Hello, this is Ryuta Hamamoto from TIMEWELL. When I talk with the people responsible for doing business in China, conversations about economic security usually boil down to two worries. One is a "people" problem: could an expatriate or a business traveler suddenly be detained one day? The other is a "data" problem: if we bring our own devices and data into China, or send data from a local subsidiary back to headquarters, are we breaking the law?
Behind both of these anxieties sits the body of national-security-related legislation that China has been building out since 2014. The names that come up most often are the Counter-Espionage Law (Anti-Espionage Law) and the National Intelligence Law. Yet very few companies have actually read the text and translated it into their own operating rules. When you stop at "it just feels scary," you tend to swing to one of two extremes: either becoming excessively risk-averse, or sending people over completely unprepared. In this article, drawing on primary sources from government agencies and public institutions, I lay out what is regulated and how far, and what Japanese companies should turn into operating rules.
Let me summarize in three lines up front. The Counter-Espionage Law was revised and took effect on July 1, 2023, broadening the range of information deemed espionage from "state secrets" to "any documents or data relating to national security and interests." The National Intelligence Law (enacted in 2017, revised in 2018) is structured to impose a duty to cooperate with intelligence work on any organization or individual. And the so-called "three data laws"—the Data Security Law, the Personal Information Protection Law, and the Cybersecurity Law—extend regulation even to data transfers from local subsidiaries back to headquarters. If you want to start by confirming whether the technology and data you handle in China are subject to regulation, use the free export control readiness assessment to establish where you stand before reading on; it will help you prioritize the practical measures in the second half.
Why economic security risk in China is rising now
China's thinking on national security is captured in a guiding doctrine called the "holistic view of national security." This framing does not confine national security to diplomacy or the military but treats it as extending across broad domains—economy, finance, science and technology, networks, data, AI, food, biology, and resources. Put the other way around, the legal framework is built on the premise that even the management information, technical documents, and employee data that companies handle every day can bear on "national security."
Under this doctrine, a series of laws has been enacted and revised in rapid succession since 2014. Laying out the full picture with effective dates makes it clear how the regulatory net has grown finer year by year. Organizing the material based on a report1 that JETRO commissioned from Mori Hamada & Matsumoto, we get the following.
| Statute | Effective (or revised-effective) date | Main relevance to companies |
|---|---|---|
| National Security Law | July 2015 | Sets out the basic policy for national security |
| Cybersecurity Law (Network Security Law) | June 1, 2017 | Obligations of network operators; data protection |
| National Intelligence Law | Enacted June 2017; revised-effective April 2018 | Duty of organizations and individuals to cooperate with intelligence work |
| Anti-Foreign Sanctions Law | June 2021 | Countermeasures against foreign sanctions |
| Data Security Law | September 1, 2021 | Handling of important data and cross-border restrictions |
| Personal Information Protection Law (PIPL) | November 1, 2021 | Preconditions for cross-border transfer of personal information |
| Counter-Espionage Law (revised) | July 1, 2023 | Expanded scope of espionage; corporate prevention duties |
| Law on Guarding State Secrets (revised) | May 2024 | Strengthened management of state secrets |
Laid out this way, you can see that the danger is not any single statute but the way the body of laws complements one another to form a single control regime. The Counter-Espionage Law widens the entry point of "what counts as espionage," the three data laws constrain "which data can move where," and the National Intelligence Law puts in place a structure under which "cooperation can be demanded." As a matter of corporate risk, these three must be understood not separately but as one connected whole. If you want to first grasp the contrast with Japan's own economic security framework, I recommend also reading our article explaining economic security from the ground up.
What changed with the revision of the Counter-Espionage Law
The Counter-Espionage Law is a revision—adopted in April 2023 and effective July 1, 2023—of the earlier version promulgated in 2014, which itself was built on the 1993 National Security Law. The number of provisions grew substantially, from 5 chapters and 40 articles to 6 chapters and 71 articles. What matters to companies is less the increase in volume than the substance of what was added.
