>
HomeServicesData ProtectionChina

Data Protection in China

An international technology company establishing a wholly foreign-owned enterprise (WFOE) in Shanghai discovers that its standard privacy policy – drafted under EU rules – is non-compliant from day one. China's data protection regime is distinct, detailed, and enforced by multiple government bodies with overlapping jurisdiction. The gap between a foreign company's existing compliance posture and what Chinese law actually demands is often wider than anticipated. Additionally. The cost of bridging it under regulatory scrutiny is significantly higher than building it correctly at the outset.

Data protection in China is governed by a trio of overlapping legislative regimes: the Personal Information Protection Law, the Data Security Law. Additionally, the Cybersecurity Law. All administered through a network of regulators including the Cyberspace Administration of China and the Guojia Shichang Jiandu Guanli Zongju (State Administration for Market Regulation, or SAMR). Compliance requires appointing a local data protection representative, classifying personal data by sensitivity and volume, implementing consent mechanisms, and completing mandatory security assessments before any cross-border transfer of personal information. Timelines for regulatory filings and standard contractual approvals can range from several weeks to several months depending on the mechanism used.

This page covers the core compliance instruments available to international businesses in China, common pitfalls that affect foreign-invested entities. Cross-border transfer obligations. Additionally, a practical self-assessment checklist. so that your organisation can evaluate its current exposure before regulators do.

The regulatory environment for data protection in China

China's data protection regime has matured rapidly. Three interlocking bodies of legislation. personal information protection legislation, data security legislation. Additionally. Cybersecurity legislation. create a comprehensive set of obligations that apply to any entity processing the personal information of individuals located in China, regardless of where the entity itself is incorporated.

The primary enforcer is the Cyberspace Administration of China (CAC), which operates at national and provincial level. SAMR exercises parallel jurisdiction over consumer data practices and unfair trading conduct tied to data misuse. Sector-specific regulators – including those overseeing finance, healthcare, and telecommunications – layer further requirements on top of the baseline regime. Foreign businesses that assume the CAC is their only compliance counterparty routinely underestimate the scope of their obligations.

The legislation draws a clear distinction between a data controller and a data processor. The data controller determines the purposes and means of processing; the data processor acts on the controller's instructions. In practice, a WFOE operating in China is typically classified as a data controller for the personal information it collects directly from users or employees. It may simultaneously act as a data processor when handling data on behalf of its foreign parent company. Both roles carry independent legal duties, and the failure to document which role applies in a given processing activity is one of the most frequently cited audit findings.

China's legislation also introduces the concept of important data – information that, if tampered with or leaked, could harm national security, the public interest, or citizens' rights. Important data attracts a more demanding compliance regime, including mandatory risk assessments and restrictions on cross-border flows. Businesses in sectors such as automotive, mapping, financial services, and healthcare face a near-certain obligation to classify at least some of their data as important. Failure to do so is not a technical oversight; it is treated as a deliberate compliance failure under the enforcement posture adopted by the CAC since 2022.

The State Council (China's cabinet) has issued implementing regulations that clarify thresholds for when a security assessment must be submitted to the CAC before data leaves China. These thresholds are tied to the volume of personal information processed over a rolling twelve-month period and to whether the data concerned qualifies as sensitive. Businesses that cross these thresholds without completing a prior security assessment face administrative penalties, suspension of data transfer activities, and potential reputational consequences with Chinese joint venture partners and customers.

Key compliance instruments and their practical application

International businesses operating in China have three principal mechanisms through which to legalise cross-border transfers of personal information. Choosing the right mechanism depends on data volume, sensitivity classification, business structure, and the jurisdiction of the receiving entity. Each mechanism has a distinct procedural path, cost profile, and timeline.

Security assessment (CAC filing). This is mandatory when the transferring entity processes personal information above prescribed volume thresholds, or when the transfer involves sensitive personal information or important data. The assessment involves preparing a detailed internal review of the transfer, the recipients' data protection measures, and the risks of re-transfer to third countries. The internal review is then submitted to the CAC for official assessment. Processing times at the CAC level vary; in straightforward cases, an official response may arrive within forty-five working days, but complex or sector-specific transfers routinely take longer. A common mistake is to treat the internal assessment as a box-ticking exercise. The CAC has returned incomplete submissions – restarting the clock – when applicants fail to provide substantive analysis of recipient jurisdiction protections.

