As part of Beijing’s unprecedented scrutiny of private sector firms, Chinese regulators are considering pressing data-rich companies to hand over management and supervision of their data to third-party firms if they want US stock listings, sources said.
The regulators believe bringing in third-party information security firms, ideally state-backed, to manage and monitor IPO hopefuls’ data could effectively limit their ability to transfer Chinese onshore data overseas, one of the people said.
That would help ease Beijing’s growing concerns that a foreign listing might force such Chinese companies to hand over some of their data to foreign entities and undermine national security, added the person.
The plan is one of several proposals under consideration by Chinese regulators as Beijing tightens its grip on the country’s internet platforms in recent months, including looking to sharpen scrutiny of overseas listings.
The crackdown, which has smashed stocks and badly dented investor sentiment, has particularly targeted unfair competition and internet companies’ handling of an enormous cache of consumer data, after years of a more laissez-faire approach.
A final decision on the IPO-bound companies’ data handover plan is yet to be made, said the sources, who declined to be identified due to the sensitivity of the matter.
Regulatory officials have discussed the plan with capital market participants, said one of the sources, as part of moves to strengthen supervision of all Chinese firms listed offshore.
IPO advisers are hopeful a formal framework on the data handover issue could be delivered in September, said the source.
The China Securities Regulatory Commission and the Cyberspace Administration of China (CAC) did not respond to faxed requests for comment.
Listing plans on hold
Chinese regulators have recently put companies’ overseas listing plans, particularly in the United States, on hold pending new rules on data security.
Last month, the CAC proposed draft rules calling for companies with more than 1 million users to undergo security reviews before listing overseas.
The US Securities and Exchange Commission, which oversees US listings, did not immediately respond to a request for comment.
US policymakers are already worried Chinese firms are flouting US rules requiring public companies to disclose a range of potential risks to their financial performance, and Beijing’s data handover plan sparked renewed calls for caution.
“This is one more piece of evidence that private companies do not actually exist in the People’s Republic of China – they are all under the control of the Chinese Communist Party,” US Representative Michael McCaul, the top Republican on the House Foreign Affairs Committee, said in a statement.
“Any company that does business in the PRC must answer to the CCP, threatening investor transparency, consumer privacy, and national security,” he added.
Senator Bill Hagerty, who sits on the Senate Banking Committee, said in a statement to Reuters: “The Biden Administration and the SEC must continue to take action to ensure that Americans are aware of all the risks of investing in companies that are in any way subjected to the Chinese Communist Party’s rule, including the CCP’s management of key data.”
A total of 37 Chinese companies have raised $12.6bn via US IPOs so far this year, according to Dealogic, nearly double the $6.6bn raised over the same time last year.
Stepped up supervision
The plans to step up supervision of Chinese companies listed overseas came days after Beijing launched a cybersecurity investigation into ride-hailing giant Didi Global Inc on the heels of its $4.4bn US stock market listing.
Didi is now in talks with state-owned Westone Information Industry Inc to handle its data management and monitoring activities, Reuters reported earlier this month.
The proposed restrictions on Didi could become a possible template for other data-rich Chinese companies that look to go public in the US, said one of the sources.
Beijing’s increasing sensitivity about the collection and usage of onshore data comes as the top legislative body on Friday passed a new law designed to protect online user data privacy. It will implement the policy starting on November 1.
In September, China is also set to implement its Data Security Law, which requires companies that process “critical data” to conduct risk assessments and submit reports to authorities.
The government has in recent years increasingly seen user data as key to the country’s financial and social stability and pushed tech giants including Ant Group, Tencent and JD.com to share consumer loan data to prevent excessive borrowing and fraud, Reuters reported in January.
Ant is also in the process of spinning off its consumer-credit data operations, as part of the business revamp to revive its public share sale.