---
title: "Five Grades of Data, One Reporting Spine: The Ministry of Transport's Data Security Measures"
author: "DCC Editorial"
published: 2026-07-17T04:00:00.000Z
url: https://datacompliancechina.com/posts/transport-data-security-measures-five-grade-ladder/
description: "On June 18, 2026 the Ministry of Transport issued the Measures for Data Security Management in Transport (交科技规〔2026〕3号), effective July 1, 2026 — 41 articles that complete the sector build-out of the Data Security Law for highways, waterways and comprehensive transport. The full text reached the public record in July through an academic-society WeChat repost rather than the ministry's own site. DCC reads the Measures around four load-bearing features: a five-grade classification ladder that splits general data into Grades 3/2/1 and pulls Grade-3 general data into the hard transmission-protection net alongside important and core data; an annual risk-assessment duty that extends beyond important-data handlers to any processor holding personal information on 10 million or more people, dated the same day as the national Network Data Security Risk Assessment Measures but effective 50 days earlier; an AI clause requiring pre-deployment evaluation of corpora, training data and algorithm explainability, plus a default ban on training on entrusted data; and a single reporting spine that routes filings through provincial transport authorities to MOT, with a direct line for central transport SOEs. Storage follows the sector pattern: localization for transport-authority personal information and CIIO-collected data, MLPS Level 3 for important-data systems, Level 4 or CII protection for core data, and security-assessed cloud services only."
tags: ["transport", "mot", "important-data", "data-classification", "risk-assessment", "localization", "ai-training-data", "sector-measures", "dsl"]
laws_cited: ["transport-data-security-measures", "dsl", "network-data-security-regulations", "network-data-security-risk-assessment-measures", "miit-industrial-data-security-measures", "energy-industry-data-security-measures"]
domains: ["data-security", "energy-resources"]
account: "wangluo-xinxifa-xuehui"
original_title: "交通运输部关于印发《交通运输数据安全管理办法》的通知（交科技规〔2026〕3号）"
original_author: "交通运输部 (Ministry of Transport)"
original_publication: "网络与信息法学会 WeChat Official Account"
original_url: "https://mp.weixin.qq.com/s/Le_LbpbuNEG3_yl8shB7EQ"
source_language: "zh"
---

> **Source: Data Compliance China** — https://datacompliancechina.com/posts/transport-data-security-measures-five-grade-ladder/ · China data law, translated and annotated for overseas counsel. Cite as: Data Compliance China, "Five Grades of Data, One Reporting Spine: The Ministry of Transport's Data Security Measures", https://datacompliancechina.com/posts/transport-data-security-measures-five-grade-ladder/
> *Editor's Note — DCC.*
>
> This brief covers a single new sector instrument: the **Measures for Data
> Security Management in Transport** (《交通运输数据安全管理办法》), issued by
> the **Ministry of Transport (MOT)** as **交科技规〔2026〕3号** on **June 18,
> 2026**, effective **July 1, 2026**. A provenance note: the Measures took
> effect with the full text not yet posted on the ministry's own website —
> the 41-article text entered the public record through a full repost by the
> Cyber and Information Law Society's WeChat channel, sourced to MOT and
> marked for public release. The full text is in DCC's
> [law-catalogue entry](/laws/transport-data-security-measures/); this brief
> is the structural read, and the framing — the five-grade ladder, the
> "50 days early" comparison with the national risk-assessment rule, and the
> reporting-spine model — is DCC's.

## The one-line thesis

Transport was one of the last major infrastructure sectors still running on
a consultation draft. These Measures close that gap: highways, waterways and
comprehensive transport now have the same kind of sector rulebook that
industry got from [MIIT in 2023](/laws/miit-industrial-data-security-measures/)
and energy got from the [National Energy Administration's trial measures](/laws/energy-industry-data-security-measures/)
— classification keyed to a sector catalogue, localization plus MLPS floors,
annual risk assessment, and an incident regime. What makes the transport
version worth reading closely is where it deviates from the family pattern:
a **five-grade ladder** instead of three, a **10-million-person threshold**
that arrives ahead of the national schedule, and an **AI clause** that
reaches further than any of its sector siblings.

