When a foreign brand sets up a WFOE, representative office, or cross-border store in China, it immediately begins collecting personal information of employees, customers, leads, and partners. China’s Personal Information Protection Law (PIPL), together with the Cybersecurity Law (CSL) and Data Security Law (DSL), forms one of the strictest data regimes in the world. Non-compliance is not a theoretical risk: regulators can block cross-border data flows, suspend business, and impose fines reaching 5% of global annual turnover. This guide explains what foreign companies actually need to do in 2026.
Why Data Compliance Matters When You Enter China
Market entry is no longer only about entity setup and tax. The moment you process a Chinese individual’s data, you enter a heavily regulated space. Building compliance in from day one protects your launch timeline, your customer trust, and your ability to move operational data across borders.
The Legal Trio: PIPL, CSL and DSL
China governs data through three overlapping laws. The Cybersecurity Law (2017) introduced network security obligations and the concept of Critical Information Infrastructure (CII). The Data Security Law (2021) classifies data by importance, distinguishing “important data” and “core data”, and restricts outbound transfer of sensitive datasets. The Personal Information Protection Law (2021) is China’s dedicated privacy statute, often compared to the EU GDPR, and it regulates how any organization collects, stores, and shares personal information. For a foreign company, all three apply the moment you process data inside China or target Chinese individuals from abroad.
Who Must Comply? The Extraterritorial Reach
PIPL applies not only to entities established in China but also to overseas processors who (a) provide products or services to individuals in China, or (b) analyze and assess the behavior of individuals in China. A foreign e-commerce seller shipping to Chinese consumers, or a SaaS tool used by a China team, can fall within scope even without a local entity. This is why market-entry planning must include a data-compliance workstream from the first day.
Core Obligations for Foreign Companies
At minimum, a compliant foreign company should: (1) publish a Chinese-language privacy policy describing what data is collected and why; (2) obtain valid consent before processing sensitive personal information; (3) maintain a data inventory and records of processing; (4) appoint a Personal Information Protection Officer when processing volumes exceed statutory thresholds; (5) conduct a Personal Information Protection Impact Assessment (PIPIA) for high-risk activities such as cross-border transfer or large-scale processing; and (6) honor individual rights requests, including access, correction, and deletion.
Cross-Border Data Transfer: Three Legal Paths
Moving personal information out of China triggers PIPL’s outbound-transfer rules. You generally have three options: (1) a CAC Security Assessment, mandatory for important data, for processors handling over one million individuals’ personal information, or for sensitive data of over ten thousand people; (2) Standard Contractual Clauses (SCC) filed with the provincial CAC, suitable for moderate-volume transfers; and (3) certification through a CAC-approved body. Since 2024, several Free Trade Zones have published “negative lists” if your data is not on the list, transfer is greatly simplified. Choosing the right path depends on data volume, sensitivity, and whether you operate CII.
Cybersecurity: MLPS 2.0 and CII
Beyond privacy, network operators must follow the Multi-Level Protection Scheme (MLPS 2.0). Systems are graded (levels 1 to 5) by their importance; most commercial systems fall in levels 2 to 3 and require filing, security hardening, and an annual review. Operators of Critical Information Infrastructure face stricter local-storage and transfer obligations. Foreign companies running China-hosted websites, apps, or back-office systems should complete MLPS grading early to avoid launch delays.
Penalties and Enforcement
Violations can bring warnings, confiscation of unlawful income, and orders to suspend services. Serious breaches carry fines of up to 50 million renminbi or 5% of the prior year’s turnover, plus personal liability for directly responsible managers. Regulators increasingly coordinate cross-agency enforcement, and blocked data transfers can freeze international operations.
Frequently Asked Questions
Do foreign companies with no China entity need to comply?
Yes. PIPL’s extraterritorial scope reaches overseas processors serving individuals in China. You may need to designate a local representative.
When is a CAC security assessment required?
When transferring important data, processing over one million people’s personal information, or handling sensitive data of more than ten thousand individuals. Smaller transfers may use SCC or certification.
Do I need a local data protection officer?
If you process above the statutory threshold or are a CII operator, appointing a Personal Information Protection Officer, and a local representative for overseas processors, is required.
How long does a CAC assessment take?
Officially up to 45 working days at the CAC review stage, but preparation and provincial review typically extend the timeline to several months. Plan early.
Can I just store everything outside China?
Not for personal information and important data collected in China. Local storage and transfer mechanisms are required; blanket offshore storage is a common violation.
How 泓盛泽 Helps
泓盛泽 (Hongshengze) helps international brands enter China compliantly. Beyond WFOE and market-entry setup, we map your data flows, prepare privacy documentation, and coordinate the right cross-border transfer path with qualified local counsel. Talk to us before you launch.