Posted in

Investment and Data Security Review in China: The 2026 Compliance Matrix

  • The CAC’s Action Plan for Promoting High-Quality Development of Internet Enterprises (2026-2030), issued on 21 August 2026, commits to efficient implementation of data-export security assessments, standard contracts and certification, and to FTZ data-export negative lists and cross-border data service centres.
    中央网信办 2026 年 8 月 21 日印发《促进网信企业高质量发展行动计划(2026-2030 年)》,承诺高效实施数据出境安全评估、个人信息出境标准合同、个人信息出境认证等制度,支持自贸区发布数据出境负面清单、设立数据跨境服务中心。
  • The first batch of data-export security assessment results, mostly issued in 2023, are expiring in 2026: extensions must be requested within 60 working days before expiry, meeting six conditions including a cap of 20% growth over three years.
    首批数据出境安全评估结果(多在 2023 年出具)2026 年集中到期:须在有效期届满前 60 个工作日内申请延期,同时满足六项条件(含未来三年出境数量增幅不超过原准予数量的 20%)。
  • Foreign investment security review is controller-piercing and substance-over-form: the April 2026 prohibition of a foreign takeover of a Chinese-founded AI company illustrates that review extends to indirect transactions over Chinese-controlled assets.
    外商投资安全审查遵循穿透式、”实质重于形式”原则:2026 年 4 月对一起收购中国背景 AI 公司交易的禁止投资决定显示,审查延伸到涉及中国控制资产的间接交易。
  • Under the Foreign Investment Security Review Measures (effective January 2021), investment in military-related or critical sectors (important IT and internet products, key technologies, etc.) that obtains de facto control must be declared before implementation.
    依《外商投资安全审查办法》(2021 年 1 月施行),投资军工及关系国家安全的重要信息技术和互联网产品与服务、关键技术等重要领域并取得实际控制权的,应在实施投资前主动申报。
  • The four-part review matrix for foreign companies covers: foreign investment security review, cyber-security review (for platforms with over one million users going offshore), data-export security assessment and the network data security risk assessment regime.
    外资企业面对的”四大安全审查”矩阵包括:外商投资安全审查、网络安全审查(超 100 万用户平台赴国外上市)、数据出境安全评估与网络数据安全风险评估制度。
  • For foreign-invested companies, the 2026 checklist is to audit assessment expiry dates, map data flows against the three export routes, confirm security-review thresholds for any offshore listing or sensitive acquisition, and monitor CAC and NDRC implementation guidance.
    对外资企业,2026 年合规清单是:核查评估到期日、对照三条出境路径映射数据流、确认境外上市或敏感并购的安全审查门槛、跟踪网信办与发改委实施指引。

Investment and Data Security Review in China: The 2026 Compliance Matrix | 中国投资与数据安全审查:2026 年合规矩阵

Why this matters now

Two developments in 2026 concentrate the security-review agenda for foreign-invested companies. First, on 21 August 2026 the Office of the Central Cyberspace Affairs Commission (CAC) issued the Action Plan for Promoting High-Quality Development of Internet Enterprises (2026-2030), which commits to efficiently implementing data-export security assessments, personal-information-outbound standard contracts and personal-information-outbound certification, supporting FTZs in issuing data-export negative lists and encouraging data cross-border service centres. Second, the first batch of data-export security assessment results — mostly issued in 2023 — are expiring in 2026, forcing companies through the extension or re-application window. Separately, the April 2026 decision by the Foreign Investment Security Review Working Mechanism Office (NDRC) to prohibit a foreign acquisition of a Chinese-founded AI company demonstrates the reach of foreign investment security review. This article maps the four-part compliance matrix and the practical calendar.

