Cross-border IoT data transfer rules across seven APAC markets 04 August 26 Marios Yiatzidis

This new Cullen International benchmark analyses whether global IoT and M2M operating models can centralise data and platform functions outside the country where connected devices operate. It covers Australia, China, India, Japan, New Zealand, Singapore and South Korea, assessing how data protection, telecommunications, cybersecurity and sector-specific regulation affect the feasibility of offshore operating models.

The benchmark is designed for IoT connectivity providers, OEMs, device platform providers and regulatory teams that rely on permanent roaming, global SIMs or eSIM deployments.

Key findings

  • Network-layer metadata is subject to significantly stricter regulation than application-layer IoT data.
  • Japan and New Zealand generally permit offshore processing of network-layer metadata, while Australia, Singapore, South Korea and China typically require a domestic regulatory anchor.
  • India's June 2026 telecommunications framework fundamentally changes the assessment for new authorised entities by prohibiting offshore copies of network-associated data.
  • Application-layer telemetry can generally be processed offshore, although China and India impose additional restrictions in certain circumstances.
  • Sector-specific rules for health, connected vehicles and critical infrastructure can materially alter the assessment.

 

Why this research matters

Many organisations assume that compliance with cross-border personal data transfer rules is sufficient to operate a global IoT platform. The research demonstrates that this is only one part of the picture. Telecommunications regulation, lawful access, data retention, SIM/eSIM rules and sector-specific legislation frequently impose additional obligations that determine whether an offshore operating model is viable. As a result, two countries with similar privacy laws may reach very different conclusions for IoT connectivity.

Background and methodology

The benchmark goes beyond a traditional privacy law comparison by assessing the complete operating model. It distinguishes between network-layer metadata (such as traffic, signalling, roaming events, location records and SIM/eSIM provisioning data) and application-layer IoT data (such as telemetry, diagnostics and sensor data). Each assessment applies a three-layer legal methodology:

  • cross-border data protection and transfer rules;
  • telecommunications, cybersecurity and sector-specific obligations; and
  • domestic access, retention and regulatory accountability requirements.

The strictest applicable rule determines the final assessment. Countries are classified as 'Allowed', 'Hybrid' (offshore processing is possible but a domestic element is required) or 'Not allowed' (the proposed operating model cannot be implemented offshore for the relevant data category).

About the report

Region: Asia-Pacific
Policy area: Internet of things
Last updated: 30 July 2026