China–EU regulatory bridge
Which Chinese instrument answers which EU instrument for vehicles and for personal data, where the two only partly meet, and where no counterpart exists.
Compliance5 Sept 202613 min read
On this page
How to read this
Three bridges cross this page. The first is vehicle cybersecurity, where UN Regulation No. 155 faces GB 44495-2024 and GB 44496-2024. The second is personal data, where the General Data Protection Regulation faces the Personal Information Protection Law of the People's Republic of China, 中华人民共和国个人信息保护法, PIPL below. The third is the classified-protection scheme, which this page pairs with no EU instrument.
A row means the two instruments address the same objective. It never means that satisfying one satisfies the other. Dates and scope appear only where a text or catalogue entry supports them. Where a Chinese standard's own text was not read, the column says so and no clause is described. PIPL is cited by article in Chinese, then paraphrased.
Bridge 1 — vehicle cybersecurity
| Topic | EU paragraph | Chinese instrument | Relationship | Note |
|---|---|---|---|---|
| Scope | Para. 1.1: vehicles of Categories L, M, N and O fitted with at least one electronic control unit 1 | GB 44495-2024, 汽车整车信息安全技术要求 / Technical requirements for vehicle cybersecurity, issued 2024-08-23, in force 2026-01-01 2 | not comparable | Text not consulted |
| Conformity device | Paras. 5.1, 6.1 and 6.7: type approval only for conforming vehicle types, behind a CSMS certificate valid at most three years 3 | Both GB standards are listed as 强标, mandatory national standards, under ICS class 43 4 | not comparable | A mandatory standard and a type approval differ in kind |
| Management system | Paras. 7.2.1, 7.2.2.1 and 7.2.2.2: a system covering development, production and post-production, showing the processes listed at (a) to (h) 5 | GB 44495-2024, title only | not comparable | Text not consulted |
| Suppliers and monitoring | Para. 7.2.2.5 covers dependencies with suppliers, service providers and sub-organisations; para. 7.2.2.4 makes monitoring continual after first registration 6 | GB 44495-2024, title only | not comparable | Text not consulted |
| Per-type risk work | Paras. 7.3.3, 7.3.4 and 7.3.6: exhaustive risk assessment, mitigations drawn from Annex 5, testing before approval 7 | GB 44495-2024, title only | not comparable | Text not consulted |
| Software update | Annex 5, Part B, Table B2 pairs update-procedure threats with mitigation M16, secure software update procedures 8 | GB 44496-2024, 汽车软件升级通用技术要求 / General technical requirements for software update of vehicles, issued 2024-08-23, in force 2026-01-01 2 | not comparable | Text not consulted; the EU update regulation was not read here |
| Product-law boundary | Cyber Resilience Act Art. 2(2)(c): it does not apply to products to which Regulation (EU) 2019/2144 applies 9 | Not applicable; both GB standards sit in the vehicle route | not comparable | EU product duties for a vehicle run through the vehicle acts |
Each catalogue entry carries an Amendment No. 1, 第1号修改单, in its remarks field 10. Any clause-level mapping built before that amendment is read is provisional, which is why the Chinese column stays at title and date.
Bridge 2 — personal data
PIPL was adopted on 20 August 2021 and, by 第七十四条, is in force from 1 November 2021 11. The EU counterpart is Regulation (EU) 2016/679 of 27 April 2016 12.
