- Insights This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
How startups should deal with the stringent cybersecurity laws in China

Photo credit: beebright / 123RF Stock Photo
This article was co-authored by David Meimoun, Lucie Tusseau-Leveque, and Lauren Hallanan.
While everyone is going crazy about the GDPR, many startups have failed to notice that China has its own similar set of laws.
China’s Cybersecurity Law (CSL) was implemented a year ago as part of a massive effort to ensure that all Chinese citizens’ online profiles remain private and secure. Although it is already enforceable, a grace period has been granted for companies already operating in China so they can update their systems until December 31, 2018.
But startups preparing to enter the Chinese market should comply with the law even before their launch. Admittedly, the new personal data collection regulations may slow down their growth. But by not complying, your startup risks fines, shutdown of your website and apps, business license revocation, and even detention.
Below is an overview of the types of operations affected by the CSL’s personal identifiable information (PII) collection regulations and the five key requirements that startups need to be aware of. (For more information on the details of the CSL, you can check our report here.)
How do the CSL’s personal data protection rules affect my startup?
The CSL aims to reform data management and internet usage regulations in China and impose new requirements for network and system security. One subset of the CSL centers around the collection of PII (i.e. someone’s full name, identification number, birth date, email address, phone number, or online identifiers such as IP addresses, cookies, etc.)
These new PII regulations will significantly affect a core component of most startups’ development strategy: growth hacking. The goal of growth hacking is to rapidly acquire more customers at a lower cost. However, the user acquisition process for most modern startups requires a technology component that collects and processes personal data in automated ways. This means that the CSL hinders marketing and growth efforts by making user acquisition more complicated.
Besides marketing, many other operations may be affected, particularly CRM and HR. Your startup is also at risk of non-compliance if you use any of the following systems:
- Any online membership database (e.g. member/client/applicant areas on your website)
- Email marketing
- CRM/marketing automation (e.g. Salesforce, Marketo, Hubspot etc.)
- Central reservation systems (e.g. booking engines for hospitality, events, etc.)
- Electronic payments
- Ecommerce (e.g. order management, shipping, and handling)
- ERP/online accounting/payroll management
- Social CRM
- Knowledge management systems (e.g. Wikis)
- Usability testing and online performance tracking and measurement
- Online customer services
- Automated data exchange with third parties
Seeing as it’s fairly certain that your business will use at least one of these systems, the next step is to determine whether you fall into the category of critical information infrastructure operator (CIIO) or network operator.
Though the precise definition is still unclear, a business can be considered a CIIO if:
- You belong to strategic sectors such as energy, finance, etc.
- You operate an IT infrastructure platform.
- You collect and process a volume of data above a certain threshold.
- A data breach in your systems can cause more than a certain threshold of monetary damage.
- You process data on behalf of a CIIO. (This does not make you one, but you need to comply with the same rules.)
Any business operating in China that is not a CIIO is considered a network operator, which is defined as any company operating a network of interconnected computers.
Five key aspects to be aware of
What is the impact of the CSL so far?
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.





