Your Data and China : The Risks and Reality
Posted by Jim Noort on 31st Jul 2026
Every connected smart lock answers to a company somewhere. Here’s where each major platform actually hosts your data — and why one country is different.
When you add a gateway to a smart lock, your access events — who unlocked your door and when — start passing through a company’s cloud servers. Those servers sit in a real country, under that country’s laws. For many locks sold in Australia, that country is the United States, Singapore, Ireland, the UK, or somewhere else in Europe. For a significant number, it’s China. That distinction is the whole subject of this post.
We want to be careful and fair here: this is not a claim that any particular company has done anything wrong, and it is not a reason to panic about a lock you already own. It’s a structured look at a real question — where does each platform host its data, and what legal environment does that data sit in — so you can make an informed decision rather than an anxious one.
This guide covers:
- Why data hosting location matters for a smart lock specifically
- The China question — the actual legal framework, and another perspective on it
- How governments around the world have already reacted
- A full table of where every major smart lock platform hosts its data
- The data-hosting advantage held by ASSA ABLOY / Yale-Lockwood and other non-China platforms
If you want the companion piece on Australia’s new compliance law and what a manufacturer’s declaration should contain, see our guide to the Cyber Security Rules 2025. For a platform-by-platform comparison of the two big Chinese platforms, see our TTLock vs Tuya deep-dive.
Why Where Your Data Lives Matters
A smart lock’s data isn’t especially glamorous — it’s a log of access events, user names, PIN and credential records, and the commands your app sends. But it is genuinely sensitive: a pattern of when a house is empty, who comes and goes, and the ability to send an unlock command remotely is exactly the kind of information you’d want held somewhere accountable and legally reachable.
Local Access vs the Cloud Layer
The single most important distinction in this whole topic: Bluetooth-only operation and PIN entry at the keypad happen entirely on the lock itself. Nothing leaves your property. The data-hosting question only applies to the cloud layer — the part that switches on when you add a Wi-Fi gateway for remote access, remote code provisioning, or PMS automation.
The China Question
Two of the world’s biggest smart lock platforms — TTLock and Tuya — are Chinese companies, and TTLock in particular powers several brands sold in Australia. So the question comes up honestly and often: does it matter that the platform behind my lock is Chinese? It’s a fair question, and it deserves a careful answer rather than either dismissal or alarm.
The Legal Reality in China: Tech Companies Must Comply
The credible version of this concern is legal and structural, not accusatory. China’s National Intelligence Law (2017) requires all organisations and citizens to “support, assist and cooperate with” national intelligence work (Article 7), and separately empowers intelligence agencies to compel that assistance (Article 14). The 2017 Cybersecurity Law adds data-localisation and state-access provisions, and the Data Security Law tightens control over cross-border data transfers. These are binding legal obligations, not optional — a China-domiciled company cannot simply decline. The concern isn’t that a Chinese platform company is malicious; it’s that it operates under a legal system where, if the state asks, its ability to say no is limited. That’s a jurisdictional fact, not a claim that any specific company has ever been asked.
Another Perspective
Not everyone is so hawkish. Some legal analysts note that Article 7 sits in a “general provisions” chapter, lacks specific implementing rules, and was arguably never intended to compel active mass data collection — and that similar cooperation clauses appear in many countries’ laws. Tuya, for its part, publicly states it has never received a cross-border government request for data and isolates user data by region. There is no public evidence that TTLock’s operator, Sciener, or Tuya has handed smart lock data to the Chinese state, and no proven backdoor in either platform. (TTLock’s firmware does carry disclosed vulnerabilities under CERT/CC advisory VU#949046, but every one requires Bluetooth proximity rather than remote internet access; we cover them in our TTLock vs Tuya security breakdown.)
How Governments Have Reacted
What moves this from theory to something worth planning around is that multiple Western governments have already acted on exactly this reasoning — and not only about phones and telecoms.
- Australia, 2023: a government audit prompted by Senator James Paterson found more than 900 Chinese-made surveillance and access devices — including cameras, intercoms and electronic entry systems — across Commonwealth sites, and the Defence Minister ordered their removal from Defence properties.
