On June 12, 2026, the Cyberspace Administration of China released the China Personal Information Protection Report (2025) (the “Report”). The Report is the first comprehensive annual report on personal information protection issued by the Cyberspace Administration of China. It is intended to systematically review the principal progress, practical results, and governance experience in China’s personal information protection work in 2025; comprehensively present the achievements in institutional development, regulatory governance, social co-governance, publicity and education, and international cooperation; and provide a reference for the continued advancement of personal information protection.
For foreign-invested enterprises in China, the Report presents, in a concentrated manner, the policy direction and enforcement priorities of China’s personal information protection regulation. This article, in light of the content of the Report, analyzes several compliance scenarios of particular concern to foreign-invested enterprises in China.
I. Global Privacy Frameworks Require Localized Implementation The Report shows that, in 2025, China continued to strengthen the top-level design of personal information protection. The Regulations on the Administration of Cyber Data Security came into effect and were implemented. Systems relating to personal information protection compliance audits, security management for the application of facial recognition technology, online identity authentication, and the administration of cross-border transfers of personal information were successively established. National standards relating to personal information protection continued to be issued, including two mandatory national standards and seven recommended national standards.
This institutional trend has a direct impact on foreign-invested enterprises in China. Many multinational enterprises have already established compliance systems based on the GDPR, group privacy rules, or global data protection policies. However, China’s personal information protection regime imposes localized requirements in respect of notification and consent, sensitive personal information, cross-border transfers of personal information, personal information protection impact assessments, automated decision-making, protection of minors, identification of important data, and cyber data security management. Foreign-invested enterprises operating in China need to translate group-level privacy principles into enforceable institutional documents, system configurations, and operating procedures for their China businesses.
In practice, the common risks for foreign-invested enterprises often arise from insufficient adaptation of global templates to China-specific scenarios. For example, a group-wide privacy notice may fail to fully specify the processing purposes, processing methods, categories of personal information, retention periods, channels for exercising personal rights, and information on overseas recipients as required under Chinese law; a global Cookie or marketing preference management mechanism may fail to cover actual touchpoints such as China-based apps, mini programs, official websites, and offline stores; and a group data map may also fail to accurately reflect the flow paths of personal information of China-based employees, customers, distributors, patients, consumers, or suppliers between local systems and overseas systems. Therefore, foreign-invested enterprises in China should treat the “localization of global policies” as foundational work for personal information protection compliance, so as to ensure that group systems can operate effectively within China’s business, technical, and regulatory context.
II. Cross-Border Transfers of Data For foreign-invested enterprises in China, cross-border transfers of personal information are usually the most continuous and structural compliance issue. The Report states that, in 2025, mechanisms such as certification for cross-border transfers of personal information, compliance guidelines for cross-border flows of financial data, and negative lists for pilot free trade zones and free trade ports continued to advance, and that the administration of cross-border transfers of personal information was listed as an important component of institutional development.
Foreign-invested enterprises commonly have needs for cross-border data flows in their operations in China, involving customer relationship systems, human resources systems, finance systems, supply chain systems, compliance reporting systems, cybersecurity monitoring systems, global customer service systems, and cloud services and SaaS tools that are centrally managed by headquarters. Such outbound transfer activities are often long-term, embedded, and high-frequency in nature, and compliance review should not remain at the level of a single contract or one-off filing. Enterprises should first clarify the business purposes, data categories, scope of data subjects, overseas recipients, system deployment methods, and subsequent transfer chains for personal information processing activities within China, and then determine whether a security assessment, standard contract, certification, or a specific facilitation mechanism applies.
In practice, foreign-invested enterprises need to pay particular attention to whether access by headquarters to China data constitutes a cross-border transfer of personal information; whether overseas IT operation and maintenance involves remote retrieval or backup of China-based personal information; whether global HR systems process sensitive personal information of China-based employees; whether overseas compliance investigations require the transmission of employees’ communication records or whistleblowing materials; whether cross-border clinical research and pharmacovigilance activities involve patient or subject information; and whether distributors, agents, or platform partners form indirect outbound transfers within the business chain. For the foregoing scenarios, the compliance plan should simultaneously cover the selection of legal pathways, data minimization, restrictions on overseas recipients, responses to personal rights, control of onward transfers after export, retention of logs, and periodic review.
