SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.

China's cockpit-data guide keeps cabin data in the vehicle

TC260 published a security practice guide for cockpit data processing that bars cabin data from leaving the vehicle outside narrow exceptions and makes the carmaker responsible for what every in-car application collects.

China’s National Cybersecurity Standardization Technical Committee published a security practice guide for cockpit data processing on September 15, issued under notice 网安秘字〔2026〕112号 and numbered TC260-PG-202615A.

The guide covers personal-information data collected inside the cabin by camera, infrared sensor, fingerprint reader or microphone, together with data derived from it, taking its definition from the national standard GB/T 41871—2022. It defines a cabin data processor to include carmakers, component and software suppliers, and providers of in-car application services.

Cabin data should not be transmitted out of the vehicle except under the exceptions that standard already allows, and separate consent is required before sensitive personal information is processed. Voice wake-word data should be held no longer than wake recognition requires, with voiceprints kept in a separate on-vehicle space and never stored alongside identity data. Dialogue records should be anonymized on the vehicle before leaving it, and users should be able to view and delete them.

For driver monitoring, the guide asks that camera positions be disclosed, that capture be limited to the area directly above the driver’s seat, and that face data be processed in the vehicle and stored in a separate on-vehicle space. Remote viewing requires identity verification, in-cabin notice and a means to terminate, and live-only implementations should not store cabin video in the cloud.

The document also asks carmakers to know what every in-cabin component and in-car application collects and transmits, to bind suppliers contractually, and to supervise compliance. Operation logs should be kept at least six months, or three years where sensitive personal information is involved.

A practice guide is guidance rather than a mandatory national standard. Drafting support named on the document includes CESI, Xiaomi Auto, Beijing Li Auto, CNCERT/CC, SMVIC, Yinwang Intelligent Technology and Beihang University.

Why it mattersIt writes cockpit-specific duties onto an existing data standard and places them on the carmaker rather than the supplier, which turns in-car application sourcing into a compliance decision.

Source: TC260 (National Cybersecurity Standardization Technical Committee)

The SDV Sector Brief

The month in vehicle software — top stories, what our readers read most, and an editor's take. First Tuesday of the month, 08:30 CET. Double opt-in, unsubscribe anytime.