Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ TAG · CYBERSECURITY-REVIEW

Filed under cybersecurity-review

Every brief tagged "cybersecurity-review".

  • § 01 · CYBERSECURITY-REVIEW

    China Opens a Cybersecurity Review of Palo Alto Networks: The Micron Playbook, Now Pointed at Firewalls

    On 6 August 2026 the Cybersecurity Review Office announced a cybersecurity review of Palo Alto Networks (派拓公司) products sold in China, citing the National Security Law, the Cybersecurity Law and the Cybersecurity Review Measures. DCC reads the announcement against the Measures themselves. The review is an Article 16 own-motion proceeding initiated by the working mechanism and cleared by the Central Cyberspace Affairs Commission — not the Article 5 pathway where a CIIO declares a procurement — so there is no applicant, no declared transaction, and the Article 11/14 clocks apply only by analogy. Article 21 puts cybersecurity equipment and cloud computing services squarely in scope; Article 10 supplies the risk factors that a cloud-synchronized firewall estate maps onto almost line by line. The operative question for overseas counsel is not what happens now — nothing does — but what a failed outcome would mean: CIIOs must stop procuring, and CSL Article 37/67 as amended in 2025 exposes a CIIO that keeps using un-passed products to a fine of 1× to 10× the procurement amount plus RMB 10,000–100,000 personally. Non-designated companies acquire no legal obligation at all. Based on commentary from 数据何规, checked against the official announcement and the Micron precedent.

    cybersecurity-review · palo-alto-networks · 派拓
  • § 02 · SECURITY-REVIEW

    One Company, Four Reviews: JunHe Maps China's Security-Review 'Matrix' in the Security-First Era

    With the Measures for Network Data Security Risk Assessment (Order No. 24) in place, China's security-review architecture has four operating pillars: foreign investment security review (NDRC + MOFCOM), cybersecurity review (CAC + 12 departments), data export security assessment (CAC), and the new normalized network data security risk assessment (CAC coordination + sectoral authorities). JunHe lawyer Chen Sijia walks each regime through the same five questions — who reviews, what is reviewed, when review is triggered, and with what legal consequences — and lands on two points overseas counsel should not miss. First, the four regimes differ in kind: the first three are ex-ante, admission-style reviews with veto power, while the risk assessment is an annual, improvement-oriented 'physical exam.' Second, review decisions are effectively final — the mainstream view treats them as final administrative acts with no administrative reconsideration or litigation available — so cooperation during the review is the only real strategy. A closing lifecycle walkthrough shows how a single AI-model company can trip all four lines in sequence: FDI review at fundraising, cybersecurity review at GPU procurement, export assessment at model training, cybersecurity review again at foreign listing, and the annual risk assessment as a standing duty.

    security-review · national-security · cybersecurity-review
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →