Global products and platforms
Websites, apps, SaaS, e-commerce, advertising, support and analytics serving users in China and abroad.
PIPL · GDPR · DATA TRANSFERS
Cross-border data compliance is not solved by adding language to a privacy notice. The business must know where data comes from, why it is processed, who makes decisions, where it travels, how long it is retained and who responds to an incident. China's Personal Information Protection Law, data-security rules, the GDPR and local laws may apply to the same flow. Ada Ren helps businesses connect data mapping, lawful basis, notice and consent, transfer mechanisms, vendor contracts, internal governance and product design.
Situations and issue spotting
When personal information or important business data crosses borders, legal, product and technical teams must work together.
Websites, apps, SaaS, e-commerce, advertising, support and analytics serving users in China and abroad.
Chinese entities sharing employee, customer, supplier, financial or operational data with overseas headquarters.
International CRM, email, collaboration, storage, AI or analytics tools processing China-related data.
Diligence, closing, system integration, data-product circulation and joint development.
Key legal questions
Rules should follow the data lifecycle, not sit in isolated documents.
Identify categories, subjects, purposes, systems, storage, recipients and controller, processor or entrusted-party roles.
Confirm legal basis, necessity, notice, consent, sensitive information, children's data and rights handling.
Assess security review, standard contract, certification, separate consent, impact assessment and local transfer tools.
Allocate security, audit, sub-processing, incident notice, deletion and return responsibilities.
Working pathway
Prioritise high-risk flows and gaps that most directly affect launch or operations.
Interview business and technical teams and map priority flows, systems, entities and jurisdictions.
Compare applicable rules with documents and operations, then rank regulatory and business impact.
Update privacy materials, DPAs, consent, permissions, retention and vendor controls.
Implement incident, rights, vendor-review, recordkeeping and new-project assessment processes.
Document checklist
A review can start with the highest-risk product or flow before the enterprise map is complete.
Multi-jurisdiction strategy
The same flow may be a personal information export under Chinese law, an international transfer under the GDPR and a locally regulated disclosure at destination. Documents should reflect the real flow, not combine templates without analysis.
Ada has worked on a bilingual DPA for processing across Europe and Asia and on compliance review for enterprise-credit data products. Technical controls remain the responsibility of technology and security specialists; legal work defines applicable rules, accountability and auditable governance.

CHINA · AUSTRALIA · NEW ZEALAND
Professional foundation
Public reporting describes work on a bilingual GDPR-aligned data processing agreement for a digital-services business and participation in the compliance assessment of enterprise-credit data products for circulation on the Shenzhen Data Exchange. Every project still requires a current, flow-specific review.
LEGAL INSIGHTS
Continue with rule analysis, risk identification and practical action lists.
A practical 2026 guide to China cross-border data transfer compliance, covering security assessments, standard contracts, certification, exemptions and PIPL audits.
Read insight →EU Market AccessA practical legal update for China exporters, e-commerce sellers and EU importers on immediate PPWR chemical, conformity and EPR checks, plus the 2028–2030 packaging roadmap.
Read insight →FAQ
The actual storage, access and processing path matters. Overseas remote access may be relevant even where a server is in China, while irreversibly anonymised information may no longer be personal information.
Usually not by itself. Necessity, notice, separate consent, sensitive information, impact assessment and any security review, standard contract, certification or other mechanism must be considered.
They can share a data map and governance framework, but roles, lawful bases, transfer tools, rights timelines and regulator expectations differ. Jurisdiction-specific provisions are normally required.
START A CONVERSATION
For an initial enquiry, identify the jurisdictions, type of matter, critical dates and documents available.
