Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · TRANSPORT DATA SECURITY MEASURES

Measures for Data Security Management in Transport.

交通运输数据安全管理办法

Promulgated by: Ministry of Transport.
Document No.: 交科技规〔2026〕3号 (Jiao Ke Ji Gui [2026] No. 3).
Issued June 18, 2026. Effective July 1, 2026.

Translation note — DCC. Translated from the full text released to the public via the 网络与信息法学会 (Cyber and Information Law Society) WeChat channel, sourced to the Ministry of Transport and marked for public release (“此件公开发布”); at the time of translation the final text had not yet been posted on mot.gov.cn. Article count and structure verified against the issuing notice (seven chapters, forty-one articles).


Chapter I General Provisions

Article 1. These Measures are formulated in accordance with the Data Security Law of the People’s Republic of China, the Cybersecurity Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China, the Regulation on Network Data Security Management and other laws and regulations, in order to regulate transport data processing activities, ensure data security, protect the legitimate rights and interests of individuals and organizations, and safeguard national security and the public interest.

Article 2. Transport data security work shall adhere to the principles of “whoever manages the business manages the business data and manages its data security” and “territorial administration”, and shall implement tiered management with responsibilities assigned by division of functions.

Article 3. Under the overall coordination of the national data security work coordination mechanism, the Ministry of Transport shall be responsible for data security management work in the fields of integrated transport and highways and waterways, and the National Railway Administration, the Civil Aviation Administration of China and the State Post Bureau shall, according to their respective duties, be responsible for data security management work in the railway, civil aviation and postal fields respectively.

The body in charge of data security of the Ministry of Transport shall be responsible for data security supervision in the fields of integrated transport and highways and waterways, and shall organize the formulation of data security-related policies, systems and standards. The business management bodies of the Ministry of Transport shall, according to their duties, be responsible for data security supervision in their respective business fields. The Maritime Safety Administration of the Ministry of Transport, the Changjiang River Administration of Navigational Affairs, the Rescue and Salvage Bureau and the China Classification Society shall be responsible for data security supervision within their respective systems.

Provincial-level transport authorities shall be responsible for supervising transport data processing activities and security protection in their respective regions, guide municipal- and county-level transport authorities in carrying out data security management work, and cooperate with the Ministry of Transport and the cyberspace administration, public security, state security, data administration and other departments at the same level in carrying out related work.

Article 4. Transport data processors (hereinafter, data processors) shall bear primary responsibility for data security, fulfill data security protection obligations, strengthen security protection across the full data lifecycle, establish and improve management systems, and take technical measures and other necessary measures to protect data from being tampered with, destroyed, leaked, or illegally obtained or illegally used.

Article 5. The open sharing, authorized operation, and trading and circulation of transport data in accordance with the law, as well as innovation in related technologies, products and services, shall be encouraged and supported, so as to promote the secure and compliant circulation and efficient development and utilization of data elements.

Chapter II Data Classification and Grading Protection

Article 6. The Ministry of Transport shall guide the conduct of data classification and grading protection work in the fields of integrated transport and highways and waterways, determine the sector catalogue of important data, put forward recommendations for the catalogue of core data, and strengthen the dynamic management of the catalogues.

Provincial-level transport authorities shall organize the conduct of data classification and grading protection work in their respective regions, and report the identification of important data to the Ministry of Transport.

Data processors shall establish data classification and grading protection procedures, carry out data classification and grading protection work, regularly update their data catalogues, and identify and declare important data in accordance with relevant provisions. For data confirmed as important data, the transport authorities shall promptly notify the data processor or publish the determination.

Article 7. According to the degree of importance of data to economic and social development and to the operation of transport, and the degree of harm caused to national security, the public interest, or the legitimate rights and interests of individuals or organizations once the data is tampered with, destroyed, leaked, or illegally obtained or illegally used, transport data is divided into three grades: core data, important data and general data. Among these, general data is divided, from highest to lowest, into Grade 3 general data, Grade 2 general data and Grade 1 general data.

Article 8. Where the originally determined grade is no longer applicable due to changes in data content, scale, timeliness, application scenarios, processing methods or the like, or due to relevant State requirements, the data processor shall promptly change the data grade.

Where a change in the grade of important data or core data is involved, data classification and grading work shall be conducted anew in accordance with relevant provisions. Where a change in the information of important data or core data is involved, a report shall be made within 30 days.

Chapter III Full-Lifecycle Data Security Management

Article 9. Data processors shall establish and improve a full-lifecycle data security management system, clarify the procedures and authority for registration, approval, processing, operation and the like, and, according to the data grade, take security protection measures under the strictest applicable (highest-grade) requirements.

