Posted in

Data Security Review in China: CAC-Led Controls for 2026

  • China’s data-security review is led by the CAC under the 2022 《网络安全审查办法》, reinforced by the 2021 《数据安全法》 and 《个人信息保护法》, all in force through 2026.
    中国的数据安全审查由网信办依据2022年《网络安全审查办法》主导,并辅以2021年《数据安全法》与《个人信息保护法》,上述规则在2026年持续有效。
  • Network security review is mandatory for CII operators procuring network products/services that may affect national security, and for platforms holding over one million users’ personal information seeking overseas listing.
    网络安全审查对采购可能影响国家安全的网络产品/服务的关基运营者,以及拟境外上市、掌握超100万用户个人信息的平台具有强制性。
  • A “data export” security assessment by the CAC is required before important data or large-scale personal information leaves China, gating many inbound and outbound deals.
    重要数据或大规模个人信息出境前,须通过网信办的数据出境安全评估,这构成众多境内外交易的关口。
  • As of 2026, review focus has sharpened on cross-border data flows, algorithm filing, and the security of core data centres and cloud services.
    截至2026年,审查重点已聚焦跨境数据流动、算法备案,以及核心数据中心与云服务的安全。
  • Deal teams must screen data assets for “important data” classification and build CAC assessment timelines into the transaction schedule.
    交易团队须对数据资产是否构成”重要数据”进行筛查,并将网信办评估时限纳入交易时间表。
  • Penalties for non-compliance include rectification, suspension of data-export activities, fines, and in serious cases criminal referral.
    违规后果包括责令改正、暂停数据出境活动、罚款,严重者移送刑事处理。

Data Security Review in China: CAC-Led Controls for 2026 | 中国数据安全审查:2026年网信办主导的管控

The Legal Triad

China’s data governance rests on three pillars, all operative in 2026:

  • The 《网络安全法》 (Cybersecurity Law, effective 1 June 2017);
  • The 《数据安全法》 (Data Security Law, effective 1 September 2021);
  • The 《个人信息保护法》 (PIPL, effective 1 November 2021).

These are implemented and enforced, for security-review purposes, primarily by the Cyberspace Administration of China (CAC, 国家互联网信息办公室). The central procedural instrument is the 《网络安全审查办法》 (Network Security Review Measures), revised by the CAC with twelve other departments and effective from 1 June 2022 (CAC Order No. 8).

When Network Security Review Is Mandatory

Two scenarios trigger a mandatory CAC-led review:

  1. Critical Information Infrastructure (CII) operators procuring network products or services that may affect national security. The CII operator must apply for review through its industry regulator; the product or service cannot be procured before clearance.
  2. Platform operators with personal information of more than one million users that seek an overseas listing (initial public offering outside mainland China). Such a listing requires a CAC security review beforehand.

The review examines risks of control by foreign governments, data tampering or leakage, supply-chain disruption, and the concentration of important data.

Data Export Security Assessment

Perhaps the most transaction-relevant mechanism is the CAC’s security assessment for cross-border data transfers. Under PIPL and the Data Security Law, before “important data” or large volumes of personal information are transferred outside China, the handler must pass a CAC-led assessment (or meet an alternative pathway such as certification or a standard contract, subject to thresholds). For market entrants, this gates:

  • Sharing group data with an overseas parent;
  • Cloud or SaaS arrangements routing data offshore;
  • M&A where the target’s data must be integrated into a foreign group.

The assessment evaluates the necessity of the transfer, the volume and sensitivity of data, and the protection level in the receiving jurisdiction.

2026 Enforcement Emphasis

Entering 2026, CAC activity has concentrated on:

  • Cross-border flow governance, including tightening of important-data inventories and the promotion of free-trade-zone “negative lists” for data export;
  • Algorithmic governance, with the 2022 《互联网信息服务算法推荐管理规定》 requiring algorithm filing for recommendation services;
  • Core infrastructure security, covering data centres, cloud, and large-platform resilience.

The through-line is that data is treated as a sovereign asset: control over it, and its movement across borders, is a national-security question, not merely a privacy one.

