Cross-border "inbound data processing" lands in Guangzhou Nansha — how can enterprises expand overseas in compliance and navigate legal minefields?
On September 1, 2026, the launch meeting for the Guangzhou pilot of international cooperation in the national data field was held in Nansha. Guangzhou officially introduced business models such as the "Data Processing Factory" and "Token Export," aiming to address the industry pain points of data being unable to "flow out" or "come in." On the same day, the Medical-Engineering Trusted Research Collaboration Platform (TREMAC) was released, enabling cross-border research collaboration through a mechanism of "models moving while data stays put." These initiatives mark a critical step forward in data collaboration across the Guangdong-Hong Kong-Macao Greater Bay Area, but for many enterprises involved in cross-border data flows, compliance risks and legal boundaries urgently need to be clarified. As a lawyer with extensive experience in legal services in the Greater Bay Area, I will break down the legal key points behind this hot topic from a practical perspective.
Behind the "Guangzhou Solution" for data going global: the legal framework has quietly shifted.
The core of the "Data Processing Factory" is "foreign data, domestic computation"—overseas enterprises transmit desensitized data to Nansha, where it undergoes cleaning and model training before the finished product is exported. It sounds appealing, but legally, cross-border data flow is far more complex than the simple notion of "transmission."
Article 21 of China's Data Security Law establishes a system for classified and graded protection of data, while Article 31 requires that important data collected and generated by operators of critical information infrastructure during their operations within China must undergo security assessment before being transferred abroad. Article 38 of the Personal Information Protection Law, on the other hand, stipulates three lawful channels for the cross-border transfer of personal information: passing a security assessment organized by the national cyberspace administration, obtaining personal information protection certification from a professional institution, or signing a standard contract with the overseas recipient.
In March 2024, the Cyberspace Administration of China issued the "Provisions on Promoting and Regulating Cross-Border Data Flows," further refining the circumstances exempt from security assessments, such as cross-border flows in international trade and academic cooperation that do not involve personal information or important data. However, in the "data processing for inbound business" scenario, even if the original data has been desensitized, if it can still be linked to identify specific individuals, or if it involves criteria for identifying important data, strict compliance with assessment or filing obligations is required.
In practice, many enterprises mistakenly believe that "de-identification" equals "compliance." In reality, according to the "Information Security Technology — Guidelines for Evaluating the Effectiveness of Personal Information De-identification," data that has been de-identified may still have the identities of data subjects restored through re-identification attacks, and the legal requirements for "anonymization" are extremely stringent. In the Nansha benchmark project, if the "de-identified business data" transmitted by Hong Kong-listed enterprises contains personal information, it must be ensured that it meets the standard of being impossible to re-identify; otherwise, it still constitutes the cross-border transfer of personal information and must trigger the corresponding compliance procedures.
Legal Characterization of "Token Going Global": Data Export or Service Trade?
The naming of "Token Going Global" is quite innovative, and its essence lies in the cross-border extension of underlying large model invocation and processing services. When enterprises provide model services overseas through API interfaces, the input and output tokens may implicitly contain commercial secrets, users' personal information, and even important data.
From a legal characterization perspective, this involves two levels: first, if the token content contains personal information, it falls under the regulation of the Personal Information Protection Law, requiring an assessment of the necessity of cross-border transfer and obtaining separate consent from the individual (Article 39). Second, if it involves industry data such as healthcare, finance, or energy, it may fall within the catalog of important data under the Data Security Law, necessitating a security assessment for cross-border data transfer.
Notably, the 2024 Provisions on Promoting and Regulating Cross-Border Data Flows clarified that the requirement for outbound data transfer assessment does not apply to cases where "personal information collected and generated by data processors outside China is transmitted into China for processing," which facilitates the reverse operation of "data processing for foreign clients." However, "token export" involves transferring data from within China to abroad, which is different in nature and must be checked item by item.