The four-part review matrix

For a foreign-invested company, four regimes intersect. First, foreign investment security review under the Measures (NDRC and MOFCOM Order, effective 18 January 2021): investment in military-related fields, or in critical sectors — important agriculture, energy and resources, major equipment manufacturing, critical infrastructure, key transport services, important culture products, important IT and internet products and services, important financial services, key technologies and other important fields — that obtains actual control must be declared before implementation. Review is substance-over-form and controller-piercing: the April 2026 prohibition decision applied to a transaction between two foreign parties because the underlying assets, technology and data originated in China. Second, cyber-security review under the Cyber Security Review Measures (2021): network platform operators holding data of more than one million users must declare before going public abroad. Third, data-export security assessment under the Data Export Security Assessment Measures and the Promoting and Regulating Cross-Border Data Flow Provisions: critical information infrastructure operators, important data exports, and personal-information exports above volume thresholds must pass assessment. Fourth, the network data security risk assessment regime introduced by the Measures on Network Data Security Risk Assessment (effective 20 August 2026): important data processors must conduct an annual assessment.

The 2026 expiry wave and the extension conditions

The first batch of data-export security assessment results was mostly issued in 2023. Under Article 9 of the Provisions, the assessment result is valid for three years from issuance; the validity period was extended from two to three years by the March 2024 Provisions. Companies wishing to continue exporting must apply for an extension within 60 working days before expiry, through the provincial cyberspace administration to the national office. Six conditions must all be met: the purpose and scope of data export are unchanged; the data processor and overseas recipient are unchanged; for personal information, the number of individuals involved over the next three years does not exceed 20% of the amount approved in the original assessment; for important data, the volume growth over three years does not exceed 20%; the legal documents with the overseas recipient comply with Article 9 of the Measures; and no major data-security incident occurred during the past three years. Where any condition fails, the company must re-apply, a longer process.

The CAC action plan and data-flow facilitation

The CAC’s 2026-2030 action plan, issued 21 August 2026, signals both enforcement and facilitation. It commits to guiding internet enterprises to establish sound data-security compliance systems, efficiently implementing the three data-export routes, supporting FTZs in issuing data-export negative lists under the national classification system, organising industry-specific guidelines on cross-border data flows, and encouraging regions to set up data cross-border service centres. For foreign-invested companies, this means the three-route framework will be administered more efficiently, but compliance obligations are not relaxed — the plan also calls for cracking down on data-related violations.

Practical calendar for foreign companies

First, locate every data-export security assessment notice and check its issue date; calendar the 60-working-day extension window before expiry. Second, run the six-condition self-check for extension eligibility; where growth will exceed 20% or other conditions fail, budget for a full re-application. Third, map data flows against the three routes — security assessment, standard contract (with provincial filing within 10 working days of execution) and certification — and confirm which applies to HR data, global-system access and SaaS operations. Fourth, for any offshore listing or acquisition of a sensitive-sector target, assess cyber-security review and foreign investment security review thresholds before signing. Fifth, monitor CAC Q&A releases (the July 2026 Q&A clarified extension conditions) and NDRC guidance. Sixth, for important-data processors, complete the first annual network data security risk assessment under the regime effective 20 August 2026.

Compliance notes

Extension is not automatic: approval is discretionary and re-application is materially longer, so start compliance self-audits six months before expiry. The 20% growth cap is measured against the amount approved in the original assessment, not current volumes, and companies should keep annual data-transfer ledgers. Foreign investment security review applies to indirect and “substance-over-form” transactions; the April 2026 prohibition shows that Chinese-founded, Chinese-asset AI companies remain in scope even after restructuring abroad. Finally, the security-review landscape is evolving — the CAC plan and pending sectoral data-classification catalogues will reshape the map, so treat 2026 as a year for proactive mapping rather than reactive compliance.


中国投资与数据安全审查:2026 年合规矩阵

为什么当下重要

2026 年两项动态把安全审查议程推到外资企业面前。其一,2026 年 8 月 21 日,中央网络安全和信息化委员会办公室印发《促进网信企业高质量发展行动计划(2026-2030 年)》,承诺高效实施数据出境安全评估、个人信息出境标准合同、个人信息出境认证等制度,支持自贸区发布数据出境负面清单,鼓励设立数据跨境服务中心。其二,首批数据出境安全评估结果(多在 2023 年出具)2026 年集中到期,迫使企业进入延期或重新申报窗口。此外,2026 年 4 月外商投资安全审查工作机制办公室(国家发展改革委)对一起外国企业收购中国背景 AI 公司的交易作出禁止投资决定,展示了外商投资安全审查的穿透范围。本文梳理四大审查矩阵与实务时间表。

