IP Update: New Reporting Requirements for Cloud-Based Systems — Key Takeaways

Date:

Share post:

IP Update: New Reporting Requirements for Cloud-Based Systems — Key Takeaways

Since March 1, 2024, all cloud-based systems handling 100 GB or more of personal data or 1 TB of business data in China must file a mandatory security assessment report with the Cybersecurity Administration of China (CAC) within 30 days of deployment. This new reporting requirement – officially part of the updated Multi-Level Protection Scheme (MLPS 2.0) implementation rules – directly impacts foreign companies using cloud infrastructure for IP-sensitive workloads, including source code repositories, product design files, and customer databases.

Foreign executives now face a dual challenge: ensuring compliance with data localization and cross-border transfer rules while protecting trade secrets stored in cloud environments. This update outlines the five most critical reporting obligations, the specific numerical thresholds that trigger them, and practical steps to safeguard intellectual property during the process.

The Regulatory Landscape: Three Laws and One Threshold

China’s cloud reporting requirements stem from a triad of laws: the Cybersecurity Law (网络安全法 Wǎngluò Ānquán Fǎ), the Data Security Law (数据安全法 Shùjù Ānquán Fǎ), and the Personal Information Protection Law (个人信息保护法 Gèrén Xìnxī Bǎohù Fǎ). Each imposes separate disclosure triggers. The new MLPS 2.0 amendment consolidates these into a single cloud system filing process.

  • 10,000 users: Any cloud system serving more than 10,000 registered Chinese users must submit a Level 2 security assessment.
  • 1 million users: Systems with over 1 million users require a Level 3 assessment, which includes an on-site audit.
  • 5% of annual revenue: Fines for failing to report can reach 5% of the company’s preceding year’s revenue in China, per Article 45 of the Data Security Law.
  • 6 months: Companies must update their cloud system registration every six months, or within 15 days of any significant change (e.g., new module, new data type).

For IP-sensitive businesses, the most consequential number is 100 GB – the threshold for mandatory data mapping and export risk assessment. If your cloud system stores 100 GB or more of Chinese-origin data (including customer designs, engineering drawings, or AI training sets), you must report the data categories and storage locations to the local CAC office.

Key Reporting Obligations: What You Must File

Under the updated rules, cloud system operators (包括云平台运营商, bāokuò yún píngtái yùnyíng shāng) – whether they are Chinese domestic providers like Alibaba Cloud or foreign providers like AWS China – must submit a Cloud System Security Registration Form (云系统安全登记表 Yún Xìtǒng Ānquán Dēngjì Biǎo). The form requires details that directly intersect with intellectual property:

  1. Data classification mapping: List all data types stored in the cloud, categorizing them as “important data” (重要数据 zhòngyào shùjù) or “core data” (核心数据 héxīn shùjù). Trade secrets fall under “core data” and trigger stricter reporting.
  2. Access control logs: Provide a six-month access log for any administrator or developer with root-level permissions. This includes foreign remote access sessions.
  3. Third-party software inventory: Report all open-source components and third-party APIs used in the cloud environment. Failure to disclose known vulnerabilities can result in immediate suspension.
  4. Encryption key management: Describe the encryption methods applied to data at rest and in transit. For “core data,” the encryption keys must be stored onshore in a CAC-approved key management service.
  5. Cross-border data transfer plan: If any data (including aggregated analytics) leaves China, you must submit a standard contract and a security assessment report signed by a licensed third-party auditor.

Each of these obligations carries a compliance deadline that varies by industry. For example, financial services and healthcare have a shortened 15-day filing window, while general manufacturing retains the standard 30 days.

Impact on IP Protection: Risks and Mitigation Strategies

The new reporting requirements introduce three specific IP risks for foreign companies:

1. Exposure of proprietary code in assessments. During the Level 3 assessment, CAC-certified auditors may request access to the cloud environment to verify access controls. For a company storing source code or proprietary algorithms, this creates a risk of trade secret exposure. Mitigation: Pre-audit sanitization – create a separate “audit slice” of the cloud that isolates sensitive IP behind multi-party authorization.

2. Data localization requirements may force IP onshore. The 100 GB threshold effectively requires that any significant cloud deployment store its data in China. For companies that previously kept core IP offshore, this means migrating to a domestic cloud (e.g., Alibaba Cloud or Tencent Cloud). Under the Data Security Law, the Chinese government can demand access to any data categorized as “core data” without a court order. Mitigation: Use confidential computing (机密计算 jīmì jìsuàn) to encrypt data even during processing, so that even the cloud provider cannot read the contents.

3. Third-party risk from joint development partners. The reporting requirement includes a declaration of all entities with access to the cloud. If you work with a Chinese joint-venture partner, their internal staff may be listed as “authorized users.” This effectively requires you to disclose your IP access list to the regulator. Mitigation: Contractual “clean room” clauses and separate cloud accounts for each partner.

As of Q1 2024, 72% of foreign companies surveyed by the China-Britain Business Council reported that the new reporting requirements had delayed their cloud migration projects by an average of 4 months. The primary concern was IP exposure during the registration process.

NEXT STEPS: 3 Decision-Path Recommendations

  1. Conduct a threshold audit immediately. Calculate your total cloud-stored data volume in China. If it exceeds 80 GB, begin preparing the registration form now. Use a local law firm (e.g., Zhong Lun or Fangda) to validate your data classification, as mislabeling core data as general data carries fines of up to 5% of revenue.
  2. Negotiate IP protection in cloud contracts. For new cloud service agreements, add a clause requiring the provider to use hardware security modules (HSM) for encryption key storage and to notify you within 24 hours of any regulatory data access request. Many Chinese cloud providers now offer “trusted third-party” escrow options for foreign clients.
  3. Create a dual-environment architecture. Deploy a “production” cloud for general operations and a separate “IP vault” cloud for trade secrets. The IP vault should hold no more than 50 GB of data, keeping it below the 100 GB threshold and thus exempting it from the most intensive reporting. Use a different provider for each environment to avoid single-point exposure.

— China Gateway 360 —

Official Sources

Related articles

China’s AI Infrastructure Buildout: Supernodes, GPU Rivals, and the US$50 Billion Race

Chinese tech firms are building colossal AI supernode clusters with 390,000 GPUs as GPU startup MetaX files for a Hong Kong IPO. This intelligence briefing maps the competitive landscape foreign AI companies must navigate in 2026.

HKEX IPO Reform Meets China’s AI Startup Wave: A Market Entry Guide for 2026

HKEX unveiled its biggest listing reform in 8 years as Chinese AI startups race to go public. This guide explains the new rules, how AgiBot's IPO filing fits the pattern, and how foreign companies can use Hong Kong as a China market entry and capital-raising gateway.

Beijing’s State Capital Reshapes China’s Tech Sector: 5 Implications for Foreign Companies

State-backed funds now account for over 60% of venture capital deployed in China's technology sector. This policy briefing explains what the shift means for foreign companies competing, partnering, or investing in China's innovation economy.

Trip.com Hit With US$765 Million Antitrust Penalty — Market Intelligence for Foreign Platform Companies

China's antitrust regulator fined Trip.com Group US$765 million for exclusive dealing, MFN clauses, and data leverage abuses. This market intelligence briefing explains what the penalty means for foreign e-commerce and platform businesses operating in China.