CHINA Trends and Developments Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Patrick Guo, Fangda Partners
reach to overseas conduct that endangers China’s cybersecurity, not just conduct harming critical infor - mation infrastructure. At the same time, regulators continue to calibrate rules around CBDT and AI governance to maintain commercial activity. The CAC’s 2025 Q&A on CBDT and FTZ negative lists confirms that ordinary data and limited personal information can flow freely while the exports of “important data” and sensitive personal information or bulk personal information remain gated by transfer mechanisms. Theme for 2026: Enforcement will intensify, but the operative question remains “what is reasonable cybersecurity?” Regulators balance national security, crime prevention, personal information protection, economic development and technology growth when enforcing the law. Companies that can demonstrate proportionate technical and organisational controls, including permits, certifications, audits and structured processes, will have stronger affirmative defences in enforcement actions. The remainder of this article unpacks three enforce - ment vectors foreign businesses should prepare for in 2026: • enforcement against illegal CBDT; • data breach compliance and response; and • AI regulation. Enforcement against illegal CBDT CBDT of personal information In 2025, CAC issued multiple interpretations of the CBDT mechanisms stipulated in the PIPL, reflecting China’s emphasis on data sovereignty. These interpre - tations can be found in its Q&As dated April, May and October 2025, respectively. Additional interpretations can be found in the guidelines issued by the FTZs and the technical standards issued by the State Adminis - tration for Market Regulation. Together, they form a comprehensive set of implementing rules on CBDT, supplementing the otherwise high-level and general provisions of CBDT mechanisms under the PIPL and other CAC regulations.
In addition, CAC established a new Data Security Division, tasked with enforcement alongside the pre- existing Cybersecurity Division and Enforcement Divi - sion. With these developments, regulatory require - ments and expectations are now clearly articulated, and heightened enforcement activity can be antici - pated in 2026. A case in point is international hotels. Through a CAC Q&A dated October 2025, CAC clarified that using a central reservation system to process bookings for Chinese domestic travellers does not satisfy the “necessity” requirement for CBDT. Other potential triggers for CBDT enforcement would include international data breaches. Typically, these involve global notice-and-report obligations of multi - national company (MNC) headquarters, which cover Chinese residents, if affected. Once notifications reach Chinese residents, they often circulate the infor - mation on social media, potentially drawing regulatory attention. Regulators may then query the China opera - tion of the MNC to investigate the breach: why Chi - nese residents were affected, how their data ended up in a global database, and whether proper transfer mechanisms were followed. If the local management of the China operation cannot explain, or if it turns out that the transfer mechanism was not fulfilled, for instance, filing is not complete or there is evidence of “gun jumping”, regulators may initiate a formal inves - tigation and impose penalties as a result. CBDT of important data In addition to the enforcement against illegal CBDT of personal information, regulators are increasingly focused on the illegal CBDT of important data. In a US context, important data is similar to controlled unclas - sified information. In a nutshell, it refers to regulated, non-public data relating to the government regulators, state-owned enterprises, private-public projects or critical infrastructure operators that matter to national security. For example, in the electronic vehicle sector, large-scale data concerning vehicle traffic flows and logistics that reflect the macroeconomic operation of a municipality are designated by law as important data. This is because roadway networks constitute critical infrastructure, and operational data relating to such networks may have national security implications.
91 CHAMBERS.COM
Powered by FlippingBook