Data Security Law
- Organization
- National People's Congress
Provides baseline rules for data classification, important data protection, data security review, and data export controls.
Open sourceSource check current as of
The first version prioritizes official, regulator, court, and international organization sources. Media sources are used only where official pages do not fully cover labour, litigation, or business developments.
This table aggregates all external sources used in cases, updates, background, scholarship, practice, and the authority library.
| Source | Type | Used in |
|---|---|---|
| A Framework for OFAC Compliance Commitments | regulator guidance | Authority Library |
| A retrospective and agenda for future research on Chinese outward foreign direct investment | article | Scholarship |
| Arkansas Attorney General, Temu lawsuit announcement | state-attorney-general | Temu Arkansas data lawsuit: consumer protection and mobile-permission risk |
| Australia foreign investment national security guidance | official guidance | Authority Library |
| Australia Modern Slavery Statements Register | official registry | Authority Library |
| Baker McKenzie: global sanctions, trade, tax, and data compliance insights | law firm insights | Practice |
| BIS Entity List | regulator list | Authority Library |
| BIS guidance on developing an export compliance program | regulator guidance | Authority Library |
| BMI German notice on Huawei and ZTE 5G components | government | Germany 5G component phase-out: Huawei and ZTE under European network-sovereignty scrutiny |
| Brazil Administrative Council for Economic Defense | regulator portal | Authority Library |
| Brazil Public Labour Prosecutor's Office | regulator | BYD Brazil labour case: contractor labour becomes group reputation and criminal risk |
| Brazil registry of employers using slave-like labour conditions | official registry | Authority Library |
| Brazilian National Data Protection Authority | regulator portal | Authority Library |
| CAC, DiDi cybersecurity review penalty decision | regulator | DiDi cybersecurity review and delisting: data security affecting overseas capital-market paths |
| Canada forced labour and supply chains reporting portal | official portal | Authority Library |
| Canada, further national security review of TikTok Canada | government | TikTok Canada national security review: from wind-up order to binding undertakings |
| Canada, wind-up order for TikTok Technology Canada | government | TikTok Canada national security review: from wind-up order to binding undertakings |
| CBP de minimis information | regulator | U.S. changes low-value shipment rules for China/Hong Kong |
| CBP UFLPA operational guidance | regulator | UFLPA apparel and e-commerce risk: small parcels still need supply-chain proof |
| CBP UFLPA statistics | regulator | CBP UFLPA statistics dashboard continues updating |
| CFIUS foreign investment security review portal | regulator portal | Authority Library |
| China's International Investment Strategy: Bilateral, Regional, and Global Law and Policy | book | Scholarship |
| China's regulatory framework for outward foreign direct investment | article | Scholarship |
| Clifford Chance: foreign investment screening, financial regulation, and disputes insights | law firm insights | Practice |
| Court of Justice of the EU case-law search | court | Nuctech EU Foreign Subsidies Regulation case: inspections and subsidy review |
| CourtListener docket, U.S. WeChat Users Alliance v. Trump | court | WeChat U.S. ban litigation: national security, speech, and platform dependence |
| CPSC Commissioners' statement on foreign e-commerce sites | regulator | CPSC scrutiny of Temu and Shein: product-safety duties for low-cost cross-border e-commerce |
| Cyberspace Administration of China | regulator | China's cross-border data-flow facilitation rules take effect |
| Data Security Law | official law | Authority Library |
| Dentons Dacheng: BRI, construction, and cross-border compliance insights | law firm insights | Practice |
| DoD PDF, entities identified as Chinese military companies | government-list | Tencent 1260H listing: non-sanctions lists still affect capital markets and procurement |
| Due Diligence Guidance for Responsible Business Conduct | international guidance | Practice |
| EU Artificial Intelligence Act | official law | Authority Library |
| EU Batteries Regulation | official law | Authority Library |
| EU Carbon Border Adjustment Mechanism Regulation | official law | Authority Library |
| EU Corporate Sustainability Due Diligence Directive | official law | Authority Library |
