GB/T 44464-2024General Requirements of Vehicle Data (English PDF)
汽⻋数据通用要求
Open the GB/T 44464-2024 preview as PDF
This is a limited preview
Buy now to download the full PDF (31 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
August 23, 2024
Implementation date
August 23, 2024
Scope
GB/T 44464-2024 is the English-translated version of 汽⻋数据通用要求.
This standards specifies the general requirements, personal information protection requirements, important data protection requirements, audit and evaluation, and test requirements for data generated and collected during the R&D, design, production and manufacturing processes of automotive products, and describes the corresponding test methods. This document applies to automotive products and vehicle data processors.
Document preview — GB/T 44464-2024
National Standard of the People's Republic of China
- ICS
- 43.020
Issued by: State Administration for Market Regulation; Standardization Administration of the People’s Republic of China.
Contents
- Foreword
- 1 Scope3
- 2 Normative References3
- 3 Terms and Definitions3
- 4 General Requirements5
- 5 Requirements for Personal Information Protection7
- 6 Requirements for Important Data Protection12
- 7 Audit, Evaluation and Test Requirements13
- Appendix A Example of Vehicle Data Classification and Grading
- Appendix B Test Method for Anonymization of Personal Information
- Appendix C Calculation Method for Anonymization False Detection Rate
- Appendix D Test Method for Personal Information and Important Data Processing
- Bibliography31
Foreword
This document was drafted in accordance with the rules provided in GB/T 1.1-2020 Directives for Standardization - Part 1: Rules for the Structure and Drafting of Standardizing Documents.
Please be noted that certain content of this document may involve patents. The institution issuing this document does not undertake the responsibility of identifying these patents.
This document was proposed by Ministry of Industry and Information Technology of the People’s Republic of China.
This document shall be under the jurisdiction of National Technical Committee of Auto Standardization (SAC/TC 114).
The drafting organizations of this document: Ministry of Industry and Information Technology Equipment Industry Development Center; China Automotive Technology and Research Center Co., Ltd.; Beijing Horizon Robotics Information Technology Co., Ltd.; Chongqing Changan Auto Co., Ltd.; GreatWall Motor Co., Ltd.; NIO Automotive Technology (Anhui) Co., Ltd.; Shanghai Motor Vehicle Inspection Certification & Tech Innovation Center Co., Ltd.; Huawei Technologies Co., Ltd.; Guangzhou Xiaopeng Motors Technology Co., Ltd.; BYD Auto Industry Co., Ltd.; Qualcomm Wireless Communication Technology (China) Co., Ltd.; Beijing Saimo Technology Co., Ltd.; China Information Communication Technologies Group Corporation; China Software Testing Center (Software and Integrated Circuit Promotion Center of the Ministry of Industry and Information Technology); Beijing CHJ Automotive Co., Ltd.; Beijing Automotive Technology Center; 360 Digital Security Group; Banma Information Technology Co., Ltd.; Mercedes Benz (China) Investment Co., Ltd.; VOLVO Car (Asia Pacific) Investment Co., Ltd.; Pan Asia Technical Automotive Center Co., Ltd.; BMW (China) Service Co., Ltd.; FAW Jiefang Automotive Co., Ltd.; GEELY Automobile Research Institute (Ningbo) Co., Ltd.; China Industrial Control Systems Cyber Emergency Response Team; National Innovation Center of Intelligent and Connected Vehicles; Anhui Jianghuai Automobile Group Co., Ltd.; Volkswagen (China) Investment Co., Ltd.; Shanghai Lingang Jueying Intelligent Technology Co., Ltd.; Beijing Baidu Intelligent Mobility Technology Co., Ltd.; Neusoft Reach Automotive Technology (Shenyang) Co., Ltd.; PATEO (Shanghai) Co., Ltd.; Shanghai Songhong Intelligent Automobile Technology Co., Ltd.
