This new Cullen International benchmark analyses whether global IoT and M2M operating models can centralise data and platform functions outside the country where connected devices operate. It covers Australia, China, India, Japan, New Zealand, Singapore and South Korea, assessing how data protection, telecommunications, cybersecurity and sector-specific regulation affect the feasibility of offshore operating models.
The benchmark is designed for IoT connectivity providers, OEMs, device platform providers and regulatory teams that rely on permanent roaming, global SIMs or eSIM deployments.
Key findings
- Network-layer metadata is subject to significantly stricter regulation than application-layer IoT data.
- Japan and New Zealand generally permit offshore processing of network-layer metadata, while Australia, Singapore, South Korea and China typically require a domestic regulatory anchor.
- India's June 2026 telecommunications framework fundamentally changes the assessment for new authorised entities by prohibiting offshore copies of network-associated data.
- Application-layer telemetry can generally be processed offshore, although China and India impose additional restrictions in certain circumstances.
- Sector-specific rules for health, connected vehicles and critical infrastructure can materially alter the assessment.
Why this research matters
Many organisations assume that compliance with cross-border personal data transfer rules is sufficient to operate a global IoT platform. The research demonstrates that this is only one part of the picture. Telecommunications regulation, lawful access, data retention, SIM/eSIM rules and sector-specific legislation frequently impose additional obligations that determine whether an offshore operating model is viable. As a result, two countries with similar privacy laws may reach very different conclusions for IoT connectivity.
Background and methodology
The benchmark goes beyond a traditional privacy law comparison by assessing the complete operating model. It distinguishes between network-layer metadata (such as traffic, signalling, roaming events, location records and SIM/eSIM provisioning data) and application-layer IoT data (such as telemetry, diagnostics and sensor data). Each assessment applies a three-layer legal methodology:
- cross-border data protection and transfer rules;
- telecommunications, cybersecurity and sector-specific obligations; and
- domestic access, retention and regulatory accountability requirements.
The strictest applicable rule determines the final assessment. Countries are classified as 'Allowed', 'Hybrid' (offshore processing is possible but a domestic element is required) or 'Not allowed' (the proposed operating model cannot be implemented offshore for the relevant data category).
About the report
Region: Asia-Pacific
Policy area: Internet of things
Last updated: 30 July 2026
more news
27 July 26
Spectrum policy adapts to support new network models in the Americas
Cullen International's latest Americas Spectrum Benchmarks compare regulatory approaches across the Americas for a range of topics, including 5G deployment, spectrum assignments, spectrum refarming and private networks.
27 July 26
Most European countries require 10 Mbps for adequate fixed broadband
Cullen International's latest European benchmark on universal service obligation investigates the minimum download speed required in 33 countries.
27 July 26
What is the state of implementation of the Cyber Resilience Act in the EU?
Cullen International's latest Benchmark analyses how 19 EU countries are preparing to implement the Cyber Resilience Act (CRA). It tracks national laws, designated authorities, incident notification bodies and penalties ahead of the regulation’s application dates.