This new Cullen International benchmark analyses whether global IoT and M2M operating models can centralise data and platform functions outside the country where connected devices operate. It covers Australia, China, India, Japan, New Zealand, Singapore and South Korea, assessing how data protection, telecommunications, cybersecurity and sector-specific regulation affect the feasibility of offshore operating models.
The benchmark is designed for IoT connectivity providers, OEMs, device platform providers and regulatory teams that rely on permanent roaming, global SIMs or eSIM deployments.
Key findings
- Network-layer metadata is subject to significantly stricter regulation than application-layer IoT data.
- Japan and New Zealand generally permit offshore processing of network-layer metadata, while Australia, Singapore, South Korea and China typically require a domestic regulatory anchor.
- India's June 2026 telecommunications framework fundamentally changes the assessment for new authorised entities by prohibiting offshore copies of network-associated data.
- Application-layer telemetry can generally be processed offshore, although China and India impose additional restrictions in certain circumstances.
- Sector-specific rules for health, connected vehicles and critical infrastructure can materially alter the assessment.
Why this research matters
Many organisations assume that compliance with cross-border personal data transfer rules is sufficient to operate a global IoT platform. The research demonstrates that this is only one part of the picture. Telecommunications regulation, lawful access, data retention, SIM/eSIM rules and sector-specific legislation frequently impose additional obligations that determine whether an offshore operating model is viable. As a result, two countries with similar privacy laws may reach very different conclusions for IoT connectivity.
Background and methodology
The benchmark goes beyond a traditional privacy law comparison by assessing the complete operating model. It distinguishes between network-layer metadata (such as traffic, signalling, roaming events, location records and SIM/eSIM provisioning data) and application-layer IoT data (such as telemetry, diagnostics and sensor data). Each assessment applies a three-layer legal methodology:
- cross-border data protection and transfer rules;
- telecommunications, cybersecurity and sector-specific obligations; and
- domestic access, retention and regulatory accountability requirements.
The strictest applicable rule determines the final assessment. Countries are classified as 'Allowed', 'Hybrid' (offshore processing is possible but a domestic element is required) or 'Not allowed' (the proposed operating model cannot be implemented offshore for the relevant data category).
About the report
Region: Asia-Pacific
Policy area: Internet of things
Last updated: 30 July 2026
For more information and access to the update, click Access full content – or Request access if you are not yet a subscriber to the IoT service.
more news
21 August 26
Sustainability targets of car manufacturers
Our latest benchmark summarises the sustainability targets put in place by the major car manufacturers.
19 August 26
Regulating submarine cable infrastructure
Our latest Global Trends benchmark analyses policies and regulations of relevance to international submarine cables used for electronic communications in 17 jurisdictions around the world.
18 August 26
Countries around the world take different approaches to data centre development
Cullen International’s new benchmark provides insights into how 19 countries, including 13 in Europe, have introduced rules to incentivise and/or regulate the development of data centres.