Processors of important data and core data shall strengthen monitoring, early warning and disposal throughout the entire process of data processing activities, and adopt commercial cryptography technology to safeguard security across the full data lifecycle.

Article 10. Data processors shall strengthen education and training for practitioners on data security knowledge and skills, and assign data security management personnel as needed.

Processors of important data shall, in accordance with relevant provisions, clarify the person responsible for data security and the data security management body. The person responsible for data security shall be a member of the data processor’s management, and shall have the authority to report the data security situation directly to the relevant transport authorities.

Processors of core data shall conduct security background reviews of the person responsible for data security and personnel in key positions, the entities undertaking the construction and the operation and maintenance of core data information systems, and the like.

Article 11. Data processors shall collect data in accordance with the principles of legality, legitimacy and necessity, and shall not steal data or collect data by other illegal means. Where the collection of personal information is involved, they shall clearly inform individuals of the rules for collection and use, and obtain the individual’s consent. Where the collection of sensitive personal information is involved, they shall in addition obtain the individual’s separate consent. This does not apply where, in accordance with the relevant provisions of laws and regulations, it is permissible not to inform the individual and not necessary to obtain the individual’s consent.

Where data is collected through indirect channels, they shall ensure that the data source is lawful, authentic and trustworthy, and guarantee the integrity and availability of the data. Where automated tools are used to access or collect data, they shall ensure that no impact is caused to network services.

Article 12. Data processors shall determine the data storage method, retention period and protection measures according to business needs and the data grade. Personal information processed by transport authorities, personal information and important data collected and generated by critical information infrastructure operators (CIIOs) in the course of their operations within the territory of China, and personal information and important data for which domestic storage is expressly required by relevant laws and regulations, shall be stored within the territory.

Information systems storing important data shall at a minimum meet the requirements of Level 3 of the Multi-Level Protection Scheme (MLPS), and those storing core data shall at a minimum meet the requirements of Level 4 or the security protection requirements for critical information infrastructure, with priority given to the use of secure and trusted products and services. Where cloud computing services are used to store important data, cloud computing services that have passed a security assessment shall be selected.

Data processors shall strengthen the management of data storage and backup media, and back up data regularly. For important data and core data, disaster-tolerant backup shall be implemented, and data recovery tests and disaster recovery drills shall be conducted regularly.

Article 13. Data processors shall, according to the data grade, take protection measures such as access control, data de-sensitization and encryption, and operation auditing, so as to ensure that the process of data use and processing is secure, compliant, controllable and traceable.

Where important data and core data are used and processed, strict access control shall be implemented, and technical systems for trusted and controllable data, log retention and auditing, risk monitoring and assessment, data traceability and the like shall be established and improved.

Article 14. Data processors shall formulate data transmission security policies and take necessary protection measures according to the data type, data grade, application scenario and other factors.

Where Grade 3 general data, important data or core data are transmitted, protection measures such as verification technology, cryptographic technology, secure transmission channels or secure transmission protocols shall be adopted.

Article 15. In the course of data provision such as exchange and sharing and authorized operation, data processors shall provide the data recipient with the data needed in accordance with the minimum necessary principle. Where the data provided involves sensitive information, necessary de-sensitization shall be carried out.

Where personal information, important data or core data is provided, the data security protection capability of the data recipient shall be verified; the purpose, method, scope and other aspects of the data processing shall be agreed upon by signing contracts or agreements and the like; the protection obligations and measures of the data recipient shall be clarified; supervision of performance shall be strengthened; and where it is discovered that the recipient fails to perform as agreed, the provision of data shall be stopped immediately.

Article 16. Transport authorities shall disclose government data in a timely and accurate manner in accordance with relevant provisions, except where such data is not to be disclosed in accordance with the law.

Data processors shall strengthen the security management of open-source data, and standardize the management of the disclosure of highway and waterway video images and scientific data.

Data processors shall not disclose the personal information they process, except where the individual’s separate consent has been obtained.

Article 17. Data processors shall establish a data deletion system, record and retain records of deletion activities, and adopt information erasure technology to ensure that data cannot be recovered after deletion. Where the deletion of data is technically difficult to achieve, processing other than storage and the taking of necessary security protection measures shall cease.

Data processors shall, in accordance with the law, delete personal information that laws and regulations require to be deleted on their own initiative or that an individual requests to be deleted, as well as data whose deletion is agreed in a contract or agreement.

For the deletion of important data and core data, a data deletion plan shall be formulated before the operation, the risks that may exist shall be assessed, and a report shall be made in advance.