Standard contract (personal information protection standard contract). Where volume thresholds are not triggered and the data does not qualify as important. Businesses may use a state-prescribed standard contractual clause (SCC) agreed between the data exporter and the overseas recipient. The standard contract is not freely negotiable. Its core clauses are fixed by regulation, and deviation from the prescribed text renders the contract ineffective as a transfer mechanism. Before the contract takes effect, the data exporter must file a copy with the competent provincial CAC branch. This filing is administrative in nature, but it must be completed before the first transfer takes place – not retrospectively. Many foreign businesses integrate their China SCC programme with their parallel GDPR compliance SCC process, which is possible structurally but requires careful attention to the points where the two regimes diverge.

Personal information protection certification. Certification by a state-accredited body provides a third pathway, used primarily by large platform operators and entities with intra-group transfer needs. The certification process is more resource-intensive than the SCC route but offers flexibility for ongoing, large-volume intra-group flows. The accredited certification bodies and the certification standards they apply are designated by the CAC; businesses should verify current accreditation status before engaging a certifier.

Beyond the transfer mechanisms, every entity subject to China's personal information protection legislation must implement a functioning consent mechanism. Consent must be informed, voluntary, and specific. Bundled consent – where a single checkbox covers multiple unrelated processing purposes – does not meet the standard. For sensitive personal information (which includes biometric data, health records, financial information, precise location data, and information relating to minors under the age of fourteen), consent must be separate and explicit. Processing sensitive personal information without explicit consent is one of the enforcement triggers most frequently cited in published regulatory actions.

Entities that qualify as large-scale processors under the legislation must also designate a data protection officer with sufficient authority and resources to perform the role effectively. The officer must be a named individual – not a committee – and must have direct access to senior management. Where the officer is stationed outside China, the legislation requires designation of a domestic representative responsible for accepting regulatory communications and enforcement notices.

For businesses that have engaged local counsel to structure their Chinese operations, the data protection compliance programme should be built in parallel with the corporate structure. Our guide on company formation in China covers the structural options available for foreign-invested enterprises and their interaction with regulatory obligations.

To receive an expert assessment of your data protection compliance posture in China, contact us at info@ferrazwhitmore.com.

Practical pitfalls for international businesses

The majority of enforcement actions against foreign-invested entities in China involve not deliberate misconduct but procedural gaps that accumulated over time. Understanding where those gaps typically arise is as important as understanding the substantive rules.

Employee data is systematically under-managed. Foreign companies routinely apply their global HR privacy notices to their Chinese employees, assuming that a translated version of their European or US notice is sufficient. In practice, Chinese employment data requires its own purpose-specific notice, its own consent record, and – where sensitive categories such as health data or biometric attendance records are processed – explicit consent documented separately. An HR audit conducted as part of a group compliance review will almost always identify this gap in a China subsidiary.

Third-party vendor contracts are rarely adequate. Where a WFOE engages a Chinese cloud provider, payroll bureau, or marketing platform, it is acting as a data controller and the vendor is a data processor. Chinese data security legislation requires a written data processing agreement that specifies the purposes, duration, type of data, protection measures, and the vendor's obligations on deletion and return of data. Generic service agreements that do not address these points do not satisfy the legislative requirement. Businesses that discover this during a CAC audit face a two-stage problem: they must remediate the contracts and also explain why the gap existed.

Intra-group transfers are transfers. A common misconception is that sharing personal information between a WFOE and its foreign parent company does not constitute a cross-border transfer requiring regulatory approval. It does. The nationality of the parent is irrelevant. What matters is whether personal information of individuals in China is being accessed from or sent to a location outside China. The parent company receiving the data is the overseas recipient; the WFOE is the exporting entity. The applicable transfer mechanism must be in place before the first access event – not when the group becomes aware of the requirement.

