Author: Lawyer Zhang Jingxinyue, PRC-qualified Lawyer | Singapore Registered Foreign Lawyer
These cases jointly illustrate that data compliance no longer remains at the level of system construction and declaration review, but has entered a more specific, accountable, and punishable enforcement stage.
However, in practice, many multinational companies still have a misunderstanding - they only focus on the data export requirements of Chinese law, but ignore the data protection obligations of the recipient country Singapore under the PDPA. For cross-border enterprises involving business in both China and Singapore, the compliance challenges arising from the superposition of dual requirements are particularly prominent.
This article uses recent law enforcement cases as an entry point to systematically sort out the three compliance paths for data export from China and the data protection obligations of recipients under the Singapore PDPA. It also combines common misunderstandings in practice to provide overseas companies with full-process operational guidance from data inventory to continuous monitoring.
01 Latest case review: intensive release of law enforcement signals
In 2025, the Shanghai Public Security Bureau publicly disclosed a case of administrative penalties for the protection of personal information of a multinational company. The relevant companies were pointed out to have three illegal facts: first, they illegally transmitted users’ personal information to overseas headquarters without using any compliance channels; second, they failed to fully inform users of the overseas recipient’s processing methods and failed to obtain "individual consent"; third, they failed to adopt security technical measures such as encryption and de-identification of the collected personal information. This case is one of the few publicly disclosed cases in which a multinational company was subject to administrative penalties for illegally exporting data since the Personal Information Protection Law came into effect, and it has important warning significance.
In January 2026, the Shanghai Cyberspace Administration of China released a number of typical cases of data compliance enforcement during the "Liang Jian Pujiang" special operation, two of which involved the export of illegal data:
Case 1: Case of a hotel management company illegally exporting user data abroad
Because the hotel's online booking scenario involves data export, the company took the initiative to apply for a data export security assessment to the cybersecurity and informatization department. However, after receiving the "Notice of Assessment Result" from the national cybersecurity and informatization department, which clearly informed that the relevant personal information data items were "not necessary for export abroad", the company did not take corrective measures and continued to transfer personal information overseas in violation of regulations. In accordance with the "Personal Information Protection Law" and the "Network Data Security Management Regulations", the cyberspace department ordered it to make corrections within a time limit and imposed a fine. This is one of the few publicly disclosed data export enforcement cases in which fines have been imposed.
The important warning is that if an enterprise continues to transmit relevant personal information without taking corrective measures after receiving an assessment conclusion of "failed" or "insufficient necessity to exit the country," regulatory authorities will usually consider it to have clearly understood the compliance risks, and it will be more likely to be found to have a high degree of subjective fault in subsequent law enforcement.
Case 2: A property management company’s illegal export of user data abroad
The APP operated by this company mainly helps users manage member accounts and book and check-in procedures. After investigation, it was found that it provided user accommodation information overseas on its own without declaring a data export security assessment, entering into a standard contract for personal information export, or passing personal information protection certification, and involved sensitive personal information such as financial accounts. The cybersecurity and informatization department ordered him to make corrections within a time limit and issued a warning and punishment. The company's violation was more of a "comprehensive avoidance" - it did not pass any compliance path, but because there was no "knowing violation", the penalty was relatively light.
The signal sent by these two cases is very clear: the law enforcement of data export has entered a normalized stage, with multiple departments of cybersecurity and informatization and public security cooperating in law enforcement, and the penalty gradient is linked to the degree of subjective malice. For enterprises, compliance is not a one-time reporting act, but a continuous obligation throughout the entire life cycle of data export.
02 Three hurdles for China’s data export: security assessment, standard contract, and certification
According to Article 38 of the Personal Information Protection Law and the Provisions on Promoting and Regulating Cross-Border Data Flows, China has established three compliance paths for data export, and enterprises need to choose the applicable path based on their own circumstances.
The first level: Data export security assessment (the most stringent review)
Applicable situations mainly include: critical information infrastructure operators provide personal information or important data overseas; non-critical information infrastructure operators provide important data overseas, or provide overseas personal information of more than 1 million people (excluding sensitive personal information) or sensitive personal information of more than 10,000 people since January 1 of that year. Note: The Shanghai Negative List will include personal information of more than 10 million people into important data management.
