08-10-2026

Checking in, Checking out – Chinese New Rules to Data Silver Road

Introduction
The beginning of 2026 marked a definitive turning point in China’s digital regulatory landscape. With the simultaneous implementation of the revised Cybersecurity Law (“CSL”) and the Measures for Certification of Cross-Border Provision of Personal Information (“Certification Measure”), Chinese authorities effectively completed its sophisticated legal framework for digital economy that prioritizes accountability and national security. The impact of the changes brought might be best understood through an illustrative scenario of hotel booking.

In a recent policy Q&A, the Cyberspace Administration of China ("CAC") offered a highly illustrative clarification regarding exemptions for data transfers. While sending data abroad to fulfill a customer's overseas hotel reservation is strictly necessary for contract performance and therefore fully exempt from complex filing requirements, transferring that same data for a domestic booking merely because a company's servers are in another country is not.

This distinction cuts to the heart of the new rulebook. Chinese authorities have effectively completed their sophisticated legal framework for the digital economy by moving away from rigid mandates toward a system that rewards precise, necessity-based data governance over blanket IT strategies.

This article unpacks the key regulatory updates introduced by these developments and examines their compliance implications for businesses.

Key updates of Cybersecurity Law (CSL): Moving Towards Nuanced Enforcement
AI Supervision and Ethical Review: The new CSL introduces a dual-track approach that balances state support for AI research and core technology infrastructures such as algorithms, training data resources and computing power with mandatory ethical norms and safety supervision. By embedding AI governance into the primary cybersecurity regulatory frameworks, companies deploying AI shall anticipate a future where risk assessments and ethical audits are mandatory components of their operational strategy. AI is thus positioned as both an object of regulation and a means of enforcement to strengthen cybersecurity management.

Graduated Penalties System: The revised provisions introduce a welcome shift from fixed, nominal fines to a graduated penalty system. Penalties are now directly tied to the severity of a violation’s actual impact. This is a highly practical change that helps avoid a rigid, one-size-fits-all approach, making the regulatory environment more predictable for businesses.

Good Faith Exemptions: Crucially, the amended CSL introduces an exemption from punishment for companies that can demonstrate good faith. If a violation occurs but the company has implemented robust compliance systems, voluntarily mitigates harm, cooperates actively with authorities, or corrects minor violations promptly without causing damage, lighter or exempted punishments can apply. This vital provision distinguishes responsible companies that fall victim to cyberattacks from those demonstrating deliberate negligence.

Extraterritorial Reach: The regulatory reach has also expanded beyond China’s physical borders. The amended CSL explicitly allows authorities to freeze assets or impose sanctions on foreign entities engaging in activities that endanger China’s cybersecurity. This sends a clear message that global operations must now be calibrated against Chinese national security standards, regardless of where servers or headquarters are located.

The Certification Measure and CAC Q&A: Practical Pathways for Data Transfers
The introduction of Certification Measure that was published in October 2025 and came into effect at the beginning of 2026 completes the missing puzzle of the regulatory framework for all compliance pathways of data transfers. 

A Durable Solution for Recurring Data Flows: Once certified, a company can facilitate recurring data flows to multiple overseas affiliates for three years without the administrative burden of filing individual standard contracts for every single data transfer. This fundamentally changes the compliance calculus for companies engaged in high-volume or repetitive data flows, particularly multinational corporations that centrally manage employee, client, or transactional data across multiple global jurisdictions.

Clear Thresholds: This highly efficient pathway is not open to everyone. It is available to organizations that are not critical information infrastructure operators, do not transfer "important data," and whose annual data export volumes fall between 100,000 and 1 million individuals for non-sensitive personal information (or fewer than 10,000 for sensitive data).

Observations
The updated CSL and the promulgation of the Certification Measure are undoubtedly welcome news for international companies seeking practical, long-term compliance pathways. These regulatory updates signal a clear policy wind: Chinese authorities are actively rewarding comprehensive, system-level data governance with tangible operational efficiencies.

Sectoral implementation is also advancing. In February 2026, authorities issued the Automotive Data Outbound Security Guidelines (2026 Edition), which set out exemption scenarios and detailed important-data identification rules for the automotive industry. Similar sector-specific guidance is expected in other industries, and businesses should monitor developments in their respective sectors.

Looking ahead, authorities released the draft Regulation on the Protection of Personal Information by Large-Scale Personal Information Processors for public comment. The draft proposes designation criteria for “large-scale” processors (including processing the personal information of more than 10 million individuals) and would subject designated companies to enhanced obligations, such as appointing a personal information protection officer, establishing independent oversight arrangements and conducting regular compliance audits. Companies approaching these thresholds should monitor the final rules closely.

Moving forward, international businesses should proactively embrace the policy developments, especially new efficiency tools like certification, while carefully and honestly evaluating their localized operations against these clarified rules. 

Key contacts

Jan Holthuis

Partner | Lawyer
Send me an e-mail
+86 (0)21 61730388

Yongmei Evers-Cai

Partner | Lawyer
Send me an e-mail
+31 (0)20 333 8390

Follow us!
Subscribe newsletter LinkedIn

Related news & updates