Privacy notices are often legally deficient. Notices must identify the data controller by its Chinese registered name, specify the purposes and legal basis for each category of processing. Disclose any third-party recipients and their locations, state the retention period. Additionally, explain how individuals can exercise their rights. Notices that meet GDPR standards frequently fail the Chinese standard on one or more of these points. particularly on the disclosure of overseas recipients and the explanation of individual rights. This differ from their GDPR equivalents in important respects.

Enforcement is multi-directional. SAMR and the CAC can both initiate enforcement actions independently. SAMR is particularly active in relation to consumer-facing applications, algorithmic recommendation systems, and dark patterns in consent interfaces. A business that has satisfied the CAC's filing requirements but whose app uses deceptive design to obtain consent may still face an SAMR investigation. Practitioners in China note that coordinated enforcement actions involving both agencies are becoming more frequent.

Businesses that are simultaneously managing data compliance obligations in both China and the Gulf region should review our analysis of data protection in the UAE. This covers the interaction between UAE data rules and cross-border transfers to Asia-Pacific jurisdictions.

Cross-border transfer strategy and the EU–China dimension

For European businesses operating in China, the interaction between China's outbound transfer rules and the EU's GDPR requirements creates a genuine compliance tension that cannot be resolved by applying either regime in isolation. The two regimes operate in opposite directions: GDPR governs what leaves the EU; China's personal information protection legislation governs what leaves China. A business with operations on both sides faces inbound and outbound obligations simultaneously.

Consider a standard scenario: a European company's WFOE collects customer data in China and transmits it to the European headquarters for consolidated CRM purposes. The transmission requires a valid Chinese transfer mechanism (SCC or security assessment, depending on volume). The European headquarters' receipt and further processing of that data is governed by GDPR, including obligations around data subject rights and adequacy determinations. Neither regime defers to the other. Both sets of documentation must be in place.

A further complication arises where the European recipient intends to onward transfer the data to a third country – for example, to a US-based cloud infrastructure provider. Chinese personal information protection legislation restricts onward transfers by overseas recipients. The SCC must address this restriction explicitly, and the onward transfer must be approved by the Chinese data exporter. Businesses that assume standard EU-to-US transfer mechanisms automatically satisfy this requirement are operating under a misapprehension.

For businesses whose Chinese data operations interact with their AI development activities. for instance. There. Personal data collected in China is used to train or fine-tune machine learning models. there is a separate layer of AI-specific regulation that applies. The interplay between personal information protection legislation and China's AI governance rules is covered in our analysis of AI law in China.

From a dispute resolution perspective, enforcement actions by the CAC are subject to administrative reconsideration and administrative litigation procedures. Civil claims by data subjects may be brought before the Chinese courts. Where disputes arise in the context of international commercial relationships. for instance. Between a WFOE and an overseas parent over compliance costs. the China International Economic and Trade Arbitration Commission (CIETAC) provides an arbitration pathway that is recognised in a broad range of jurisdictions. The China International Court of the Internet (also referred to in English as the Internet Court) has jurisdiction over online disputes involving personal information and has issued a number of decisions clarifying the standard of consent required in digital environments.

The UAE–China bilateral investment and trade relationship generates a specific category of cross-border transfer issue. Gulf-headquartered businesses with Chinese operations frequently need to transfer employee and customer data between jurisdictions that operate entirely distinct legal regimes. Neither regime recognises an adequacy determination in respect of the other. Each transfer must be documented under the applicable mechanism in both jurisdictions.

To explore a tailored cross-border transfer strategy for your operations in China and the EU or UAE, contact us at info@ferrazwhitmore.com.

Self-assessment checklist for international businesses in China

The following checklist is applicable where your business: processes personal information of individuals located in China. operates through a WFOE, joint venture. Alternatively. Representative office. transfers personal information to entities outside China. or uses third-party Chinese vendors who access personal information on your behalf.

