We use essential cookies for the website to function, as well as analytics cookies for analyzing and creating statistics of the website performance. To agree to the use of analytics cookies, click "Accept All". You can manage your preferences at any time by clicking "Cookie Settings" on the footer. More Information.

Only Essential Cookies
Accept All

SDK Compliance Guide

After the Personal Information Protection Law of the People's Republic of China was released on November 1, 2021, supervisory authorities, industry participants, and consumers are increasingly concerned about user privacy protection. In addition, supervisory authorities have formulated relevant standards and regulations to effectively govern illegal collection and use of personal data by apps.

As a developer providing services for end users, you understand and acknowledge that you will comply with applicable laws, regulations, and standards to fulfill your obligation of personal data protection, and that you will process users' personal data in accordance with the principles of legality, legitimacy, necessity, and good faith, including but not limited to Personal Information Protection Law of the People's Republic of China, Cybersecurity Law of the People's Republic of China, Data Security Law of the People's Republic of China, and other applicable laws, regulations, and standards.

This document helps you better understand and compliantly use the HMS Core Navi SDK. It is applicable only when your service area is the Chinese mainland.

1. Basic Requirements

Your product and service must respect user privacy and comply with applicable data protection laws and regulations. Do not engage in any activities that may disrupt, interfere with, damage, or access any device, server, or network without prior authorization.

(I) Privacy Policy Requirements

You shall release a privacy policy in your own name in accordance with applicable laws, and obtain users' consent for the processing of their personal data. The privacy policy requirements include but are not limited to the following:

  1. The privacy policy must be a separate document, and cannot be a part of the user agreement.
  2. Before your app collects and processes users' personal data for the first time, you need to remind users to read the privacy policy in a striking way. You must provide users an easy way to view the privacy policy, for example, by consecutively tapping or sliding your app's main function screen no more than 4 times.
  3. The privacy policy must contain language that is clear and simple, comply with common reading habits, and avoid ambiguous words.
  4. The privacy policy must include the purpose, method, and scope for your product and service to collect and use personal data, as well as the name and contact method of the personal data processor.
  5. If your product and service need to share personal data with third parties or have integrated third-party SDKs, you need to disclose this to users in the privacy policy and obtain their authorization or consent.

(II) Personal Data Processing Requirements

When processing users' personal data, your product and service must comply with requirements including but not limited to the following:

  1. Personal data must be processed based on the purpose of use and following the data minimization principle.
  2. The scope and purpose of actually collected and processed personal data must be consistent with those specified in the privacy policy.
  3. The personal data collection frequency must be consistent with that specified in the privacy policy. It is prohibited to collect personal data at a frequency higher than the specified one.
  4. There must be a clear mechanism for deleting expired personal data, and the personal data retention period must be consistent with that specified in the privacy policy. Expired personal data shall be deleted or anonymized in a timely manner.
  5. If personal data of a minor under the age of 14 needs to be processed, you shall obtain the consent of the minor's parent or guardian.
  6. If personal data needs to be processed for personalized recommendation or big data analysis, you shall notify end users and obtain their consent in advance.
  7. If sensitive personal data needs to be processed, you shall obtain consent from end users separately.
  8. If cross-border transfer of personal data is required, you shall perform a security assessment and comply with all regulations and requirements issued by relevant supervisory authorities. In addition, you shall obtain consent from end users separately.
  9. Users can conveniently exercise their rights as personal data subjects, such as viewing, copying, modifying, and deleting personal data.

2. Personal Data Processing

Before accessing and using the Navi SDK and its services, your app must provide end users with the following information about the Navi SDK in its privacy policy: SDK name, SDK provider name, categories of personal data to be collected, purposes for the use of such data, and a link to the privacy statement. Your app shall only allow end users to access the SDK after obtaining their consent or other legal bases. You can display the aforementioned SDK information in either of the following forms:

  • In text form

Third-party SDK: HMS Core Navi SDK

Provider: Huawei Software Technologies Co., Ltd.

Personal data to be collected: location information and system settings

Purpose of use: To provide support for the route planning service, navigation service, and product operations and maintenance.

Privacy policy: SDK Privacy Statement

  • In table form
Expand

Third-Party SDK

Provider

Personal Data to Be Collected

Purpose of Use

Privacy Policy

HMS Core Navi SDK

Huawei Software Technologies Co., Ltd.

Location information and system settings

To provide support for the route planning service, navigation service, and product operations and maintenance.

SDK Privacy Statement

3. Required Permissions

The Navi SDK requires minimum system permissions to provide services. You need to apply for relevant system permissions based on the SDK capabilities you use, and notify users and obtain their consent.

Expand

Permission

Description

Purpose of Use

Network status obtaining permission

Permission to obtain the network status.

To check whether the current network connection is valid when using the route planning and navigation services as well as performing product operations and maintenance.

Network access permission

Permission to access the network.

To access the network when using the route planning and navigation services as well as performing product operations and maintenance.

4. Associated App Startup

Using the HMS Core Navi SDK for an app on non-Huawei devices may cause HMS Core (APK) to start. The APK will build a unified persistent connection channel and perform unified identity authentication to ensure the security of calls to the SDK. Developers must inform end users of this in the privacy policies of their apps, and obtain the end users' consent or other legal bases.

5. Delayed Initialization

To prevent the Navi SDK integrated into your app from processing end user's personal data before obtaining their consent, the SDK provides the MapNavi.getInstance API, which can be called to initialize the SDK only after the app has obtained the end user's consent.

6. Rights Protection for Personal Data Subjects

Data processing activities performed by the Navi SDK cannot identify specific individuals. If developers associate data with individuals when using the Navi SDK, they must protect the rights of personal data subjects by themselves.

Search
Enter a keyword.