- United States, 2022: the FCC banned new equipment authorisations for several Chinese electronics makers on national security grounds, and successive administrations have moved against Chinese-platform connected devices.
- United Kingdom, 2022: government departments were instructed to stop deploying Chinese-made surveillance cameras at sensitive sites.
The detail that matters for a lock buyer: the Australian audit explicitly named electronic entry systems, not just cameras. Access-control hardware was already on the list — this isn’t a hypothetical extension of the surveillance-camera debate to door hardware. For the international regulatory picture behind these moves — the UK PSTI Act, the EU Cyber Resilience Act and Australia’s own rules — see Chapter 11’s global comparison and our compliance guide.
Where Each Smart Lock Platform Hosts Its Data
This is the heart of the post. Below is where each major smart lock platform on the Australian market hosts its cloud data, based on each vendor’s own published documentation. Remember the golden rule from earlier: this applies to the cloud layer only — Bluetooth-only operation on any of these platforms stores nothing off the lock.
China-Hosted Platforms
| Platform | Brands you’ll see it under | Where the cloud data sits |
|---|---|---|
| TTLock (operated by Sciener) | McGrath Locks, Lockton, Austyle, Auslock, Zanda and Vault. Auslock, the McGrath Locks app and Vault are re-branded TTLock front-ends on the same Sciener backend. | China (Sciener, Beijing). Gateway event logs and remote commands transit Sciener’s servers. Bluetooth-only stores nothing in the cloud. |
| Tuya | A very large number of white-label and generic smart locks worldwide. The one you’re most likely to meet in Australia is Häfele’s ‘Smart Living’ range, which appears to run on Tuya. | Chinese company, but regionally distributed — Australian accounts typically map to Tuya’s Singapore or US data centres (AWS / Alibaba Cloud / Azure), not necessarily mainland China. See the fairness note below. |


The Tuya nuance — be fair here
Tuya is a Chinese company, and that means the legal-environment argument above applies to it as a corporate entity. But unlike TTLock, Tuya runs a genuinely regionally-distributed cloud: it publishes seven data centres (US East, US West, Central Europe, Western Europe, India, Singapore and China) run on AWS, Azure and Alibaba Cloud, and maps users to the nearest one. An Australian Tuya account’s data typically lives in Singapore or the US, not China. The jurisdiction-of-parent-company question remains; the physical-location-of-data question is more favourable than people assume.
Platforms Hosted Outside China
| Platform | Brands you’ll see it under | Where the cloud data sits |
|---|---|---|
| Yale Home / Lockwood Home (ASSA ABLOY) | Yale (Australian range) and Lockwood smart locks — the Yale Home and Lockwood Home apps are two badges on one ASSA ABLOY platform. | Ireland / UK. The data controller for the Australian range is Security & Risk Communications Ltd (Dublin), part of ASSA ABLOY, under GDPR. |
| Igloohome | Igloohome deadbolts, mortice locks, padlocks and keyboxes. | Singapore — AWS Singapore hosting, GDPR/PDPA compliant. Biometric data stays on the lock, not in the cloud. |
| Carbine Connect | Carbine CEL2-BT range. | Nowhere — it’s Bluetooth-only with no cloud at all. No event data ever leaves the lock. Independently penetration-tested as low-risk by SilentGrid, an Australian firm. |
| Dormakaba | dormakaba mobile access (multi-residential and commercial). | Switzerland / EU. Mobile keys run on LEGIC Connect, a Swiss dormakaba subsidiary; only minimal resident data reaches the cloud. |
| Salto | SALTO KS, Homelok and Space access control. | EU. KS and Homelok run on AWS in the EU under a Spanish (GDPR) controller; SALTO Space is self-hosted on the customer’s own server. |
| SMARTair (ASSA ABLOY) | SMARTair escutcheons, readers and Openow mobile keys. | EU / on-site. Administered from the TS1000 software on the customer’s own server, with ASSA ABLOY’s EU cloud handling Openow mobile keys. |
| KAS | KASAccess cloud locks and readers. | Australia — KA Security Pty Ltd is an Australian company (Gold Coast, QLD). Its published policy doesn’t name a hosting region, but there is no China involvement. |
| Borg | Borg mechanical digital keypad locks. | No app, no cloud, no battery, no data — a purely mechanical PIN lock. The strongest data-sovereignty answer is having no data at all. |
The ASSA ABLOY / Yale-Lockwood Data Advantage



If data sovereignty is a priority for you, the clearest advantage in the connected-lock market belongs to ASSA ABLOY, the parent of Yale and Lockwood. ASSA ABLOY is a Swedish company, headquartered in Stockholm and listed on Nasdaq Stockholm, and is the world’s largest lock manufacturer — not a small operation you’d struggle to hold accountable.
