I. Executive Summary
On 1 June 2026, the State Administration for Market Regulation (SAMR) and the Standardization Administration of China (SAC) released a revised draft of the Personal Information Security Specification (the Draft Specification), which is intended to replace the current GB/T 35273-2020 standard. Although the Draft Specification is a recommended national standard and is not legally enforceable, it has long been treated by regulators as an authoritative operational guide for compliance with the Personal Information Protection Law (PIPL), and regulatory enforcement has closely tracked its requirements.
Several areas warrant particular attention. These include the narrowed scope of the contractual lawful basis and its implications for marketing (Article 5.3), the restrictions on the processing of employee personal information (PI) in the context of labor management arrangements (Article 5.4), a new conflict-of-laws framework for cross-border transfers (Article 11) and enhanced incident response obligations (Article 12).
These developments are potentially significant. They narrow, to some extent, the operational flexibility that multinational corporations (MNCs) have historically relied on when structuring cross-border data flow, and they signal a regulatory environment in which PI governance has become an increasingly central component of China’s national security framework. MNCs operating in China should therefore treat the Draft Specification as an important practical compliance benchmark and review their data governance arrangements in consideration of the changes discussed below.
With China’s core legal framework for PI and data security now largely in place, regulators have decisively shifted from rulemaking to enforcement, and MNCs are becoming an increasing focus. Some recent cases demonstrate that Chinese authorities now regard cross-border data compliance as a mature enforcement priority rather than a transition issue. This includes actions against a leading French luxury brand for bulk transfers of mainland consumer data to its global headquarters in France without using any of the required outbound transfer mechanisms, obtaining separate consent or implementing adequate safeguards, and an RMB 10 million penalty against Ctrip, a company dual-listed in the U.S. and Hong Kong, for the improper cross-border transfer of highly sensitive travel data. With these recent actions in mind, the Draft Specification for MNCs operating in China serves as a timely and practical compliance roadmap at a moment when enforcement risks are clearly rising.
II. Marketing Activities Excluded from Contract Performance as a Lawful Basis
PIPL Article 13(2) permits the processing of PI where necessary for the conclusion or performance of a contract. Article 5.3 of the Draft Specification further operationalizes this lawful basis by limiting it to processing that is necessary to achieve the core purpose of the contract. Processing activities that are not directly related to that core purpose fall outside the scope of this, including personalized advertising for marketing purposes, behavioral analysis beyond what is necessary for contract performance and user profiling that is not required to fulfill contractual obligations. Activities such as risk assessments and quality improvements that are ancillary to contract performance must also demonstrate a direct connection to the contractual purpose. Processors are also required to maintain, as part of their records of their processing activities, field-level mapping linking each category of PI to the specific contractual provision relied upon to justify the processing.
A common data flow in MNC operations—where a China entity collects customer PI, transfers it to the global headquarters to generate customer profiles, and then uses those profiles to direct targeted commercial communications—cannot be justified end-to-end based on contract performance. While that lawful basis may support the initial collection and transfer to the extent necessary to perform the transaction, it does not extend to subsequent marketing-related use. Under the Draft Specification, such marketing use must be supported by standalone consent obtained independently of the underlying transaction. Article 8.1(a) of the Draft Specification reinforces this requirement by requiring renewed notice and fresh consent where the purpose of the processing changes.
III. Employee PI: Restrictions Under HR Management
Article 5.4 imposes similar restrictions on the processing of employee PI under labor rules and collective bargaining agreements. Processing is limited to the data strictly necessary for workforce management purposes such as attendance, payroll, performance evaluation and disciplinary administration. Employee profiling and commercial marketing uses are expressly excluded. MNCs should review whether PI transferred to global human resources or to payroll systems is limited to these purposes and obtain separate consent where any such data is used for analytics or cross-system profiling.
A positive development is that transfers of employee PI for ‘disciplinary administration’ are expressly permitted. This suggests that regulators now recognize the need for MNCs to make such transfers to conduct internal audits and investigations and to implement enterprise compliance policies.
IV. Conflict-of-Laws in Cross-Border Data Transfers
MNCs sometimes face requests from foreign judicial or law enforcement authorities for PI stored in China. Under the current requirements of the PIPL and the Data Security Law (DSL), PI processors are prohibited from providing such information to foreign judicial or law enforcement authorities without prior approval from the competent PRC authorities. This creates a classic conflict-of-laws problem: on the one hand, MNCs may be required to comply with the laws of their home jurisdictions and respond to requests from overseas regulators or enforcement agencies; on the other hand, providing China-based PI or other data to foreign authorities without PRC governmental approval is not permitted under Chinese law. Subject to limited exceptions, such as the transfer of audit working papers through SEC/PCAOB-CSRC mechanisms, there appears to be no readily available approval route. Although the Hague Evidence Convention provides an official channel through which courts may seek evidence in cross-border commercial or civil disputes, in practice that process is not always used because of the time, cost and procedural burden involved. As a result, this conflict-of-laws issue exposes processors to regulatory risk on both sides.
The Draft Specification addresses this issue for the first time by acknowledging situations in which there may be a conflict between Chinese law and the laws of a foreign jurisdiction.
The Draft Specification sets out clear priorities for addressing these conflicts. Compliance with mandatory PRC laws takes precedence above all else. Subject to that overriding requirement, MNCs may then seek to comply with the applicable mandatory foreign laws. Where the foreign legal requirements are ambiguous, priority should be given to those rules that present a material risk of enforcement action or injunctive relief. Any remaining gaps may be addressed through contractual arrangements or industry self-regulatory measures, with international standards and established best practices serving as a final reference point.