III. Compliance Audits and Demonstration of Accountability The Report identifies the personal information protection compliance audit system as an important element of institutional development in 2025, and refers to the advancement of personal information protection certification and compliance audit service certification. This means that enterprises’ personal information protection compliance is entering a stage in which evidentiary records and verifiability are given greater emphasis.
Foreign-invested enterprises in China usually have relatively mature global compliance management systems, but the requirements for verifiable performance of responsibilities in China’s regulatory context have their own characteristics. When conducting inspections or handling complaints, regulatory authorities are concerned not only with whether an enterprise has formulated a privacy policy, data protection policy, or employee handbook, but also with whether the enterprise has completed an inventory of personal information processing activities, conducted personal information protection impact assessments, retained records of notification and consent, can demonstrate the necessity of permission calls, manages SDKs, suppliers, and group affiliates, has established an emergency response mechanism for personal information security incidents, and responds to user rights requests in a timely manner.
Therefore, foreign-invested enterprises should embed personal information protection compliance audits into their local governance systems. The audit subjects should not be limited to legal texts, but should also cover system permissions, business processes, supplier contracts, cross-border transfers, data retention, deletion mechanisms, employee training, and incident response records. For systems uniformly managed by group headquarters, the China entity needs to retain sufficient local compliance evidence to demonstrate that it is able to identify, control, and supervise personal information processing activities within China. Such evidence may play a key role in administrative inspections, customer due diligence, investments and mergers and acquisitions, data security incidents, labor disputes, and consumer complaints.
IV. Apps, SDKs, Official Websites, and Smart Terminals The Report shows that, in 2025, regulatory authorities continued to carry out centralized rectification and special inspections targeting the unlawful collection and use of personal information in key scenarios such as apps, SDKs, smart terminals, public places, and offline consumption. For foreign-invested enterprises in China, this trend has strong practical significance. In the Chinese market, foreign-invested enterprises usually reach consumers through official websites, apps, mini programs, e-commerce flagship stores, CRM systems, membership systems, after-sales service platforms, smart devices, and offline stores. The foregoing digital touchpoints may all become entry points for personal information regulation and complaint reporting.
In practice, common issues for foreign-invested enterprises include China-based apps or mini programs continuing to follow overseas product logic and excessively invoking permissions such as location, contacts, camera, microphone, and device identifiers; insufficient continuous monitoring and version-update review after third-party SDKs are embedded; official website Cookie banners or marketing consent mechanisms failing to meet Chinese user experience and notification requirements; membership registration processes tying marketing authorization to the use of services; offline stores lacking clear notice when collecting consumers’ identity documents, facial images, or contact information; and smart devices continuously transmitting device logs, voice, images, or usage behavior data in the background.
Foreign-invested enterprises in China should adopt “touchpoint governance” as a method and conduct compliance reviews of all data entry points oriented toward Chinese users, employees, and business partners. Apps and mini programs should focus on reviewing permission calls, SDK inventories, display of privacy policies, pop-up windows upon first launch, minors’ modes, account cancellation mechanisms, and channels for exporting or deleting personal information. Official websites and marketing systems should focus on Cookies, profiling analysis, precision marketing, cross-platform tracking, and mechanisms for refusing personalized recommendations. Smart terminals and after-sales systems should focus on default settings, remote diagnostics, log backhaul, collection of voice and image data, and requirements for clearing personal information when devices are transferred second-hand.
V. Facial Recognition and Offline Scenarios The Report identifies security management for the application of facial recognition technology as an important element of institutional development and regulatory governance, and refers to governance work in scenarios such as facial recognition in public places and smart terminals. For foreign-invested enterprises in China that have offline operating networks, office campuses, factories, hotels, commercial stores, medical institutions, or education and training scenarios, facial recognition compliance should be included in the key risk list.
The compliance difficulty of facial recognition lies in the fact that enterprises often introduce the technology for purposes of security, efficiency, or identity verification, while the processing objects constitute highly sensitive personal information and the processing consequences are irreversible. Foreign-invested enterprises should prudently assess the need for facial recognition in access control and attendance, visitor registration, member identification, payment verification, security monitoring, hotel check-in, patient identification, or campus management. The compliance determination should focus on the legitimacy and necessity of the processing purpose, and should further review whether non-facial-recognition alternatives exist, whether separate consent has been obtained, whether the processing rules have been fully notified, whether retention periods and access permissions are restricted, and whether technical suppliers are prevented from retaining, training on, or secondarily using the relevant data.
