C-DRONE GUIDE · 3 SEPTEMBER 2026
Data security and Chinese drones (DJI): what businesses and local authorities should check in 2026
A large majority of the professional drones used in France carry a Chinese brand, DJI foremost — a fact that raised almost no eyebrows three years ago. In 2026, the question has changed shape: an audit commissioned by the French Interior Ministry flagged grey areas in the DJI Assistant software, the United States added all foreign-made drones and critical UAS components to the FCC's "covered" list at the end of December 2025, and the European Commission is preparing an "EU Trusted Drone" label for the end of the year. For a business or local authority buying a drone service — or arming its own fleet — these three signals converge on the same practical question: what do we actually know about where the collected data travels, and should that be spelled out in a tender specification?
Published on 3 September 2026, reviewed on 3 September 2026 — regulations in force as of September 2026.
What the Interior Ministry's audit found on DJI drones
The Interior Ministry, which was preparing to renew part of its drone fleet through DJI, commissioned a technical audit of the Chinese manufacturer before deciding. The findings focus first on the DJI Assistant software, used to update the aircraft's firmware: part of its operation is obfuscated, preventing precise analysis of what it does on the machine and what data it handles. The audit also points to a precedent: DJI's Aeroscope drone-detection unit transmitted usage data to servers in China for years — position, speed, serial number, drone model, and even the exact GPS position of the ground pilot.
A second, more recent signal illustrates the same risk from a different angle: in June 2026, a security flaw on DJI's SkyPixel sharing platform exposed the email addresses of tens of thousands of users, including accounts belonging to government administrations, emergency services and public bodies in several countries. This is not proof of organised espionage — DJI routinely disputes such claims — but a reminder that a professional drone's exposure surface reaches far beyond the flight itself: companion app, cloud platform and firmware update are each a data channel in their own right.
In the United States, the late-2025 regulatory shift and DJI's legal challenge
The most concrete signal comes from the United States. The National Defense Authorization Act (NDAA) required a national-security review of DJI and its Chinese rival Autel within one year. On 21 December 2025, a White House-convened interagency body issued an adverse determination, and the very next day the FCC (the US telecoms regulator) added all foreign-made drones and critical UAS components to its "Covered List" — the register of equipment deemed a national-security risk. In practice, DJI can no longer obtain approval for new models, radios or radio components in the US, which effectively blocks the legal import of new hardware. The list does not, however, give the FCC power to remotely disable or ground drones already in service: existing fleets keep flying.
DJI disputes the decision: the company filed a petition for review with the Ninth Circuit Court of Appeals on 20 February 2026, and the public-comment window on the reconsideration request closed on 11 May 2026. The outcome remains open as this guide is written. This US case has no direct regulatory translation in France — no French text bans the professional use of DJI drones today — but it already weighs on decisions: major public buyers and insurers are watching this precedent closely, and several French local authorities have started asking their providers about equipment origin even before any legal obligation exists.
What digital-forensics research shows about DJI drones
The debate over Chinese drones is not just a matter of diplomacy: it also rests on an already solid body of scientific literature. A study by Fahad E. Salamh, M. Mahroof Mirza and Umit Karabiyik, published in 2021 in the journal Electronics, compared several digital-forensics software tools on a DJI Phantom 4 and a DJI Matrice 210: it documents precisely which flight, position and configuration data remain extractable from log files and the companion app, often without robust encryption (see the study on Google Scholar). A second study, by Zubair Baig, Majid Ali Khan, Nazeeruddin Mohammad and Ghassen Ben Brahim, published in 2022 in Sustainability, proposes machine-learning models to process at scale the data extracted this way from drones seized during investigations — proof, by the reverse use case, that this data exists, is structured, and is of primary interest to investigators (see the study on Google Scholar).
What this research mainly shows is that the same data richness that serves forensic police during an investigation can, conversely, escape the legitimate operator's control if the manufacturer — or any third party with access to the firmware — chooses to exploit it. That is exactly the concern raised by the obfuscated software flagged in the Interior Ministry's audit: a black box that cannot be audited by its own operator is, by construction, a black box whose behaviour cannot be guaranteed.
