Back to insights
    Reference

    China–EU regulatory bridge

    Which Chinese instrument answers which EU instrument for vehicles and for personal data, where the two only partly meet, and where no counterpart exists.

    Compliance5 Sept 202613 min read

    GB 44495-2024GB 44496-2024Regulation (EU) 2016/679UN Regulation No. 155 [2025/5]
    On this page
    <!-- Living page: reviewed quarterly. Re-verify every row on refresh. -->

    How to read this

    Three bridges cross this page. The first is vehicle cybersecurity, where UN Regulation No. 155 faces GB 44495-2024 and GB 44496-2024. The second is personal data, where the General Data Protection Regulation faces the Personal Information Protection Law of the People's Republic of China, 中华人民共和国个人信息保护法, PIPL below. The third is the classified-protection scheme, which this page pairs with no EU instrument.

    A row means the two instruments address the same objective. It never means that satisfying one satisfies the other. Dates and scope appear only where a text or catalogue entry supports them. Where a Chinese standard's own text was not read, the column says so and no clause is described. PIPL is cited by article in Chinese, then paraphrased.

    Bridge 1 — vehicle cybersecurity

    TopicEU paragraphChinese instrumentRelationshipNote
    ScopePara. 1.1: vehicles of Categories L, M, N and O fitted with at least one electronic control unit 1GB 44495-2024, 汽车整车信息安全技术要求 / Technical requirements for vehicle cybersecurity, issued 2024-08-23, in force 2026-01-01 2not comparableText not consulted
    Conformity deviceParas. 5.1, 6.1 and 6.7: type approval only for conforming vehicle types, behind a CSMS certificate valid at most three years 3Both GB standards are listed as 强标, mandatory national standards, under ICS class 43 4not comparableA mandatory standard and a type approval differ in kind
    Management systemParas. 7.2.1, 7.2.2.1 and 7.2.2.2: a system covering development, production and post-production, showing the processes listed at (a) to (h) 5GB 44495-2024, title onlynot comparableText not consulted
    Suppliers and monitoringPara. 7.2.2.5 covers dependencies with suppliers, service providers and sub-organisations; para. 7.2.2.4 makes monitoring continual after first registration 6GB 44495-2024, title onlynot comparableText not consulted
    Per-type risk workParas. 7.3.3, 7.3.4 and 7.3.6: exhaustive risk assessment, mitigations drawn from Annex 5, testing before approval 7GB 44495-2024, title onlynot comparableText not consulted
    Software updateAnnex 5, Part B, Table B2 pairs update-procedure threats with mitigation M16, secure software update procedures 8GB 44496-2024, 汽车软件升级通用技术要求 / General technical requirements for software update of vehicles, issued 2024-08-23, in force 2026-01-01 2not comparableText not consulted; the EU update regulation was not read here
    Product-law boundaryCyber Resilience Act Art. 2(2)(c): it does not apply to products to which Regulation (EU) 2019/2144 applies 9Not applicable; both GB standards sit in the vehicle routenot comparableEU product duties for a vehicle run through the vehicle acts
    The EU column cites the consolidated Official Journal text of UN Regulation No. 155. The Chinese column carries titles, categories and dates from the catalogue; neither GB standard's own text was consulted. "Not comparable" here means not comparable on the evidence available.

    Each catalogue entry carries an Amendment No. 1, 第1号修改单, in its remarks field 10. Any clause-level mapping built before that amendment is read is provisional, which is why the Chinese column stays at title and date.

    Bridge 2 — personal data

    PIPL was adopted on 20 August 2021 and, by 第七十四条, is in force from 1 November 2021 11. The EU counterpart is Regulation (EU) 2016/679 of 27 April 2016 12.

