Intelligence Analysis
China’s New Digital Measures Likely to Affect International Businesses and Travelers
24 FEB 2026
/
3 min read

China’s amended Cybersecurity Law, which sets broad data protection and network security requirements, and the recently agreed Measures for the Certification of Outbound Personal Information Transfer took effect Jan. 1. The amended law and new measures will increase compliance obligations for international companies and tighten cross-border data flows, with early effects including fines, operational restrictions, and paused or certified data transfers.
Key Takeaways
- International businesses now must follow China’s cybersecurity standards, strengthen internal controls, conduct regular risk assessments, and secure certification before transferring data across borders.
- Travelers’ personal data also is now under closer scrutiny as a result of the regulations, affecting airlines, travel agencies, payment platforms, and logistics companies.
- In the next 12 months, businesses should anticipate that Chinese authorities will issue further guidance, more frequent audits, stricter enforcement, and expanded reporting obligations.
The Amended Cybersecurity Law (CSL): Expanded Oversight of Data and Networks
The amended Cybersecurity Law strengthens state oversight of network operations and establishes a broader set of obligations for international companies operating in China. The Chinese government now requires international companies to implement technical measures to protect data, report cybersecurity incidents within defined timeframes, conduct periodic security assessments, and maintain records of compliance for inspection. International companies are expected to integrate compliance into daily operations, maintain logs and audit trails, and be prepared for government inspections or requests for additional information.
As an example of tighter restrictions international businesses can anticipate in the year ahead, Chinese authorities in September 2025 issued an administrative penalty, including a fine, to Christian Dior’s Shanghai subsidiary after it purportedly transferred Chinese customers’ personal information to its headquarters in France without completing the allegedly required data export procedures, including security assessments, standard contracts, or consent processes.
International firms must also carefully understand areas where the law is ambiguous or enforcement guidelines are not fully public. Noncompliance can result in administrative penalties, operational restrictions, or suspension of services.
Measures for the Certification of Outbound Personal Information Transfer: Formalizing Approval for Cross-Border Data Flows
The Measures for the Certification of Outbound Personal Information Transfer have established a formal process for international companies to obtain approval for exporting personal information from China. Organizations transferring certain volumes of personal data outside China must apply for certification, conduct risk assessments, implement technical protections such as encryption or desensitization, and maintain monitoring and documentation of the transfers.
The measures build on guidance provided by the Cyberspace Administration of China in October 2025 stating that companies engaged in cross-border transfers, including technology firms and travel-related service providers, should complete certification before exporting data. The measures suggest that companies handling personal information for international transactions or operations are required to integrate certification procedures into their processes, including internal audits and coordination with regulators. Failure to comply may result in administrative penalties, restrictions on cross-border transfers, or temporary suspension of services.
Implications for International Businesses and Travelers
The new data export and cybersecurity measures are likely to influence operational planning for international businesses and travel-related service providers, as well as the handling of travelers’ personal information. Travelers’ data may be subject to additional verification and processing requirements by Chinese authorities when exported for services such as hotel bookings, airline reservations, and payment processing.
International businesses, especially those in technology, cloud services, finance, e-commerce, and travel, will likely prioritize compliance by updating IT systems, implementing internal audit and reporting mechanisms, and documenting consent and security procedures. Service providers transferring large volumes of personal data outside China, including multinational corporations with headquarters abroad, are likely to be most affected.
In 2026, companies may experience phased adjustments as Chinese regulators provide additional guidance, conduct inspections, and assess certification applications. Organizations handling sensitive categories of data, such as financial, travel-related, or similar information, and conducting operations involving non-Chinese nationals are likely to face closer scrutiny.
International businesses can anticipate ongoing monitoring, audits, and potential operational restrictions if compliance measures are deemed to be incomplete, which may influence the planning of IT infrastructure, data storage, and international services.
Learn more about leveraging intelligence to stay ahead of risks to your people and operations.
Related
Tags
Sharpen your
view of risk
Subscribe to our newsletter to receive our analysts’ latest insights in your inbox every week.
Intelligence & Insights
Intelligence
Worth Gathering
Employing a team of 200+ analysts around the world, Crisis24 is the only source you need for on-point, actionable insights on any risk-related topic.

Intelligence Analysis
Why Identity-Based Cyber Attacks Are Becoming the Bigger Threat
Attackers increasingly target identities over networks. Learn how credential theft, AI-driven social engineering, and non-human identities create risk.
October 6, 2026

Article
Insider Risk Lessons for Security Leaders Following Flight FZ1073
Crisis24 helps organizations assess insider risk and strengthen preparedness for incidents such as flydubai flight FZ1073.
By Graeme Hudson
October 2, 2026

Intelligence Analysis
Bangladesh’s Concurrent Dengue and Measles Outbreaks Strain Healthcare System
Bangladesh is confronting concurrent large-scale outbreaks of dengue and measles, intensifying pressure on an already strained health system, particularly in urban centers and high-burden districts.
By Crisis24 Health Intelligence Team
September 29, 2026

Case Study
Unauthorized Access to Sensitive Internal Data: A Coordinated Insider Threat Response
See how Crisis24 coordinated forensic, legal, security, and operational expertise to investigate and contain a complex insider threat incident.
September 23, 2026