The change with the greatest impact is the expanded definition of espionage. Article 4 of the revised law provides that, in addition to the theft and similar handling of the previous "state secrets and intelligence," the act of stealing, spying on, buying, or unlawfully providing "other documents, data, materials, and items relating to national security and interests" also constitutes espionage. In other words, information that has not been designated as a state secret can still fall within scope. And what "national security and interests" refers to is not clearly defined in law. This very ambiguity is, in my view, the single greatest risk for foreign companies, because you cannot draw a line in advance around what is off-limits, so you cannot rule out that ordinary business activity ends up being judged as espionage. Attacks on, intrusions into, and disruptions of networks were also brought within the scope of espionage in this revision.
Another point you cannot overlook is the imposition of duties on ordinary companies. The revised law added a chapter on "security prevention," placing the principal responsibility for espionage prevention (a security-prevention duty) on ordinary companies as well (Article 12). Where a company fails to fulfill this duty, state security organs can order correction, hold interviews, issue warnings, and impose penalties on those responsible (Article 56). In addition, citizens and organizations have a duty to report (Article 16), and informants are eligible for commendations and incentives. Under the reporting-incentive rules promulgated by the Ministry of State Security in 2022, rewards are given according to the degree of contribution, and in particularly significant cases 100,000 yuan (roughly 2 million yen) or more is paid. The fact that society as a whole is structured to have an incentive to report is not something you can ignore when thinking about how to conduct yourself on the ground.
Enforcement powers were also strengthened. Article 25 of the revised law expressly provides that, in carrying out counter-espionage work and after completing the prescribed procedures, state security organs may inspect the electronic equipment, facilities, programs, and tools of the individuals and organizations concerned. Articles 23 and 24 also establish the authority to bar suspected spies from leaving the country and to deny entry to those who may pose a danger. In April 2024, the Provisions on Administrative Enforcement Procedures and the Provisions on Handling Criminal Cases by state security organs were promulgated, taking effect on July 1 of the same year. Inspection of electronic equipment, in principle, requires the approval of a responsible official at the municipal level or above along with an inspection notice, while in urgent situations an on-the-spot inspection can be conducted upon obtaining a responsible official's approval and presenting identification. Even though there is a procedural framework, you should be aware that on-site device checks are contemplated as part of the system.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
The National Intelligence Law and its structure of a "duty to cooperate"
The law spoken of in the same breath as the Counter-Espionage Law is the National Intelligence Law. It was enacted in 2017 and revised in 2018. The reason this law is viewed as a corporate risk is that it is structured so that any organization or individual has a duty to cooperate with the state's intelligence work.
Let me think concretely about what this means from a Japanese company's standpoint. If you have a local subsidiary in China and employ Chinese nationals, then it is possible, as a matter of the system, for those employees or the entity to be asked by the authorities to cooperate with intelligence activities. Overlay this with the expanded range of information that qualifies as espionage under the revised Counter-Espionage Law, and you cannot say it is entirely zero that your own technical information or management data could be included among the "targets of a cooperation demand." The existence of this duty to cooperate is also part of the reason foreign governments and companies have been on edge about Chinese-made communications equipment and apps.
Here I want to keep a cool head: the fact that this structure exists does not mean that every local subsidiary and employee is routinely forced to hand over information day to day. Stoking excessive anxiety is of no practical use. What matters is to accept the premise that "cooperation can be demanded" and, on that basis, adopt a design philosophy of not placing—or minimizing—sensitive information that could become a target of cooperation in the first place. Japanese companies cannot change the system itself, but you can control, to a considerable degree through your own operations, the volume and quality of the data you expose to that system.
Detention risk for expatriates and business travelers (the "people" problem)
More than abstract legal theory, real numbers tend to resonate with the people responsible. According to the China spot notice on the Ministry of Foreign Affairs' Overseas Safety website2, since the Counter-Espionage Law took effect in 2015, 17 Japanese nationals have been confirmed detained by Chinese authorities on "national security"-related charges, of whom 5 remain in detention (as stated as of July 22, 2025). This figure can be updated, so please check the Ministry of Foreign Affairs page for the latest situation before traveling.
The emblematic case involves a Japanese employee of Astellas Pharma. A man in his sixties who was an executive at the local subsidiary was detained in Beijing in March 2023, and on July 16, 2025, the Beijing No. 2 Intermediate People's Court handed down a prison sentence of 3 years and 6 months for espionage (a violation of the Counter-Espionage Law). A Ministry of Foreign Affairs spokesperson called this "extremely regrettable" and stated that the detention of Japanese nationals is one of the greatest impediments to improving people-to-people exchange and public sentiment between Japan and China. Ambassador to China Kenji Kanasugi attended the sentencing hearing and explained that Japan had sought early release at every level. Japanese business organizations have also repeatedly expressed concern over the detention of nationals. This case drives home the reality that, once the system starts moving, it is not easy for a single company to protect an individual on its own.