| EU Corporate Sustainability Due Diligence Directive practice portal | regulatory explainer | Practice |
| EU Deforestation Regulation | official law | Authority Library |
| EU Digital Markets Act | official law | Authority Library |
| EU Digital Services Act | official law | Authority Library |
| EU FDI Screening Regulation | official law | Authority Library |
| EU Forced Labour Regulation | official law | Authority Library |
| EU Foreign Subsidies Regulation | official law | Authority Library |
| EU General Data Protection Regulation | official law | Authority Library |
| EU General Product Safety Regulation | official law | Authority Library |
| European Commission AliExpress DSA proceedings | regulator | EU opens DSA proceedings against AliExpress |
| European Commission CBAM portal | regulator portal | Authority Library |
| European Commission designated VLOPs and VLOSEs | regulator | Shein EU platform regulation: VLOP duties and consumer-product safety |
| European Commission Forced Labour Regulation | regulator | EU forced-labour product ban countdown begins |
| European Commission Foreign Subsidies Regulation portal | regulator portal | Authority Library |
| European Commission investment screening portal | regulator portal | Authority Library |
| European Commission IP/24/5581 | regulator | EU imposes countervailing duties on Chinese EVs |
| European Commission sustainability due diligence | regulator | CSDDD moves into transposition and phased application |
| European Commission Temu DSA preliminary findings | regulator | Temu receives DSA preliminary findings on illegal-product risk |
| European Commission, AI Act | regulator | EU AI Act: risk classification and documentation duties for AI products abroad |
| European Commission, Temu DSA fine | regulator | Temu EUR 200 million DSA fine: risk assessments cannot be generic templates |
| European Commission, TikTok Lite rewards commitments | regulator | TikTok Lite rewards case: growth mechanics require systemic-risk assessment |
| Evaluation of Corporate Compliance Programs | prosecutorial guidance | Authority Library |
| Fangda: cross-border transactions, antitrust, and regulatory investigation practice | law firm insights | Practice |
| FATF guidance and publications | international-organization | Alternative payments and sanctions risk: de-dollarization does not eliminate compliance risk |
| FATF Recommendations | international standard | Authority Library |
| FCC Covered List | regulator list | Authority Library |
| FCC equipment authorization order | regulator | FCC Covered List: market-access blockage for telecoms and surveillance equipment |
| Federal Register, addition of Huawei entities to Entity List | regulator | Huawei Entity List case: export controls reshaping global supply chains |
| Federal Register, BIS export administration regulations | regulator | BIS semiconductor controls: equipment, software, and Entity List tightening |
| Federal Register, Executive Order 13943 on WeChat | executive-order | WeChat U.S. ban litigation: national security, speech, and platform dependence |
| Federal Register, Executive Order 13971 on Chinese connected software | executive-order | Alipay, WeChat Pay, and connected-software order: national securitization of payments and app ecosystems |
| Federal Register, Executive Order 14034 revoking prior app orders | executive-order | Alipay, WeChat Pay, and connected-software order: national securitization of payments and app ecosystems |
| Federal Register, FCC supply-chain national security rule | regulator | FCC secure-equipment authorization ban: from procurement restrictions to market-access restrictions |
| Federal Register, Huawei non-U.S. affiliates and direct-product rule updates | regulator | Huawei Entity List case: export controls reshaping global supply chains |
| Federal Register, ZTE denial order termination | regulator | ZTE denial-order crisis: breach of compliance undertakings can become existential risk |
| Foreign acquisitions by Chinese firms: A strategic intent perspective | article | Scholarship |
| Freshfields: global regulatory, antitrust, and disputes briefings | law firm insights | Practice |
| FTC, lawsuit against TikTok and ByteDance | regulator | TikTok children's privacy lawsuit: COPPA compliance as platform product governance |
| Garante Privacy | regulator | Italian regulator acts on DeepSeek data protection |
| German Federal Ministry of the Interior, 5G security announcement | government | Germany 5G component phase-out: Huawei and ZTE under European network-sovereignty scrutiny |
| Globalization of Chinese firms: Theoretical universalism or particularism | article | Scholarship |
