Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 085 · TRANSPORT

Five Grades of Data, One Reporting Spine: The Ministry of Transport's Data Security Measures

On June 18, 2026 the Ministry of Transport issued the Measures for Data Security Management in Transport (交科技规〔2026〕3号), effective July 1, 2026 — 41 articles that complete the sector build-out of the Data Security Law for highways, waterways and comprehensive transport. The full text reached the public record in July through an academic-society WeChat repost rather than the ministry's own site. DCC reads the Measures around four load-bearing features: a five-grade classification ladder that splits general data into Grades 3/2/1 and pulls Grade-3 general data into the hard transmission-protection net alongside important and core data; an annual risk-assessment duty that extends beyond important-data handlers to any processor holding personal information on 10 million or more people, dated the same day as the national Network Data Security Risk Assessment Measures but effective 50 days earlier; an AI clause requiring pre-deployment evaluation of corpora, training data and algorithm explainability, plus a default ban on training on entrusted data; and a single reporting spine that routes filings through provincial transport authorities to MOT, with a direct line for central transport SOEs. Storage follows the sector pattern: localization for transport-authority personal information and CIIO-collected data, MLPS Level 3 for important-data systems, Level 4 or CII protection for core data, and security-assessed cloud services only.

Editor’s Note — DCC.

This brief covers a single new sector instrument: the Measures for Data Security Management in Transport (《交通运输数据安全管理办法》), issued by the Ministry of Transport (MOT) as 交科技规〔2026〕3号 on June 18, 2026, effective July 1, 2026. A provenance note: the Measures took effect with the full text not yet posted on the ministry’s own website — the 41-article text entered the public record through a full repost by the Cyber and Information Law Society’s WeChat channel, sourced to MOT and marked for public release. The full text is in DCC’s law-catalogue entry; this brief is the structural read, and the framing — the five-grade ladder, the “50 days early” comparison with the national risk-assessment rule, and the reporting-spine model — is DCC’s.

The one-line thesis

Transport was one of the last major infrastructure sectors still running on a consultation draft. These Measures close that gap: highways, waterways and comprehensive transport now have the same kind of sector rulebook that industry got from MIIT in 2023 and energy got from the National Energy Administration’s trial measures — classification keyed to a sector catalogue, localization plus MLPS floors, annual risk assessment, and an incident regime. What makes the transport version worth reading closely is where it deviates from the family pattern: a five-grade ladder instead of three, a 10-million-person threshold that arrives ahead of the national schedule, and an AI clause that reaches further than any of its sector siblings.

Who regulates, who is regulated

The Measures run on the now-standard principle — “whoever manages the business manages the business data and manages its data security” — plus territorial administration (Article 2). MOT covers comprehensive transport and the highway and waterway fields; rail, civil aviation and postal data stay with the State Railway Administration, the CAAC and the State Post Bureau respectively (Article 3). Provincial transport authorities supervise their regions and feed identification results upward.

The addressee list is its own compliance map: besides the transport bureaucracy it names the three central transport SOEs — COSCO Shipping, China Merchants Group, CCCC — and, generically, highway and waterway critical information infrastructure operators and important-data processors. If a group sits anywhere in that list, the Measures are not abstract.

The five-grade ladder

The family pattern since the MIIT measures has been three tiers: general, important, core. Article 7 keeps the three levels but then splits general data into Grade 3, Grade 2 and Grade 1 (descending). That would be a cosmetic refinement except that obligations attach to the top grade: Article 14 requires verification technology, cryptographic technology, secure channels or secure transmission protocols for transmitting Grade 3 general data — the same protections it requires for important and core data.

The practical effect is a middle band of data that is not important data — so it does not trigger cataloguing, annual assessment or the important-data export security-assessment gate — but is also not free: its transmission is regulated. Transport operators will need their classification regimes to produce a defensible Grade 3/2/1 split of general data, a step the three-tier sectors never had to take.

Classification itself follows the catalogue model (Article 6): MOT determines the sector catalogue of important data and manages it dynamically; processors classify, keep their own catalogues current, and identify and declare important data; transport authorities notify or publish confirmations. Where the grade of important or core data changes, classification and grading must be redone; where their registered information changes, a report is due within 30 days (Article 8).

Storage: the localization-plus-MLPS pattern

Article 12 is the sector’s localization clause, and it is broader than the CII baseline. Three categories must be stored within China: personal information processed by transport authorities themselves; personal information and important data collected and generated by CII operators in domestic operations; and personal information and important data that other laws and regulations expressly require to be stored domestically. System floors follow the family pattern — MLPS Level 3 or above for systems storing important data, Level 4 or CII protection for core data — and important data may only sit on cloud services that have passed security assessment. Important and core data also require disaster-recovery backup with periodic restoration tests.