According to the "Regulations on Promoting and Standardizing Cross-border Data Flows", the data export security assessment results are valid for 3 years; after the expiration of the validity period, if you need to continue to carry out relevant data export activities and no situation requires re-declaration, you can apply for an extension in accordance with the law before the expiration of the period. Key points of the process: Preliminary review by the provincial cyberspace department → review by the national cyberspace department, the whole process takes about 2–4 months.
Second level: personal information transfer standard contract filing (most commonly used in practice)
Applicable situations: Non-critical information infrastructure operators provide personal information of more than 100,000 people but less than 1 million people, or sensitive personal information of less than 10,000 people to overseas countries in the year. Enterprises need to enter into standard contracts with overseas recipients and file them with the provincial cyberspace department. This is currently a more suitable path for most multinational companies.
The third level: Personal information protection certification (emerging path)
Applicable situations: The data level is the same as standard contract filing, and enterprises can choose either one. As one of the three compliance paths, personal information protection certification has relevant certification specifications and implementation rules as the basis. However, in practice, compared with the standard contract filing path, the cases of enterprises adopting the certification path are still relatively limited. When applicable, it needs to be judged based on the requirements of the certification agency and the latest regulatory standards.
Practical Tips: Exemptions from Notification
- Export of data that does not contain personal information or important data in activities such as international trade, cross-border transportation, and academic cooperation
- Personal information collected overseas is transferred back to China for processing and then provided overseas, without introducing domestic personal information or important data.
- The personal information of less than 100,000 people was provided to overseas countries in total that year (excluding sensitive information)
- It is really necessary to provide personal information overseas for the performance of personal contracts (such as cross-border shopping, flight and hotel reservations, etc.)
Special note: "Domestic individuals booking domestic hotels" are not exempt and shall not be exempted from declaration. This is clearly stipulated in the policy Q&A issued by the Cyberspace Administration of China in October 2025.
New developments in negative list In April 2026, the Shanghai Cyberspace Administration and the Data Bureau jointly released a new version of the negative list for data export abroad, extending the coverage from the free trade zone to the entire city, covering the four major industries of reinsurance, international shipping, commerce and meteorology. Data outside the list can be exempted from declaration after completion of filing and can flow freely and in an orderly manner in accordance with the law. As of now, nine regions across the country have implemented negative lists for data export.
03 Data protection obligations under Singapore’s PDPA: overseas companies cannot only look at Chinese law
When many Chinese companies build data flows between China and Singapore, they tend to only focus on the "data outbound" path under Chinese law, but ignore the data protection obligations of Singaporean recipients under the PDPA. Strictly speaking, the PDPA does not simply regulate so-called "data input", but requires Singaporean organizations to continue to meet statutory requirements when collecting, using, disclosing, protecting, retaining and further transferring personal data overseas.
Especially in a cross-border group structure, if a Singaporean entity receives data from China and then continues to transmit it to the headquarters, cloud service provider, third-party service provider or other country nodes, special attention needs to be paid to the Transfer Limitation Obligation under PDPA, that is, to ensure that subsequent recipients provide protection standards equivalent to PDPA.
In practice, supervision is more concerned about:
- Whether the enterprise has established a data processing agreement;
- Whether internal access rights are restricted;
- Whether there is a deletion and tracking mechanism;
- Whether to manage third-party suppliers;
- Whether a data breach response process has been established;
- Do you really know where your data ends up?
Regarding enforcement trends: In October 2025, Singapore’s PDPC fined Marina Bay Sands (MBS) S$315,000 for a configuration error during the software migration process that resulted in the theft of personal data of approximately 665,000 customers. Although this case is not simply a penalty for cross-border data transmission, it reflects the PDPC’s increasingly strict review of corporate data protection capabilities, access control and security management measures. This trend is also of cautionary significance for Singaporean entities responsible for the reception, storage and subsequent processing of cross-border data.
In addition, what deserves the attention of many Chinese companies is that Singapore has gradually strengthened its regulatory requirements for the use of identity information in recent years. PDPC has issued public guidelines recommending that companies reduce their over-reliance on NRIC (identity card number) and gradually adjust business processes that have long used ID number as the default identity verification method. For many cross-border companies that have long followed the Chinese ID card verification logic, this is a regulatory direction that is easily overlooked but may continue to be strengthened in the future.
04 Five levels of dual compliance: from data inventory to continuous monitoring
For multinational companies operating in China and transmitting data to Singapore, they need to meet the legal requirements of both countries. We summarize it as "Five Passes":
The first level: data inventory and classification
Comprehensively sort out all business flows of personal information transmitted from China to overseas; distinguish general data, personal information, sensitive personal information, and important data; count the cumulative amount of outbound data for the year, and determine the applicable compliance path.
Common misunderstandings: Many companies do not include "hidden outbound travel" into the scope of inventory, such as overseas companies remotely accessing domestic server data, group unified HR systems synchronizing employee information, etc.
Second level: Selection of Chinese law compliance path
Important data or large-scale personal information → declare data export security assessment; medium-volume personal information → sign a standard contract for filing or pass personal information protection certification; small-volume or meet exemption conditions → be exempted from declaration; located in pilot areas such as free trade zones → prioritize the use of negative lists to reduce compliance costs.
The third level: Implementation of Singapore law compliance path
Sign a data processing agreement containing PDPC model clauses with overseas recipients; or implement certified Binding Corporate Rules (BCRs); or pass the CBPR/PRP certification system.
Important: Companies need to take compliance responsibility for every node in a cross-border data flow, not just the first hop.
Level 4: Informed Consent and Impact Assessment
- Chinese law: Providing personal information overseas requires "individual consent" from the user, and blanket check-boxes are not allowed.
- Singapore law: Consent shall not be made a condition of the provision of services and shall not be obtained by fraudulent means.
Both countries require a Personal Information Protection Impact Assessment (PIA).
Level 5: Safety technical measures and continuous monitoring
Take encryption and de-identification measures for transmitted and stored personal information; establish a data outbound log retention mechanism to regularly check the consistency of actual outbound data and declared content; formulate a data leakage emergency plan (Singapore requires notification to the PDPC within 3 calendar days after confirmation); pay attention to the annual reporting obligations after the negative list is filed (Shanghai requires the overall situation of data outbound for the year to be reported at the end of each year).
05 Quick self-check list for overseas companies
Based on the above five requirements, it is recommended that overseas enterprises check the following list one by one:
- Sort out all cross-border data transmission scenarios (including "hidden outbound": overseas remote access, group system synchronization, etc.)
- Confirm the compliance path under Chinese law (security assessment/standard contract/certification/exemption) and keep corresponding declaration records
- Confirm the compliance path (contractual arrangements/BCRs/CBPR certification) under Singapore PDPA, sign and archive the data processing agreement
- Review whether the informed consent mechanism meets the dual requirements of "individual consent" in China and "voluntary consent" in Singapore
- Check security technical measures: whether encryption, de-identification and other protective measures have been adopted for transmitted data
- Evaluate NRIC usage scenarios: Are there scenarios that rely on ID numbers for identity verification? Pay attention to PDPC’s regulatory trends on reducing the use of NRICs and plan ahead.
- Establish a data leakage emergency mechanism: ensure the ability to promptly notify PDPC and conduct regular emergency drills
The above list is not a one-time exercise. As enterprise business expands, data volume increases, and regulatory rules are updated, it is recommended to recheck every six months to ensure that the compliance status matches the actual business.
Conclusion
Data export compliance is increasingly becoming an unavoidable core issue for multinational companies. Judging from the recent law enforcement cases of China's cyberspace information and public security departments, data export law enforcement has entered a normalized stage; the regulatory intensity and penalty standards of Singapore's PDPA have also shown a trend of strengthening.
For enterprises going overseas, data export is not a one-time declaration, but a continuous compliance obligation throughout the entire business life cycle. Enterprises need to establish a three-in-one compliance system of "legal-technology-management" and meet the dual compliance requirements of China and destination countries at the same time, in order to pass the global data governance test steadily.
Compliance is not a cost, it is competitiveness. Only companies that make early layout and early rectifications can win the initiative in the new pattern of cross-border data flow.
— END —
- This article is based on public information, industry research and cross-border investment regulatory trends. It is for communication and reference only and does not constitute any specific legal advice or investment advice. Different companies have different industry attributes, target countries, transaction structures and regulatory environments. It is recommended that professional cross-border lawyers analyze specific matters on a case-by-case basis.
- If you want to learn more about cross-border data compliance and data export security assessment and other related matters, please contact the professional consultants of Sino-Singapore Faxun
—
Author|Cross-border Investment Team Review|To be confirmed by the background
This article is for informational purposes only and does not constitute formal legal advice.
This article is general information and not legal advice. Specific matters require assessment by appropriately qualified professionals.