| Google Play Protect overview | platform-guidance | Pinduoduo app security incident: app-store governance and mobile trust risk |
| Guidelines on the National Security Review of Investments | official guidance | Authority Library |
| Han Kun: technology expansion, data, and capital markets practice | law firm insights | Practice |
| How emerging market governments promote outward FDI: Experience from China | article | Scholarship |
| ICO guidance on international transfers | regulator guidance | Authority Library |
| IFC Performance Standards on Environmental and Social Sustainability | international standard | Authority Library |
| ILO Indicators of Forced Labour | international guidance | Authority Library |
| ILO Tripartite Declaration of Principles concerning Multinational Enterprises | international standard | Authority Library |
| India Digital Personal Data Protection Rules | official rule | Authority Library |
| India Enforcement Directorate press releases | regulator | Vivo India enforcement case: distribution structure, fund flows, and criminal investigation |
| India Press Note 3 foreign investment policy | official policy | Authority Library |
| International Maritime Organization security page | international-organization | Red Sea shipping disruption: how security events enter contract performance |
| Investment Canada Act, national security decisions | government | Hikvision Canada wind-up order: security equipment and investment national-security review |
| Irish Data Protection Commission press releases | regulator | TikTok fined by Irish DPC over cross-border data transfers |
| Japan METI trade control portal | regulator portal | Authority Library |
| JunHe: overseas expansion, export controls, data, and cross-border transaction updates | law firm insights | Practice |
| KrebsOnSecurity, Google suspends Pinduoduo over malware | security-reporting | Pinduoduo app security incident: app-store governance and mobile trust risk |
| KWM: going-global and global compliance insights | law firm insights | Practice |
| Measures for Security Assessment of Data Exports | regulator rule | Authority Library |
| Measures for the Administration of Overseas Investment | official rule | Authority Library |
| Measures for the Administration of Overseas Investment by Enterprises | official rule | Authority Library |
| Measures on the Standard Contract for Personal Information Export | regulator rule | Authority Library |
| MOFCOM: 2024 Statistical Bulletin of China's Outward FDI | official statistics | Background |
| National Bureau of Statistics: 2025 Statistical Communique | official statistics | Background |
| Network Data Security Management Regulation | official regulation | Authority Library |
| NVIDIA SEC filings | company | H20/MI308 licensing risk: compliant chips can be restricted again |
| OECD Due Diligence Guidance for Responsible Business Conduct | international guidance | Authority Library |
| OECD Guidelines for Multinational Enterprises on Responsible Business Conduct | international standard | Authority Library |
| OECD: FDI Regulatory Restrictiveness Index | international organization | Background |
| OFAC Sanctions List Service | regulator list | Authority Library |
| OFAC sanctions programs | regulator | Alternative payments and sanctions risk: de-dollarization does not eliminate compliance risk |
| OFAC, Chinese Military Companies sanctions program | regulator | SenseTime OFAC CMIC listing: AI, human rights, and capital-market restrictions intersect |
| OFAC, ZTE settlement | regulator | ZTE 2017 U.S. sanctions and export-control settlement: third-party channels are not safe harbors |
| Party-State Capitalism in China | article | Scholarship |
| People's Daily: State Council Regulation on Outbound Investment | official media | Background |
| Personal Information Protection Law | official law | Authority Library |
| Perspectives on China's outward foreign direct investment | article | Scholarship |
| Provisions on Facilitating and Regulating Cross-Border Data Flow | regulator rule | Authority Library |
| Regulation on Export Control of Dual-Use Items | official regulation | Authority Library |
| Repository data | repository | Initial source-check date |
| Reuters coverage of BYD Brazil labour allegations | media | BYD Brazil labour case: contractor labour becomes group reputation and criminal risk |
| SEC exhibit, SAMR administrative penalty decision for Alibaba | company-filing | Alibaba antitrust penalty: platform ecosystem governance affecting global investor disclosure |