For multinational groups, attention must also be paid to whether facial information is incorporated into global security systems, access control systems, or employee management systems. If overseas headquarters, overseas security teams, or overseas suppliers can access facial information collected within China, the enterprise must also simultaneously assess the compliance pathway for cross-border transfers of data. Data collection in offline scenarios is more easily overlooked than in online scenarios, but once it triggers employee complaints, consumer disputes, or media attention, the risk may spill over more rapidly.
VI. Employee Personal Information and Internal Governance The Report emphasizes that personal information protection covers all scenarios and the entire process, and refers to personal information protection work in key industries such as education, taxation, finance, and postal services, as well as specific scenarios such as recruitment. For foreign-invested enterprises in China, employee personal information processing is one of the compliance areas that is relatively easy to underestimate.
Multinational enterprises usually rely on global HR systems, performance systems, compensation systems, equity incentive platforms, travel systems, compliance reporting systems, and internal investigation mechanisms to process employee personal information, involving identity documents, bank accounts, health information, family members, background checks, performance evaluations, disciplinary actions, communication records, location information, entry and exit records, biometric information, and the like. Because employment relationships have a managerial subordinate nature, enterprises cannot simply treat employees’ signing of a unified consent form as the lawful basis for all processing activities. For sensitive personal information, cross-border transfers, automated assessments, background checks, and internal investigations, enterprises need to separately substantiate the necessity of processing, the sufficiency of notice, and access control measures.
In labor disputes and internal compliance investigations, issues relating to the processing of employee personal information may quickly turn into disputes over the legality of evidence, privacy infringement, protection of personality rights and interests, and compliance with cross-border data transfers. Foreign-invested enterprises should establish rules for processing the personal information of China-based employees, and set processing boundaries respectively for recruitment, onboarding, in-service management, performance appraisal, monitoring and security, internal reporting, investigation and evidence collection, separation management, and file retention. Where overseas headquarters are involved in investigations or approvals, data transmission and materials-sharing mechanisms should also be designed in advance, so as to avoid the ad hoc processing of highly sensitive data in urgent incidents.
VII. Automated Decision-Making and Artificial Intelligence The Report refers to the development of a national standards system for personal information protection, and covers key links such as automated decision-making based on personal information, processing of sensitive personal information, transfer of personal information, and compliance audits. For foreign-invested enterprises in China, compliance in relation to artificial intelligence and automated decision-making is becoming a new key issue.
Multinational enterprises may use globally unified recommendation algorithms, marketing models, credit assessment models, anti-fraud models, recruitment screening tools, customer service robots, generative artificial intelligence tools, or production and operation forecasting systems in their China businesses. If the foregoing systems use the personal information of Chinese users, employees, or business partners, or have a substantive impact on their rights and interests, they need to be reviewed under China’s personal information protection rules. Enterprises should pay attention to whether model input data has been lawfully obtained; whether feature variables involve sensitive personal information; whether inferred information can identify specific individuals; whether automated decision-making has a material impact on transaction terms, price displays, position screening, credit lines, or service opportunities; and whether individuals have channels to refuse, obtain explanations, or seek human intervention.
When global AI tools are implemented in China, issues of local data minimization, isolation of training data, management of prompts and output content, supplier access control, and cross-border transfers must also be addressed. For foreign-invested enterprises in China, AI compliance should not be uniformly determined solely by headquarters’ technical teams based on global standards, but should instead be jointly assessed by China legal, compliance, information security, and business teams with respect to personal information protection requirements in China-specific scenarios.
Conclusion The China Personal Information Protection Report (2025) provides an important window for foreign-invested enterprises in China to observe China’s personal information protection regulation. The institutional development and regulatory priorities it presents indicate that China’s personal information protection compliance has entered a stage that places greater emphasis on scenario identification, process control, implementation of responsibilities, and retention of evidence.