The main drafters of this document: Qiu Bin, Wu Hanbing, Sun Hang, Xie Hanguang, Zhang Lu, Tian Shengming, Zhang Xiaodong, Jin Xiulian, Xia Xianzhao, Zhao Zijian, Pan Kai, Chen Jinfeng, Zhong Yilin, Wang Jiangsheng, Zhang Yanan, Li Guangyou, Hou Xintian, Bai Zhimin, Fang Jiayi, Wang Wei, Zhang Chunwang, Mou Hongyu, Yan Minrui, Man Zhiyong, Liu Fan, Li Tong, Gu Jinjin, Wu Yan, Zhao Chao, Xia Huan, Pan Yan, Chen Guihua, Zhu Chenwei, Zhao Wen, Shi Jianping, Cheng Zhou, Qi Shuai, Li Yujia, Li Xuesong, Teng Tianyi, Zou Bosong, Zou Xue, Tang Yan, Huo Yanyan.
1 Scope
This document specifies the general requirements, personal information protection requirements, important data protection requirements, audit and evaluation, and test requirements for data generated and collected during the R&D, design, production and manufacturing processes of automotive products, and describes the corresponding test methods.
This document applies to automotive products and vehicle data processors.
2 Normative References
This document does not have normative references.
3 Terms and Definitions
The following terms and definitions are applicable to this document.
3.1 collect
The act of obtaining vehicle data in a certain mode.
A systematic approach to standardize the process of vehicle data processing activities to ensure vehicle data security.
3.3 cabin data
Data that may contain personal information collected from the car cabin through various means, such as: cameras, infrared sensors, fingerprint sensors or microphones, as well as data generated after processing.
3.4 personal information subject
The natural person identified by personal information.
3.5 face object
The part between the uppermost tip of the eyebrows and the bottom line of the chin, and between the left ear and the right ear (excluding the ears) on the front of a natural person’s head.
3.7 vehicle license plate object
An official motor vehicle license plate installed on a vehicle with a metal base material.
3.9 mask covering rate
The ratio of the anonymization area within the face or license plate boundary frame to the area of the entire boundary frame.
face boundary frame area, the dotted line part is the anonymization area, the shaded part is the overlapping area of the solid line part and the dotted line part, and the mask covering rate is the area ratio of the shaded part to the solid line part.
3.10 detection rate
The percentage of the number of positive detections of face or license plate object to the expected number of detections.
accordance with the requirements of this document.
accordance with the requirements of this document.
3.11 false detection rate
The percentage of the number of false detections of face or license plate object to the number of detected objects.
that do not satisfy the definition of anonymized objects in this document.
4 General Requirements
4.1 Requirements for Vehicle Data Security Management System
4.1.1 Vehicle data processors shall establish and implement a vehicle data security management system and adopt vehicle data security protection technical measures to ensure that vehicle data is continuously effectively protected and legally used. 4.1.2 Vehicle data processors shall formulate vehicle data security objectives and policies, analyze the internal and external environment of the vehicle data security management system, and determine the boundaries and scope of application of the vehicle data security management system. 4.1.3 Vehicle data processors shall establish a vehicle data security management institution and determine the responsibilities of relevant personnel. 4.1.4 Vehicle data processors shall establish a vehicle data classification and grading system and form a vehicle data asset management ledger. 4.1.5 Vehicle data processors shall formulate specific hierarchical protection requirements and operating procedures for data collection, storage, use, processing, transmission, provision, disclosure, and deletion processes for the entire life cycle of vehicle data. 4.1.6 Vehicle data processors shall at least establish a data security process management system for the entire life cycle of the vehicle, including R&D, design, production and manufacturing, etc. 4.1.7 If vehicle data processors need to store personal information and important data collected and generated within the territory of the People’s Republic of China, it shall be stored within the country; if it needs to be provided overseas, it shall pass the data outbound security assessment. 4.1.8 Vehicle data processors shall establish a vehicle data security risk monitoring and incident management system. When a vehicle data security risk is found, remedial measures shall be immediately taken. When a vehicle data security incident occurs, disposal measures shall be immediately taken, users shall be informed in a timely manner in accordance with regulations, and a report shall be filed to the relevant competent authorities. In addition, in accordance with regulations, risk assessments shall be regularly conducted on important data processing activities, and risk assessment reports shall be submitted to the relevant competent authorities. 4.1. […]
5 Requirements for Personal Information Protection
5.2 Individual Consent
5.2.1 General requirements for individual consent
When processing personal information, vehicle data processors shall obtain individual consent; when processing sensitive personal information, separate consent shall be obtained. The above two circumstances shall be notified to individuals in at least one prominent mode, clearly explaining the specific circumstances and necessity of processing personal information, and providing convenient personal information management functions, such as: review, copy and deletion, etc. The specific requirements are as follows. […]
5.2.2 Options for obtaining individual consent
Vehicle data processors shall set up options for obtaining individual consent in accordance with the following requirements:
---Provide modes for consent and refusal;
personal information, and the period shall not be set as always allowed or permanent.