| SEC, DiDi Form 6-K on delisting | company-filing | DiDi cybersecurity review and delisting: data security affecting overseas capital-market paths |
| SEC, Luckin Coffee accounting fraud settlement | regulator | Luckin SEC accounting-fraud case: financial-control risk for overseas-listed companies |
| SEC, PDD Holdings 2023 Form 20-F | company-filing | Pinduoduo app security incident: app-store governance and mobile trust risk |
| State Capitalism and International Investment Law | book | Scholarship |
| State Council policy database | regulator | Network Data Security Management Regulation takes effect |
| State Council Regulation on Outbound Investment | official law | Authority Library |
| State ownership effect on firms' FDI ownership decisions under institutional pressure | article | Scholarship |
| The determinants of Chinese outward foreign direct investment | article | Scholarship |
| The UK Sanctions List | regulator list | Authority Library |
| U.S. BIS export controls | regulator | H20/MI308 licensing risk: compliant chips can be restricted again |
| U.S. BIS regulations | regulator | U.S. updates advanced semiconductor export controls on China |
| U.S. Congress, PAFACA text | legislation | TikTok U.S. divestiture law: platform, data, and national security converge |
| U.S. Customs and Border Protection, USMCA | regulator | Mexico nearshoring: origin, transshipment, and USMCA compliance |
| U.S. Department of Defense releases | regulator | Battery firms and security listings: customer procurement and capital-market risk |
| U.S. Department of Defense, Section 1260H list release | government | Tencent 1260H listing: non-sanctions lists still affect capital markets and procurement |
| U.S. DOJ FCPA resources | regulator | DOJ issues new FCPA enforcement guidance |
| U.S. DOJ, Meng Wanzhou deferred prosecution agreement announcement | prosecutor | Meng Wanzhou DPA: sanctions, bank compliance, and executive exposure |
| U.S. DOJ, TikTok COPPA lawsuit | prosecutor | TikTok children's privacy lawsuit: COPPA compliance as platform product governance |
| U.S. DOJ, ZTE guilty plea and penalties | prosecutor | ZTE 2017 U.S. sanctions and export-control settlement: third-party channels are not safe harbors |
| U.S. Export Administration Regulations | official regulation | Authority Library |
| U.S. Outbound Investment Security Program | regulator portal | Authority Library |
| U.S. Supreme Court opinion, TikTok Inc. v. Garland | court | TikTok U.S. divestiture law: platform, data, and national security converge |
| U.S. Treasury Outbound Investment Security Program | regulator | U.S. outbound investment security rules take effect |
| U.S. Treasury, serious human rights abuse sanctions release | regulator | SenseTime OFAC CMIC listing: AI, human rights, and capital-market restrictions intersect |
| UFLPA Entity List | regulator list | Authority Library |
| UFLPA Operational Guidance for Importers | regulator guidance | Authority Library |
| UK export controls guidance | official guidance | Authority Library |
| UK government, Huawei to be removed from UK 5G networks by 2027 | government | Huawei UK 5G removal decision: allied sanctions changing market access |
| UK High Court, InterDigital v Lenovo FRAND judgment | court | Lenovo/InterDigital FRAND dispute: global rates and injunction risk |
| UK National Security and Investment Act notification guidance | official guidance | Authority Library |
| UN Guiding Principles on Business and Human Rights | international standard | Authority Library |
| USITC Section 337 investigations portal | agency portal | Authority Library |
| USTR China Section 301 tariff actions | regulator portal | Authority Library |
| WCO Rules of Origin portal | international customs guidance | Authority Library |
| What determines Chinese outward FDI? | article | Scholarship |
| White House presidential actions | regulator | FCPA 2025 enforcement adjustment: priorities may shift, third-party red lines remain |
| World Bank debarred firms list | regulator | MDB sanctions: one corruption or fraud case can affect global bidding eligibility |
| World Bank Sanctions System | multilateral enforcement | Authority Library |
| World Investment Report 2025 | international report | Authority Library |
| WTO anti-dumping rules portal | international legal framework | Authority Library |
| WTO subsidies and countervailing measures portal | international legal framework | Authority Library |
| WTO Technical Barriers to Trade portal | international legal framework | Authority Library |
| Zhong Lun: overseas expansion, data compliance, and international trade remedies research | law firm insights | Practice |