## Who regulates, who is regulated

The Measures run on the now-standard principle — "whoever manages the
business manages the business data and manages its data security" — plus
territorial administration (Article 2). MOT covers comprehensive transport
and the highway and waterway fields; rail, civil aviation and postal data
stay with the State Railway Administration, the CAAC and the State Post
Bureau respectively (Article 3). Provincial transport authorities supervise
their regions and feed identification results upward.

The addressee list is its own compliance map: besides the transport
bureaucracy it names the three central transport SOEs — COSCO Shipping,
China Merchants Group, CCCC — and, generically, **highway and waterway
critical information infrastructure operators and important-data
processors**. If a group sits anywhere in that list, the Measures are not
abstract.

## The five-grade ladder

The family pattern since the MIIT measures has been three tiers: general,
important, core. Article 7 keeps the three levels but then splits general
data into **Grade 3, Grade 2 and Grade 1** (descending). That would be a
cosmetic refinement except that obligations attach to the top grade:
Article 14 requires verification technology, cryptographic technology,
secure channels or secure transmission protocols for transmitting **Grade 3
general data** — the same protections it requires for important and core
data.

The practical effect is a middle band of data that is *not important data*
— so it does not trigger cataloguing, annual assessment or the
important-data export security-assessment gate — but is also *not free*:
its transmission is regulated. Transport
operators will need their classification regimes to produce a defensible
Grade 3/2/1 split of general data, a step the three-tier sectors never had
to take.

Classification itself follows the catalogue model (Article 6): MOT
determines the **sector catalogue of important data** and manages it
dynamically; processors classify, keep their own catalogues current, and
**identify and declare important data**; transport authorities **notify or
publish** confirmations. Where the grade of important or core data changes,
classification and grading must be redone; where their registered
information changes, a report is due **within 30 days** (Article 8).

## Storage: the localization-plus-MLPS pattern

Article 12 is the sector's localization clause, and it is broader than the
CII baseline. Three categories must be stored within China: personal
information processed by **transport authorities** themselves; personal
information and important data collected and generated by **CII operators**
in domestic operations; and personal information and important data that
other laws and regulations expressly require to be stored domestically. System floors follow the family pattern — **MLPS Level 3** or above
for systems storing important data, **Level 4 or CII protection** for core
data — and important data may only sit on **cloud services that have passed
security assessment**. Important and core data also require disaster-recovery
backup with periodic restoration tests.

## The risk-assessment mirror — 50 days early

Articles 23–28 build a compact copy of the machinery the national
[Network Data Security Risk Assessment Measures](/laws/network-data-security-risk-assessment-measures/)
(Order No. 24) established: an annual assessment with report submission,
event-triggered reassessment (major incidents or notified major risks,
providing, entrusting or jointly processing important data, M&A-scale
changes, cross-border transfers), third-party assessors drawn from
recognized institutions, **three-year
report retention**, rectification duties, and personal information
protection compliance audits.

Two details matter. First, the trigger population is wider than the
national rule's: the annual duty binds important-data and core-data
processors **and any processor of personal information on 10 million or
more people** (Article 23) — a pure-volume PI threshold living inside a
data-security instrument. Second, the timing: the MOT notice is dated
**June 18, 2026 — the same day** the CAC, MIIT and MPS published Order
No. 24 — but the transport rule took effect **July 1**, fifty days before
the national rule's August 20 date. Under Order No. 24's own
sector-priority clause, where a sector authority has provisions, those
prevail — so for transport operators, this is the risk-assessment regime
that counts, and it started first. DCC's structural read of the national
rule is in [the Order No. 24 brief](/posts/network-data-risk-assessment-measures-operationalizing-the-dsl/).

## The AI clause

Article 21 is the furthest-reaching AI provision yet seen in a sector
data-security rule. Before putting a model or algorithm into use, data
processors must evaluate the **rationality, legitimacy and explainability**
of the corpus, the training data and the algorithm, together with the
impact of the data use on affected parties' rights, ethics risks, and the
effectiveness of controls. AI-**generated** data must be classified and
graded like any other data, with the corresponding duties attached. And
generative-AI service providers must manage training data security and run
**labeling quality assessment**.