So what should travelers watch out for? The quickest route is to translate the conduct the Ministry of Foreign Affairs cautions against directly into operating rules. Specifically, photographing military facilities; collecting or obtaining geographic information through unauthorized archaeological surveys and the like; possessing maps; and conducting statistical surveys by distributing questionnaires without permission are said to potentially violate the Criminal Law and the Counter-Espionage Law as well as the Law on the Protection of Military Facilities and the Surveying and Mapping Law, and to be subject to detention or criminal penalties. Actions intended as "just tourist photos" or "market research for work" can become a risk depending on the authorities' judgment. Simply putting these in writing as a "list of things not to do" in a pre-travel briefing can go a long way toward preventing unwitting missteps.
The risk of bringing in corporate devices and data (the "things" problem)
After people come things—devices and data. As noted above, Article 25 of the revised Counter-Espionage Law expressly authorizes state security organs to inspect electronic equipment. It is safest to assume that the contents of a laptop or smartphone a traveler brings in are, as a matter of the system, contemplated as something that could be checked for some reason.
The JETRO report1 notes, in light of this situation, that some companies are considering and implementing practices such as not bringing data unnecessary for business into China as a precaution. I think this one sentence is the heart of device-side measures. Technical encryption and screen locks matter, of course, but the idea of "not bringing it in at all" is effective before any of that. Use a clean loaner device carrying only the minimum data for the trip, and reference sensitive materials only as needed via the cloud. If you can make this "data minimization" your standard, then even in the event of a device check, you have less to lose.
What happens when data is deemed "sensitive information"? After the Data Security Law took effect, the Ministry of State Security disclosed the first case in which information was actually deemed sensitive. An overseas research institution commissioned a Chinese domestic IT company to collect railway communications information—including IoT, mobile communications, and dedicated mobile communications network information for railways—and received 500 gigabytes of data in one month. This data was deemed sensitive information, and those involved received prison sentences for the crime of unlawfully providing state secrets or intelligence (Article 111 of the Criminal Law). This should be taken seriously as a real example of information gathering intended as business developing into a criminal case depending on volume and subject matter. Incidentally, the crime of espionage (Article 110 of the Criminal Law) carries fixed-term imprisonment of 10 years or more, or life imprisonment, and even where the circumstances are minor, imprisonment of 3 to 10 years—the sentencing is by no means light.
Cross-border data transfer from local subsidiaries (the "data" problem)
It is not only travelers' devices; the everyday flow of data that a local subsidiary sends to headquarters and group companies is also subject to regulation. The authority overseeing this is the Cyberspace Administration of China (CAC), which, building on the three data laws, requires one of the following as a precondition for cross-border transfer: passing a security assessment by the authorities, obtaining certification from a specialized body, or concluding and filing a standard contract between the parties. A security assessment takes 57 business days from the date of submission to completion and is valid in principle for 3 years, while a standard contract must be filed with the authorities within 10 business days of conclusion3.
There is some good news here. On March 22, 2024, the CAC promulgated and put into effect the Provisions on Promoting and Regulating Cross-Border Data Flows (the "Provisions Promoting Data Flows"), newly establishing exemptions that dispense with the preconditions in certain situations. What is particularly effective in Japanese companies' practice is the provision of employee personal information in cross-border human-resources management conducted in accordance with lawful labor rules or collective agreements (Article 5(2)). Chinese subsidiaries share employee data with headquarters on a routine basis, so the impact of exempting this is not small. The volume-based thresholds were also organized. I summarize the key points in a table.