Article 18. Where a data processor needs to transfer data due to merger, division, dissolution, bankruptcy, or the like, it shall clarify the data transfer plan, and shall, by means of agreements, undertakings and the like, stipulate that the data recipient fully assumes the security protection obligations for the corresponding data. Where personal information is involved, the individual shall be informed of the name or personal name and contact information of the data recipient.

Where important data, core data or the personal information of 10 million or more individuals is involved, the data transfer plan, the name or personal name and contact information of the recipient, and other such matters shall be reported in advance. Data transfer shall be carried out in a secure and controllable manner, ensuring that the process is traceable.

Article 19. Where a data processor entrusts others to process data or processes data jointly with others, its data security responsibility shall not change by reason of the entrustment, and it shall, by signing contracts or agreements and the like, clarify the data security responsibilities and obligations of both parties. Without the consent of the entrusting party, the data recipient shall not provide the data to others, shall not further process the data, use it for training or misappropriate it, and shall not carry out data correlation analysis.

Where the processing of important data and core data is entrusted, the data security protection capability and qualifications of the data recipient shall also be verified or assessed.

Article 20. Where data processors provide data overseas, they shall comply with relevant State provisions on cross-border data security management, fulfill data security protection obligations, and take technical measures and other necessary measures to safeguard the security of data crossing the border. They shall not adopt means such as data splitting to circumvent the relevant obligations. Where personal information is provided overseas, obligations such as giving notice, obtaining the separate consent of the individual and conducting a personal information protection impact assessment shall be fulfilled in accordance with relevant provisions.

Article 21. Where data processing activities are carried out using artificial intelligence (AI) technology, the data processor shall, before the models and algorithms are put into use, assess the reasonableness, legitimacy and explainability of the corpus, the training data and the algorithms, as well as the impact of the data utilization on the legitimate rights and interests of the relevant subjects, the ethical risks, and the effectiveness of the prevention and control measures.

The security management of AI-generated data and AI products shall be strengthened, and the corresponding data security management requirements shall be strictly implemented in accordance with the classification and grading corresponding to the generated data and the data processing results.

Those providing generative AI services shall strengthen the security management of training data and training data processing activities, and strengthen the quality assessment of data labeling.

Article 22. Data processors shall retain network logs of data processing, permission management, personnel operations, and the like, covering the full data lifecycle, and shall manage them by classification and grading, so as to meet the needs of risk traceability and incident disposal.

The retention period of network logs shall be not less than six months. The retention period of logs relating to access to government affairs application systems, database operations and important data security incidents shall be not less than one year. Logs relating to core data security incidents, and records of the circumstances of processing where personal information and important data are provided to other data processors, entrusted for processing or jointly processed, shall be retained for not less than three years.

Chapter IV Data Security Risk Assessment

Article 23. Processors of important data and core data, and personal information handlers processing the personal information of 10 million or more individuals, shall conduct a data security risk assessment (hereinafter, risk assessment) every year, and submit risk assessment reports.

Processors of general data are encouraged to conduct a risk assessment at least once every three years.

Large network platform operators shall conduct risk assessments in accordance with relevant provisions.

Article 24. Where any of the following circumstances exists, the data processor shall conduct a risk assessment:

(I) a major data security incident occurs, or the data processor has been notified of the existence of a major data security risk;

(II) important data is provided, entrusted for processing or jointly processed, except where this is done in the performance of statutory duties or obligations;

(III) a processor of important data undergoes a major change such as merger, division or dissolution, or a major change occurs in an information system carrying important data;

(IV) high-risk data processing activities such as providing data overseas are carried out;

(V) other circumstances that may endanger national security or the public interest, or seriously harm the legitimate rights and interests of individuals or organizations.

Article 25. Data processors may conduct risk assessments on their own or entrust a third party to do so; the third party shall be a professional testing and assessment institution recognized by the relevant State departments, or another institution that meets relevant State provisions.

Article 26. Risk assessment reports shall comply with relevant provisions and be kept for at least three years, and may serve as a basis for data security supervision and inspection by the transport authorities.

Article 27. Data processors shall promptly rectify problems identified in risk assessments and eliminate risks and hidden dangers.

Where a major data security risk, incident or special emergency is discovered in the course of a risk assessment, processors of important data and core data shall report it promptly.

Article 28. Personal information handlers in the transport sector shall, in accordance with relevant provisions, regularly conduct personal information protection compliance audits on their own or by entrusting a professional institution.

Chapter V Data Security Monitoring, Early Warning and Emergency Response

Article 29. The Ministry of Transport shall coordinate the establishment of a sector working mechanism for network and data security risk monitoring, early warning and information notification, and provincial-level transport authorities shall establish working mechanisms for their respective regions, strengthening information sharing with the cyberspace affairs, public security, national security, data administration and other departments.

