A narrower definition, admitted the hard way
On June 16, 2026, China's Ministry of Commerce, the National Development and Reform Commission, and the Ministry of Finance jointly issued the Action Plan for Stabilizing and Improving Foreign Investment Utilization (商资发〔2026〕97号). Buried in a 15-point document about foreign investment is a specific, technical instruction: free trade zones and pilot service-opening cities should keep writing "scenario-based, field-level" negative lists for data exports, and regulators should develop national standards for identifying "important data" catalogs across manufacturing, telecoms, geospatial information, automotive, pharmaceuticals, seeds, aerospace, and civil aviation.
That instruction is a quiet admission. "Important data" has been a defined legal category since the 2021 Data Security Law, but the law never said what it actually covers — leaving companies to guess whether ordinary operational data (fleet telematics, drug trial records, satellite imagery, retail transaction logs) might trigger a mandatory security assessment before it can leave China. The Cyberspace Administration of China's own 2024 cross-border data provisions tried to patch this by telling companies to assume their data is not "important" unless a regulator says otherwise — a workaround, as MERICS notes, that treats the underlying vagueness as a permanent feature rather than fixing it.
The negative-list experiment is already showing results
The free trade zone negative list is not new — Tianjin's FTZ issued the first one in May 2024, and by late 2025 eight zones (Tianjin, Shanghai/Lingang, Beijing, Hainan, Zhejiang, Jiangsu, Chongqing, and Guangxi) had published their own, each tailored to local industry, according to China Briefing. Beijing's list, for instance, spans automotive, pharma, civil aviation, AI training data, and banking; Shanghai's covers reinsurance and shipping; Hainan's covers deep-sea and aerospace. Data that falls outside the list can move overseas without a security assessment or standard-contract filing at all.
The CAC's own one-year review of the broader 2024 provisions, published in March 2025, reports the mechanism working roughly as intended: monthly security-assessment cases fell by roughly 60%, standard-contract filings dropped by about half, and average assessment processing time compressed from 45 days to under 30. More than 2,400 enterprises were briefed on the new rules across 16 cities. The June 2026 Action Plan is essentially an instruction to do more of what has already worked — extend the negative-list logic into more sectors and, crucially, try to standardize what "important data" means so companies outside a free trade zone get some of the same clarity.
Steelmanning Beijing's caution
It would be unfair to treat this purely as red tape for its own sake. Some of the sectors on the list — aerospace, seeds, geospatial mapping, autonomous-vehicle sensor data — genuinely touch dual-use or strategically sensitive information in every major jurisdiction, not just China; the US, EU, and India all restrict exports of high-resolution mapping and certain biotech data too. China's amended Cybersecurity Law, effective January 1, 2026, also raised penalties for serious data-security violations to as much as RMB 10 million, which suggests Beijing intends the narrower important-data catalogs to be taken seriously rather than treated as a loophole. A government that is simultaneously tightening enforcement and narrowing scope is not necessarily being inconsistent — it is trying to trade breadth for precision, which is the correct instinct even if the execution has lagged.
Why the fix is still partial
The catch is that this remains a patchwork, not a rule. National standards for "important data" catalogs are described as something regulators should "advance" (推动制定) — no statutory deadline, no binding text yet, and the negative lists so far apply only inside free trade zones and pilot cities, leaving the much larger population of foreign-invested firms operating outside those zones stuck with the original, undefined statutory term. A pharmaceutical company in Shanghai's Lingang zone gets a clear list; the same company's plant in a non-pilot province does not. That asymmetry itself becomes a compliance cost — companies must track which of dozens of overlapping zone-specific catalogs might apply to them, an administrative burden that only partially replaces the uncertainty it was meant to solve.
The honest reading is that Beijing has correctly diagnosed the problem — an overbroad, undefined security category was suppressing cross-border data flows and deterring the foreign investment China says it wants more of — but has chosen the slowest available fix: zone-by-zone experimentation rather than a single, presumption-of-openness rule applied nationwide. Given that the CAC's own data shows negative lists cutting assessment volume by half within a year, extending that logic economy-wide, on a fixed timeline, would do more for investment confidence than another year of sector-by-sector pilots. Until the national standard actually exists in text, "important data" remains whatever the nearest regulator decides it is on a given day — which is precisely the uncertainty this Action Plan claims to be solving.