5.2.4 Withdrawal of individual consent
Vehicle data processors shall provide a channel of withdrawing individual consent.
5.3 Collection of Personal Information
5.3.1 When collecting personal information, vehicle data processors shall determine the coverage and resolution of cameras and radars, etc. based on the data accuracy requirements of the functional services provided.
5.3.2 If the same data collection equipment supports multiple functional services with different requirements for data accuracy, at least one functional service shall comply with the requirements of 5.3.1. For other functional services that do not comply with the requirements of 5.3.1, the vehicle data processors shall provide a reasonable explanation.
5.4 Storage of Personal Information
5.4.1 Vehicles shall adopt secure access technology, encryption technology or other security technologies to protect sensitive personal information stored in the vehicle and prevent unauthorized access and acquisition.
5.4.2 Vehicles shall adopt security defense mechanisms to protect the vehicle identification number (VIN) and other data stored in the vehicle for vehicle identification, and prevent unauthorized deletion and modification.
authorization include secure access technology and read-only technology, etc.
5.5 Use of Personal Information
5.5.1 When using personal information, vehicle data processors shall take access control measures to prevent unauthorized access to stored personal information.
5.5.2 Personal biometrics shall not be used as the only means to achieve personal identity authentication.
5.6 Transmission of Personal Information
5.6.1 Requirements for transmission outside the vehicle
5.6.1.1 Vehicles shall implement confidentiality protection measures for sensitive personal information sent outside the vehicle. 5.6.1. […]
5.6.2 Anonymization requirements
5.6.2.1 Anonymization objects
5.6.2.2 Anonymization performance requirements
5.6.2.2.1 Anonymization detection rate
The anonymization detection rate of face object and vehicle license plate object shall be greater than or equal to 90%.
6 Requirements for Important Data Protection
6.1 General Requirements for Important Data Processing
When processing important data, vehicle data processors shall hold clarified and reasonable purposes, which shall be directly related to the purpose of processing. […]
6.2 Important Data Collection
6.2.1 When collecting important data, vehicle data processors shall determine the coverage and resolution of cameras and radars, etc. based on the data accuracy requirements of the functional services provided.
6.2.2 If the same data collection equipment supports multiple functional services with different requirements for data accuracy, at least one functional service shall comply with the requirements of 6.2.1. For other functional services that do not comply with the requirements of 6.2.1, the vehicle data processors shall provide a reasonable explanation.
6.3 Storage of Important Data
Vehicles shall adopt secure access technology, encryption technology or other security technologies to protect important data stored in the vehicle and prevent unauthorized access and acquisition.
6.4 Use of Important Data
When using important data, vehicle data processors shall take access control measures to prevent unauthorized access to stored important data.
6.5 Transmission of Important Data
Vehicles shall implement confidentiality protection measures for important data sent outside the vehicle.
6.6 Deletion of Important Data
Deleted important data shall be irretrievable and inaccessible.
7 Audit, Evaluation and Test Requirements
7.1 Vehicle data processors shall pass the conformity evaluation that satisfies the requirements of 4.1.
7.2 The vehicle shall be tested for anonymization of personal information in accordance with Appendix B, and the vehicle shall be tested for processing personal information and important data in accordance with Appendix D, and the corresponding requirements of each test shall be satisfied.
7.3 Anonymization false detection rate tests should be conducted on vehicles in accordance with Appendix C.
Appendix A Example of Vehicle Data Classification and Grading
A.1 Principles of Data Classification and Grading
The principles for the classification and grading of vehicle data are as follows.
---Compliance: comply with national laws and regulations and relevant provisions of relevant competent authorities; comply with relevant requirements in the standards for data security management in the field of industry and information technology.
multi-dimensional characteristics of the data and the logical relations that objectively exist among them.
---Practicality: make sure that there is data under each category and no meaningless categories are set up.
---Scalability: it is general and inclusive, and can realize the classification and grading of various types of data to satisfy the data types and data levels that may appear in the future.
---Salience: in accordance with the salient features of the data content, determine the classification scheme of data.
---Timeliness: it has a certain validity period and can be adjusted in a timely manner.
security requirements apply to data of the same level.
A.2 Data Classification
Vehicle data processors classify the data generated and collected during the R&D, design, production and manufacturing of automotive products in accordance with the requirements of relevant laws, regulations and standards.
A.3 Data Classification
A.3.1 Classification elements
A.3.1.2 Affected objects
Affected objects refer to those affected by tampering, destruction, leakage, illegal acquisition, and illegal utilization of data generated and collected during the R&D, design, production and manufacturing processes of automotive products, including national security, industry security, organizational security, and personal rights and interests, among which: ---The situation where the affected object is national security means that once the data is leaked, tampered, destroyed or illegally acquired, it may have an impact on national political security, national economic security, national public security, national resource security, national scientific and technological security and national network security, etc.; […]
A.3.1.3 Degree of impact
The degree of impact can be divided from high to low into serious harm, general harm, minor harm, and no impact. When judging the degree of impact on different affected objects, different criteria are used. […]
Appendix B Test Method for Anonymization of Personal Information
B.2 Test Equipment
B.2.1 Test equipment record contents
During the test, additional test recording equipment shall be installed and recorded. At least the following contents shall be recorded:
---Video information of the test vehicle’s surrounding environment.
B.2.2 Accuracy of test recording equipment
The resolution of the test recording equipment shall be no less than (1,920 × 1,080) pixels, and the video sampling frame rate shall be at least 30 f/s.
B.2.3 Installation and operation of test recording equipment
The installation and operation of the test recording equipment shall not affect the original configuration of the test vehicle and the normal operation of its personal information collection and transmission functions.
B.2.4 Requirements for test result annotation capability
B.2.4.1 Requirements for image collections with annotation capabilities
Select 500 anonymized images and 500 non-anonymized images to form an image collection for the verification of annotation capabilities. The image collection shall meet the following requirements.
Contain at least 200 face objects and 200 vehicle license plate objects;
Documentation with the true pixel values of each side length of each face object and vehicle license plate object boundary frame;
Documentation with the true values of the visible range area of each face object.
Contain at least 200 face objects and 200 vehicle license plate objects that have been anonymized;
Documentation with the true pixel values of each side length of each face object and vehicle license plate object boundary frame;
Documentation with the true values of the visible range area of each face object;
Documentation with the true values of the anonymization area and coverage rate of each face object and vehicle license plate object that have been anonymized;
There are no identical images in the non-anonymized image collections.
Remaining clauses in the full document
- B.3 Test Process of Anonymization Performance Requirements
- B.4 Test End Conditions of Anonymization Performance Requirements
- B.5 Test Result Processing
- B.6 Evaluation of Anonymization Effect
- Appendix C Calculation Method for Anonymization False Detection Rate
- Appendix D Test Method for Personal Information and Important Data Processing
- D.2 Test Method for Individual Consent
- D.5 Test Method for Use of Personal Information
- Bibliography
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 31 pages — is available in the English PDF.
How to Buy GB/T 44464-2024
- 1Add to cart. Click the "Buy GB/T 44464-2024" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil — Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
$390.00
USD · One-time purchase
Secure payment via Stripe
Payments accepted
GB/T 44464-2024
$390.00