China proposes stricter data governance rules requiring local nationals as compliance officers

China’s Cyberspace Administration has unveiled draft rules extending data oversight, mandating foreign-residency restrictions for compliance officers and data storage, in a move that could significantly impact multinational corporations operating in the country.

China’s Cyberspace Administration has put forward draft rules that would sharply widen the country’s data-governance regime, requiring large-scale personal-information processors to appoint a compliance officer who is a Chinese national and has never held permanent residency or a long-term residence permit abroad. The proposal, open for public comment until September 7, 2026, would also require personal information collected in China to be stored in data centres run by Chinese nationals who meet the same residency conditions. According to the draft, the measures are intended to tighten oversight of data handling and align corporate governance more closely with Beijing’s security priorities.

The scope of the proposal is broader than the earlier consultations it replaces. Rather than targeting only large online platforms, it would cover any organisation deemed a large personal-information processor, including businesses with more than 50 million registered users or 10 million monthly active users, as well as entities whose data holdings could affect national security, the economy or the public interest if compromised. That would pull in financial institutions, healthcare groups, logistics operators and enterprise software firms alongside the better-known internet giants that have long been the focus of Chinese regulators.

The draft’s most striking feature is its personnel test. The personal information protection officer would have to come from senior management, possess more than five years’ relevant experience and hold authority to veto data-processing decisions and escalate serious breaches to regulators. Legal analysts cited by TechTimes say the nationality-and-residency requirement goes further than China’s own state-secrets rules, which call for Chinese citizenship but do not add the same foreign-residency restriction.

Beijing is building the proposal on top of an already dense legal framework. China’s National Intelligence Law requires organisations and citizens to support and cooperate with intelligence work, while the personal-information regime already imposes localisation and transfer controls on data processed in China. The new draft would add a further layer of human oversight, making compliance not just a systems issue but also a staffing and governance problem for multinationals that rely on centralised data structures or global cloud operations.

The timing is also notable. China has already been moving towards tighter enforcement of cross-border data rules, and the draft arrives after recent penalties and investigations involving foreign brands. For companies with significant operations in China, the practical task now is to test whether existing data flows, transfer mechanisms and local management structures would survive the new standard. If adopted in its current form, the rule set would amount to one of the most demanding compliance frameworks China has yet proposed for large corporate data handlers.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.