| Topic | GDPR article | PIPL article | Relationship | Gap |
|---|---|---|---|---|
| Territorial scope | Art. 3(1) and 3(2): an establishment in the Union, and offering goods or services to, or monitoring the behaviour of, data subjects in the Union 13 | 第三条: processing inside the territory, and offshore processing aimed at supplying products or services to people inside it, or analysing their conduct 14 | partial | 第三条 adds an open third limb, other circumstances set by laws and administrative regulations |
| Principles | Art. 5(1)(a) to (f): lawfulness, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality 15 | 第五条 to 第九条: lawful, proper, necessary and good-faith processing; a clear purpose and minimum scope; openness; data quality; responsibility with security measures 16 | partial | No storage-limitation principle in that block; retention surfaces in 第十七条 as a notice item and in 第四十七条 as a deletion trigger 17 |
| Lawful bases | Art. 6(1)(a) to (f): consent, contract, legal obligation, vital interests, public task, legitimate interests 18 | 第十三条 lists seven circumstances, among them consent, contract and statutory personnel management, statutory duties, emergencies, public-interest news reporting, lawfully published information 19 | partial | No legitimate-interests basis; 第十四条 requires consent to be voluntary and explicit, on a fully informed basis 20 |
| Sensitive data | Art. 9(1) prohibits a closed list of special categories unless a condition in Art. 9(2) applies 21 | 第二十八条 defines sensitive personal information by the harm a leak would cause, with an open list; 第二十九条 requires separate consent 22 | partial | The PIPL list is harm-based and open, and 第二十八条 treats all personal information of minors under fourteen as sensitive |
| Individual rights | Arts. 15 to 22: access, rectification, erasure, restriction, portability, objection, and a rule on solely automated decisions 23 | 第四十四条 to 第五十条: to know and decide, restrict or refuse; access and copy; transfer; correction; deletion; explanation; a request-handling mechanism 24 | partial | Transfer under 第四十五条 applies only on conditions the national cyberspace authority sets, and 第四十九条 gives close relatives rights over a deceased person's information |
| Controller and processor duties | Art. 24 accountability, Art. 25 data protection by design and by default, Art. 28 processor terms and sub-processor authorisation 25 | 第二十一条: the entrusting handler fixes purpose, period, method, categories and protection measures by agreement and supervises; 第五十九条 binds the entrusted party 26 | partial | No article among those read matches Art. 25; under 第二十一条 sub-entrusting needs the handler's consent |
| Security measures | Art. 32(1)(a) to (d): risk-appropriate measures, pseudonymisation and encryption, resilience, restoration, regular testing 27 | 第五十一条 lists six measures: internal rules, classified management, encryption and de-identification, permissions and training, an incident plan, and others set in law 28 | partial | Art. 32 is outcome-worded and risk-calibrated; 第五十一条 names a fixed list, and 第五十四条 adds a periodic compliance audit |
| Breach notification | Art. 33(1): notify the supervisory authority without undue delay and, where feasible, within 72 hours; Art. 34(1): tell individuals where the risk is high 29 | 第五十七条: on leakage, tampering or loss, or its possibility, take remedial measures immediately and notify the competent department and the individuals 30 | partial | No hour clock in 第五十七条; individual notice is the default and may be dropped only where measures effectively avoid harm |
| Impact assessment | Art. 35(1): an assessment before processing likely to result in a high risk 31 | 第五十五条 requires a prior assessment in five listed cases; 第五十六条 fixes its content and keeps the report and records at least three years 32 | partial | GDPR triggers on risk, PIPL on enumerated activities including every cross-border provision; Art. 35 sets no retention period |
| Officer and representative | Art. 37(1) sets three cases for a data protection officer, Art. 37(7) requires publication and notice; Art. 27(1) requires a Union representative 33 | 第五十二条: handlers above the volume the authority sets appoint a protection officer and file the details; 第五十三条: an offshore handler names an establishment or representative 34 | partial | The PIPL trigger is a regulator-set volume threshold rather than an activity test, and the appointment is filed with the department |
| Cross-border transfer | Art. 44 general principle, Art. 45 adequacy, Art. 46 safeguards including standard clauses, Art. 47 binding corporate rules, Art. 49 derogations 35 | 第三十八条 gives four routes: a state security assessment, certification by a specialised body, the regulator's standard contract, or conditions set elsewhere in law 36 | partial | No adequacy route; 第三十九条 adds separate consent with a recipient-specific notice, and 第四十条 adds localisation 37 |
| Penalties | Art. 83(4): up to EUR 10 000 000 or two per cent of worldwide annual turnover; Art. 83(5): up to EUR 20 000 000 or four per cent, whichever is higher 38 | 第六十六条: correction orders, warnings, confiscation, and up to CNY 1 000 000 where correction is refused. Serious cases reach CNY 50 000 000, or five per cent of the previous year's turnover 39 | partial | 第六十六条 also fines responsible individuals and can bar them from named posts; its turnover base is the previous year's, not worldwide |
Bridge 3 — the classified-protection scheme
The national standards catalogue lists GB/T 22239-2019, 信息安全技术 网络安全等级保护基本要求, as a recommended national standard with status 现行, issued on 10 May 2019 and effective from 1 December 2019 40. Its predecessor, GB/T 22239-2008 信息安全技术 信息系统安全等级保护基本要求, is listed as 废止, withdrawn 40. The title names 网络安全等级保护, classified protection of cybersecurity; MLPS and 等保 2.0 are conventions, not designations.