Data processors shall establish data security risk monitoring mechanisms, and promptly discover, dispose of and report security risks and incidents.

According to the scope of impact and the degree of harm caused to national security, social order, economic construction, the public interest, and the like, transport data security incidents are divided into four levels: especially major, major, relatively major and general.

Article 30. Transport authorities and data processors shall formulate emergency response plans for data security incidents, strengthen early-warning response and emergency linkage, and regularly organize the conduct of emergency drills. Processors of important data and core data shall conduct emergency drills annually.

Article 31. For data security incidents that cause harm to the legitimate rights and interests of individuals or organizations, data processors shall promptly notify the interested parties; where leads suggesting suspected violations of law or crimes are discovered, they shall file a report with the public security organ or the national security organ in accordance with relevant provisions, and cooperate in carrying out the criminal investigation, investigation and disposal work.

Article 32. After the disposal of a data security incident is completed, data processors shall complete the investigation and assessment of the incident, and propose improvement measures and implement them.

Chapter VI Supervision, Inspection and Accountability

Article 33. Transport authorities shall regularly organize the conduct of risk assessments, carry out data security inspections in accordance with the law, and guide and supervise data processors in fulfilling their data security protection obligations. Data processors shall cooperate, and promptly rectify risks and hidden dangers.

Article 34. In carrying out data security supervision and inspection, transport authorities shall be objective and impartial, shall not charge fees to the entities under inspection, and shall not access or collect business information unrelated to data security; the information obtained shall be kept confidential in accordance with the law, may be used only as needed for safeguarding data security, and shall not be used for other purposes.

Where it is discovered that data processing activities involve relatively major security risks, they may, in accordance with the prescribed authority and procedures, require data processors to suspend the relevant services, improve technical measures, and the like, so as to eliminate hidden dangers to data security.

Article 35. When carrying out data security supervision and inspection, transport authorities shall strengthen coordination, cooperation and information communication, reasonably determine the frequency and methods of inspection, and avoid unnecessary inspections and overlapping and duplicative inspections.

Article 36. Where the content relating to data security overlaps among risk assessments, Multi-Level Protection Scheme (MLPS) grading evaluations, critical information infrastructure security inspections and commercial cryptography application security assessments, the results may be mutually recognized.

Article 37. Where these Measures are violated, the transport authorities shall order corrections to be made, and the directly responsible persons in charge and other directly liable persons shall be given sanctions or penalties in accordance with the law. Where a violation of law or crime is suspected, the matter shall be reported to the relevant departments in accordance with relevant provisions.

Chapter VII Supplementary Provisions

Article 38. The reporting and submission circumstances involved in Article 8, Article 17, Article 18, Article 23 and Article 27 of these Measures shall be reviewed by the provincial-level transport authorities and then reported to the Ministry of Transport. Entities directly under the Ministry and central transport enterprises may report directly to the Ministry of Transport.

Article 39. Data processing activities involving core data, or involving data related to State secrets or work secrets, shall be carried out in accordance with relevant State provisions.

Article 40. The Ministry of Transport is responsible for the interpretation of these Measures.

Article 41. These Measures shall come into force on July 1, 2026.

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

1 brief references this law.

  • § 01 · TRANSPORT

    Five Grades of Data, One Reporting Spine: The Ministry of Transport's Data Security Measures

    On June 18, 2026 the Ministry of Transport issued the Measures for Data Security Management in Transport (交科技规〔2026〕3号), effective July 1, 2026 — 41 articles that complete the sector build-out of the Data Security Law for highways, waterways and comprehensive transport. The full text reached the public record in July through an academic-society WeChat repost rather than the ministry's own site. DCC reads the Measures around four load-bearing features: a five-grade classification ladder that splits general data into Grades 3/2/1 and pulls Grade-3 general data into the hard transmission-protection net alongside important and core data; an annual risk-assessment duty that extends beyond important-data handlers to any processor holding personal information on 10 million or more people, dated the same day as the national Network Data Security Risk Assessment Measures but effective 50 days earlier; an AI clause requiring pre-deployment evaluation of corpora, training data and algorithm explainability, plus a default ban on training on entrusted data; and a single reporting spine that routes filings through provincial transport authorities to MOT, with a direct line for central transport SOEs. Storage follows the sector pattern: localization for transport-authority personal information and CIIO-collected data, MLPS Level 3 for important-data systems, Level 4 or CII protection for core data, and security-assessed cloud services only.

    transport · mot · important-data
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →