A European business group has called on Beijing to clarify cross-border data transfer regulations it considers too vague or too strict, as they have created challenges such as higher costs for companies doing business in China.
The European Union Chamber of Commerce in China made the remarks on Wednesday as it released a survey on the impact of Chinese data regulations.
The findings show that 96% of 54 European companies on the Chinese mainland surveyed have transferred data to overseas headquarters or regional offices, which the chamber said poses a relatively low risk to data security. Meanwhile, only 6% of the companies have transferred what Beijing deems “important data” outside of the mainland.
In recent years, China has stepped up its efforts to protect data security, setting up a legal regime for data exports. Starting September last year, companies seeking to transfer data overseas must apply for a security assessment from the country’s top cybersecurity watchdog, the Cyberspace Administration of China (CAC), if they trigger regulatory thresholds.
Those security assessment requirements, coupled with other data regulations, have increased compliance costs for around 60% of the companies surveyed. Results also show that 41% of the firms are under pressure to localize their data, information technology systems, or operations.
More than 80% of the respondents want Beijing to further clarify what “important data” encompasses, while 59% and 39% would like to see clearer definitions of “personal information” and “critical information infrastructure,” respectively, according to the survey.
“European businesses hope to see more clarity on related terms, and that their legitimate business needs are taken into consideration for sectoral rules as well as for compliance timelines,” Stefan Bernhart, a vice president of the chamber, said in a press release for the survey.
The survey shows that China’s data rules have prompted some European companies to shift or consider shifting their investments outside of the mainland, though only 2% and 4% of the respondents, respectively, have done so. A further 13% said they had postponed investment or product-related decisions.
In September, the CAC issued draft rules proposing a measure that would exempt companies seeking to transfer data overseas from security assessment applications under certain circumstances, such as when the data are expected to involve fewer than 10,000 people within a year.
“It is positive that China’s relevant authorities are signaling an intent to optimize the country’s data regulations,” Bernhart said. Still, the European chamber suggests raising the threshold to 100,000 people to ease the compliance burden on small businesses while allowing authorities to identify targets of a greater regulatory value more efficiently.
China’s vague cross-border data regulations have posed challenges to not only foreign companies but also domestic ones.
As a result of the vagueness, many Chinese companies have trouble attracting foreign investment or getting listed overseas, a capital markets lawyer previously told Caixin on the condition of anonymity.
Source: Caixin Global







