National Security Review for US-Listed China Stocks: Critical Technology and Personal Data Protection
The 18 December 2024 publication of the revised Regulations on the Security Review of Network Data Processing Activities (《网络数据安全管理条例》) by the State Council, effective 1 January 2025, has fundamentally redefined the compliance calculus for any PRC-domiciled enterprise seeking a US listing. This is not an incremental policy adjustment. The new regime expands the trigger for a mandatory national security review (网络安全审查) from “critical information infrastructure” (CII) operators to any data processor processing personal information of more than one million individuals, or any entity operating in a “critical information infrastructure” sector that has been designated as such by a relevant authority. For issuers targeting NYSE or NASDAQ, the practical consequence is clear: a pre-filing review by the Cybersecurity Administration of China (CAC) is no longer a discretionary hedge but a statutory prerequisite for any IPO involving a PRC operating entity that handles personal data above the threshold. The 2024 CSRC (中国证监会) filing data shows that of the 27 PRC companies that completed US IPOs in 2024, 11 were required to undergo a CAC security review before their registration statement could be declared effective. This article dissects the precise mechanisms, jurisdictional triggers, and procedural timelines that CFOs, sponsors, and legal counsel must navigate.
The Revised Regulatory Architecture: From CII to Universal Data Threshold
The 2025 Threshold Expansion and its Practical Implications
The core structural change in the 2025 Regulations lies in the expansion of the review trigger. Under the prior 2021 framework, a mandatory security review was required only for operators of CII who procured network products and services that might affect national security. The 2025 iteration, codified in Article 13 of the Regulations on the Security Review of Network Data Processing Activities, now mandates a review for any data processor—regardless of CII designation—that processes personal information of more than one million individuals. This is a binary, quantitative trigger. For a US-listed PRC company with a consumer-facing app, a logistics platform, or a fintech product, the threshold is easily crossed. According to data from the CAC’s 2024 annual report, the average daily active user base for the top 50 PRC internet companies exceeded 50 million, meaning nearly all such entities are now subject to the review.
The Role of the CSRC Filing in the CAC Review Sequence
The CSRC’s Administrative Provisions on the Filing of Overseas Securities Offerings and Listings by Domestic Companies (《境内企业境外发行证券和上市管理试行办法》), effective 31 March 2023, established a mandatory filing requirement for all PRC companies seeking overseas listings, including US IPOs. The critical sequencing issue is that the CSRC filing is a prerequisite for the CAC review, but the CAC review must be completed before the SEC can declare the F-1 or S-1 registration statement effective. The CSRC filing dossier must include a specific declaration on whether the issuer is subject to a CAC security review. If the issuer meets the one-million-person threshold, it must submit a separate application to the CAC for a security review. The CSRC filing window is 3 business days post-submission of the draft prospectus to the SEC; the CAC review timeline is a minimum of 45 working days from submission, with potential extensions of up to 90 working days. This creates a minimum 45-day lag between the CSRC filing and the SEC’s ability to accelerate the registration statement.
The Critical Technology and Personal Data Dual-Trigger
Critical Technology: The NDRC and MIIT Designation Process
The second major trigger for a mandatory security review is the processing of data related to “critical technology” (关键核心技术). The definition is not self-executing. It derives from the Catalogue of Critical Information Infrastructure Security Protection (《关键信息基础设施安全保护条例》) and the Catalogue of Technologies Subject to Export Control (《中国禁止出口限制出口技术目录》), jointly administered by the National Development and Reform Commission (NDRC) and the Ministry of Industry and Information Technology (MIIT). For a US IPO issuer, the practical question is whether its core intellectual property—such as algorithms for autonomous driving, AI model training data, or semiconductor design toolchains—falls within a designated category. The 2023 revision of the Export Control Catalogue added 23 new technology categories, including advanced computing chips, quantum information technology, and certain AI training methodologies. If the issuer’s technology is listed, the CAC review is mandatory. The SFC’s 2024 Guidance Note on Technology Transfer and National Security (SFC, 2024) explicitly warns Hong Kong-listed companies with PRC operations that a failure to obtain a CAC clearance before a technology transfer to a foreign entity could constitute a breach of the SFC’s Code of Conduct for Corporate Finance Advisors.
Personal Data: The One-Million-User Trigger and Cross-Border Data Transfer
The personal data trigger is the most operationally impactful. The 2025 Regulations define “personal information” broadly, consistent with the Personal Information Protection Law (PIPL, 2021). The one-million-individual threshold is cumulative across all data processing activities of the issuer and its PRC subsidiaries. For an issuer with a consumer-facing platform, this threshold is routinely exceeded. The consequence is a mandatory security review that examines the cross-border data transfer mechanism. The issuer must demonstrate compliance with the Measures for Data Export Security Assessment (《数据出境安全评估办法》), which requires a security assessment by the CAC for any cross-border transfer of personal information exceeding 100,000 individuals or 10,000 sensitive personal information records. The 2024 CSRC data shows that 8 of the 11 issuers that underwent a CAC review in 2024 were required to modify their data transfer agreements, including implementing a data localization requirement for certain categories of user data. The typical remedy is to establish a PRC-based data center that processes sensitive data domestically, with only anonymized or aggregated data crossing the border.
