Cybersecurity 2026

CHINA Trends and Developments Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Patrick Guo, Fangda Partners

The status quo for important data in China is that there is no overarching, unified catalogue for important data with sufficient granularity to allow organisations to determine with certainty whether the data they hold qualifies as important data. Instead, catalogues for important data are “spotty”, appearing in negative lists issued by FTZs, sector-specific regulatory speci - fications, technical standards, and, in some cases, through case-by-case designation by the regulators. CBDT of important data is subject to approval by CAC. Under the existing CAC rules, before applying for such approval, the data exporter must already have knowledge that the data in question has been classified as important data by a sector regulator or relevant regulations. Given the “spotty” nature of the important data, organisations may inadvertently trans - fer potential important data out of China without seek - ing the requisite approval. Against the backdrop of heightened geopolitical ten - sions, data related to high technology with national security relevance, especially data concerning critical minerals, manufacturing supply chain chokepoints, or key components in technology supply chain is highly likely to be deemed important data, if not clas - sified as state secrets. Any cross-border transfer of such data, unless approved by regulators or certi - fied through a prescribed risk assessment, is likely to trigger enforcement action from CAC or other law enforcement regulators such as public security bureau or national security bureau. In addition, Article 36 of the DSL establishes a block - ing statute that prohibits the provision of any data to foreign governments or foreign courts in connection with law enforcement or judicial proceedings with - out prior approval from the Chinese regulators. While the specific approval regulator has not been clearly identified, existing sectoral regulations endorsed by the CAC suggest that the approval process will, at a minimum, involve one or more of the following regula - tors: (i) the relevant sector-regulator; (i) the Ministry of Justice; and (iii) the CAC. Data breach compliance and response The volume, scale, sophistication and impacts of data breaches have drastically increased over the past few

years. With assistance from AI technologies, it has become significantly easier for threat actors to imper - sonate employees, retrieve credentials and launch successful cyberattacks. Therefore, foreign business - es operating in China must remain highly vigilant with respect to data breach and their legal implications. Following the rollout of China’s CBDT regime, most MNCs’ China-based entities, acting as data handlers, have entered into the standard contractual clauses (SCCs) with their global data recipients. All of these SCCs follow a government-mandated standard tem - plate, which imposes binding data breach notice and report obligations on the overseas data recipients, to the extent that the breach involves the personal infor - mation of individuals in China covered by the SCCs. Notice-and-report In this context, China must be considered as a signifi - cant jurisdiction in the event of a global data breach. The Measures for the Reporting of National Cyber - security Incidents issued by CAC in 2025 requires a network operator to notify CAC within four hours after the discovery of a “relatively severe” data breach. Although this rule remains unclear whether the same reporting timelines apply uniformly to global data breaches, the requirement warrants close attention in practice. Where a data breach is reportable, an organisation must fulfil its notice-and-report obligations. Here, “notice” refers to notice-to-individuals, requiring the organisation to inform the breach to the impacted indi - viduals so that they may take precautions. “Report” refers to report-to-regulator, requiring the organisation to report the breach to regulators for them to take action, including investigation and law enforcement. China follows a “harm-based” approach to breach notification. Where the organisation discovers that no actual harm has occurred, for example, there has been no data exfiltration, then notice is not mandatory. In practice, Chinese regulators may also provide guid - ance on notice, particularly where public notification could raise national security concerns. By contrast, a report is generally required, and as already referred to above, the reporting timeline can be as short as four hours.

92 CHAMBERS.COM

Powered by