New Guide for Cross-Border Personal Data Transfers in the GBA: A Roadmap for Compliance and Security
The Technical Committee for Information Security Technology (TC260) has released a new guide to standardize cross-border personal data transfers between the Chinese Mainland and Hong Kong within the Guangdong-Hong Kong-Macao Greater Bay Area (GBA). This guide introduces enhanced security standards and mutual recognition mechanisms, aiming to facilitate smoother data flows while ensuring robust protection of personal information.
Personal Data Regulation in China: Personal Information Protection Law, Other Rules Amended
Internet businesses and companies processing personal data in China are advised to track latest regulatory developments supporting data security to remain compliant.
Cross-Border Data Transfers – New Draft Measures Clarify Personal Information Protection Certification
China’s new draft measures provide clarity on the certification process for personal information protection in cross-border data transfers (CBDT).
New Guidelines for Personal Information Protection Audits – Clarifying Requirements and Processes
The new guidelines clarify requirements and processes for conducting personal information protection audits, compulsory for companies processing high volumes of personal information as of May 1, 2025.
China Clarifies Cross-Border Data Transfer Rules: Key Takeaways from Official Q&A (I)
China’s Cyberspace Administration clarifies cross-border data transfer rules, offering foreign businesses guidance on streamlined data exports and compliance.
Shanghai Streamlines Data Export with New Data Negative List
Shanghai’s new data export negative list facilitates cross-border data transfers for companies in reinsurance, shipping, and commerce in the Pilot Free Trade Zone and Lingang New Area.
Personal Information Protection Audits in China: Final Measures Effective May 1
China’s Cyberspace Administration has unveiled the final rules on conducting personal information protection audits. The new measures, which require fewer companies to conduct less frequent audits than the draft version, offer an opportunity for businesses to strengthen compliance.
China Issues New Regulations on Network Data Security Management, Effective January 1, 2025
On September 30, 2024, China announced the new Network Data Security Management Regulations, effective January 1, 2025, aimed at enhancing data security and privacy while establishing compliance requirements for both domestic and international entities.