China

China’s new Automotive Data Cross-border Transfer Guidelines are most useful when read through four practical questions for industry participants: what counts as automotive data, what conduct constitutes a cross-border transfer, which transfers may now benefit from exemptions, and which categories of data remain likely to attract heightened scrutiny as important data.
Continue Reading China’s 2026 Automotive Data Cross-Border Transfer Guidelines

Texas AG Ken Paxton states that the drone company misrepresented its data privacy and security practices to consumers in violation of the Texas Deceptive Trade Practices Act and allegedly concealed ties to China.

Continue Reading Texas Attorney General Announces Investigation into Drone Company over Data Privacy, Surveillance Concerns

On March 22, 2024, the centralized regulator of cyber and data security, the Cybersecurity Administration of China (CAC), published the Provisions on Promoting and Regulating the Cross-border Flow of Data (New Provisions), relaxing the existing requirements relating to cross-border data transfers. The New Provisions took immediate effect on March 22, 2024.

Continue reading the full

On June 24, 2022, China’s National Information Security Standardization Technical Committee (commonly referred to as “TC260”) finalized the Technical Guideline on Personal Information Cross-Border Transfer Certification (Final Cert Guideline). Although the Final Cert Guideline largely remains the same as the draft version released this past April, which is described in our prior blog post, China

On April 29, 2022, China’s National Information Security Standardization Technical Committee (commonly referred to as “TC260”) released a draft Technical Guideline on Personal Information Cross-Border Transfer Certifications (Cert Guideline). While the Cert Guideline is still in draft form and thus subject to change, it provides some clarification regarding the certification process for cross-border transfers of