The app “Amap” (高德地圖) has recently sparked a cybersecurity controversy in Taiwan. Amap, fully owned by China’s Alibaba Group, is an online map that features traffic light countdown and lane-level guidance. A government security review found nine out of fifteen indicators about the app that flagged as high-risk—including continuous transmission of user data to Chinese servers, even when the application is closed. This controversy, together with Singapore-based Grab’s USD 600 million acquisition of Foodpanda’s Taiwan operations (a food delivery platform with the highest market share in Taiwan), has exposed a gap in Taiwan’s regulatory framework: the governance of geospatial data. These two cases point to the same underlying reality—mapping data, location tracking, and movement traces are not merely commercial assets, but core issues of national security and digital sovereignty.
At the micro level, what logistics companies collect are individual location data and behavioral patterns. Yet when aggregated, these data points allow platforms to infer identifiable object flow patterns and infrastructure distribution. The key lies not in the data itself, but in its “inferability”––i.e., the capability to analyze specific entity or individuals based on data aggregation. A single data point may be harmless, but when data reaches sufficient scale and depth of integration, platforms acquire the capacity to map how a society operates. This inferential capacity is what concerns the strategic value of geospatial data—and it is the common thread of the two cases in this article.
Two Concerning Cases
Amap released traffic-light countdown and 3D street view functions in Taiwan in April, which immediately went viral on social media. However, when tested by the National Security Bureau (NSB, 國家安全局) against fifteen cybersecurity criteria, nine categories were flagged as high-risk—including the continuous collection and transmission of communications data and real-time audio and video to servers in China, even when the app was closed. Subsequently, the Ministry of Digital Affairs (數位發展部) identified Amap as a “product endangering national cybersecurity” under the Cybersecurity Management Act (資通安全管理法), prohibiting its use in all government institutions. Minister of National Defense Koo Li-hsiung (顧立雄) likewise issued a blanket ban on its use for military personnel.
On a parallel track, the Singaporean company Grab’s acquisition of Foodpanda’s Taiwan operations has elevated cross-border data governance to a new level. GrabMaps — Grab’s proprietary online map equipped with crowd-density and traffic-behavior features –– signed a memorandum of cooperation with the Chinese company Huawei’s Petal Maps in June 2025. Notably, with cloud storage hosted on Alibaba Cloud, Grab has claimed that this partnership does not cover Taiwan; however, without independent third-party auditing, it remains difficult to verify the data flow from an external vantage point. Grab’s announced acquisition of Foodpanda’s Taiwan business, if completed, would give Grab access to vast amounts of Taiwanese user data: including addresses, contact information, and consumption patterns. The problem is not whether Grab harbors any specific intent, but rather the risk that such concentrated and granular lifestyle data—held by a platform associated with Chinese digital infrastructure and capital structure — could more easily fall into the hands of adversarial actors.
Grab’s potential acquisition of Foodpanda has also stoked concerns of further consolidation in the food delivery market. Uber holds 13.5 percent of Grab’s shares and 19.5 percent of Delivery Hero (the parent firm of Foodpanda)’s shares –– creating a “triangular stake” in which the same shareholder sits on both sides of the transaction. In the past, Uber tried to acquire Foodpanda in Taiwan, which was rejected by Taiwan’s Fair Trade Commission (公平交易委員會) due to monopoly concerns. Additionally, with Uber directly holding Uber Eats—Foodpanda’s primary rival in Taiwan—and controlling Grab through its 13.5 percent stake, concerns over de facto market concentration are mounting. Furthermore, Grab’s ownership structure and technological collaboration have also fueled concerns regarding the security of Taiwanese user data. The Chinese company Didi Chuxing (滴滴出行) holds less than 5% of Grab’s shares, and GrabMaps maintains technical partnerships with the Chinese companies WeRide and Momenta for autonomous-vehicle development. In other words, Grab’s capital structure and technology ecosystem are closely connected to Chinese industry.
Amap and Foodpanda are not the same types of applications, and therefore pose different risks. Amap presents a direct technical risk, where software is programmed to transmit location data even when the app is closed, posing an immediate and verifiable threat. On the other hand, Grab represents an indirect structural risk, expressed through capital connections, technical cooperation, and cloud architecture—through which data may flow into adversarial legal jurisdictions.

Image: A partial map of downtown Taipei, produced by the “Amap” navigation app. (Image source: Amap.com)
Data Security in Mapping Platforms
Modern mapping platforms collect data that may have applications beyond normal commercial activity. Through aggregating millions of users’ locations, traffic flows, and movement traces, platforms can calculate traffic signal cycles, pedestrian flow patterns, and infrastructure operating rhythms. Given sufficient data, these inputs could be used to locate sensitive facilities. As noted in a report by Taiwan media outlet TVBS, correspondent Lin En-ru 林恩如 was able to find the exact location of military infrastructure in Taiwan through Amap. This illustrates the dual-use character of geospatial data: it is simultaneously a commercial asset and a strategic resource.