The coming "EU Trusted Drone" label and European alternatives
On the European side, the response currently takes the shape of a label rather than a ban: the European Commission is preparing an "EU Trusted Drone" label, expected by the end of 2026, meant to identify equipment whose supply chain and electronic components have undergone enhanced security screening. The stakes are not purely defensive: MEPs are also pushing to develop alternative component sources and recycling capacity for critical raw materials, after China began restricting exports of drone components and rare earths to Ukraine and several Western buyers — a reminder that dependence plays out on the hardware supply side too, not only in software.
On the ground, France already has a manufacturer ticking part of these boxes: Parrot, whose data-processing chain is designed to stay under European control, is gaining traction for sensitive missions — Seveso sites, critical infrastructure, homeland-security tenders — even though its range remains narrower than DJI's catalogue on some fronts (range, endurance, entry-level price). For a routine mission, the choice of manufacturer is still mostly performance and price; it is on sensitive missions that equipment origin becomes a criterion in its own right.
What this changes in a tender specification or choosing a provider
For a local authority drafting a public tender for drone services, data security can now warrant its own clause in the tender specification, separate from the usual requirements (AlphaTango declaration, aerial liability insurance, pilot qualification). Three concrete points to have the bidder specify: where mission data is processed and stored — on the pilot's own device, on a French or European server, or on a manufacturer's cloud platform whose location remains uncertain; whether the drone can operate in local mode, without automatic syncing to a third-party app or cloud during the mission; and who has access to the firmware and its updates, with what traceability if it is modified.
For a private business, the stakes scale with how sensitive the site is: an SME subcontracting a roof orthophoto does not carry the same obligations as a top-tier Seveso site. But vigilance is growing fast on the buyer side: insurers and large industrial accounts are starting to ask, ahead of a tender, for a declaration on equipment origin — rare at the end of 2025, markedly more common a year later.
Method and price of a data-security audit in 2026
In practice, three services answer this rising demand: a fleet audit, reviewing equipment origin, firmware version and the exact data path between the drone, the companion app and the manufacturer's cloud, with recommendations for isolating or replacing the most exposed units; drafting a data-security clause for a tender specification or framework contract, turning these requirements into verifiable criteria without unfairly ruling out DJI-equipped providers who can demonstrate compliance; and, for the most sensitive missions, a disconnected-mode flight — equipment offline for the whole mission, data transferred manually on landing —, the simplest and cheapest safeguard regardless of manufacturer.
The regulatory information on this page reflects the situation known in September 2026; DJI's legal challenge in the US courts and the timeline of the European label may still change this framework.
Orders of magnitude observed in 2026 (excl. VAT):
| Service | Observed price (excl. VAT) |
|---|---|
| Fleet data-security audit (up to 10 units) | €1,500 to €3,500 |
| Drafting a data-security clause for a tender specification | €600 to €1,500 |
| One-off disconnected-mode mission (sensitive site) | 15 to 30% surcharge on the standard rate |
| Support choosing a "sovereign" drone for a sensitive site | €500 to €1,200 |
Whether the request comes from a local authority preparing a public tender for drone services or a business securing its subcontractor chain, request a quote stating how sensitive the site is: that is what determines whether a simple contractual commitment suffices or a technical audit is warranted. Our reference guide to 2026 drone regulations places this topic within the full framework applicable to professional operators.
Put it into practice
- Drone security & surveillance: rates and cities covered from €600
- Security & surveillance in Blois Centre-Val de Loire
- Security & surveillance in Angoulême Nouvelle-Aquitaine
- Security & surveillance in Chartres Centre-Val de Loire
Also worth reading
- Drone Services in Tarn-et-Garonne (82): Orchards, River Confluences, Golfech and the Garonne Canal
- Drone Services in Saône-et-Loire (71): Nuclear Forging, the Kodak Brownfield, Côte Chalonnaise Vineyards and the Navigable Saône
- Drone Services in Doubs (25): Vauban Citadel, Microtechnology, Sochaux and the High Jura