Filed under cross-border
Every brief tagged "cross-border".
- § 01 · COMPUTE-CENTERS
One Machine Room, Five Regulatory Identities: MaaS Compliance for China's AI Compute Centers
AnJie Broad partners Cai Hang and Yao Ting and associate Liu Zeqiang argue that the IDC-era compliance checklist no longer fits the AI compute center. Their thesis: one machine room now carries five regulatory identities at once — domestic IDC operator, cross-border AI service provider, service exporter under the Export Control Law, supplier of self-deployed model capability, and responsible entity for the agents it ships — each with its own logic, and each transmitting obligations to the others. The brief works through value-added telecom licensing (B11/B12), energy-conservation review and PUE caps, the continuing duties under the Regulation on Network Data Security Management (State Council Decree No. 790), the token-export exemptions in CAC Decree No. 16 and what they do not exempt, the territorial limits of the GenAI Interim Measures, the Export Control Law catch-all, the unsettled line between large-model filing (备案) and large-model registration (登记), open-weight license trigger clauses, and the criminal exposure that follows an agent's tool calls under Criminal Law Article 285.
- § 02 · ENFORCEMENT
What the Data Inspectors Actually Find
An empirical read of 392 Chinese data-compliance administrative penalty decisions published between January 2024 and June 3, 2026, resting on the Data Security Law and the Personal Information Protection Law. Four findings for overseas counsel. First, the routine outcome is not a fine: 74.5% of decisions ended in a warning and public criticism, 16.6% carried a fine, and 92% were issued by public security organs rather than the Cyberspace Administration. Second, the citation chain is remarkably narrow — DSL Article 27 via Article 45 (173 decisions) and PIPL Article 51 via Article 66 (50 decisions) carry the file, and what inspectors find are the enumerated basics: no training record (58), unencrypted personal information (35), weak passwords (24), MLPS grading not completed (12), no contingency plan (11), log retention under six months (7). Third, what moves a case off the warning default is failure to rectify within the deadline, not scale of exposure: 19.28 million exposed records drew RMB 50,000, while a hospital that missed its rectification deadline drew RMB 80,000 plus licence-tier measures — and where DSL Article 45 fines are imposed, they anchor at the RMB 50,000 statutory floor. Fourth, in all 392 decisions, zero cited PIPL Articles 38–42, the cross-border transfer provisions, and only three cited the impact-assessment duties in Articles 55–56.
- § 03 · CROSS-BORDER
The Negative-List Map, Region by Region: Ten Zones, Two Models, and the Year Data Export Went Province-Wide
As of July 2026, ten Chinese regions — nine free-trade zones plus the Hainan Free Trade Port — have published data-export negative lists under Article 6 of the 2024 Cross-border Data Flows Provisions, and this year Beijing and Shanghai took the mechanism province- and city-wide, off the FTZ footprint entirely. DCC's roundup maps the full set: which sectors each zone lists (from Tianjin's 13 commodity categories to Guangdong's smart-manufacturing and personal-credit fields, Chongqing's intelligent-connected-vehicle chain, and Jiangsu's biopharma-only list), the two management models that have crystallized — pre-export filing versus Shanghai and Guangdong's 'transfer-first, report-after' — and how an overseas team should read the map. Compiled from the CAC's national negative-list index and each region's official notice, and paired with DCC's new downloadable negative-list registry.
- § 04 · CROSS-BORDER
First Filing Under Shanghai's Citywide Data-Export Negative List: Inditex's China Arm Drops from Security Assessment to Standard-Contract Filing
On June 26, 2026, ITX Asia Pacific Enterprise Management Co., Ltd. (爱特思亚太企业管理有限公司) — the Inditex group entity behind ZARA and Pull&Bear in China — received Shanghai's first data-export negative-list filing result notice (数据出境负面清单备案结果通知书) issued under the Shanghai Data-Export Negative List Administrative Measures, cleared jointly by the Shanghai CAC and the Shanghai Data Bureau after same-day district-level initial review at the Jing'an District Cross-Border Data Service Center. The practical effect: member-information exports that previously sat in Data Export Security Assessment territory now clear on a Personal Information Standard Contract filing. DCC reads the case as the first operational proof of Shanghai's two policy moves — negative-list eligibility extended citywide beyond Pudong-registered enterprises, and volume thresholds inside listed scenarios (retail member management) raised so that non-sensitive member data between 1 and 10 million individuals falls to the standard-contract/certification tier. For overseas retail groups running membership programs out of China, this is the template case.
- § 05 · GBT-35273
From Consent to Governance: What the 2026 Draft Revision of GB/T 35273 Changes Against the 2020 Standard
On June 17, 2026 the National Cybersecurity Standardization Technical Committee (TC260), with CESI as drafting lead, released for public comment a systematic revision of GB/T 35273 — China's most-cited personal-information standard, the de-facto 'small PIPL.' The draft retitles the standard from 'Information Security Technology' to 'Data Security Technology' and expands its normative references from one standard to eight. DCC reads the revision as a role change, not a clause count: the standard moves from a consent-and-notice manual into a governance-capability framework. The substantive increments against GB/T 35273-2020: a new Chapter 5 importing PIPL Article 13's seven lawful bases as a standalone chapter with hard boundaries on each (contract-necessity, HR, public-disclosure) plus an evidence-chain duty; a sensitive-PI redefinition aligned to PIPL Article 28 with a new aggregation rule (multiple items that together meet the threshold are treated as sensitive as a whole); a formal 'separate consent' definition (3.7) with a negative list; a new eighth basic principle, 'quality assurance' (Chapter 4(f)); dedicated AI clauses on the collection side (6.7), in minimum-necessity (6.1 d–f), in aggregation/training (8.4), and a new generative-AI use clause (8.5.4) with output review and a 15-working-day deletion SLA; a unified-account-system clause (8.6) aimed at one-account-many-products groups; a terminal/IoT collection clause (6.8); a wholly new Chapter 11 on overseas-jurisdiction determination and conflict handling; and a systematized internal-control chapter (13) covering the person in charge of personal information protection, working body, processing-activity records, impact assessment, and a GB/T 46903-anchored compliance audit. Subject-rights response time tightens from 30 days to 15 working days. Clause numbers are from the comment draft and are not final; formal release is expected after 2027.
- § 06 · HEALTH-DATA
China's Hospitals Get Their Own Data Rulebook: Reading the 2026 Healthcare Data Security & PI Measures
On 12 February 2026 five agencies — the National Health Commission, the Ministry of Public Security, the Cyberspace Administration of China, the National Administration of Traditional Chinese Medicine, and the National Disease Control and Prevention Administration — jointly issued the Measures for the Administration of Data Security and Personal Information Protection of Healthcare Institutions (Trial). It is the first operational, sector-specific rulebook that turns the Data Security Law, PIPL, and the Network Data Security Regulation into concrete hospital obligations: a three-tier core/important/general data classification keyed to MLPS levels and commercial cryptography; a five-pillar full-lifecycle security system; a ten-item data prohibition list and an eight-item personal-information prohibition list; heightened protection for special groups; limits on facial recognition and AI; and a real enforcement chain running from named-person accountability through regulatory interviews, administrative penalties, civil tort liability, and criminal referral. DCC reads it for overseas pharma, medtech, and hospital-JV counsel — with the cross-border choke point and its academic-cooperation carve-out as the parts that most affect global clinical-data flows.