| Legal relationship | The 2021 trial provisions establish baseline rules for automotive data processing and important-data cross-border transfers. | The 2026 guideline implements those baseline duties within the current national cross-border data transfer framework; it does not replace the 2021 provisions. | i Clarified | Compliance programs should apply both documents together. | The 2026 issuance announcement expressly cites the 2021 provisions.Previous sourceCurrent source |
| Transfer-route selection | The 2021 provisions focus on the security-assessment requirement for important-data cross-border transfers and annual reporting. | The 2026 guideline identifies conditions for security assessment, standard contract and personal-information protection certification for cross-border transfers. | + Added | Automotive exporters gain a sector-specific route-selection sequence. | 2026 guideline, general section and cross-border transfer process.Current source |
| Exemptions | The 2021 provisions do not provide the 2026 guideline's nine-scenario export exemption framework. | The 2026 guideline states nine circumstances exempt from the three named export mechanisms, subject to their conditions. | + Added | Teams should test exemption conditions before initiating a transfer mechanism. | Official MIIT Q&A describes nine categories.Current source |
| Important-data identification | The 2021 provisions define automotive important data at a baseline level. | The 2026 guideline provides scenario-based identification across R&D, manufacturing, driving automation, software updates and connected operations. | i Clarified | Data inventories should map category, item and description to the sector-specific identification rules. | Official MIIT Q&A.Current source |
| Security controls | The 2021 provisions establish processing and security-management duties. | The 2026 guideline organizes export safeguards around management systems, technical protection, logs and incident response. | i Clarified | Export controls should be evidenced across governance, technical, logging and response workstreams. | Official MIIT Q&A.Current source |