| Data being transferred cross-border | Treatment (as of March 2024) |
|---|---|
| Trade, manufacturing, marketing, and similar data containing no personal information or important data | No precondition required (Article 3) |
| Personal information necessary to perform a contract (cross-border shopping, remittance, reservations, visa procedures, etc.) | No precondition required (Article 5(1)) |
| Employee personal information in accordance with lawful labor rules | No precondition required (Article 5(2)) |
| Personal information of fewer than 100,000 individuals cumulatively in the year (excluding sensitive; non-CIIO) | No precondition required (Article 5(4)) |
| Personal information of 1 million or more individuals cumulatively in the year (excluding sensitive) | Security assessment mandatory |
| Sensitive personal information of 10,000 or more individuals | Security assessment mandatory |
| Important data, or cross-border transfer of personal information or important data by a CIIO | Security assessment mandatory |
There is relief in how important data is handled. Article 2 of the Provisions Promoting Data Flows clarified that where relevant authorities or regions have not notified or publicly announced data as "important data," the data handler need not declare it for a security assessment as important data. In other words, your data is not arbitrarily treated as important data, triggering a required assessment; it is enough to operate by checking industry and regional announcements. That said, some fields—such as the automotive industry—have industry-specific catalogs of important data, so you should check whether a catalog specific to your industry exists. Note that even where an exemption applies, obligations under the Personal Information Protection Law still remain, including notice to individuals, obtaining individual consent, conducting and retaining records of a personal information protection impact assessment (PIA), and security measures. This point tends to fall through the cracks if you focus only on the numeric thresholds.
The often-overlooked intersection: China's data rules and Japan's export controls
So far I have discussed China's domestic law, but the trickiest thing in practice is that the same data transfer is regulated across multiple legal systems. The JETRO report also makes this intersection explicit in a footnote3.
On the Chinese side, Article 25 of the Data Security Law provides that export controls apply to data relating to maintaining national security and interests and to fulfilling international obligations. Under China's Export Control Law (effective December 1, 2020), controlled items are said to include data such as item-related technical documents, so you must comprehensively judge whether the data you transfer cross-border falls under China's export control lists. In other words, you have to check the same data not only from the standpoint of personal information protection but also from the standpoint of export controls.
And then there is the Japanese side. The overseas provision of technical data can fall under the service-transaction controls of Japan's Foreign Exchange Law (the Foreign Exchange and Foreign Trade Act). Furthermore, even a provision between residents can qualify as a "deemed export," which regulates the provision of sensitive technology to persons under the influence of a non-resident. A case such as teaching technology within Japan to a Chinese employee of a Chinese subsidiary is exactly where deemed export becomes the issue. I discuss the concept of deemed export in detail in our article organizing deemed-export risk, but the point to grasp here is the structure whereby a single data transfer can be caught by a triple net: China's data rules, China's export controls, and Japan's Foreign Exchange Law. That is precisely why taking inventory of the classification—which regulation, and where within it, applies to the data and technology you handle—is the starting point for every measure. For how to conduct classification itself, our article explaining METI's classification guidelines is also a useful reference.
Measures Japanese companies should take, and hints for systematizing them
Let me turn the points so far into a checklist you can actually run. The order matters too, so I recommend putting them in place from the top down.
First, a travel policy and a device/data minimization policy. Do not bring in, and do not send, data unnecessary for business. Use a clean loaner device for trips. In pre-travel briefings, put in writing the prohibited acts the Ministry of Foreign Affairs cites, such as photographing military facilities and possessing maps. Second, take inventory of the sensitivity and regulatory applicability (classification) of the data and technology you handle. Categorize what could fall under state secrets or "data relating to national security and interests," and whether it constitutes controlled technology under Japan's Foreign Exchange Law—based on criteria rather than a staff member's intuition. Third, screen your counterparties and involved parties. Make visible who you exchange what with, and detect in advance any counterparties that pose a high economic-security risk. Fourth, confirm the preconditions for cross-border transfer flows and keep records. Confirm whether a case falls under the CAC's security assessment, standard contract, or an exemption ground, and preserve the basis for your judgment as evidence. Fifth, put an emergency communication structure in place. Prepare in advance a route to promptly reach the relevant parties inside the company, the local subsidiary, and the consular desk of the Embassy of Japan in China should a detention or similar event occur.
What these five have in common is the idea of converting "cautionary advice" into "operable rules." The cautions from the Ministry of Foreign Affairs and JETRO are all correct, but as they stand the front line cannot act on them. Only once you decide who judges what and how do the cautions start to function.