    TopicGDPR articlePIPL articleRelationshipGap
    Territorial scopeArt. 3(1) and 3(2): an establishment in the Union, and offering goods or services to, or monitoring the behaviour of, data subjects in the Union 13第三条: processing inside the territory, and offshore processing aimed at supplying products or services to people inside it, or analysing their conduct 14partial第三条 adds an open third limb, other circumstances set by laws and administrative regulations
    PrinciplesArt. 5(1)(a) to (f): lawfulness, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality 15第五条 to 第九条: lawful, proper, necessary and good-faith processing; a clear purpose and minimum scope; openness; data quality; responsibility with security measures 16partialNo storage-limitation principle in that block; retention surfaces in 第十七条 as a notice item and in 第四十七条 as a deletion trigger 17
    Lawful basesArt. 6(1)(a) to (f): consent, contract, legal obligation, vital interests, public task, legitimate interests 18第十三条 lists seven circumstances, among them consent, contract and statutory personnel management, statutory duties, emergencies, public-interest news reporting, lawfully published information 19partialNo legitimate-interests basis; 第十四条 requires consent to be voluntary and explicit, on a fully informed basis 20
    Sensitive dataArt. 9(1) prohibits a closed list of special categories unless a condition in Art. 9(2) applies 21第二十八条 defines sensitive personal information by the harm a leak would cause, with an open list; 第二十九条 requires separate consent 22partialThe PIPL list is harm-based and open, and 第二十八条 treats all personal information of minors under fourteen as sensitive
    Individual rightsArts. 15 to 22: access, rectification, erasure, restriction, portability, objection, and a rule on solely automated decisions 23第四十四条 to 第五十条: to know and decide, restrict or refuse; access and copy; transfer; correction; deletion; explanation; a request-handling mechanism 24partialTransfer under 第四十五条 applies only on conditions the national cyberspace authority sets, and 第四十九条 gives close relatives rights over a deceased person's information
    Controller and processor dutiesArt. 24 accountability, Art. 25 data protection by design and by default, Art. 28 processor terms and sub-processor authorisation 25第二十一条: the entrusting handler fixes purpose, period, method, categories and protection measures by agreement and supervises; 第五十九条 binds the entrusted party 26partialNo article among those read matches Art. 25; under 第二十一条 sub-entrusting needs the handler's consent
    Security measuresArt. 32(1)(a) to (d): risk-appropriate measures, pseudonymisation and encryption, resilience, restoration, regular testing 27第五十一条 lists six measures: internal rules, classified management, encryption and de-identification, permissions and training, an incident plan, and others set in law 28partialArt. 32 is outcome-worded and risk-calibrated; 第五十一条 names a fixed list, and 第五十四条 adds a periodic compliance audit
    Breach notificationArt. 33(1): notify the supervisory authority without undue delay and, where feasible, within 72 hours; Art. 34(1): tell individuals where the risk is high 29第五十七条: on leakage, tampering or loss, or its possibility, take remedial measures immediately and notify the competent department and the individuals 30partialNo hour clock in 第五十七条; individual notice is the default and may be dropped only where measures effectively avoid harm
    Impact assessmentArt. 35(1): an assessment before processing likely to result in a high risk 31第五十五条 requires a prior assessment in five listed cases; 第五十六条 fixes its content and keeps the report and records at least three years 32partialGDPR triggers on risk, PIPL on enumerated activities including every cross-border provision; Art. 35 sets no retention period
    Officer and representativeArt. 37(1) sets three cases for a data protection officer, Art. 37(7) requires publication and notice; Art. 27(1) requires a Union representative 33第五十二条: handlers above the volume the authority sets appoint a protection officer and file the details; 第五十三条: an offshore handler names an establishment or representative 34partialThe PIPL trigger is a regulator-set volume threshold rather than an activity test, and the appointment is filed with the department
    Cross-border transferArt. 44 general principle, Art. 45 adequacy, Art. 46 safeguards including standard clauses, Art. 47 binding corporate rules, Art. 49 derogations 35第三十八条 gives four routes: a state security assessment, certification by a specialised body, the regulator's standard contract, or conditions set elsewhere in law 36partialNo adequacy route; 第三十九条 adds separate consent with a recipient-specific notice, and 第四十条 adds localisation 37
    PenaltiesArt. 83(4): up to EUR 10 000 000 or two per cent of worldwide annual turnover; Art. 83(5): up to EUR 20 000 000 or four per cent, whichever is higher 38第六十六条: correction orders, warnings, confiscation, and up to CNY 1 000 000 where correction is refused. Serious cases reach CNY 50 000 000, or five per cent of the previous year's turnover 39partial第六十六条 also fines responsible individuals and can bar them from named posts; its turnover base is the previous year's, not worldwide
    The PIPL column gives the article in Chinese and a paraphrase. It is not a translation; no English rendering of the law is authoritative.

