Chinese electric cars under scrutiny: The Nio ES8 case reveals a lot about data, data privacy, and connected vehicles
When the researchers drove the Chinese electric SUV deep into a Norwegian mine, it wasn't about a stress test for the suspension or the battery. The goal was clearly more unusual: the vehicle should be cut off from its surroundings as completely as possible. But even down there, far from mobile networks and everyday infrastructure, the car demonstrated a behavior that made the researchers sit up and take notice. The vehicle continued trying to contact servers – many of them in China.
The experiment is part of 'Project Lion Cage,' a research project by Norwegian security expert Tor Indstøy. The head of risk and threat analysis at the telecommunications company Telenor had already purchased a Nio ES8 in 2022 to study its data traffic over several years. The results are now sparking discussions well beyond Norway.
Car as a computer on wheels
When you drive a modern electric car today, you are not just driving a vehicle. Cameras, sensors, navigation systems, voice control, online services and over-the-air updates generate constant data streams. This applies not only to Chinese manufacturers. European, American and Korean vehicles also regularly communicate with the servers of their manufacturers. Map data is updated, software is checked, vehicle statuses are transmitted or new features installed.
The real question, therefore, is not whether a car transmits data, but which data flows where and who can access it. This is exactly where Project Lion Cage comes in.
90 percent of connections led to China
During a multi-year analysis, the researchers logged more than 200,000 network requests from the Nio ES8. The result: around 90 percent of the observed connections led to servers in China. The remaining data traffic went to systems in Germany, the United States, the Netherlands and Switzerland. The researchers were able to identify the destinations of the data packets, but could usually not read the contents. The communication was predominantly encrypted. Therefore, the investigations do not prove that personal data or sensitive information were actually transmitted to China. However, they show where the connections were established.
Particularly conspicuous was a small data set that was repeatedly downloaded from a server in Beijing and accounted for a large portion of the communications. The researchers have not yet been able to clearly determine what purpose this file served.
Nio denies the allegations
The Chinese manufacturer has emphasized for years that European customer data is processed within Europe. However, the company's privacy statements also provide for international data transfers, including to China and the United States, as long as this is legally permissible.
Nio has repeatedly rejected the researchers' interpretation. From the company's perspective, the observed network connections do not prove that personal data is transmitted to China. The debate, however, shows a fundamental problem: for outsiders, it is often hardly possible to understand which data a modern vehicle actually collects and processes.
Why the topic is relevant for taxi companies
For private car drivers the discussion may seem abstract. In commercial passenger transport the situation looks different. Taxi companies, car rental providers and ride-hailing services handle daily large amounts of sensitive information. Location data, driving routes, charging profiles, usage times or information about passengers can be economically valuable.
At the same time, vehicles are increasingly integrated into digital fleet management systems. Many operators analyze utilization, energy consumption and driving behavior almost in real time. The more interconnected the vehicles are, the more important questions of data security and data sovereignty become. Especially larger fleet operators therefore now examine not only acquisition prices, ranges, or maintenance costs. Cybersecurity and data protection are also increasingly part of tenders and procurement decisions.
Political dimension
The discussion about Chinese vehicles reminds some observers of the debate about Huawei and the expansion of European 5G networks. The background is the Chinese National Intelligence Law. This obliges companies under Chinese jurisdiction to cooperate with state authorities if corresponding requests are made. Critics see this as a potential risk. Manufacturers, however, point to international data protection regulations and compliance with European laws.
Several European authorities are now dealing with the question of how connected vehicles should be regulated in the future. In Germany, a data protection proceeding against Nio has already been initiated, the outcome of which remains to be seen.
No Chinese special problem
Among all the attention to Chinese brands, it would, however, be too short-sighted to restrict the debate solely to vehicles from China. Security experts point out that modern cars are generally among the most data-intensive consumer products. Cameras, microphones, GPS systems and cellular modules are now found in virtually every connected vehicle.
The actual challenge, therefore, is to create transparency. Users, companies and authorities must be able to understand which data are collected, where they are stored and who can access them.
More than a data privacy debate
The case of the Nio ES8 shows above all one thing: Electric mobility is increasingly becoming an interface between the automotive industry, IT security and geopolitics. For taxi and fleet operators, a new question becomes relevant. Until now, ranges, acquisition costs and charging infrastructure were at the center. In the future, another criterion could be added: the digital footprint of a vehicle. Because the car of the future transports not only people. It also transports data. And the question of where this journey leads now concerns not only privacy advocates, but the entire mobility industry.
Content automatically translated.Taxi-Fahrzeuge (Pkw) , Taxi-Newsletter, Taxameter, Taxi-Fahrer , BZP – Deutscher Taxi- und Mietwagenverband , Straßenverkehrsordnung (StVO) , Krankenbeförderung , Weiterbildung , Taxi-Konzessionen , Verkehrspolitik , Mietwagenbranche , Taxi-Apps , Berufskraftfahrer-Qualifikations-Gesetz BKrFQG) , Taxizentralen , Personal, Gehälter, Arbeitsschutz , Wirtschaftsnachrichten , Werbung , Taxi-Folierung , Taxi-Umrüster , Straßenverkehr , Elektromobilität, Taxifuhrpark und -flottenmanagement , Taxi-Versicherungen , Hybrid, Diesel, Erdgas , Taxi-Magazin