The Draft Specification expressly requires MNCs to establish an internal review process for handling such requests, rather than responding directly, and to consider notifying the affected data subjects and pursuing available legal remedies before disclosing any information. The Draft Specification also requires MNCs to designate a cross-border compliance officer with documented responsibilities spanning legal, data governance and information security functions. The compliance officer would maintain structured records of the relevant jurisdictions, PI flows and transfers and the supporting documentation.
While the prohibition under the PIPL on providing China-based PI to overseas judicial and regulatory authorities remains unchanged, a positive development in the Draft Specification is that Chinese regulators have, for the first time, expressly recognized the related conflict-of-laws issue and appear to provide some useful clarification or flexibility in this regard.
MNCs should consider a range of structural measures to mitigate cross-border transfer risks. Where operationally feasible, PI should be processed onshore, with only aggregated or otherwise non-identifiable outputs transferred overseas. Where full localization is impracticable, anonymization prior to transfer may serve as an alternative. It is also important to distinguish between transfers to overseas judicial or regulatory authorities, which remain subject to the PIPL prohibition without PRC approval, and transfers by a China subsidiary to its overseas headquarters for legitimate business purposes, which are not prohibited as such but must still comply with the applicable PRC cross-border data transfer rules. Where the cross-border transfer of PI remains necessary, depending on the nature and volume of the data involved, this may require a CAC-led security assessment, personal information protection certification, or execution and filing of the CAC’s prescribed standard contract.
V. PI Security Incidents
The Draft Specification also sets out more detailed procedural requirements for incident response. MNCs should not wait until an incident occurs to establish an appropriate response framework. At a minimum, this should include a written incident response plan with clearly defined escalation procedures and regulatory notification timelines, supported by internal testing or tabletop exercises at least annually. Where an incident involves sensitive PI, notification to the affected individuals is mandatory. Agreements with third-party processors should also include clear incident notification deadlines, cooperation obligations and provisions governing data return or deletion upon termination. Where a third-party processor causes or contributes to an incident, the controller should be able to request immediate remedial action and, where appropriate, terminate the arrangement without delay.
VI. Enforcement Trends and Practical Takeaways for MNCs in China
China has clearly shifted its focus to enforcement. The French luxury brand case was widely viewed as a benchmark signal to multinational groups that ‘global database integration’ is not an automatic exemption under Chinese law. The Ctrip case also underscored the importance of maintaining full-process outbound data governance and audit mechanisms. Regulators have also taken action against the China offices of overseas data providers that automatically synchronized domestic user identity, search and behavior data to foreign servers for algorithm training, while an earlier Didi case remains the principal enforcement reference point for large-scale cross-border data compliance, particularly in sectors involving mobility, critical infrastructure and mass user data. In addition, there have reportedly been unpublished investigations involving data breach incidents at the overseas headquarters of MNCs where large volumes of the PI of Chinese nationals were affected.
The enforcement message is now clear. Chinese regulators no longer treat cross-border data compliance as a transition issue; it is now an enforcement priority. The most frequently challenged scenarios include failure to use one of the three lawful transfer mechanisms for outbound data transfers, automatic group-level data synchronization, failure to obtain separate consent for outbound transfers, attempts to split data across affiliates or batches to avoid regulatory thresholds, unauthorized disclosure of China-originated data to foreign regulators or law enforcement authorities, failure to conduct a PI impact assessment before transfer and inadequate security controls. Under the PIPL, fines can reach RMB 50 million or 5% of annual turnover, and regulators are increasingly prepared to combine corporate penalties with personal liability for the responsible officers, along with corrective orders, the suspension of outbound transfer channels, public naming and credit consequences.
China is adopting a more ‘facilitation plus control’ approach to cross-border data regulation. The 2024 rules on promoting and regulating cross-border data flows, together with expanded local negative-list regimes in places such as Shanghai and Beijing and certain free trade zones, have introduced meaningful exemptions and simplified procedures for ordinary commercial scenarios, including cross-border trade, HR management, payment processing, travel bookings and transfers necessary for contract performance. The legal framework is also becoming more detailed and tailored. MNCs operating in China must still assess whether their cross-border transfers fall within one of the three lawful mechanisms under PIPL Article 38: CAC security assessment, standard contract filing or PI protection certification. Security assessment remains mandatory for larger-scale transfers, important data and CIIOs, while the standard contract route remains the most practical option for smaller and recurring transfers. Certification now provides an additional pathway for qualifying transfers. Overall, China is moving toward a more refined and risk-based supervision of PI and other data, while allowing more workable routes for lower-risk PI, commercial data, de-identified R&D data and routine intra-group transfers.
The Draft Specification offers further practical guidance, and MNC compliance obligations are becoming more structured and better documented. The narrowing of the contractual lawful basis, the introduction of a conflict-of-laws framework and the strengthening of the incident response requirements all suggest that regulators expect MNCs to adopt a granular, China-specific approach to data governance rather than relying on a single global privacy model. Companies that continue to treat China data compliance merely as an extension of their global privacy programs may find that approach increasingly difficult to sustain. A more deliberate and carefully governed operating model will likely be necessary as the regulatory environment continues to evolve.

For further information, please contact:
Kenneth ZHOU, Partner, JunHe
Zhou_Kenneth@junhe.com