    Bridge 3 — the classified-protection scheme

    The national standards catalogue lists GB/T 22239-2019, 信息安全技术 网络安全等级保护基本要求, as a recommended national standard with status 现行, issued on 10 May 2019 and effective from 1 December 2019 40. Its predecessor, GB/T 22239-2008 信息安全技术 信息系统安全等级保护基本要求, is listed as 废止, withdrawn 40. The title names 网络安全等级保护, classified protection of cybersecurity; MLPS and 等保 2.0 are conventions, not designations.

    Nothing further is claimed. The text is not on disk, so no protection level, control count or grading method appears here. The statutory basis is left open too, because the Cybersecurity Law text was not read. No EU counterpart is named: none of the texts read here grades systems into levels, and the Cyber Resilience Act attaches to products made available on the market 41.

    Where the bridge breaks down

    • There is no adequacy route. GDPR Art. 45 lets a transfer proceed on a Commission decision that a third country protects data adequately 42. PIPL 第三十八条 offers a state security assessment, certification, a standard contract, or conditions set elsewhere in law. Consequence: an adequacy argument travels in neither direction; each transfer needs its own route.
    • Separate consent sits on top of the route. PIPL 第三十九条 requires a notice naming the offshore recipient, its contact details, purpose, method and data categories, plus separate consent 43. Consequence: a signed standard contract is necessary but not sufficient, and consent design carries the recipient list.
    • The security-assessment route comes with localisation. PIPL 第四十条 requires operators of critical information infrastructure, and handlers above the regulator's volume threshold, to store domestically what they collect inside the territory. Transfer abroad then runs through the state security assessment 44. Consequence: architecture, not paperwork, decides whether the route is open.
    • Foreign judicial requests are blocked from both sides. PIPL 第四十一条 forbids providing personal information stored inside the territory to a foreign judicial or law-enforcement body without approval of the competent authority 45. GDPR Art. 48 recognises a third-country judgment only on the basis of an international agreement in force 46. Consequence: a group under discovery pressure meets two blocking rules.
    • Consent is the default in a way it is not in the Union. GDPR Art. 6(1)(f) allows processing necessary for legitimate interests, subject to a balancing test. Nothing in the seven circumstances of PIPL 第十三条 answers it. Consequence: processing justified on legitimate interests needs another basis, usually consent, for the Chinese leg.
    • The vehicle instruments are different legal devices. UN Regulation No. 155 works through a type approval and a certificate for the management system. GB 44495-2024 and GB 44496-2024 are mandatory national standards in force since 1 January 2026 4. Consequence: existing R155 evidence is input to the Chinese route; how that route consumes it is not described here.

    One expected term is absent. The phrase 重要数据, important data, does not occur anywhere in the PIPL text read here, so no claim about it is made.

    Glossary

    TermDefinitionSource
    个人信息 (personal information)Information recorded electronically or otherwise, relating to identified or identifiable natural persons, excluding information after anonymisationPIPL 第四条 47
    Personal dataAny information relating to an identified or identifiable natural personRegulation (EU) 2016/679 Art. 4(1) 48
    个人信息处理者 (personal information handler)An organisation or individual that independently decides the purpose and the method of processingPIPL 第七十三条 49
    ControllerThe body that, alone or jointly with others, determines the purposes and means of processingRegulation (EU) 2016/679 Art. 4(7) 50
    受托人 (entrusted party)The party a handler entrusts with processing, bound by the agreed purpose, period, method and categoriesPIPL 第二十一条 51
    ProcessorA body that processes personal data on behalf of the controllerRegulation (EU) 2016/679 Art. 4(8) 52
    敏感个人信息 (sensitive personal information)Information whose leakage or unlawful use easily harms personal dignity, or the safety of a person or their propertyPIPL 第二十八条 53
    Special categories of personal dataThe closed list named in Art. 9(1), prohibited unless a condition in Art. 9(2) appliesRegulation (EU) 2016/679 Art. 9 21
    匿名化 (anonymisation)Processing after which a specific natural person cannot be identified and the information cannot be restoredPIPL 第七十三条 49
    Cyber Security Management SystemA risk-based approach that fixes the organisational processes, responsibilities and governance used against cyber risk to vehiclesUN Regulation No. 155 [2025/5] para. 2.3 54

    Change log

    DateChange
    2026-09-05First publication. GDPR, PIPL, UN Regulation No. 155 and the Cyber Resilience Act read as published texts; the GB standards from the catalogue only.