Of this systematization, the parts covering Japanese-side export controls, classification, and counterparty screening can be standardized and automated with an AI agent. Our TRAFEED (formerly ZEROCK ExCHECK) is an export control AI agent that complies with the standards of Japan's Ministry of Economy, Trade and Industry; from the specifications and intended use, the AI performs an initial determination of whether the data or technical documents you handle constitute controlled technology under Japan's Foreign Exchange Law (that is, whether they are subject to overseas provision or deemed export). Based on joint proof-of-concept work, the AI determination accuracy is 95% or higher, allowing you to replace the intuition-dependent practice of "not sending data unnecessary for business" with a reproducible mechanism grounded in classification. It can also automatically cross-check counterparties and involved parties against each country's regulatory lists and watchlists to detect high-risk transactions in advance. The thinking behind this cross-checking also carries over to our article organizing sanctions-list and watchlist screening.
One thing I want to convey accurately is that TRAFEED does not directly make determinations under China's Counter-Espionage Law or data rules themselves. TRAFEED's main focus is export controls and economic security under Japan's Foreign Exchange Law and related laws; compliance with Chinese domestic law presupposes coordination with local experts such as attorneys. And the final classification determination is made by your company's export control officer. Even so, turning the Japanese-side determination and counterparty screening into a standardized process with an evidence trail is a solid first step for management, legal, and trade-control teams that want to avoid the heavy consequences of an expatriate detention or a data crackdown. We also track the latest developments in China's export restrictions on Japan in our article listing the Japanese companies placed on China's export control lists, so please check that as well.
Summary
This ran long, so let me organize the key points.
- The Counter-Espionage Law was revised and took effect on July 1, 2023, expanding the information deemed espionage from "state secrets" to "documents and data relating to national security and interests" (Article 4). The ambiguity of the definition is itself the greatest risk.
- The National Intelligence Law is structured to impose a duty to cooperate with intelligence work on organizations and individuals. Approach it with a design that keeps sensitive information out of the country, or minimizes it.
- The detention of nationals is a real threat. Per the Ministry of Foreign Affairs, 17 people have been confirmed detained since 2015, with 5 currently in detention (as of July 22, 2025). An Astellas Pharma employee received a sentence of 3 years and 6 months for espionage on July 16, 2025.
- For devices and data, "do not bring in, do not send" is the baseline. Cross-border transfers from local subsidiaries in principle require the CAC's security assessment, certification, or a standard contract, with some cases—such as employee data—exempted under the March 2024 Provisions Promoting Data Flows.
- The same data can straddle China's data rules, China's export controls, and Japan's Foreign Exchange Law. Taking inventory of classification is the starting point for everything.
Japanese companies cannot change the system itself. But the volume and quality of information you expose to that system, and the mechanism by which you make judgments, can be controlled to a considerable degree on our side. Whether you can go beyond "it's scary" to "how do we operate" is, I feel, the dividing line between a company merely exposed to risk and a company that can manage it. Start by making visible the classification of the data and technology you handle and the risk of your counterparties. To check where you stand on export control readiness, use the free export control assessment; to discuss a specific challenge, reach out via TRAFEED individual consultation.
Please note that this article is intended to provide general information; for individual matters, consult an attorney or an export control expert. Because the operation and numeric standards of Chinese domestic law can be revised, please confirm the latest version of the primary sources just before acting on any determination.
Footnotes
-
JETRO, "Overview of and Points to Note on Recent China National-Security-Related Laws: Policy Commentary by Experts" (January 2025, prepared by the Research Department of the Shanghai Office and Mori Hamada & Matsumoto) https://www.jetro.go.jp/ext_images/_Reports/01/c4f5a32439d71ff8/20240038_02.pdf ↩ ↩2
-
Ministry of Foreign Affairs of Japan, Overseas Safety website, China spot notice, "Cautionary Advice Regarding the Enforcement of the Counter-Espionage Law and Related Laws" (updated July 22, 2025) https://www.anzen.mofa.go.jp/info/pcspotinfo_2025C029.html ↩
-
JETRO, "Latest Developments in China's Cross-Border Regulation of Data and Personal Information (as of March 2024)" (April 2024, prepared by the Research Department of the Shanghai Office and Mori Hamada & Matsumoto) https://www.jetro.go.jp/ext_images/_Reports/01/690307ed2a411652/20240004_02.pdf ↩ ↩2
