TAIPEI (Taiwan News) — China’s Amap (Gaode) has come under scrutiny after tests showed it uploads user data roughly every three seconds and contains a device identifier that persists even after reinstalling, The Reporter reported Friday.
The app, a widely used navigation service developed by Alibaba Group, surged in Taiwan’s app rankings in late April, with some users praising its detailed traffic features and real-time driving assistance.
Taiwan’s National Security Bureau flagged the app in May as a potential cybersecurity risk. The Ministry of Digital Affairs later confirmed that Amap requests permissions unrelated to its core functions and may transmit data when not in use.
To assess its behavior, The Reporter said it conducted a test using identical phones, routes, and network conditions, comparing Amap with Google Maps and Taiwan’s NaviKing 3D. The analysis tracked transmission frequency and server destinations.
The results showed Amap sent data to external servers about once every three seconds, significantly more frequently than Google Maps, which transmitted at roughly 30-second intervals. NaviKing 3D updates about every 22 minutes.
Researchers also identified a fixed device identifier in Amap’s data packets known as “CAID,” which remained unchanged even after reinstalling the app. In tests, the identifier persisted unless the device was fully reset, raising concerns it could function as a form of device fingerprinting.
Amap also transmitted not only location data but additional sensor information, including movement direction and altitude, according to packet analysis. All observed server connections were routed to Alibaba Cloud infrastructure in China.
On May 27, the Ministry of Digital Affairs reported eight risk behaviors on iOS devices, including access requests unrelated to navigation functions and reading device identifiers. Amap’s privacy policy states that it may share personal information, including location and usage behavior, with companies and partners in China and abroad for service and security purposes.
Taiwanese officials have since classified Amap as a cybersecurity-risk product for government use, while legal experts note challenges for companies without a local presence in Taiwan.