Nothing further is claimed. The text is not on disk, so no protection level, control count or grading method appears here. The statutory basis is left open too, because the Cybersecurity Law text was not read. No EU counterpart is named: none of the texts read here grades systems into levels, and the Cyber Resilience Act attaches to products made available on the market 41.
Where the bridge breaks down
- There is no adequacy route. GDPR Art. 45 lets a transfer proceed on a Commission decision that a third country protects data adequately 42. PIPL 第三十八条 offers a state security assessment, certification, a standard contract, or conditions set elsewhere in law. Consequence: an adequacy argument travels in neither direction; each transfer needs its own route.
- Separate consent sits on top of the route. PIPL 第三十九条 requires a notice naming the offshore recipient, its contact details, purpose, method and data categories, plus separate consent 43. Consequence: a signed standard contract is necessary but not sufficient, and consent design carries the recipient list.
- The security-assessment route comes with localisation. PIPL 第四十条 requires operators of critical information infrastructure, and handlers above the regulator's volume threshold, to store domestically what they collect inside the territory. Transfer abroad then runs through the state security assessment 44. Consequence: architecture, not paperwork, decides whether the route is open.
- Foreign judicial requests are blocked from both sides. PIPL 第四十一条 forbids providing personal information stored inside the territory to a foreign judicial or law-enforcement body without approval of the competent authority 45. GDPR Art. 48 recognises a third-country judgment only on the basis of an international agreement in force 46. Consequence: a group under discovery pressure meets two blocking rules.
- Consent is the default in a way it is not in the Union. GDPR Art. 6(1)(f) allows processing necessary for legitimate interests, subject to a balancing test. Nothing in the seven circumstances of PIPL 第十三条 answers it. Consequence: processing justified on legitimate interests needs another basis, usually consent, for the Chinese leg.
- The vehicle instruments are different legal devices. UN Regulation No. 155 works through a type approval and a certificate for the management system. GB 44495-2024 and GB 44496-2024 are mandatory national standards in force since 1 January 2026 4. Consequence: existing R155 evidence is input to the Chinese route; how that route consumes it is not described here.
One expected term is absent. The phrase 重要数据, important data, does not occur anywhere in the PIPL text read here, so no claim about it is made.
