Overseas businesses often begin with the question of whether their website needs a privacy notice. In real operations, however, customer records, employee information, marketing leads, support records, supplier contacts and system access are all part of the risk picture.
A more useful starting point is not a lengthy policy manual. It is understanding where information comes from, where it is used, which people and systems can access it, and whether any outsourcing or cross-border flow is involved.
1. Four operating questions to ask first
What information does the business hold?
Consider customers, staff, applicants, distributor contacts, website visitors, payment data and support records—not only the primary customer database.
Why is each category used?
Sales, delivery, accounting, recruitment, customer support, marketing, risk management and system security should each have a clear operational purpose.
Who can access it?
China teams, overseas headquarters, external providers and software vendors may have different access. Permission should follow a role and workflow, not convenience.
Does it leave China?
Cloud tools, global CRM systems, shared inboxes and overseas management reporting may require a closer look at the relevant information flows.
2. Basic controls a business can establish
- Data minimisation: collect only what is relevant and necessary for a defined business purpose.
- Roles and permissions: allocate viewing, downloading, exporting and deletion rights by role, with basic record keeping.
- Consistent documents: compare website notices, forms, customer terms, employee documents and vendor agreements with actual processing.
- Incident readiness: prepare an internal escalation path for lost devices, account anomalies, misdirected files or provider incidents.
3. When to seek an early legal assessment
Before a new system goes live
For example, a CRM, membership programme, recruitment platform, customer-support tool or new cloud service.
When China and overseas teams share information
For example, headquarters needs access to China customer or employee information, or a provider outside China processes it.
When a counterparty asks questions
For example, a large customer, platform or investor requires a data, security or supply-chain compliance questionnaire.
Map the information flow before placing compliance controls.
Legal counsel can help turn broad compliance requirements into business processes that can be allocated, documented and maintained.
This article is general information only. Do not submit personal information, system data or confidential material through an initial enquiry form.