Article 19 adds the quiet companion rule: absent the entrusting party's
consent, a data recipient in an entrusted- or joint-processing arrangement
**may not process, train on, or divert the data, and may not run data
correlation analysis**. A no-training-by-default term is now written into
transport-sector contracts by operation of law — worth checking against
every model-development and analytics vendor arrangement touching sector
data.

## The operational details that will bite

| Duty | Rule | Article |
|---|---|---|
| Log retention ladder | 6 months (network logs generally) → 1 year (government-application access, database operations, important-data incidents) → 3 years (core-data incidents; records of providing, entrusting or jointly processing PI and important data) | 22 |
| M&A / restructuring transfers | Transfer plan and recipient details reported **in advance** where important data, core data, or PI of 10M+ people is involved | 18 |
| Deletion | Deletion must be irrecoverable and logged; important/core data deletion needs a pre-operation plan, risk evaluation and advance report | 17 |
| Cross-border | National regime applies; **data splitting to evade obligations is expressly prohibited**; PI transfers need notice, separate consent and impact assessment per the national rules | 20 |
| Mutual recognition | Overlapping results of risk assessment, MLPS testing, CII inspection and commercial-cryptography assessment are mutually recognized | 36 |
| Personnel | **Important-data processors** must designate a person responsible for data security — a management member entitled to report directly to transport authorities — plus a data-security management body; core-data processors run security background reviews on that person, key personnel, and core-data system construction and O&M contractors | 10 |
| Crypto | Important- and core-data processors must use **commercial cryptography** across the full data lifecycle | 9 |

The reporting spine ties it together (Article 38): the reports and filings
scattered through the Measures — change-of-information reports (Article 8),
deletion plans (Article 17), transfer plans (Article 18), annual assessment
reports (Article 23), and reports of major risks or incidents surfaced by
assessments (Article 27) — route through **provincial transport authorities
for review, then to MOT**; MOT-affiliated units and **central transport
enterprises may report directly**. For a central SOE group, that direct
line concentrates the compliance interface; for everyone else, the
provincial authority is the working counterparty.

## What changes for compliance programs

For operators — port and shipping groups, highway and logistics platforms,
ride-hailing and freight-matching businesses with transport-sector
touchpoints — the sequence the Measures impose is concrete:

- **Classification first.** Every hard duty keys off the grade. The
  five-grade ladder means even the "general" bucket needs internal
  sub-grading with documentation that survives inspection.
- **Count your personal-information base.** The 10M threshold converts
  scale alone into an annual assessment duty, independent of whether
  anything is important data.
- **Re-paper vendor arrangements.** The Article 19 no-training default and
  its capability-and-qualification vetting belong in entrustment contracts
  now, not at renewal; sharing and authorized-operation contracts need the
  separate Article 15 recipient-capability verification.
- **Map the overlap.** The national Order No. 24 regime, this sector rule,
  and MLPS/CII obligations interlock; Article 36's mutual-recognition
  clause is the cost-control lever — one assessment file, reused across
  four supervisory tracks.

One drafting note: the January consultation draft ran 45 articles; the
final text runs 41. The tightening is real but the architecture survived
consultation intact.

The Measures do not invent a new theory of data security. They finish a
job: after industry, automotive, natural resources, finance and energy,
the transport sector now has its own operating rulebook under the
[Data Security Law](/laws/dsl/) — and in two places, the five-grade ladder
and the 10-million-person trigger, it quietly sets the pace for the family.

---

— *交通运输部, 交通运输数据安全管理办法 (Measures for Data Security Management
in Transport), 交科技规〔2026〕3号, issued June 18, 2026, effective July 1,
2026; full text published via the 网络与信息法学会 WeChat Official Account.
[Original text (Chinese).](https://mp.weixin.qq.com/s/Le_LbpbuNEG3_yl8shB7EQ)
Full English translation in DCC's [law-catalogue entry](/laws/transport-data-security-measures/).*

*Not legal advice. The above is DCC's structural analysis of a new sector
rule. Article numbers refer to the Measures as issued under
交科技规〔2026〕3号.*