Central to the issue of data governance is legal jurisdiction—the dimension over which Taiwan currently lacks regulatory control regarding risks and scale, focusing instead on case-by-case management rather than holistic governance. As former RAND researcher Murray Scot Tanner has argued in Lawfare, China’s National Intelligence Law (國家情報法) shifts legal obligations from intelligence “defense” to “offense,” explicitly requiring any individuals, organizations or institutions –– whether private or state-funded ones –– to assist authorities in conducting intelligence work. If a large volume of Taiwanese user data falls within the People’s Republic of China’s (PRC) legal jurisdiction, companies may face significant legal pressure to comply with PRC government data access requests. Yang Chang-Jung (楊長蓉), an assistant research fellow at the Institute for National Defense and Security Research (國防安全研究院), commented: “When civilian data enters a system governed by another state’s national security or intelligence laws, it may be converted into intelligence assets of strategic value.”
Democratic Countries’ Approaches to Limiting Cross-Border Data Leaks
Taking a broad view of how democratic countries address PRC involvement in native applications, their strategies are different yet converging. The United States passed the Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACA) in 2024, mandating divestiture or a ban from the parent company. The European Union enacted the Digital Services Act (DSA), regulating platform transparency and systemic risk assessment.
Since the Sino-Indian Galwan Valley conflict in 2020, India has invoked Section 69A of the Information Technology Act to ban more than 300 applications progressively, including TikTok and WeChat.
In Taiwan, the government has invoked the Cybersecurity Management Act to identify Amap as a product threatening national cybersecurity, prohibiting its use across government institutions. However, the legislation primarily focuses on national-level regulation, with relatively limited attention to the disclosure of data flow and access permissions on private-sector platforms. More fundamentally, the current measures are designed for confronting individual cases—which come to the fore only after a risk is identified. Specifically, the risks associated with inferability from geospatial data are always accumulating, and it is therefore hard to regulate against vulnerabilities which have not yet been described.
Recommendations for Shoring Up Taiwan’s Geospatial Data Security
What Taiwan needs is not just a response to individual cases, but a systemic review framework. The following recommendations should therefore be considered:
First, establish tiered cybersecurity standards for software. The Cybersecurity Management Act applies primarily to government institutions, leaving civilian applications without a unified regulatory baseline. The government should specifically define which categories of data are considered sensitive geospatial information—including real-time location data, high-precision mapping of areas adjacent to military facilities, and movement traces linked to personal identity—and impose tiered disclosure obligations on platforms accordingly.
Second, introduce mandatory auditing and data localization requirements. In the same vein as the European Union’s regulations for very large online platforms under the DSA, Taiwan can mandate platforms above a certain user threshold—or those handling sensitive geospatial data—to undergo periodic independent third-party audits disclosing storage locations, backend technical architecture, and explanation of cross-border data sharing arrangements. Currently, the Ministry of Digital Affairs already has the institutional standing to serve as the leading body, but lacks statutory authorization to conduct these measures.
Third, the shareholding structure of foreign investors should be incorporated into platform risk assessments. The existing framework for reviewing foreign acquisitions focuses primarily on market competition, with data security treated as a secondary consideration. The Committee on Foreign Investment in the United States (CFIUS) could be a feasible reference for the Taiwanese government. CFIUS incorporates foreign ownership interest, control rights, and access to sensitive data as risk assessment criteria in platform acquisitions involving large volumes of user data.
Conclusion
The Amap and Grab cases not only present cybersecurity concerns, but raise the broader question of how democratic societies maintain governance capacity in a digital era. In recent years, Taiwan has prioritized semiconductor and hardware supply chain security, yet it still lacks a comprehensive policy framework for the strategic value of soft infrastructure such as mapping, location, and movement data. What the Amap controversy and the Grab acquisition expose is not merely a single-platform problem: instead, it reveals Taiwan’s institutional gap in cross-border data and digital infrastructure governance.
The main point: The Amap controversy and Grab’s acquisition of Foodpanda Taiwan reveal a shared institutional gap: Taiwan currently lacks the legal instruments to track, audit, or intervene in the accumulation of geospatial inferential capacity by platforms connected to foreign technology and legal frameworks. Taiwan should establish tiered cybersecurity standards for civilian applications, mandatory independent auditing for large-scale platforms, and incorporate foreign equity structures into data security reviews of platform acquisitions.