For the Australian Yale and Lockwood smart range, the data controller is Security & Risk Communications Ltd, a Dublin-registered ASSA ABLOY company, with hosting in Ireland and the UK under the GDPR framework — one of the strictest privacy regimes in the world. That gives you a European legal environment, a named corporate entity you can actually reach, and a company whose entire business is built on being trusted with physical security. Every current Yale and Lockwood SKU carries its own signed ASSA ABLOY declaration — the full set is in our compliance guide, with example PDFs for the Yale ByYou Pro and the Lockwood Home Hub.
Igloohome (Singapore, AWS, GDPR/PDPA) and the enterprise platforms from Dormakaba, Salto and SMARTair sit in the same broad category: hosted in trusted jurisdictions, under recognised privacy law, by accountable companies. And Carbine Connect and Borg sidestep the question entirely by holding no cloud data at all. The point of this post isn’t “buy Yale” — it’s that there are many strong options hosted anywhere but China, across every price point and use case.
What This Means for Your Decision
None of this means a Chinese-platform lock is unsafe, or that you should rip out one you already have. It means matching the platform to how sensitive the application actually is.
- A single home, run mostly on Bluetooth: the hosting question is largely moot. Buy on features, reliability and support. A TTLock-platform lock is a perfectly reasonable choice.
- You want remote access and prefer a trusted jurisdiction: Yale or Lockwood (Ireland/UK, GDPR) or Igloohome (Singapore, AWS) give you the cloud convenience without the China-hosting question.
- You want cloud convenience off the table entirely: Carbine Connect (Bluetooth-only) or a Borg mechanical keypad hold no data anywhere.
- Government, defence-adjacent, NDIS, body corporate or commercial portfolio: data jurisdiction is a legitimate procurement factor. Favour a trusted-jurisdiction or no-cloud platform, and document the decision.
For a scenario-by-scenario platform decision, our five questions that decide your platform narrows it down quickly, and the full cross-platform comparison lives in Chapter 15’s security and data sovereignty table.
Frequently Asked Questions
Is a Chinese-platform smart lock unsafe to use?
Not inherently, and there’s no proven backdoor or evidence of data being handed over. The concern is jurisdictional — the legal environment the platform operates in — and it’s most relevant when you use the cloud layer for remote access, and most relevant for sensitive or organisational applications rather than a single home.
Does McGrath Locks or Auslock store my data in China?
Both run on the TTLock platform, operated by Sciener in China — Auslock is a re-branded TTLock platform, and the McGrath Locks app is an Australian-branded front-end for the same backend. If you use a gateway, event logs and remote commands transit Chinese servers. Used Bluetooth-only, nothing leaves the lock.
Which smart lock keeps my data out of China entirely?
Yale and Lockwood (Ireland/UK under GDPR), Igloohome (Singapore, AWS) and the Dormakaba/Salto/SMARTair enterprise platforms (Europe) all host outside China. Carbine Connect and Borg mechanical keypads hold no cloud data at all.
What exactly does China’s National Intelligence Law require?
It requires all organisations and citizens to support, assist and cooperate with national intelligence work (Article 7), and lets intelligence agencies compel that assistance (Article 14). The 2017 Cybersecurity Law adds data-localisation and state-access provisions. These are binding obligations a China-based company cannot simply refuse — the legal basis for the data-sovereignty concern, separate from any question of whether a request has ever been made.
Does Australia’s new cyber security law fix the data-hosting question?
