China’s Draft Regulations Set to Impact Cross-Border Data Flow and Privacy

In a noteworthy development concerning international data regulations, the Cyberspace Administration of China (CAC) released draft regulations at the close of September 2023, aimed at regulating the cross-border flow of personal data and critical data out of the People’s Republic of China (PRC).

A recent report highlighted the major changes encapsulated in the draft regulations, with the CAC providing an unofficial English translation. The comment period for this framework ended on October 15, 2023, and the CAC reserves the right to modify the regulations based on the comments received during that timeframe. However, the initial draft provides valuable insight into how the CAC might regulate cross-border data flows moving forward.

While the adjustments to the incoming regulations are at this point speculation, understanding the principles laid down in this initial draft could be crucial for large corporations and law firms that engage in frequent handling of cross-border data emanating from China.

As international regulatory bodies continue to adjust to the digital age, legislation around data privacy and cybersecurity inevitably emerges as a hot-button issue. The changing dynamics of data regulation may pose challenges, but also offer opportunities for innovative legal mores concerning data privacy and cross-border data exchange to be established around the world.