China’s Privacy Draft Bars Foreign Residents From Key Data Protection Roles

Abeerah Hashim  - Security Expert
Last updated: August 11, 2026
Share
China Proposes Data Officer Rule Requiring Chinese Citizenship and No Foreign Residency
  • China's internet regulator wants big data handlers to hire a data officer who is Chinese and has no foreign residency card.
  • This rule is tougher than China's own rules for people who guard state secrets.
  • The draft covers banks, hospitals, and tech firms, not just apps like Alibaba and Tencent.

China’s Cyberspace Administration (CAC) shared a new draft rule this month. It wants every big company that handles personal data to hire a special data officer.

That officer must be a Chinese citizen. The officer also cannot hold a green card or long-term visa in another country. People can send comments on the draft until September 7, 2026.

Which companies must follow the rule?

The draft, shared on August 10, joins two older drafts into one. It no longer targets just big internet apps. Now it covers any group known as a large personal-information processor. A company falls into this group if it has more than 50 million signed-up users.

It also counts if the app has 10 million users each month. Groups holding data that could hurt national safety or the economy count too, according to legal tracker Lexology.

This means banks, hospitals, delivery firms, and software makers in China now face the same rules as giant apps like Alibaba. Regulators plan to list these companies by name. The CAC and the police will work together to pick who makes that list.

Officer to pass a tough nationality test

The toughest part of the draft asks for a senior staff member to take on the data officer job. That person needs four things at once. They must hold Chinese nationality. They must not hold a green card or long visa abroad. They need real knowledge of data protection. They also need five years of matching work experience.

This nationality-plus-no-foreign-home rule is rare, even in China. China Law Translate, a group that studies Chinese law closely, found something surprising. Recent updates to China’s own State Secrets Law once thought about a “no foreign residency” rule too.

But lawmakers dropped that idea. They kept only the citizenship rule, China Law Translate explains. So this new privacy draft asks for more loyalty proof than the rules guarding actual state secrets.

The data officer also has strong power. They can block data decisions inside the company. They can also report straight to regulators if something goes wrong. The officer must write internal data rules, watch over children’s data, run compliance checks, and publish a yearly report.

For foreign companies, finding the right person is hard. They need a senior Chinese staff member with no foreign residency and the right experience. That is a bigger task than just updating a privacy policy.

The nationality rule does not stop with the officer. Data centers storing Chinese user data must also have a lead manager who is Chinese and has no foreign residency. China’s Cybersecurity Law and Personal Information Protection Law (PIPL) already made companies store Chinese data inside the country. This draft adds a new layer on top: a person, not just a server, must meet the nationality test.

What happened to Dior Shows the risk

On September 9, 2025, Chinese regulators punished Dior’s Shanghai branch. This marked the first major PIPL fine against a foreign company for moving data across borders, Lexology reported. A data breach in May 2025 led police to investigate.

Officials found that Dior sent Chinese customer data to its France office. The company skipped every legal step needed for that kind of transfer. It also failed to ask users for separate consent. It did not use encryption to protect the data either, according to DaHui Lawyers. The exact fine amount was never shared publicly.

Legal experts say Dior’s mistakes were common ones. Many foreign firms in China likely have the same gaps in their systems. Under PIPL, similar violations can bring fines up to ¥50 million, or five percent of yearly income, whichever costs more. Regulators can also shut down apps or freeze business activity.

The focus on data security is not just a domestic priority; China-linked hackers have been observed using proxy networks to evade detection in attacks targeting the UK and other nations, prompting warnings from Western intelligence agencies.

What companies should do now?

Firms operating in China should check their user numbers against the new limits. They should also check if their current data officer holds a foreign green card, since that would disqualify them under this draft. Companies should review how they move data out of China too.

The comment period closes on September 7. No date has been set for when the rule becomes final. But firms in finance, health care, and tech should start preparing now, before the rules take full effect.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.