No — it is a different question. The Cyber Security (Security Standards for Smart Devices) Rules 2025 require no universal default passwords, a published vulnerability-disclosure channel and stated support-period transparency; they do not regulate where a platform hosts your data. A lock can be fully compliant with the new law and still host its cloud data in China. We cover the law in our companion compliance guide.
Is Tuya’s data actually stored in China?
Usually not for an Australian account. Tuya runs a regionally-distributed cloud and typically maps Australian users to its Singapore or US data centres, not mainland China. The parent company is Chinese, so the legal-jurisdiction argument still applies to the company — but the physical location of the data is more favourable than many assume. Tuya is a white-label platform Terry’s doesn’t stock; there is more detail in our TTLock vs Tuya comparison.
Where is Yale and Lockwood data held, and who controls it?
For the Australian Yale and Lockwood range, the data controller is Security & Risk Communications Ltd, a Dublin-registered ASSA ABLOY company, with hosting in Ireland and the UK under GDPR. Yale Home and Lockwood Home are two brand apps on the same ASSA ABLOY platform, and each current SKU carries its own signed cyber security declaration — the full set is in our compliance guide.
I want a video doorbell smart lock but not Chinese hosting — what are my options?
Most all-in-one video-intercom locks today run on Chinese platforms: the Vault Vision range is TTLock-based, and most other video locks are Tuya. To keep the cloud layer out of China, the practical route is a trusted-jurisdiction or no-cloud lock (Yale, Lockwood, Igloohome or Carbine) paired with a separate video doorbell such as Ring, Nest or Reolink, each with its own Australian support. We walk through the category in our TTLock vs Tuya doorbell section.
Which brands run on the TTLock platform?
In Australia the TTLock platform — operated by Sciener in Beijing — sits behind Auslock, Austyle, Lockton, Zanda, Vault and the McGrath Locks app. They share one Sciener backend, so with a gateway their event logs and remote commands transit Chinese servers; run them Bluetooth-only and nothing leaves the lock.
Are Dormakaba, Salto and SMARTair really hosted in Europe?
Yes. Dormakaba mobile keys run on LEGIC Connect in Switzerland and the EU, Salto KS and Homelok run on AWS in the EU (SALTO Space is self-hosted on the customer’s own server), and SMARTair is run from an on-site server with ASSA ABLOY’s EU cloud handling mobile keys. None of them touches China.
Does adding a Wi-Fi gateway change where my data goes?
Yes — that’s the switch. Without a gateway, the lock works over Bluetooth at the door and nothing leaves your property. Add a Wi-Fi gateway for remote access and your event logs and remote commands start passing through the platform’s cloud, wherever that platform hosts it.
I’ve seen Häfele smart locks — where’s that data?
Häfele’s ‘Smart Living’ range appears to be a Tuya white-label. Tuya maps users to regional data centres, and an Australian account usually lands in Singapore or the US rather than mainland China — but the assigned region isn’t published per product, and the parent company is Chinese, so the jurisdiction point still applies. There’s more in our TTLock vs Tuya comparison.
Related Guides
The full cross-platform comparison including the security and data sovereignty table.
How the TTLock platform works, its China hosting, and its full published CVE disclosure.
A direct comparison of the two major Chinese platforms — architecture, security and data sovereignty.
The companion piece on the Cyber Security Rules 2025 and Yale’s compliance declarations.
A scenario-based decision guide matching platform to buyer — Airbnb, residential, commercial and NDIS.
Want a Lock That Keeps Your Data Where You Can Reach It?
Tell us how you’ll use it and we’ll match you to a platform — trusted-jurisdiction, no-cloud, or whatever fits your situation.
Ask an ExpertVisit Australia’s leading Smart Lock showroom and workshop:
Gold Coast Smart Locks
9/2 Prosper Crescent
Burleigh Heads, QLD
See working models, compare gateways, and get real advice before you commit.

Disclaimer: Data-hosting details are based on each vendor’s own published documentation at the time of writing and can change; verify the current privacy notice for the exact product before making a decision where data jurisdiction is critical. This post describes legal environments and vendor practices, not proven misconduct by any company, and it is not legal advice. For a specific compliance or procurement question, consult a qualified professional.