Legal practice advice: When signing cross-border AI service contracts, enterprises should clearly stipulate the data flow nodes, storage locations, security measures, and liability for breach, referencing the standard clause rules under Article 496 of the Civil Code to avoid unilateral modification of data processing terms by overseas service providers. Additionally, in accordance with Article 21 of the Cybersecurity Law, enterprises should implement the classified protection system to ensure that technical safeguards meet legal requirements.
The innovative mechanism of "data stays put, models move": balancing privacy protection and research sharing.
The federated modeling technology adopted by the TREMAC platform keeps each hospital's data locally, exchanging only encrypted model parameters. This mechanism technically avoids the cross-border transfer of raw data, but from a legal perspective, there is room for interpretation as to whether model parameters constitute "data" or "important data."
Currently, the definition of "data export" in Chinese law is primarily based on Article 4 of the Measures for Security Assessment of Data Export, which refers to the transfer or storage of data collected and generated during domestic operations by data processors to overseas locations, or the ability of overseas institutions, organizations, or individuals to access or retrieve such data. If model parameters, after training, encapsulate the statistical characteristics of the original data, they could, in extreme cases, be reverse-engineered to infer individual information. Therefore, they cannot be categorically excluded from the scope of "data export."
The field of medical engineering involves a large amount of patient health information, which falls under the category of "sensitive personal information" as defined in Article 28 of the Personal Information Protection Law. Processing such information requires specific purposes, sufficient necessity, and separate consent. When research institutions share model parameters, it is necessary to ensure that all participating parties possess the corresponding data security capabilities, and collaborative research must undergo ethical review. The approach taken by Guangzhou Laboratory in collaboration with Macau University of Science and Technology and other institutions reflects the principle of "minimum necessity." However, lawyers recommend that detailed agreements be signed regarding the ownership of intellectual property rights for model parameters and the allocation of liability for data leakage, referencing the confidentiality obligations clause in Article 501 of the Civil Code, to prevent data disputes in the event of collaboration breakdown.
Enterprise Data Cross-Border Compliance Roadmap: Full-Chain Risk Control from Assessment to Contracts
Facing the opportunities brought by Guangzhou's pilot program, how can enterprises seize the dividends while avoiding crossing the line? Drawing on recent enforcement cases, I offer the following practical guidance:
First, conduct a self-assessment of risks associated with cross-border data transfers. In accordance with Article 5 of the Measures for Security Assessment of Cross-Border Data Transfers, the assessment should cover the purpose, scope, and method of the data transfer, as well as the security safeguards of the overseas recipient. It is recommended to establish a routine assessment mechanism rather than a one-time response.
Second, accurately identify data types. Distinguish between personal information, important data, and core data, and apply different rules accordingly. Ordinary commercial data enjoys greater freedom in cross-border transfer, but caution is required when it involves areas such as government affairs, military industry, or population health. Reference can be made to the Guidelines for Identification of Important Data to conduct item-by-item checks.
Third, make good use of standard contracts and certification. For small and medium-sized enterprises that are not operators of critical information infrastructure and have not reached the threshold for security assessment, signing the standard contract formulated by the Cyberspace Administration of China with overseas recipients and completing the filing is the most efficient compliance path. For high-value data, consideration may be given to applying for personal information protection certification to enhance international trustworthiness.
Fourth, attention should be paid to aligning rules with Hong Kong and Macao. This pilot places emphasis on collaboration among Guangdong, Hong Kong, and Macao. As an international data hub, Hong Kong's Personal Data (Privacy) Ordinance differs from the mainland's Personal Information Protection Law. When operating across borders, enterprises must comply with the requirements of both regions simultaneously to avoid the risk of a "compliance gap."
Guangdong Zhiming Law Firm has established a dedicated data compliance team and has assisted multiple listed companies in completing data export security assessments and standard contract filings. If you are currently planning cross-border data business or facing compliance reviews, please feel free to contact us. We will provide full-process legal support ranging from risk assessment to institutional framework development.
The wave of cross-border data flows has arrived; law serves both as a constraint and a safeguard. Only by deeply understanding the rules can one navigate steadily and far in the blue ocean of the digital economy.