Guide · Business

Building a Data, Privacy and Cybersecurity Inventory for Operations in China

Before operating in China, a company should inventory personal information, important data, systems, suppliers and cross-border flows. Every collection and use must have a defined purpose, necessary scope, retention period, access controls and exit method, with separate procedures assessed for high-risk and cross-border activities.

China, in FactBuilding a Data, Privacy and Cybersecurity Inventory for Operations in China

Map the Flow of Data

Do not start with a privacy policy template. Choose a real process, such as customer registration, employee onboarding, video surveillance or an after-sales ticket, and map who collects what data, which device it enters through, which system stores it, who can view it, whether it is sent to a supplier or an overseas headquarters, and when it is deleted. Pause any expansion of data collection if these questions cannot be answered.

  • Who the data subjects are.

  • The specific fields and files involved.

  • The business purpose and necessity.

  • The collection interface and notice provided.

  • The storage system and its location.

  • Internal recipients, suppliers and overseas recipients.

Separate Ordinary, Sensitive and Important Data

Names, contact details, account information, location, health, financial and biometric data, and information about minors carry different risks. If sensitive personal information is leaked or misused, it may more readily harm personal dignity or personal and property safety, so stricter standards of necessity, notice and protection apply. Important data is identified according to industry, region and official catalogues; a company cannot designate it on intuition alone.

  • Customer and prospect information.

  • Information about employees, candidates and family members.

  • Location, movement trails and surveillance images.

  • Payment, banking and credit information.

  • Medical, identity and biometric information.

  • Industrial, transport and supply-chain data.

Create a Register of Processing Activities

  1. Assign a business owner to each process.

  2. List the data fields and data subjects.

  3. Record the purpose and legal basis for processing.

  4. Set a retention period and deletion action.

  5. List the systems, administrators and access roles.

  6. List suppliers and cross-border recipients.

  7. Flag sensitive, high-risk and unresolved items.

Reconcile the register with the systems actually in use. Spreadsheets created by marketing teams, sales staff's personal WeChat accounts, customer-service screenshots, access-control systems, cloud drives and test environments are often missing from formal inventories. Each quarter, sample-check the actual fields, permissions and retention periods, and close interfaces and accounts that no longer serve a business purpose.

Maintain a log of personal information requests, recording identity verification, the request, systems involved, the responsible person, the response and completion time. Frontline customer-service staff should not casually send requesters full screenshots of back-office systems, and legal and technical teams must not each assume the other has handled the matter. If data cannot be deleted, explain the lawful reason for retaining it, restrict further use and perform the deletion again when the retention period expires.

Control Every Stage from Collection to Deletion

  1. Before collection, confirm the purpose and minimum fields required.

  2. Provide clear notice of the processing rules.

  3. Where consent is required, record valid consent.

  4. Grant access and export permissions according to job role.

  5. Apply appropriate security measures to transmission and storage.

  6. Support requests for access, correction, deletion and other rights.

  7. Delete or anonymize data when the retention period expires.

One consent cannot cover new purposes indefinitely. Marketing, profiling, provision to third parties, processing of sensitive information and cross-border activities must each be assessed against their own conditions. Refusing nonessential processing should not cause users to lose access to basic services they could otherwise use normally. Power imbalances must also be considered where children and employees are concerned.

Manage Suppliers and Cross-Border Transfers Separately

  • Conduct due diligence on cloud, customer-service, payment and marketing providers.

  • Use contracts to limit purposes, fields and personnel.

  • Set terms for security, subcontracting and incident notification.

  • Require data to be returned or deleted on termination.

  • Identify access by overseas headquarters and regional systems.

  • Determine whether an exemption, standard contract or security assessment applies.

  • Retain records of volume, scope and recipients.

Policy Q&As issued by the Cyberspace Administration of China in 2025 explain scenarios for outbound data transfers, exemptions and filing questions, but companies must still establish whether a transfer occurs and identify the type and volume of data. Remote access to Chinese systems by overseas personnel, automatic synchronization to an overseas cloud or centralized analysis by headquarters must all be included in the assessment.

Leaks, Ransomware and Accidental Sharing

If an account is compromised, a file is sent to the wrong recipient, a database is exposed or ransomware is detected, immediately isolate the affected systems, preserve logs, stop further transmission and activate the incident team. Restoring operations must not come at the cost of destroying evidence. Assess the data, number of people, timeframe and possible consequences, then make notifications and reports as required by law.

The business owner must be able to pause activity when an employee sends a customer list to a personal email account, a supplier adds a subcontractor without authorization or headquarters requests a full data sync. Post-incident reviews should result in specific improvements to permissions, processes and training, rather than placing all responsibility on the individual operator.

Differences by Industry, Scale and Region

Finance, healthcare, automotive, mapping, telecommunications, industrial and public services may be subject to sector-specific data rules and important data catalogues. Operators of critical information infrastructure and companies processing large volumes of personal information face higher requirements. Small companies may not collect or disclose personal information without limit merely because they are small.

Data rules and filing standards change. Conduct a change assessment before adding AI, location, recording, profiling or a new overseas cloud service to a product. Rewrite global group templates to reflect the company's operations in China, Chinese-language notices, actual suppliers and local response channels.

Official Basis and Verification Date

The framework for personal information and outbound data transfers is based on the Personal Information Protection Law, the Data Security Law, the Provisions on Facilitating and Regulating Cross-Border Data Flows and policy Q&As issued by the Cyberspace Administration of China in 2025, verified through 2026-8-4. Important data, volume thresholds, exemptions and filing requirements must be assessed specifically under the latest regulations, industry catalogues and the company's facts.

Sources and checks

  1. 数据出境安全管理政策问答(2025年4月)
  2. 促进和规范数据跨境流动规定实施一周年
  3. PIPL Compliance Guide
Data, Privacy and Cybersecurity for Operations in China | China, in Fact