China’s cyberspace regulator has released a draft rule for “large personal-information processors,” consolidating two earlier platform-focused drafts into one accountability regime for the biggest data holders.国家网信部门发布《大型个人信息处理者个人信息保护规定(征求意见稿)》,将早前两份聚焦平台的规定整合为面向最大规模数据处理者的统一责任制度。 A processor handling over 10 million individuals’ personal information, or meeting other significance tests, … China’s Draft Rule for Large Personal-Information Processors: What Foreign-Invested Platforms and Apps Need to KnowRead more
Data Export
Cybersecurity Review and Critical Information Infrastructure Procurement Compliance for Foreign-Invested Enterprises
The Cybersecurity Review regime applies whenever a Critical Information Infrastructure (CII) operator procures network products or services that may affect national security — and foreign-invested enterprises supplying those products are squarely within scope. 当关键信息基础设施(CII)运营者采购可能影响国家安全的网络产品与服务时,网络安全审查制度即被触发;向这些运营者供应产品的外商投资企业同样被直接纳入监管视野。 The legal backbone is the Cybersecurity … Cybersecurity Review and Critical Information Infrastructure Procurement Compliance for Foreign-Invested EnterprisesRead more
Data Classification, Grading and Critical Information Infrastructure Obligations for Foreign-Invested Enterprises
China mandates a data classification and grading (数据分类分级) baseline; the national standard GB/T 43697-2024 took effect on 1 October 2024. 中国确立了数据分类分级基线制度,国家标准GB/T 43697-2024于2024年10月1日施行。 The Network Data Security Management Regulations (State Council Order No. 790, effective 1 January 2025) require handlers to … Data Classification, Grading and Critical Information Infrastructure Obligations for Foreign-Invested EnterprisesRead more
China’s amended Cybersecurity Law in force from 1 January 2026: AI clauses, tenfold penalties and wider extraterritorial reach
The Decision amending the Cybersecurity Law was adopted on 28 October 2025 and takes effect on 1 January 2026, with 14 amendments and a reissued text. 修改《网络安全法》的决定于2025年10月28日通过、2026年1月1日起施行,共14项修改并重新公布。 A new Article 20 builds the first basic-law “development plus oversight” framework for … China’s amended Cybersecurity Law in force from 1 January 2026: AI clauses, tenfold penalties and wider extraterritorial reachRead more
China’s Network Data Security Regulation: what foreign-invested firms must do
China’s Network Data Security Regulation (State Council Order 790) took effect on 1 January 2025, turning the Cybersecurity Law, Data Security Law and PIPL into operational, enforceable obligations for every network data processor — including foreign-invested firms. 《网络数据安全管理条例》(国务院令790号)自 2025 年 … China’s Network Data Security Regulation: what foreign-invested firms must doRead more
Cross-border data: scenario-based, field-level negative lists
The 2026 action plan supports FTZs and service-opening pilot cities in exploring scenario-based, field-level data-export negative lists. 2026年行动方案支持自贸区、服务业扩大开放试点城市在更多领域制定场景化、字段级数据出境负面清单。 National standards for “important data” identification catalogs will be promoted for eight industries (industrial, telecom, geoinformation, automotive, pharma, seeds, aerospace, civil aviation). … Cross-border data: scenario-based, field-level negative listsRead more
Cross-border data transfer rules (PIPL)
Under PIPL (in force 1 Nov 2021), personal information may leave China only through one of three mechanisms: a CAC security assessment, a standard contract (SCC), or certification. 依《个人信息保护法》(2021 年 11 月 1 日施行),个人信息出境仅可经三种机制之一:安全评估、标准合同或认证。 The applicable route is driven mainly … Cross-border data transfer rules (PIPL)Read more
FTZ Data-Export Negative Lists Accelerate: Beijing, Hengqin, Chongqing and Nansha Go Live
China’s free-trade-zone (FTZ) data-export negative-list mechanism is moving from policy design to live, enforceable cases. 自贸试验区数据出境负面清单机制正从制度设计走向可落地的实际案例。 Beijing, Hengqin (Guangdong), Chongqing and Nansha (Guangzhou) have each recorded its first negative-list data-export case. 北京、横琴(广东)、重庆、南沙(广州)均已出现首单负面清单数据出境案例。 Beijing’s “Two Zones” negative list (May 2026) adopts … FTZ Data-Export Negative Lists Accelerate: Beijing, Hengqin, Chongqing and Nansha Go LiveRead more
FTZ Data Export Negative List and Facilitated Cross-Border Channels
The CAC “Provisions on Promoting and Regulating Cross-Border Data Flows” (CAC Decree No. 16, 22 March 2024) let free-trade zones formulate their own data-export negative lists under the national data classification framework. 国家网信办《促进和规范数据跨境流动规定》(2024年3月22日,第16号令)授权自由贸易试验区在国家数据分类分级保护制度框架下自行制定数据出境负面清单。 A free-trade zone’s negative list identifies the … FTZ Data Export Negative List and Facilitated Cross-Border ChannelsRead more
China’s Data Export Security Assessment Route (2026): a Field Guide for Foreign-Invested Enterprises
The security assessment is the highest-threshold of China’s three data-export routes and is mandatory when a Critical Information Infrastructure Operator (CIIO) exports personal information, or when any processor exports important data or large volumes of personal information. 安全评估是中国数据出境三条通道中门槛最高的一条,当关键信息基础设施运营者(CIIO)出境个人信息,或任何处理者出境重要数据、或大规模出境个人信息时,必须申报安全评估。 The statutory … China’s Data Export Security Assessment Route (2026): a Field Guide for Foreign-Invested EnterprisesRead more