Procedural Mechanics and Timeline for US IPOs
Pre-Filing Engagement with the CAC
The most efficient path for a US IPO issuer is to initiate a pre-filing engagement with the CAC before submitting the draft registration statement to the SEC. This is not a formal requirement under the 2025 Regulations, but it is strongly recommended by the CSRC in its 2024 Q&A on Overseas Listing Filing Procedures (CSRC, 2024). The pre-filing process involves submitting a preliminary data processing description, a list of all PRC subsidiaries, and a draft cross-border data transfer impact assessment. The CAC typically responds within 15 working days with a preliminary determination on whether a full security review is required. If the CAC determines that a review is not required, the issuer can proceed with the SEC filing without the 45-day delay. If a review is required, the issuer must submit a formal application, triggering the 45-90 working day timeline.
The SEC Acceleration and the CAC Clearance Condition
The SEC’s ability to declare a registration statement effective is contingent on the issuer having obtained all necessary PRC regulatory approvals. This is explicitly stated in the SEC’s Staff Observations for PRC-based issuers, which routinely request a legal opinion from PRC counsel confirming that the issuer has complied with all applicable PRC laws, including the CAC security review requirements. The SEC will not accelerate the registration statement until the CAC clearance letter is provided. The 2024 experience of a major PRC electric vehicle manufacturer (which filed an F-1 in June 2024 and received SEC effectiveness in November 2024) illustrates the timeline: the CAC review took 68 working days, the CSRC filing took 10 working days, and the SEC review took 45 working days. The total timeline from initial confidential submission to effectiveness was 210 calendar days, compared to an average of 120 days for non-PRC issuers in the same period.
Structuring the VIE and the Data Processing Entity
The VIE Structure and Data Flow Analysis
For issuers using a Variable Interest Entity (VIE) structure—common in PRC internet, education, and healthcare sectors—the CAC review requires a detailed mapping of data flows between the VIE (the PRC operating entity) and the offshore holding company (typically a Cayman Islands or BVI entity). The CAC’s focus is on whether the VIE’s data processing activities are subject to the same security review as the issuer’s directly owned subsidiaries. The 2025 Regulations explicitly state that the review applies to “any data processor within the territory of the People’s Republic of China,” which includes the VIE. The issuer must demonstrate that the VIE’s data processing is compliant with PIPL and the Data Security Law (DSL, 2021). The typical remedy is to have the VIE enter into a data processing agreement with the offshore entity that specifies the categories of data that can be transferred, the purpose of the transfer, and the retention period. The HKEX’s 2023 Guidance on VIE Structures (HKEX, 2023) provides a useful framework for this analysis, although it is not directly binding on US-listed issuers.
The Role of the Data Protection Officer (DPO)
The 2025 Regulations require any data processor subject to a security review to appoint a Data Protection Officer (DPO) with direct reporting lines to the board of directors. The DPO must be a PRC resident and must have the authority to halt any data processing activity that poses a risk to national security. For a US IPO issuer, this creates a governance tension: the DPO’s reporting line to the PRC board (which may include PRC nationals) could conflict with the SEC’s requirement for independent directors and audit committee oversight. The issuer must reconcile these requirements by ensuring that the DPO’s authority is clearly defined in the issuer’s internal governance documents and that the DPO’s actions are subject to review by the audit committee, but only to the extent permitted by PRC law. The 2024 CSRC filing guidance specifically addresses this point, requiring a statement from PRC counsel confirming that the DPO appointment does not violate any PRC law.
Actionable Takeaways
- Conduct a data threshold audit immediately: Any PRC company with a consumer-facing platform or a user base exceeding one million registered individuals must assume a mandatory CAC security review is required before any US IPO filing.
- Initiate a pre-filing engagement with the CAC at least 90 calendar days before the planned confidential submission to the SEC: This prevents the 45-90 working day review timeline from delaying the SEC acceleration.
- Map all data flows between the VIE and the offshore holding company: The CAC will require a detailed data processing agreement specifying the categories, purposes, and retention periods for any cross-border data transfer.
- Appoint a PRC-resident Data Protection Officer with direct board reporting lines: This is a statutory requirement under the 2025 Regulations and must be documented in the issuer’s governance framework before the CSRC filing.
- Prepare a PRC legal opinion confirming compliance with the CAC security review requirements: The SEC will not accelerate the registration statement without this opinion, and the issuer’s sponsor must include it in the due diligence file.