China China Cybersecurity Law data localisation

China's Citizenship-Plus-No-Foreign-Residency Test for Data Officers Turns Data Governance Into a Loyalty Screen

China's August 2026 draft for large personal-information processors extends a nationality-and-residency test to banks, hospitals and software firms. It adds little security.

China's Draft Rules for Large Data Processors People of Internet Research · China 50M Registered-user threshold Large-platform test in the Novembe… 10M+ Individuals processed threshold Headline criterion in the August 2… 5 yrs Officer experience required Experience required of the officer… peopleofinternet.com
China's Draft Rules for Large Data Pro… People of Internet Research · China 50M Registered-user threshold 10M+ Individuals processed thresh… 5 yrs Officer experience requi… peopleofinternet.com

Key Takeaways

China's Cyberspace Administration (CAC) has asked for comment on a draft that would require large personal-information processors to appoint a data protection officer who is a Chinese national and holds no foreign permanent residency or long-term residence permit. It would also require all personal information collected in China to be stored in data centres whose principal manager meets the same test. The notice on the CAC website is dated 7 August 2026, though some outlets report 10 August. Comments closed on 7 September.

What the draft actually does

The draft merges two earlier consultations. One was the November 2025 draft Provisions on Personal Information Protection for Large Online Platforms. That draft defined a large platform as one with 50 million or more registered users or 10 million monthly active users. It also covered holders of data whose compromise would seriously affect national security, the economy or public welfare. The new text is broader. As described by Reed Smith, it applies to "large-scale personal information handlers", and it reaches beyond consumer apps to banks, hospitals, logistics firms and enterprise software vendors. The CAC notice lists a headline criterion of processing personal information of 10 million or more individuals. Press accounts differ on the exact thresholds, which is a reason to wait for the final text before building compliance plans around any one figure.

The carried-over mechanism matters most. The November 2025 draft required a personal-information protection officer who is a Chinese citizen "without permanent residence or long-term residence permit abroad", with at least five years of relevant experience. It required data-centre principals to meet the same test.

The strongest case for the rule

Regulators have a real argument. Large processors hold records on hundreds of millions of people, and a compliance officer with a direct line to the regulator has real power. The state wants officers who cannot easily leave the country and who answer to Chinese authorities. Many governments set nationality or residency conditions for roles that touch critical infrastructure. Governments also have good reason to want accountable people physically within reach, because a breach at a bank or hospital group is a public-welfare event.

Why the test fails on its own terms

Three problems weaken that case.

First, the test measures identity, not competence or integrity. A data officer's job is to understand retention schedules, consent flows, breach response and cross-border transfer assessments. Whether someone holds a foreign green card says nothing about whether they can do that work. It does exclude a large pool of experienced privacy professionals, including Chinese citizens who studied or worked abroad and kept a residence permit. For multinationals, the requirement removes the option of a global privacy lead who also serves their China entity.

Second, the rule appears stricter than China's own treatment of state secrets. Privacy Savvy reports, citing China Law Translate, that lawmakers considered and dropped a "no foreign residency" condition for state-secret protectors, keeping only citizenship. This claim rests on one secondary account and I could not check it against the statute text, because the National People's Congress site did not load for me. If it holds, a customer's delivery address is guarded by a stricter personnel standard than a state secret. That is hard to justify as proportionate to the risk.

Third, localisation has costs that the draft does not weigh. The draft says personal information "collected and generated" in China must be stored in China, in data centres physically located in the mainland. Firms with integrated global systems face duplicated infrastructure and fragmented analytics. Hospitals and logistics firms that run joint research or cross-border supply chains face the same bind. Cross-border transfers are already controlled through security assessments and standard contracts under the Personal Information Protection Law. A storage mandate stacked on those controls adds friction. It does not obviously add protection, because security comes from encryption, access controls and audit, none of which depend on a manager's passport.

What a proportionate version would look like

A workable rule would keep the useful parts. These are a named, senior, regulator-accessible officer, mandatory filing of that officer's details, and audit duties. It would replace the identity test with objective qualifications: professional experience, no conflicts of interest, and personal accountability for failures. It would also tie localisation to the sensitivity of the data. A bank's core customer ledger and a retailer's delivery history are not the same risk, and the draft's sector-wide reach treats them alike.

The wider effect is the one to watch. Consultations like this one let China's regulators test how far a trust-based, nationality-linked model of data governance can extend beyond the large platforms that were its original target. When enterprise-software firms and hospital groups face the same personnel screen as the largest social apps, the costs fall on ordinary commercial activity. Those costs are lost talent, duplicated infrastructure and slower product cycles, and they land on Chinese firms as well as foreign ones.

The draft is not final. The CAC can still narrow thresholds, accept a qualified-officer alternative to the residency test, or allow exemptions for data centres run by regulated entities. Industry comments filed before 7 September are the main chance to push for those changes. If the text stays as drafted, it will show that China's data regime prioritises political reliability over technical safeguards. Security outcomes will not improve to match.

Sources & Citations

  1. CAC: Large personal information processors draft (Aug 2026)
  2. CAC: Large online platforms draft (Nov 2025)
  3. Reed Smith: China proposes enhanced rules for large-scale handlers
  4. Privacy Savvy: Draft bars foreign residents from data officer roles