Glossary
| Term | Definition | Source |
|---|---|---|
| 个人信息 (personal information) | Information recorded electronically or otherwise, relating to identified or identifiable natural persons, excluding information after anonymisation | PIPL 第四条 47 |
| Personal data | Any information relating to an identified or identifiable natural person | Regulation (EU) 2016/679 Art. 4(1) 48 |
| 个人信息处理者 (personal information handler) | An organisation or individual that independently decides the purpose and the method of processing | PIPL 第七十三条 49 |
| Controller | The body that, alone or jointly with others, determines the purposes and means of processing | Regulation (EU) 2016/679 Art. 4(7) 50 |
| 受托人 (entrusted party) | The party a handler entrusts with processing, bound by the agreed purpose, period, method and categories | PIPL 第二十一条 51 |
| Processor | A body that processes personal data on behalf of the controller | Regulation (EU) 2016/679 Art. 4(8) 52 |
| 敏感个人信息 (sensitive personal information) | Information whose leakage or unlawful use easily harms personal dignity, or the safety of a person or their property | PIPL 第二十八条 53 |
| Special categories of personal data | The closed list named in Art. 9(1), prohibited unless a condition in Art. 9(2) applies | Regulation (EU) 2016/679 Art. 9 21 |
| 匿名化 (anonymisation) | Processing after which a specific natural person cannot be identified and the information cannot be restored | PIPL 第七十三条 49 |
| Cyber Security Management System | A risk-based approach that fixes the organisational processes, responsibilities and governance used against cyber risk to vehicles | UN Regulation No. 155 [2025/5] para. 2.3 54 |
Change log
| Date | Change |
|---|---|
| 2026-09-05 | First publication. GDPR, PIPL, UN Regulation No. 155 and the Cyber Resilience Act read as published texts; the GB standards from the catalogue only. |
References
<!-- Sources block generated from the markers above. EU acts read through the Publications Office CELEX resolver; canonical citation addresses printed here. -->- European Parliament and Council. Regulation (EU) 2016/679 (General Data Protection Regulation). OJ L 119, 4.5.2016, p. 1. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng 12
- 全国人民代表大会常务委员会. 中华人民共和国个人信息保护法. 中国人大网. http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html 11
- UNECE, in the Official Journal. UN Regulation No. 155 [2025/5]. OJ L, 2025/5, 10.1.2025. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:42025X0005 1
- European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng 9
- SAMR and SAC. GB 44495-2024 汽车整车信息安全技术要求. https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=2DB552CAA58F589705C3DC7AD47AC2AB 2
- SAMR and SAC. GB 44496-2024 汽车软件升级通用技术要求. https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=8BC0D8B44DD4E71F9557BADE5175565A 2
- 全国标准信息公共服务平台. Catalogue listing for GB 44495: 强标, 现行. https://openstd.samr.gov.cn/bzgk/gb/std_list?p.p2=44495 4
- 全国标准信息公共服务平台. Catalogue listing for GB 44496: 强标, 现行. https://openstd.samr.gov.cn/bzgk/gb/std_list?p.p2=44496
- 全国标准信息公共服务平台. Catalogue listing for GB/T 22239: 2019 现行, 2008 废止. https://openstd.samr.gov.cn/bzgk/gb/std_list?p.p2=22239 40
- GRCIDE radar. GB 44495-2024 and GB 44496-2024 took effect in China on 1 January 2026. /radar#gb-44495-44496-in-force 2
Sources
- 1EU Publications Office CELEX 42025X0005 para. 1.1 · verified 2026-09-05
- 2openstd.samr.gov.cn, GB catalogue entries · verified 2026-09-03
- 3EU Publications Office CELEX 42025X0005 paras. 5.1, 6.1 and 6.7 · verified 2026-09-05
- 4openstd.samr.gov.cn, GB 44495 and GB 44496 catalogue listing · verified 2026-09-05