Before operating, verify:

  • Your entity has mapped all personal data flows – inbound, internal, and outbound – and classified each data category by sensitivity level.
  • A compliant consent mechanism is in place for each processing purpose, with separate explicit consent for sensitive personal information categories.
  • A privacy notice meeting Chinese regulatory requirements has been prepared in Mandarin and is presented to data subjects before or at the point of collection.
  • All cross-border transfers have been assessed against the applicable threshold criteria, and the correct transfer mechanism (security assessment, SCC, or certification) has been completed and, where required, filed.
  • Written data processing agreements are in place with all third-party vendors who access personal information in connection with your operations.

This compliance posture requires immediate attention if:

  • Your current privacy documentation was drafted solely to meet GDPR standards and has not been reviewed for China-specific requirements.
  • Personal information has been transferred to your overseas parent or affiliates without a completed transfer mechanism in place.
  • Your entity has exceeded volume thresholds during the past twelve months without completing a CAC security assessment.
  • Your sector (finance, healthcare, automotive, mapping) means that some of your data may qualify as important data – and this classification has not been formally assessed.
  • Your WFOE does not have a designated domestic representative for regulatory communications.

This checklist is not exhaustive. The applicable obligations depend on your specific business model, sector, data volumes, and the jurisdictions involved in your transfer flows. Organisations that identify one or more gaps through this checklist should seek specialist advice before the next regulatory filing deadline or before any planned expansion of data processing activities.

Frequently asked questions

How long does it take to complete a CAC security assessment for a cross-border data transfer from China?
Once a complete submission is filed with the CAC, the official assessment period is typically forty-five working days, with a possible extension for complex cases. However, the internal preparation phase – mapping data flows, conducting the risk assessment, and drafting the submission – commonly takes several months for businesses that have not previously completed the process. Starting this work well in advance of any planned transfer is strongly advisable. Incomplete submissions are returned and restart the clock.
Does our GDPR compliance programme satisfy China's data protection requirements?
No – and this is one of the most persistent misconceptions among European companies entering China. While there are conceptual overlaps between the two regimes (both require lawful bases for processing and respect for data subject rights), the specific mechanisms differ substantially. China requires consent mechanisms that exceed GDPR standards for sensitive data, mandatory local-language privacy notices, separate transfer filing procedures, and in some cases a domestic representative. A GDPR-compliant programme provides a useful starting point but requires significant localisation to meet Chinese requirements. Engaging a lawyer in China with cross-border experience is the most reliable way to identify the gaps.
What are the consequences of non-compliance with China's personal information protection legislation?
The consequences range from administrative warnings and fines. which can reach a significant proportion of the prior year's revenue for serious violations. to suspension of data processing activities. Mandatory rectification. Additionally, in severe cases, criminal liability for responsible individuals. For foreign-invested businesses, a regulatory action also carries reputational risk with Chinese partners, customers, and licensing authorities. The CAC has demonstrated a willingness to act against well-known international brands, and enforcement activity has increased markedly since the legislation came into full effect.

About Ferraz & Whitmore

Ferraz & Whitmore is an international law firm based in Lisbon, advising business clients across 46 jurisdictions. Our data protection practice supports international companies managing compliance obligations in China and across Asia-Pacific, the Middle East, and Europe – including WFOE operators, platform businesses, and institutional investors with cross-border data transfer needs. As a law firm in China-facing practice, we combine an understanding of the Chinese regulatory environment with the EU data protection expertise that businesses managing China–Europe data flows require. Our team has advised on data transfer mechanisms, consent architecture. Additionally, regulatory audit responses in both common law and civil law jurisdictions. Additionally. We work with a network of local counsel in China to deliver advice that is current and jurisdiction-specific. To discuss how China's data protection regime applies to your business, contact us at info@ferrazwhitmore.com.

James Kellner Legal Analyst, IP & AI Law

James Kellner leads our Anglo-Saxon and Asia-Pacific desks and our AI & Technology Law practice. He advises US, UK and Singaporean technology companies on the full IP and tech-regulatory stack — patent licensing, software contracts, GDPR, the EU AI Act, employment and immigration for tech talent. James qualified as a solicitor in England & Wales and as an attorney in California. He spent five years at a Silicon Valley boutique focusing on patent and AI policy before joining Ferraz & Whitmore.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. Ferraz & Whitmore assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@ferrazwhitmore.com.