For foreign-invested enterprises, personal information protection should be incorporated into the core compliance agenda of their China businesses. They should establish continuous review mechanisms around cross-border transfers of data, governance of apps and SDKs, employee personal information, facial recognition, smart terminals, automated decision-making, supplier management, and incident response, so as to achieve a stable balance among personal information protection, data utilization, and business development in China’s digital economy environment.
For foreign-invested enterprises in China, the Report presents, in a concentrated manner, the policy direction and enforcement priorities of China’s personal information protection regulation. This article, in light of the content of the Report, analyzes several compliance scenarios of particular concern to foreign-invested enterprises in China.
I. Global Privacy Frameworks Require Localized Implementation The Report shows that, in 2025, China continued to strengthen the top-level design of personal information protection. The Regulations on the Administration of Cyber Data Security came into effect and were implemented. Systems relating to personal information protection compliance audits, security management for the application of facial recognition technology, online identity authentication, and the administration of cross-border transfers of personal information were successively established. National standards relating to personal information protection continued to be issued, including two mandatory national standards and seven recommended national standards.
This institutional trend has a direct impact on foreign-invested enterprises in China. Many multinational enterprises have already established compliance systems based on the GDPR, group privacy rules, or global data protection policies. However, China’s personal information protection regime imposes localized requirements in respect of notification and consent, sensitive personal information, cross-border transfers of personal information, personal information protection impact assessments, automated decision-making, protection of minors, identification of important data, and cyber data security management. Foreign-invested enterprises operating in China need to translate group-level privacy principles into enforceable institutional documents, system configurations, and operating procedures for their China businesses.
In practice, the common risks for foreign-invested enterprises often arise from insufficient adaptation of global templates to China-specific scenarios. For example, a group-wide privacy notice may fail to fully specify the processing purposes, processing methods, categories of personal information, retention periods, channels for exercising personal rights, and information on overseas recipients as required under Chinese law; a global Cookie or marketing preference management mechanism may fail to cover actual touchpoints such as China-based apps, mini programs, official websites, and offline stores; and a group data map may also fail to accurately reflect the flow paths of personal information of China-based employees, customers, distributors, patients, consumers, or suppliers between local systems and overseas systems. Therefore, foreign-invested enterprises in China should treat the “localization of global policies” as foundational work for personal information protection compliance, so as to ensure that group systems can operate effectively within China’s business, technical, and regulatory context.
II. Cross-Border Transfers of Data For foreign-invested enterprises in China, cross-border transfers of personal information are usually the most continuous and structural compliance issue. The Report states that, in 2025, mechanisms such as certification for cross-border transfers of personal information, compliance guidelines for cross-border flows of financial data, and negative lists for pilot free trade zones and free trade ports continued to advance, and that the administration of cross-border transfers of personal information was listed as an important component of institutional development.
Foreign-invested enterprises commonly have needs for cross-border data flows in their operations in China, involving customer relationship systems, human resources systems, finance systems, supply chain systems, compliance reporting systems, cybersecurity monitoring systems, global customer service systems, and cloud services and SaaS tools that are centrally managed by headquarters. Such outbound transfer activities are often long-term, embedded, and high-frequency in nature, and compliance review should not remain at the level of a single contract or one-off filing. Enterprises should first clarify the business purposes, data categories, scope of data subjects, overseas recipients, system deployment methods, and subsequent transfer chains for personal information processing activities within China, and then determine whether a security assessment, standard contract, certification, or a specific facilitation mechanism applies.
In practice, foreign-invested enterprises need to pay particular attention to whether access by headquarters to China data constitutes a cross-border transfer of personal information; whether overseas IT operation and maintenance involves remote retrieval or backup of China-based personal information; whether global HR systems process sensitive personal information of China-based employees; whether overseas compliance investigations require the transmission of employees’ communication records or whistleblowing materials; whether cross-border clinical research and pharmacovigilance activities involve patient or subject information; and whether distributors, agents, or platform partners form indirect outbound transfers within the business chain. For the foregoing scenarios, the compliance plan should simultaneously cover the selection of legal pathways, data minimization, restrictions on overseas recipients, responses to personal rights, control of onward transfers after export, retention of logs, and periodic review.
III. Compliance Audits and Demonstration of Accountability The Report identifies the personal information protection compliance audit system as an important element of institutional development in 2025, and refers to the advancement of personal information protection certification and compliance audit service certification. This means that enterprises’ personal information protection compliance is entering a stage in which evidentiary records and verifiability are given greater emphasis.