- 5EU Publications Office CELEX 42025X0005 paras. 7.2.1 to 7.2.2.2 · verified 2026-09-05
- 6EU Publications Office CELEX 42025X0005 paras. 7.2.2.4 and 7.2.2.5 · verified 2026-09-05
- 7EU Publications Office CELEX 42025X0005 paras. 7.3.3, 7.3.4 and 7.3.6 · verified 2026-09-05
- 8EU Publications Office CELEX 42025X0005 Annex 5 Table B2 · verified 2026-09-05
- 9EU Publications Office CELEX 32024R2847 Art. 2(2) · verified 2026-09-05
- 10openstd.samr.gov.cn, catalogue remarks field · verified 2026-09-03
- 11PIPL, header and Art. 74 (第七十四条), npc.gov.cn · verified 2026-09-05
- 12EU Publications Office CELEX 32016R0679 title · verified 2026-09-05
- 13EU Publications Office CELEX 32016R0679 Art. 3 · verified 2026-09-05
- 14PIPL Art. 3 (第三条), npc.gov.cn · verified 2026-09-05
- 15EU Publications Office CELEX 32016R0679 Art. 5(1) · verified 2026-09-05
- 16PIPL Arts. 5 to 9 (第五条至第九条), npc.gov.cn · verified 2026-09-05
- 17PIPL Arts. 17 and 47 (第十七条、第四十七条), npc.gov.cn · verified 2026-09-05
- 18EU Publications Office CELEX 32016R0679 Art. 6(1) · verified 2026-09-05
- 19PIPL Art. 13 (第十三条), npc.gov.cn · verified 2026-09-05
- 20PIPL Art. 14 (第十四条), npc.gov.cn · verified 2026-09-05
- 21EU Publications Office CELEX 32016R0679 Art. 9 · verified 2026-09-05
- 22PIPL Arts. 28 and 29 (第二十八条、第二十九条), npc.gov.cn · verified 2026-09-05
- 23EU Publications Office CELEX 32016R0679 Arts. 15 to 22 · verified 2026-09-05
- 24PIPL Arts. 44 to 50 (第四十四条至第五十条), npc.gov.cn · verified 2026-09-05
- 25EU Publications Office CELEX 32016R0679 Arts. 24, 25 and 28 · verified 2026-09-05
- 26PIPL Arts. 21 and 59 (第二十一条、第五十九条), npc.gov.cn · verified 2026-09-05
- 27EU Publications Office CELEX 32016R0679 Art. 32(1) · verified 2026-09-05
- 28PIPL Arts. 51 and 54 (第五十一条、第五十四条), npc.gov.cn · verified 2026-09-05
- 29EU Publications Office CELEX 32016R0679 Arts. 33(1) and 34(1) · verified 2026-09-05
- 30PIPL Art. 57 (第五十七条), npc.gov.cn · verified 2026-09-05
- 31EU Publications Office CELEX 32016R0679 Art. 35(1) · verified 2026-09-05
- 32PIPL Arts. 55 and 56 (第五十五条、第五十六条), npc.gov.cn · verified 2026-09-05
- 33EU Publications Office CELEX 32016R0679 Arts. 27(1) and 37 · verified 2026-09-05
- 34PIPL Arts. 52 and 53 (第五十二条、第五十三条), npc.gov.cn · verified 2026-09-05
- 35EU Publications Office CELEX 32016R0679 Arts. 44 to 49 · verified 2026-09-05
- 36PIPL Art. 38 (第三十八条), npc.gov.cn · verified 2026-09-05
- 37PIPL Arts. 39 and 40 (第三十九条、第四十条), npc.gov.cn · verified 2026-09-05
- 38EU Publications Office CELEX 32016R0679 Arts. 83(4) and 83(5) · verified 2026-09-05
- 39PIPL Art. 66 (第六十六条), npc.gov.cn · verified 2026-09-05
- 40openstd.samr.gov.cn, GB/T 22239 catalogue listing · verified 2026-09-05
- 41EU Publications Office CELEX 32024R2847 Art. 2(1) · verified 2026-09-05
- 42EU Publications Office CELEX 32016R0679 Art. 45(1) · verified 2026-09-05
- 43PIPL Art. 39 (第三十九条), npc.gov.cn · verified 2026-09-05
- 44PIPL Art. 40 (第四十条), npc.gov.cn · verified 2026-09-05
- 45PIPL Art. 41 (第四十一条), npc.gov.cn · verified 2026-09-05
- 46EU Publications Office CELEX 32016R0679 Art. 48 · verified 2026-09-05
- 47PIPL Art. 4 (第四条), npc.gov.cn · verified 2026-09-05
- 48EU Publications Office CELEX 32016R0679 Art. 4(1) · verified 2026-09-05
- 49PIPL Art. 73 (第七十三条), npc.gov.cn · verified 2026-09-05
- 50EU Publications Office CELEX 32016R0679 Art. 4(7) · verified 2026-09-05
- 51PIPL Art. 21 (第二十一条), npc.gov.cn · verified 2026-09-05
- 52EU Publications Office CELEX 32016R0679 Art. 4(8) · verified 2026-09-05
- 53PIPL Art. 28 (第二十八条), npc.gov.cn · verified 2026-09-05
- 54EU Publications Office CELEX 42025X0005 para. 2.3 · verified 2026-09-05