Practical Steps for Entrants

  1. Classify the data. Determine whether the target holds “important data” or “core data”, and quantify personal-information volumes against the one-million-user and export thresholds.
  2. Map transfer pathways. Identify every outbound flow—group reporting, vendor access, cloud replication—and match it to the correct mechanism (assessment, certification, standard contract).
  3. File early for listings. Any overseas IPO by a qualifying platform must clear CAC review before launch.
  4. Negotiate the SPA. Make data-export clearance a condition precedent and allocate remediation costs.
  5. Localise where needed. In-sector data centres and in-China storage reduce exposure.

Consequences of Non-Compliance

CAC can order rectification, suspend data-export activities, confiscate unlawful gains, and impose fines reaching significant sums; serious cases may trigger criminal referral. For an acquirer, unmitigated data-export risk can destroy the value of a data-rich target and delay or block an overseas listing. Treating data-security review as a parallel, co-equal workstream to antitrust and foreign-investment review is now standard prudence.


中国数据安全审查:2026年网信办主导的管控

法律三重支柱

中国数据治理建立在三大支柱之上,均于2026年有效:

  • 《网络安全法》(2017年6月1日施行);
  • 《数据安全法》(2021年9月1日施行);
  • 《个人信息保护法》(2021年11月1日施行)。

就安全审查而言,上述法律主要由国家互联网信息办公室(网信办)实施与执行。其核心程序性文件是《网络安全审查办法》——由网信办联合其他十二部门修订,自2022年6月1日起施行(第8号令)。

网络安全审查的强制触发

两类情形触发网信办主导的强制性审查:

  1. 关键信息基础设施运营者采购可能影响国家安全的网络产品或服务。关基运营者须通过行业主管部门申报审查,且在获批前不得采购该产品或服务。
  2. 掌握超过100万用户个人信息的平台运营者拟赴境外上市(在中国大陆以外首次公开发行)。此类上市须事先通过网信办安全审查。

审查评估被外国政府控制、数据被篡改或泄露、供应链中断,以及重要数据集中等方面的风险。

数据出境安全评估

最具交易相关性的机制,或许是网信办主导的数据出境安全评估。依据《个人信息保护法》与《数据安全法》,在”重要数据”或大规模个人信息向境外提供前,处理者须通过网信办评估(或满足认证、标准合同等替代路径,并受门槛限制)。对市场准入者而言,这构成以下交易的关口:

  • 与境外母公司共享集团数据;
  • 将数据离岸路由的云或 SaaS 安排;
  • 标的的数据须并入外国集团的并购交易。

评估考察传输的必要性、数据的体量及敏感性,以及接收方所在法域的保护水平。

2026年执法重点

进入2026年,网信办的工作集中于:

  • 跨境流动治理,包括收紧重要数据目录,并推动自贸试验区数据出境”负面清单”;
  • 算法治理,依据2022年《互联网信息服务算法推荐管理规定》对推荐服务实行算法备案;
  • 核心基础设施安全,涵盖数据中心、云及大型平台韧性。

其内在逻辑在于:数据被视为一种主权资产——对其的控制及跨境流动,是一个国家安全问题,而非单纯的隐私问题。

市场准入实务步骤

  1. 对数据分类。 判定标的是否持有”重要数据”或”核心数据”,并量化个人信息体量,对照100万用户及出境门槛。
  2. 梳理传输路径。 识别每一处出境流向——集团报告、供应商访问、云端复制——并匹配正确机制(评估、认证、标准合同)。
  3. 上市前尽早申报。 符合条件的平台赴境外上市须在启动前通过网信办审查。
  4. 协商协议条款。 将数据出境审批设为先决条件,并分配补救成本。
  5. 必要时本地化。 境内数据中心与境内存储可降低风险敞口。

违规后果

网信办可责令整改、暂停数据出境活动、没收违法所得,并处以可观罚款;严重者可移送刑事处理。对收购方而言,未缓释的数据出境风险可能摧毁数据富集型标的的价值,并拖延或阻断境外上市。将数据安全审查视为与反垄断、外商投资审查并行且同等重要的工作流,已成为标准审慎做法。

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *