CHINA Trends and Developments Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Patrick Guo, Fangda Partners
intelligence and information technology. Mr Guo has been involved in many data protection and cybersecurity compliance projects, including establishing and implementing data protection and cybersecurity compliance systems, advising on cross-border data transfer compliance, and conducting data protection and cybersecurity compliance due diligence in IPOs and related transactions.
Fangda Partners 24/F, HKRI Centre Two, HKRI Taikoo Hui 288 Shi Men Yi Road Shanghai 200041 China
Tel: +8621 2208 1166 Fax: +8621 2208 1166 Email: email@fangdalaw.com Web: www.fangdalaw.com
Recap of Past Developments At a high-level, the development of China’s cyberse - curity regime over the past decade can be summa - rised into three stages. • Influence (2016–2021) – establishing the legal architecture through the Cybersecurity Law (CSL), Data Security Law (DSL), and Personal Information Protection Law (PIPL), while shaping the ecosys - tem via regulations, standards, name-and-shame campaigns targeting illegitimate mobile apps, pilot programmes and guidance. This stage aimed to raise public awareness of China’s data sovereignty, the importance of cybersecurity and the obliga - tions to safeguard personal information. • Monitor (2021–2025) – building administrative procedures such as cross-border data transfer (CBDT) control (including negative lists in free trade zones (FTZs)), personal information audits, security assessments, algorithm/large-model filings, and frequent rectification campaigns (ie, requiring those in breach of regulations to put them right them - selves). These measures have enabled regulators to better understand industry practices, recalibrate
enforcement priorities and gather leads for supervi - sion. • Control (2025–) – entering a decisive enforcement phase by mandating the appointment of a per - sonal information protection officer (PIPO), raising penalty ceilings, broadening extraterritorial reach, tightening incident reporting service level agree - ments and scaling sectoral inspections, while still attempting to preserve reasonable compliance burdens to allow the digital economy to function effectively. The New Trends 2026 marks the first year of the new five-year plan of the Cyberspace Administration of China (CAC), signal - ling a transition in priority from monitoring to control. The amendment to the CSL passed in October 2025 (effective 1 January 2026; amending the original 2016 law) provides the clearest signal of this shift. It mate - rially increases penalty ceilings, introduces personal liability for “directly responsible persons” covering the PIPO, chief information security officer and other management personnel; and broadens extraterritorial
90 CHAMBERS.COM
Powered by FlippingBook