Foreign-invested enterprises in China usually have relatively mature global compliance management systems, but the requirements for verifiable performance of responsibilities in China’s regulatory context have their own characteristics. When conducting inspections or handling complaints, regulatory authorities are concerned not only with whether an enterprise has formulated a privacy policy, data protection policy, or employee handbook, but also with whether the enterprise has completed an inventory of personal information processing activities, conducted personal information protection impact assessments, retained records of notification and consent, can demonstrate the necessity of permission calls, manages SDKs, suppliers, and group affiliates, has established an emergency response mechanism for personal information security incidents, and responds to user rights requests in a timely manner.
Therefore, foreign-invested enterprises should embed personal information protection compliance audits into their local governance systems. The audit subjects should not be limited to legal texts, but should also cover system permissions, business processes, supplier contracts, cross-border transfers, data retention, deletion mechanisms, employee training, and incident response records. For systems uniformly managed by group headquarters, the China entity needs to retain sufficient local compliance evidence to demonstrate that it is able to identify, control, and supervise personal information processing activities within China. Such evidence may play a key role in administrative inspections, customer due diligence, investments and mergers and acquisitions, data security incidents, labor disputes, and consumer complaints.
IV. Apps, SDKs, Official Websites, and Smart Terminals The Report shows that, in 2025, regulatory authorities continued to carry out centralized rectification and special inspections targeting the unlawful collection and use of personal information in key scenarios such as apps, SDKs, smart terminals, public places, and offline consumption. For foreign-invested enterprises in China, this trend has strong practical significance. In the Chinese market, foreign-invested enterprises usually reach consumers through official websites, apps, mini programs, e-commerce flagship stores, CRM systems, membership systems, after-sales service platforms, smart devices, and offline stores. The foregoing digital touchpoints may all become entry points for personal information regulation and complaint reporting.
In practice, common issues for foreign-invested enterprises include China-based apps or mini programs continuing to follow overseas product logic and excessively invoking permissions such as location, contacts, camera, microphone, and device identifiers; insufficient continuous monitoring and version-update review after third-party SDKs are embedded; official website Cookie banners or marketing consent mechanisms failing to meet Chinese user experience and notification requirements; membership registration processes tying marketing authorization to the use of services; offline stores lacking clear notice when collecting consumers’ identity documents, facial images, or contact information; and smart devices continuously transmitting device logs, voice, images, or usage behavior data in the background.
Foreign-invested enterprises in China should adopt “touchpoint governance” as a method and conduct compliance reviews of all data entry points oriented toward Chinese users, employees, and business partners. Apps and mini programs should focus on reviewing permission calls, SDK inventories, display of privacy policies, pop-up windows upon first launch, minors’ modes, account cancellation mechanisms, and channels for exporting or deleting personal information. Official websites and marketing systems should focus on Cookies, profiling analysis, precision marketing, cross-platform tracking, and mechanisms for refusing personalized recommendations. Smart terminals and after-sales systems should focus on default settings, remote diagnostics, log backhaul, collection of voice and image data, and requirements for clearing personal information when devices are transferred second-hand.
V. Facial Recognition and Offline Scenarios The Report identifies security management for the application of facial recognition technology as an important element of institutional development and regulatory governance, and refers to governance work in scenarios such as facial recognition in public places and smart terminals. For foreign-invested enterprises in China that have offline operating networks, office campuses, factories, hotels, commercial stores, medical institutions, or education and training scenarios, facial recognition compliance should be included in the key risk list.
The compliance difficulty of facial recognition lies in the fact that enterprises often introduce the technology for purposes of security, efficiency, or identity verification, while the processing objects constitute highly sensitive personal information and the processing consequences are irreversible. Foreign-invested enterprises should prudently assess the need for facial recognition in access control and attendance, visitor registration, member identification, payment verification, security monitoring, hotel check-in, patient identification, or campus management. The compliance determination should focus on the legitimacy and necessity of the processing purpose, and should further review whether non-facial-recognition alternatives exist, whether separate consent has been obtained, whether the processing rules have been fully notified, whether retention periods and access permissions are restricted, and whether technical suppliers are prevented from retaining, training on, or secondarily using the relevant data.
