Cybersecurity 2026

CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners

financial terminal developed by a critical ICT service providers, suffered a service disruption that could have prevented financial institutions from access - ing market data and analytical information in a timely manner, thereby undermining their trading decision- making and risk management practices. This incident exposed critical deficiencies on the part of the ven - dor, including an inadequate monitoring and detection mechanism, a poorly designed file backup and recov - ery plan, and weak network operation and manage - ment capabilities. For these failings, the vendor was issued a cautionary letter by the CSRC. Additionally, regulators have issued a substantial number of enforcement actions against financial sec - tor operators for failures to fulfill cybersecurity and data security obligations, including deficiencies in network security management, data security controls, customer identity verification and incident response. Such cases typically involve penalties imposed on both institutions and responsible individuals, with enforcement measures including warnings and fines ranging from several thousand yuan renminbi to sev - eral million yuan renminbi. 3.5 International Data Transfers With respect to China’s CBDT processes, relevant obligations currently focus primarily on personal infor - mation and important data. Under the current PRC regulatory framework, CBDT is primarily governed by three processes: CAC security assessment, standard contract filing (SCC Filing) and personal information protection certification. The Provisions on Promoting and Regulating Cross-Border Data Flows issued by CAC on 22 March 2024, introduced clear exemptions and bulk thresholds for these processes. Specifically, data handlers (other than CIIOs) are exempted from any CBDT process where they cumulatively transfer less than 100,000 individuals’ non-sensitive personal information overseas within a calendar year, or where the transfer is necessary for specific business or pub - lic interest scenarios, including contractual necessity in cross-border transactions, lawful cross-border human resources management, or emergency situa - tions to protect individuals’ vital interests. By contrast, data handlers must complete a security assessment with the CAC if they transfer data over -

seas and meet any of the following conditions/bulk thresholds: • CIIOs transfer personal information or important data abroad; or • non-CIIO data handlers transfer important data overseas, or have cumulatively transferred per - sonal information of over one million individuals (excluding sensitive personal information) or sensi - tive personal information of over 10,000 individuals overseas since January 1 of the current year. Regarding the identification of important data, if the data handler has not received a notification from rel - evant departments or regional government that the data is important data or that the data is designated as important data under rules and regulations, data han - dlers are not required to declare it as important data for the purpose of a security assessment. Transfers falling below the security assessment thresholds but above the exemption thresholds may be conducted through either SCC Filing or personal information pro - tection certification. In 2025, relevant competent authorities jointly issued the Guidelines on Promoting and Regulating Com - pliance in Cross-border Data Flows in the Financial Sector (the “Financial Data Cross-border Transfer Guidelines”, in Chinese 促进和规范金融业数据跨境流动合规 指南 ), which aim to clarify and facilitate cross-border data transfers in the financial services sector in co- ordination with existing data protection and cyber - security rules. Please note that the Guidelines were issued privately to financial institutions and have not been made public. According to the Financial Data Cross-Border Transfer Guidelines, financial institu - tions may independently transfer data stored within China overseas without undergoing any regulatory procedures, provided that such data does not include personal information and important data under Chi - nese laws. For certain business scenarios providing personal financial services, financial institutions may transfer specific types of client data overseas without going through any of the three CBDT processes, if the transfer falls within the prescribed circumstances and data categories listed in Appendix I of the Finan - cial Data Cross-Border Transfer Guidelines. For other financial business scenarios (including corporate

83 CHAMBERS.COM

Powered by