The risk-assessment mirror — 50 days early

Articles 23–28 build a compact copy of the machinery the national Network Data Security Risk Assessment Measures (Order No. 24) established: an annual assessment with report submission, event-triggered reassessment (major incidents or notified major risks, providing, entrusting or jointly processing important data, M&A-scale changes, cross-border transfers), third-party assessors drawn from recognized institutions, three-year report retention, rectification duties, and personal information protection compliance audits.

Two details matter. First, the trigger population is wider than the national rule’s: the annual duty binds important-data and core-data processors and any processor of personal information on 10 million or more people (Article 23) — a pure-volume PI threshold living inside a data-security instrument. Second, the timing: the MOT notice is dated June 18, 2026 — the same day the CAC, MIIT and MPS published Order No. 24 — but the transport rule took effect July 1, fifty days before the national rule’s August 20 date. Under Order No. 24’s own sector-priority clause, where a sector authority has provisions, those prevail — so for transport operators, this is the risk-assessment regime that counts, and it started first. DCC’s structural read of the national rule is in the Order No. 24 brief.

The AI clause

Article 21 is the furthest-reaching AI provision yet seen in a sector data-security rule. Before putting a model or algorithm into use, data processors must evaluate the rationality, legitimacy and explainability of the corpus, the training data and the algorithm, together with the impact of the data use on affected parties’ rights, ethics risks, and the effectiveness of controls. AI-generated data must be classified and graded like any other data, with the corresponding duties attached. And generative-AI service providers must manage training data security and run labeling quality assessment.

Article 19 adds the quiet companion rule: absent the entrusting party’s consent, a data recipient in an entrusted- or joint-processing arrangement may not process, train on, or divert the data, and may not run data correlation analysis. A no-training-by-default term is now written into transport-sector contracts by operation of law — worth checking against every model-development and analytics vendor arrangement touching sector data.

The operational details that will bite

DutyRuleArticle
Log retention ladder6 months (network logs generally) → 1 year (government-application access, database operations, important-data incidents) → 3 years (core-data incidents; records of providing, entrusting or jointly processing PI and important data)22
M&A / restructuring transfersTransfer plan and recipient details reported in advance where important data, core data, or PI of 10M+ people is involved18
DeletionDeletion must be irrecoverable and logged; important/core data deletion needs a pre-operation plan, risk evaluation and advance report17
Cross-borderNational regime applies; data splitting to evade obligations is expressly prohibited; PI transfers need notice, separate consent and impact assessment per the national rules20
Mutual recognitionOverlapping results of risk assessment, MLPS testing, CII inspection and commercial-cryptography assessment are mutually recognized36
PersonnelImportant-data processors must designate a person responsible for data security — a management member entitled to report directly to transport authorities — plus a data-security management body; core-data processors run security background reviews on that person, key personnel, and core-data system construction and O&M contractors10
CryptoImportant- and core-data processors must use commercial cryptography across the full data lifecycle9

The reporting spine ties it together (Article 38): the reports and filings scattered through the Measures — change-of-information reports (Article 8), deletion plans (Article 17), transfer plans (Article 18), annual assessment reports (Article 23), and reports of major risks or incidents surfaced by assessments (Article 27) — route through provincial transport authorities for review, then to MOT; MOT-affiliated units and central transport enterprises may report directly. For a central SOE group, that direct line concentrates the compliance interface; for everyone else, the provincial authority is the working counterparty.

What changes for compliance programs

For operators — port and shipping groups, highway and logistics platforms, ride-hailing and freight-matching businesses with transport-sector touchpoints — the sequence the Measures impose is concrete:

  • Classification first. Every hard duty keys off the grade. The five-grade ladder means even the “general” bucket needs internal sub-grading with documentation that survives inspection.
  • Count your personal-information base. The 10M threshold converts scale alone into an annual assessment duty, independent of whether anything is important data.
  • Re-paper vendor arrangements. The Article 19 no-training default and its capability-and-qualification vetting belong in entrustment contracts now, not at renewal; sharing and authorized-operation contracts need the separate Article 15 recipient-capability verification.
  • Map the overlap. The national Order No. 24 regime, this sector rule, and MLPS/CII obligations interlock; Article 36’s mutual-recognition clause is the cost-control lever — one assessment file, reused across four supervisory tracks.

One drafting note: the January consultation draft ran 45 articles; the final text runs 41. The tightening is real but the architecture survived consultation intact.

The Measures do not invent a new theory of data security. They finish a job: after industry, automotive, natural resources, finance and energy, the transport sector now has its own operating rulebook under the Data Security Law — and in two places, the five-grade ladder and the 10-million-person trigger, it quietly sets the pace for the family.


交通运输部, 交通运输数据安全管理办法 (Measures for Data Security Management in Transport), 交科技规〔2026〕3号, issued June 18, 2026, effective July 1, 2026; full text published via the 网络与信息法学会 WeChat Official Account. Original text (Chinese). Full English translation in DCC’s law-catalogue entry.

Not legal advice. The above is DCC’s structural analysis of a new sector rule. Article numbers refer to the Measures as issued under 交科技规〔2026〕3号.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →