent an active, specific trigger.
The rule doesn't ask what you'll do with the data. It asks whether the sensor should be recording at all.
— Marqstats Analyst Team
Why this forces a genuinely different engineering approach, not just a legal one
A company complying with a consent-based privacy law can generally build one global data architecture and adjust consent flows, retention periods and disclosure language by jurisdiction. A company complying with China's in-vehicle processing principle cannot do this, because the requirement is about physical computation location, not data handling policy. Meeting it requires genuinely different software running on genuinely different infrastructure - edge computing systems capable of processing telemetry locally without cloud dependency, and separate sovereign cloud infrastructure, hosted on domestic providers including Alibaba Cloud or Baidu AI Cloud, for whatever data legitimately needs centralized processing.
This is why automakers operating in China cannot simply extend their existing global cloud architecture with additional consent screens and data-retention policies. They need a parallel technical stack built specifically to satisfy an architectural mandate, not a policy mandate.
The cross-border transfer requirement compounds the isolation
Even for data legitimately processed and stored within China, moving it outside the country isn't simply a matter of company policy. The March 2024 Provisions on Promoting and Regulating Cross-border Flow of Data require formal government cybersecurity assessment and approval for transferring important data, a category that specifically includes high-definition spatial mapping data, logistics fleet operational data, aggregated vehicle trajectory data, and charging network utilization statistics, outside mainland China. This means even data an automaker has fully and legally processed within its sovereign Chinese infrastructure cannot simply flow back to a global analytics team without a separate government review process.
The counter-argument: isn't this just an extreme version of data localization laws elsewhere?
A fair objection is that data localization requirements exist in other jurisdictions too - Russia, India in certain sectors, and others have their own residency rules - so China's framework might be read as simply a stricter version of a familiar regulatory category rather than something categorically new. This has some merit; data localization as a general regulatory tool isn't unique to China. What appears more distinctive here is the combination of two specific elements together: an architectural mandate governing where computation itself must occur (not just where data is stored at rest), paired with a default non-collection requirement that constrains sensor behavior before any data even exists to be localized. Many data localization regimes address storage location; fewer address the upstream question of whether data collection should be happening at all absent an active justification.
What this means for automakers and technology vendors
- Any company planning China market entry should budget for genuinely separate edge computing and sovereign cloud infrastructure from the outset, not as a later compliance retrofit to an existing global architecture.
- Legal and engineering teams should collaborate from the earliest design stage, since compliance here is inseparable from system architecture decisions in a way it typically is not under consent-based privacy frameworks.
- Track the specific classification boundaries of important data closely, since cross-border transfer of that category requires government assessment regardless of how well a company otherwise complies with in-vehicle processing and non-collection requirements.
How this interacts with China's own public infrastructure investment
There's a genuine complexity worth surfacing here: China's Vehicle-Road-Cloud Integration model, which has mobilized more than 30 billion yuan across 20 pilot cities, appears at first glance to run in the opposite direction from a strict in-vehicle processing mandate - it distributes computation across public municipal infrastructure rather than keeping everything inside the vehicle. But the two policies are not actually in tension. Vehicle-Road-Cloud infrastructure operates within the same sovereign boundary the in-vehicle processing principle protects: roadside sensing nodes and municipal cloud platforms process data locally within China, broadcasting only processed spatial trajectory instructions back to vehicles, rather than routing raw sensor data through any centralized enterprise cloud, let alone one outside the country. The architecture is distributed, but the sovereignty boundary remains intact.

This distinction matters for understanding China's overall regulatory philosophy: the goal isn't necessarily minimizing all data processing outside individual vehicles, it's ensuring that whatever processing happens, wherever it happens, stays within infrastructure China's government can oversee and, if necessary, compel data access from.
What compliant companies are actually building
DENSO Corporation's D-tote platform offers a concrete illustration of what compliant engineering looks like in practice. Rather than streaming continuous sensor data to any cloud, domestic or foreign, D-tote runs containerized Linux environments directly within vehicle domain controllers, applying rule-based filters and lightweight machine learning models to detect anomalies locally. Only prioritized trigger events, such as unusual battery temperature spikes or anti-lock brake actuations, get compressed and transmitted onward - and this reduces required wireless bandwidth by more than 98% as a direct side effect, independent of any regulatory requirement to do so. This is a useful example of how compliance-driven architecture and cost-driven architecture can converge: the same engineering approach that satisfies China's in-vehicle processing principle also happens to be the approach that makes mass-market connected vehicle economics work at all, given the bandwidth and storage costs of transmitting raw sensor data at scale.
The full market picture
Marqstats' complete Asia-Pacific automotive data management market analysis, including the full regulatory landscape across China, Japan, India and Australia, is available in the linked report below.
Related reportAsia-Pacific Automotive Data Management Market Size, Share & Forecast 2025 – 2029