Sources: the Cybersecurity Administration of China has approved only ~25% of data export applications since a data security law took effect in September 2022
allowing some data to be sent abroad without review — and more permissions have been granted since then, multiple data security lawyers said it took at least six months for companies to pass a CAC review.” https://www.ft.com/... @alecolarizi : 🇨🇳has approved only 1/4 of applications to export data since the introduction of new data security laws. “The country's chief internet regulator has yet to approve thousands of requests from local and international businesses to send data”, officials said https://www.ft.com/...
Context & Ripple Effects
The low approval rate shows how restrictive the review regime that took effect in September 2022 proved in practice: companies faced a process that lawyers said could take at least six months, while thousands of requests remained unresolved. It extends earlier concerns around data-localization obligations under China’s cybersecurity law into a concrete cross-border operating constraint.
The policy direction was not wholly static. Subsequent coverage pointed to Shanghai efforts to speed offshore-data approvals for foreign firms and to national exemptions for some trade and transport data, suggesting officials were trying to narrow the bottleneck rather than abandon review altogether.
First-order effects
- Domestic and international businesses seeking to move local data abroad face prolonged uncertainty and a low probability of clearance, forcing them to defer or redesign affected data flows.
- The CAC becomes the effective gatekeeper for a large share of cross-border transfers, while limited no-review pathways become materially more valuable to companies.
Second-order effects
- Multinationals have an incentive to separate China-based data operations from global systems and to prioritize transfers that can qualify for exemptions or approvals.
- Local authorities and regulators face pressure to make approvals more predictable, reflected in the later exemptions for certain trade and transport data and Shanghai’s proposed acceleration of foreign-firm reviews.
Third-order effects
- If selective easing continues alongside strict review of other transfers, China’s data regime may evolve into a tiered system: routine commercial data moves more freely while regulators retain control over designated categories.
- The sustained compliance burden can make data governance and localization a competitive factor for firms operating across borders, rather than a one-time legal task.
The trend: China is moving toward more targeted cross-border data controls, balancing regulatory gatekeeping with exemptions intended to reduce friction for defined commercial activity.