    References

    <!-- Sources block generated from the markers above. EU acts read through the Publications Office CELEX resolver; canonical citation addresses printed here. -->
    1. European Parliament and Council. Regulation (EU) 2016/679 (General Data Protection Regulation). OJ L 119, 4.5.2016, p. 1. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng 12
    2. 全国人民代表大会常务委员会. 中华人民共和国个人信息保护法. 中国人大网. http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html 11
    3. UNECE, in the Official Journal. UN Regulation No. 155 [2025/5]. OJ L, 2025/5, 10.1.2025. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:42025X0005 1
    4. European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng 9
    5. SAMR and SAC. GB 44495-2024 汽车整车信息安全技术要求. https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=2DB552CAA58F589705C3DC7AD47AC2AB 2
    6. SAMR and SAC. GB 44496-2024 汽车软件升级通用技术要求. https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=8BC0D8B44DD4E71F9557BADE5175565A 2
    7. 全国标准信息公共服务平台. Catalogue listing for GB 44495: 强标, 现行. https://openstd.samr.gov.cn/bzgk/gb/std_list?p.p2=44495 4
    8. 全国标准信息公共服务平台. Catalogue listing for GB 44496: 强标, 现行. https://openstd.samr.gov.cn/bzgk/gb/std_list?p.p2=44496
    9. 全国标准信息公共服务平台. Catalogue listing for GB/T 22239: 2019 现行, 2008 废止. https://openstd.samr.gov.cn/bzgk/gb/std_list?p.p2=22239 40
    10. GRCIDE radar. GB 44495-2024 and GB 44496-2024 took effect in China on 1 January 2026. /radar#gb-44495-44496-in-force 2