四大审查矩阵

对外资企业,四个制度相交织。其一,《外商投资安全审查办法》(国家发展改革委、商务部令,2021 年 1 月 18 日施行)下的外商投资安全审查:投资军工领域,或投资关系国家安全的重要农产品、重要能源和资源、重大装备制造、重要基础设施、重要运输服务、重要文化产品与服务、重要信息技术和互联网产品与服务、重要金融服务、关键技术等重要领域并取得实际控制权的,须在实施投资前申报。审查”实质重于形式”且穿透式:2026 年 4 月禁止决定适用于两个境外主体之间的交易,因为底层资产、技术与数据源于中国。其二,《网络安全审查办法》(2021 年修订)下的网络安全审查:掌握超 100 万用户个人信息的网络平台运营者赴国外上市前须申报。其三,《数据出境安全评估办法》及《促进和规范数据跨境流动规定》下的数据出境安全评估:关键信息基础设施运营者、重要数据出境、超数量阈值个人信息出境须通过评估。其四,《网络数据安全风险评估办法》(2026 年 8 月 20 日施行)确立的网络数据安全风险评估制度:重要数据处理者须开展年度评估。

2026 到期潮与延期条件

首批数据出境安全评估结果多在 2023 年出具。依《规定》第九条,评估结果自出具之日起 3 年内有效(2024 年 3 月《规定》将有效期由 2 年调整为 3 年)。企业继续出境的,须在有效期届满前 60 个工作日内,经所在地省级网信部门向国家网信部门提出延期申请。六项条件须同时满足:数据出境目的、范围未变化;数据处理者与境外接收方未变化;出境个人信息的,未来三年涉及自然人数量增幅不超过原评估结果准予过去三年出境数量的 20%;出境重要数据的,未来三年出境数据规模增幅不超过 20%;与境外接收方订立的法律文件符合《办法》第九条;过去三年按评估结果合规开展且未发生重大数据安全事件。任一项不满足即须重新申报,周期明显更长。

网信办行动计划与数据流动便利化

网信办 2026-2030 行动计划(8 月 21 日印发)释放执法与便利双重信号。它承诺引导网信企业建立健全数据安全合规体系,高效实施三条数据出境路径,支持自贸区在国家数据分类分级保护制度框架下制定发布数据出境负面清单,组织重点行业制定网络数据跨境流动合规指引,鼓励有条件地区设立数据跨境服务中心。对外资企业,这意味着三条路径管理更高效,但合规义务并未放松——计划同时要求依法严厉打击涉数据违法犯罪活动。

外资企业实务时间表

其一,找出每份数据出境安全评估通知书并核对出具日期;在到期前把 60 个工作日延期窗口列入日历。其二,按六项条件自检延期资格;增长率将超 20% 或其他条件不满足的,为完整重新申报做预算。其三,对照三条路径——安全评估、标准合同(签署后 10 个工作日内省级备案)、认证——映射数据流,确认 HR 数据、全球系统访问与 SaaS 运营适用哪条。其四,任何境外上市或敏感行业标的收购,签署前评估网络安全审查与外商投资安全审查门槛。其五,跟踪网信办问答(2026 年 7 月问答已明确延期条件)与发改委指引。其六,重要数据处理者须在 8 月 20 日生效制度下完成首次年度网络数据安全风险评估。

合规提示

延期非自动:批准存在裁量空间,重新申报周期显著更长,建议在到期前 6 个月启动合规自检。20% 增幅上限以原评估结果准予的数量为基准而非当前数量,企业应留存逐年数据出境台账。外商投资安全审查适用于间接与”实质重于形式”的交易;2026 年 4 月禁止决定表明,中国创始、中国资产的 AI 公司即使在境外重组后仍在审查范围。最后,安全审查版图仍在演进——网信办行动计划与待出台的行业数据分类目录将重塑地图,2026 年应视为主动映射之年而非被动合规之年。

Sources