For years, China’s cross-border data transfer regime was long on rules but short on consequences. Companies—both foreign and domestic—were given a relatively extended period to understand the requirements, formulate suitable strategies, and implement compliance measures. Recent enforcement actions led by the Cyberspace Administration of China (CAC), the country’s data regulator, suggest that the education phase is now over.
In June 2026, the Shanghai CAC announced that it had penalized Ctrip, a multinational travel agency headquartered in Shanghai, for failing to implement required security assessments for cross-border data transfers and for illegally transferring personal data overseas in violation of the Personal Information Protection Law (PIPL). A fine of RMB 10 million was imposed alongside an order to rectify within a specified period. According to the regulator, earlier enforcement actions this year revealed that “some internet companies in livelihood-related sectors were still engaged in illegal and non-compliant cross-border transfers of personal data“.
A common assumption among many market participants has been that China’s data enforcement apparatus primarily targets multinational corporations (MNCs) transferring personal data out of China to overseas headquarters. While MNCs have indeed been targeted, the recent Ctrip case, as well as several other public cases discussed below, paints a far broader picture.
In May 2025, the Shanghai CAC imposed an administrative penalty on the Shanghai affiliate of a luxury brand for three violations: transferring users’ personal data to global headquarters without completing any cross-border compliance mechanism; failing to fully notify users and obtain separate consent for the cross-border transfer; and failing to adopt technical security measures such as encryption or de-identification.
Last year, the Shanghai CAC also released typical enforcement cases from 2025, which included two domestic enterprises in the hotel and property management sectors. One related to a failure to comply with a CAC cross-border data transfer assessment decision, for which the MNC was fined. In another, a property management company provided users’ accommodation information, including sensitive financial account details, to overseas parties without any compliant transfer mechanism—and received a warning with a rectification order.
We anticipate there may have been further enforcement actions by local CACs in other provinces, although they do not actively publish enforcement cases in the same manner as the Shanghai CAC.
Two and a half years after the issuance of the Regulations on Promoting and Regulating Cross-Border Data Flows (see our article here for details: CHINA: Cross Border Data Transfer Requirements – exemptions now available | Privacy Matters), and several rounds of public Q&A sessions organized by the CAC to clarify requirements and policies, companies can no longer argue that cross-border transfer rules were unclear or that implementing mechanisms were unavailable.
Adding further teeth to enforcement, the amended Cybersecurity Law took effect on January 1, 2026. The amendments materially increase penalty ceilings across multiple violation categories (see our article here for details: CHINA: Amendments to Cybersecurity Law Effective 1 January 2026 | Privacy Matters). Combined with the PIPL’s existing ceiling of RMB 50 million or 5% of the previous year’s turnover for serious violations, the financial exposure is now substantial.
The enforcement landscape is not limited to cross-border data transfers. For example, in March 2025 and April 2026, the CAC, jointly with the Ministry of Industry and Information Technology and the Ministry of Public Security, launched two large-scale nationwide personal data protection campaigns. The areas of focus include:
- collecting personal data without sufficient privacy notice;
- collecting personal data beyond the necessary scope;
- processing personal data without a lawful basis or by forcing consent; failing to provide an effective account deletion or cancellation function;
- lacking personal data complaint or reporting channels;
- misusing facial recognition technology; and
- failing to implement adequate minor data protection measures.
For any organization doing business in China or processing the personal data of Chinese residents, the message is clear: take compliance action now.