    Sources

    1. 1EU Publications Office CELEX 42025X0005 para. 1.1 · verified 2026-09-05
    2. 2openstd.samr.gov.cn, GB catalogue entries · verified 2026-09-03
    3. 3EU Publications Office CELEX 42025X0005 paras. 5.1, 6.1 and 6.7 · verified 2026-09-05
    4. 4openstd.samr.gov.cn, GB 44495 and GB 44496 catalogue listing · verified 2026-09-05
    5. 5EU Publications Office CELEX 42025X0005 paras. 7.2.1 to 7.2.2.2 · verified 2026-09-05
    6. 6EU Publications Office CELEX 42025X0005 paras. 7.2.2.4 and 7.2.2.5 · verified 2026-09-05
    7. 7EU Publications Office CELEX 42025X0005 paras. 7.3.3, 7.3.4 and 7.3.6 · verified 2026-09-05
    8. 8EU Publications Office CELEX 42025X0005 Annex 5 Table B2 · verified 2026-09-05
    9. 9EU Publications Office CELEX 32024R2847 Art. 2(2) · verified 2026-09-05
    10. 10openstd.samr.gov.cn, catalogue remarks field · verified 2026-09-03
    11. 11PIPL, header and Art. 74 (第七十四条), npc.gov.cn · verified 2026-09-05
    12. 12EU Publications Office CELEX 32016R0679 title · verified 2026-09-05
    13. 13EU Publications Office CELEX 32016R0679 Art. 3 · verified 2026-09-05
    14. 14PIPL Art. 3 (第三条), npc.gov.cn · verified 2026-09-05
    15. 15EU Publications Office CELEX 32016R0679 Art. 5(1) · verified 2026-09-05
    16. 16PIPL Arts. 5 to 9 (第五条至第九条), npc.gov.cn · verified 2026-09-05
    17. 17PIPL Arts. 17 and 47 (第十七条、第四十七条), npc.gov.cn · verified 2026-09-05
    18. 18EU Publications Office CELEX 32016R0679 Art. 6(1) · verified 2026-09-05
    19. 19PIPL Art. 13 (第十三条), npc.gov.cn · verified 2026-09-05
    20. 20PIPL Art. 14 (第十四条), npc.gov.cn · verified 2026-09-05
    21. 21EU Publications Office CELEX 32016R0679 Art. 9 · verified 2026-09-05
    22. 22PIPL Arts. 28 and 29 (第二十八条、第二十九条), npc.gov.cn · verified 2026-09-05
    23. 23EU Publications Office CELEX 32016R0679 Arts. 15 to 22 · verified 2026-09-05
    24. 24PIPL Arts. 44 to 50 (第四十四条至第五十条), npc.gov.cn · verified 2026-09-05
    25. 25EU Publications Office CELEX 32016R0679 Arts. 24, 25 and 28 · verified 2026-09-05
    26. 26PIPL Arts. 21 and 59 (第二十一条、第五十九条), npc.gov.cn · verified 2026-09-05
    27. 27EU Publications Office CELEX 32016R0679 Art. 32(1) · verified 2026-09-05
    28. 28PIPL Arts. 51 and 54 (第五十一条、第五十四条), npc.gov.cn · verified 2026-09-05
    29. 29EU Publications Office CELEX 32016R0679 Arts. 33(1) and 34(1) · verified 2026-09-05
    30. 30PIPL Art. 57 (第五十七条), npc.gov.cn · verified 2026-09-05
    31. 31EU Publications Office CELEX 32016R0679 Art. 35(1) · verified 2026-09-05
    32. 32PIPL Arts. 55 and 56 (第五十五条、第五十六条), npc.gov.cn · verified 2026-09-05
    33. 33EU Publications Office CELEX 32016R0679 Arts. 27(1) and 37 · verified 2026-09-05
    34. 34PIPL Arts. 52 and 53 (第五十二条、第五十三条), npc.gov.cn · verified 2026-09-05
    35. 35EU Publications Office CELEX 32016R0679 Arts. 44 to 49 · verified 2026-09-05
    36. 36PIPL Art. 38 (第三十八条), npc.gov.cn · verified 2026-09-05
    37. 37PIPL Arts. 39 and 40 (第三十九条、第四十条), npc.gov.cn · verified 2026-09-05
    38. 38EU Publications Office CELEX 32016R0679 Arts. 83(4) and 83(5) · verified 2026-09-05
    39. 39PIPL Art. 66 (第六十六条), npc.gov.cn · verified 2026-09-05
    40. 40openstd.samr.gov.cn, GB/T 22239 catalogue listing · verified 2026-09-05
    41. 41EU Publications Office CELEX 32024R2847 Art. 2(1) · verified 2026-09-05
    42. 42EU Publications Office CELEX 32016R0679 Art. 45(1) · verified 2026-09-05
    43. 43PIPL Art. 39 (第三十九条), npc.gov.cn · verified 2026-09-05
    44. 44PIPL Art. 40 (第四十条), npc.gov.cn · verified 2026-09-05
    45. 45PIPL Art. 41 (第四十一条), npc.gov.cn · verified 2026-09-05
    46. 46EU Publications Office CELEX 32016R0679 Art. 48 · verified 2026-09-05
    47. 47PIPL Art. 4 (第四条), npc.gov.cn · verified 2026-09-05
    48. 48EU Publications Office CELEX 32016R0679 Art. 4(1) · verified 2026-09-05
    49. 49PIPL Art. 73 (第七十三条), npc.gov.cn · verified 2026-09-05
    50. 50EU Publications Office CELEX 32016R0679 Art. 4(7) · verified 2026-09-05
    51. 51PIPL Art. 21 (第二十一条), npc.gov.cn · verified 2026-09-05
    52. 52EU Publications Office CELEX 32016R0679 Art. 4(8) · verified 2026-09-05
    53. 53PIPL Art. 28 (第二十八条), npc.gov.cn · verified 2026-09-05
    54. 54EU Publications Office CELEX 42025X0005 para. 2.3 · verified 2026-09-05