For multinational groups, attention must also be paid to whether facial information is incorporated into global security systems, access control systems, or employee management systems. If overseas headquarters, overseas security teams, or overseas suppliers can access facial information collected within China, the enterprise must also simultaneously assess the compliance pathway for cross-border transfers of data. Data collection in offline scenarios is more easily overlooked than in online scenarios, but once it triggers employee complaints, consumer disputes, or media attention, the risk may spill over more rapidly.
VI. Employee Personal Information and Internal Governance The Report emphasizes that personal information protection covers all scenarios and the entire process, and refers to personal information protection work in key industries such as education, taxation, finance, and postal services, as well as specific scenarios such as recruitment. For foreign-invested enterprises in China, employee personal information processing is one of the compliance areas that is relatively easy to underestimate.
Multinational enterprises usually rely on global HR systems, performance systems, compensation systems, equity incentive platforms, travel systems, compliance reporting systems, and internal investigation mechanisms to process employee personal information, involving identity documents, bank accounts, health information, family members, background checks, performance evaluations, disciplinary actions, communication records, location information, entry and exit records, biometric information, and the like. Because employment relationships have a managerial subordinate nature, enterprises cannot simply treat employees’ signing of a unified consent form as the lawful basis for all processing activities. For sensitive personal information, cross-border transfers, automated assessments, background checks, and internal investigations, enterprises need to separately substantiate the necessity of processing, the sufficiency of notice, and access control measures.
In labor disputes and internal compliance investigations, issues relating to the processing of employee personal information may quickly turn into disputes over the legality of evidence, privacy infringement, protection of personality rights and interests, and compliance with cross-border data transfers. Foreign-invested enterprises should establish rules for processing the personal information of China-based employees, and set processing boundaries respectively for recruitment, onboarding, in-service management, performance appraisal, monitoring and security, internal reporting, investigation and evidence collection, separation management, and file retention. Where overseas headquarters are involved in investigations or approvals, data transmission and materials-sharing mechanisms should also be designed in advance, so as to avoid the ad hoc processing of highly sensitive data in urgent incidents.
VII. Automated Decision-Making and Artificial Intelligence The Report refers to the development of a national standards system for personal information protection, and covers key links such as automated decision-making based on personal information, processing of sensitive personal information, transfer of personal information, and compliance audits. For foreign-invested enterprises in China, compliance in relation to artificial intelligence and automated decision-making is becoming a new key issue.
Multinational enterprises may use globally unified recommendation algorithms, marketing models, credit assessment models, anti-fraud models, recruitment screening tools, customer service robots, generative artificial intelligence tools, or production and operation forecasting systems in their China businesses. If the foregoing systems use the personal information of Chinese users, employees, or business partners, or have a substantive impact on their rights and interests, they need to be reviewed under China’s personal information protection rules. Enterprises should pay attention to whether model input data has been lawfully obtained; whether feature variables involve sensitive personal information; whether inferred information can identify specific individuals; whether automated decision-making has a material impact on transaction terms, price displays, position screening, credit lines, or service opportunities; and whether individuals have channels to refuse, obtain explanations, or seek human intervention.
When global AI tools are implemented in China, issues of local data minimization, isolation of training data, management of prompts and output content, supplier access control, and cross-border transfers must also be addressed. For foreign-invested enterprises in China, AI compliance should not be uniformly determined solely by headquarters’ technical teams based on global standards, but should instead be jointly assessed by China legal, compliance, information security, and business teams with respect to personal information protection requirements in China-specific scenarios.
Conclusion The China Personal Information Protection Report (2025) provides an important window for foreign-invested enterprises in China to observe China’s personal information protection regulation. The institutional development and regulatory priorities it presents indicate that China’s personal information protection compliance has entered a stage that places greater emphasis on scenario identification, process control, implementation of responsibilities, and retention of evidence.
For foreign-invested enterprises, personal information protection should be incorporated into the core compliance agenda of their China businesses. They should establish continuous review mechanisms around cross-border transfers of data, governance of apps and SDKs, employee personal information, facial recognition, smart terminals, automated decision-making, supplier management, and incident response, so as to achieve a stable balance among personal information protection, data utilization, and business development in China’s digital economy environment.