Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ BRIEFINGS · PAGE 13

Every brief.

The full run, most recent first.

  • § 73 · DATA-TRADING

    Mapping the Red Lines: Compliance Assessment for Surveying and Geographic-Information Data Products on a Chinese Data Exchange

    When Sichuan province's first surveying and geographic-information (测绘地理信息) data product was listed on the Shenzhen Data Exchange (深圳数据交易所), the compliance team from Si Chuan Rui Li Heng Law Firm worked through a seven-point assessment framework that goes well beyond general data-trading rules. This brief walks overseas counsel through that framework: why the surveying-and-mapping regime (测绘法 and subordinate rules) adds a specialist qualification layer on top of the Network Data Security Management Regulations; how the classified-surveying-results (涉密测绘成果) screen works in practice; what 'important geographic-information data' (重要地理信息数据) means for tradability; and why data origin — self-collected versus purchased versus project-derived — changes the due-diligence checklist materially. The operational takeaway: for this sector, general data-exchange compliance is necessary but not sufficient.

    data-trading · surveying-data · geographic-information
  • § 74 · SENSITIVE-PERSONAL-INFORMATION

    Seven Highlights of China's New Sensitive Personal Information Processing Standard — and What They Mean in Practice

    GB/T 45574-2025 《数据安全技术 敏感个人信息处理安全要求》 (Data Security Technology — Security Requirements for Processing Sensitive Personal Information) is China's first dedicated national standard on sensitive personal information (敏感个人信息), effective 1 November 2025. Authored by Wang Yi, Zhao Yanming, and Zeng Lingwei of the Shenzhen Data Exchange DEXC+ program, this brief walks through the seven highlights the standard introduces: a recalibrated scope of what counts as sensitive personal information under PIPL, dynamic classification logic, a new linkage between sensitive-PI volume and the important data threshold, industry-specific and group-specific protections, data-security-maturity requirements, a model written-consent template, and tightened lifecycle obligations covering collection, storage, display, and audit. The operational takeaway for overseas counsel: the standard converts PIPL's high-level sensitive-PI obligations into testable, auditable requirements — compliance teams should treat it as the primary implementation guide for PIPL Article 28 and beyond.

    sensitive-personal-information · pipl · national-standard
  • § 75 · PIA

    The PIA as a Trading-Compliance Line — What the Network Data Security Management Regulations Add for Personal-Information Data Products

    China's personal-information protection impact assessment (PIA / 个人信息保护影响评估) has long been a statutory requirement under PIPL, but uptake in data-trading contexts remains low. A DEXC+ analysis by Wang Senpeng of Shenzhen Data Exchange argues that the Network Data Security Management Regulations (网络数据安全管理条例, 'Network Data Regs') significantly refine when and how a PIA must be conducted before a personal-information data product changes hands. The brief maps three trigger layers — subject compliance, subject-matter compliance, and circulation compliance — and then draws out the evaluation dimensions the Regulations add: a new 'dual-list' privacy-policy requirement, data-processing-agreement minimum contents, a three-year record-keeping obligation, and tightened rules on web-scraping and de-identification. For overseas counsel: a PIA is no longer just a cross-border formality — it is the primary compliance gate for trading sensitive data, delegated-processing arrangements, and any automated-decision-making data product.

    pia · personal-information-protection · data-trading
  • § 76 · DERIVATIVE-DATA

    Derivative Data Products and Public Data Opening — Legal Challenges and Compliance Points

    As China opens public-sector datasets for commercial exploitation, companies building derivative data products (衍生数据产品) face a layered compliance problem: the definition of 'derivative data' in the National Data Administration's 2025 glossary is deliberately high-threshold (substantial transformation, significant value uplift); provincial rules on automated collection, source-labelling, and sensitive-data assessment are inconsistent; and a three-way collision between the open-data rules, third-party platform terms, and the 2025 Anti-Unfair Competition Law amendments has no clean resolution. Wang Yi and Yu Hao (both DEXCO-certified partners at Global Law Office Shenzhen) map the definitional landscape, five categories of operational red lines, and four protective strategies — including the new data-specific provision in the revised Anti-Unfair Competition Law — for practitioners building or advising on derivative-data businesses.

    derivative-data · public-data · data-property-rights
  • § 77 · DATA-PROPERTY-RIGHTS

    From Copyright to Data Property: The Three-Layer Compliance Test for Registering Employee-Created Data in China

    China's data property-rights registration regime treats copyright and data property (数据产权) as separate legal categories — a distinction that catches many applicants off guard when employee-created works are involved. This brief summarises a practitioner analysis by two Shenzhen Data Exchange compliance officers, who explain the three-layer 'penetrating review' (穿透审核) logic that registrars actually apply: lawful acquisition (合法获取), factual control (事实持有), and defined scope of use (使用范围). For overseas counsel advising clients that hold data generated by employees — including code, engineering drawings, maps, and other special categories of work-made-for-hire under China's Copyright Law — the key operational takeaway is that a copyright certificate alone is insufficient. Registration of all three data property rights (holding right, use right, operating right) requires distinct evidence chains for each, and the employment contract is the starting document, not the copyright certificate.

    data-property-rights · data-registration · work-made-for-hire
  • § 78 · IMPORTANT-DATA

    'Important Data' Is a Category, Not a Tier

    Hong Yanqing argues the mainstream reading of Article 21 of the Data Security Law confuses enterprise asset-inventory language with state-level legal-interest protection — with real consequences for cross-border transfers, enforcement, and how PIPL and DSL stack.

    important-data · dsl · commentary
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →