China Data Privacy Compliance for Foreign SMEs

By Norah Chen, Maarten Roos
For many foreign SMEs entering China, data protection may not be the first item on the incorporation checklist. But once a China subsidiary hires employees, engages customers or uses the group's global IT systems, it will almost inevitably begin processing personal information and therefore become subject to China's Personal Information Protection Law (PIPL).
The good news is that compliance for a typical SME is often quite straightforward. The key is to identify the relevant data processing activities early and put proportionate safeguards in place.
Here are some of the main issues to consider.
1. Lawful and Transparent Processing
Companies should understand what personal information they collect, why they need it and how it is used. Some actions that may becoming necessary:
- providing appropriate privacy notices;
- identifying the appropriate legal basis for processing;
- obtaining consent where required;
- collecting only information necessary for the relevant purpose; and
- avoiding unnecessary or excessive retention.
For most companies, employee, customer and website privacy arrangements are the natural starting point.
2. Sensitive Personal Information
Certain categories of personal information receive enhanced protection under Chinese law. This includes biometrics, health, financial accounting, precise location and certain identification information. Where sensitive personal information is processed, main considerations include:
- whether the processing is genuinely necessary;
- whether additional notice or consent requirements apply;
- whether enhanced security measures are needed; and
- whether a Personal Information Protection Impact Assessment (PIA) is required.
3. Third-Party Processing and Data Sharing
Foreign SMEs commonly rely on external providers for payroll, HR, legal, cloud services, CRM, IT support, marketing and other business functions.
Where personal information is processed by or shared with third parties, companies should review:
- what information is being disclosed;
- whether the recipient acts as a service provider or an independent recipient;
- whether appropriate contractual protections are in place; and
- whether additional notice, consent or assessment requirements apply.
A DPA (data processing agreement) or equivalent data protection provisions are often required as part of the relevant vendor contract.
4. Cross-Border Data Transfers
Cross-border transfers are particularly relevant to foreign-invested companies. For example, they could arise where a China subsidiary uses:
- global HR, CRM or ERP systems;
- overseas cloud infrastructure;
- regional or global reporting platforms; or
- systems that allow overseas headquarters or group companies to access China data.
Chinese law imposes specific requirements on cross-border transfers. Depending on the nature and scale of the transfer, these may include privacy notices, consent settings, a PIA (privacy impact assessment) and, in certain cases, additional regulatory transfer mechanisms.
Foreign SMEs should therefore identify cross-border data flows early rather than assume that the use of a global system is automatically compliant.
5. Personal Information Protection Impact Assessments
Before carrying out certain specified personal information processing activities, the PIPL requires companies to conduct a PIA. This is an internal compliance assessment of the legality, necessity and proportionality of the processing, the potential impact on individuals, and whether appropriate safeguards are in place.
A PIA is mandatory where the Chinese entity:
- processes sensitive personal information;
- uses personal information for automated decision-making;
- entrusts personal information processing to a third party, provides personal information to another personal information processor, or publicly discloses personal information;
- transfers personal information overseas; or
- carries out other processing activities that may have a significant impact on individuals' rights and interests.
Note that most SMEs with foreign investment will at least be transferring personal information overseas (to their central HR departments), in which case such a PIA is mandatory. It is also a great way to determine whether the company needs to meet other requirements to remain compliant.
6. Internal Data Protection Governance
Data privacy compliance should ultimately form part of the company's internal governance framework rather than consist only of external-facing privacy notices.
Depending on the size and nature of the business, relevant measures may include:
- Internal personal information protection policies
- Access controls and appropriate security measures
- Data retention and deletion procedures
- Personal information incident response plan
- Staff training
- Individual rights request procedure
For a typical SME, these arrangements can generally be designed in a proportionate manner based on the actual scale and risks of its operations.
A Practical Starting Point
For a foreign SME establishing operations in China, the very first step is usually to map the key personal information processing activities and understand:
- what personal information is collected;
- for what purposes;
- where it is stored;
- who can access it;
- which service providers receive it; and
- whether any information is transferred overseas.
Once these data flows are clear, the relevant data privacy / PIPL compliance measures can be identified and implemented in a proportionate and practical way.
R&P's data privacy team advises international companies on PRC personal information and data compliance matters, including privacy governance, personal information protection impact assessments, cross-border data transfers, regulatory filings and related compliance issues. For more information on how we can support you, please contact the authors Norah Chen ([email protected]) or Maarten Roos ([email protected]) or your trusted contact at R&P.
