Introduction

Data has woven itself into the very fabric of the global economy, with the digital economy further solidifying its presence in the wake of the COVID-19 pandemic. Against this backdrop, privacy protection has garnered significant attention, given its profound implications for international digital trade the geopolitical relations. How has China’s privacy protection strategy been developed, with its broad scope and stringent requirements for data localization and cross-border data flows? What are the broader geopolitical implications of its divergence from Western models of data privacy?

This paper argues that China's privacy protection strategy, characterized by its comprehensive regulatory framework and government access to data, is redefining the contours of global data governance and creating new geopolitical fault lines. The landscape of global data governance is experiencing a significant shift due to the divergent privacy protection strategies adopted by China in contrast to those of the United States (US) and the European Union (EU). China's approach, characterized by a comprehensive scope, stringent data localization requirements, and a substantial allowance for government intervention, represents an alternative model to the prevailing norms of digital privacy and data management championed by the US and EU.

This paper examines the evolution of China’s privacy protection strategy with a focus on the balance between individual privacy and national security. Drawing on official documents, laws, regulations, and a case study, this paper highlights the evolution of the regulatory framework in response to emerging challenges posed by technological innovations.

This paper also contributes to the broader discussion regarding the implications of China's privacy protection approach, highlighting potential normative clashes with countries that favor a more open digital economy. China's efforts in develo** its own privacy protection strategy have also resulted in the formulation of global standards for data privacy. This has created a bifurcation from the norms established by the EU's General Data Protection Regulation (GDPR), leading to a fragmentation of the global data governance regime.

For China, these different normative expectations and standards may potentially deter foreign enterprises. Different privacy standards introduce complexities into international trade, posing compliance challenges for transnational corporations and influencing the dynamics of global digital trade. These complexities can, in turn, have an impact on China's economy. For the international community, the normative competition evident in China’s approach reflects the broader geopolitical rivalries and may also influence develo** countries as they craft their own data governance policies, looking to major rule-makers such as the EU, US, and China as models to follow.

This paper proceeds as follows. The second section will lay out a theoretical framework for discussing China's privacy protection approach, focusing on China's distinct perspective on human security and the relationship between individual privacy and national security. The third section will examine the developmental path of China's privacy regulatory framework. The fourth section focuses on the case of Didi to illustrate the changing power dynamics between regulatory authorities and digital platforms, as well as the co-evolution of technological innovation and the regulatory framework. The fifth section explores the global implications of China's approach to privacy protection.

Human security and Yinsi protection

The concept of human security is highly relevant to the discussion of privacy protection, given the perceived distinctions between "collectivist" Chinese society and "individualist" liberal democracies. This concept serves as an analytical lens for exploring the different referent objects – the state and individuals – as the subjects to whom security is being provided.

This concept also helps tease out the relationship between individual privacy and national security, offering a perspective through which the states' concern regarding data sovereignty can be further examined – a concern that different types of regimes share. Given the challenges posed by technological innovation and the increasing capabilities of using data for various governance tasks, as well as the potential security risks associated with data misuse, China is not alone in its emphasis on data sovereignty. The US's decision to invalidate the EU-US Privacy Shield and the issuance of US executive orders targeting TikTok underscore Western concerns regarding the control over data sovereignty (Hu 2021). Similarly, Canada implemented its own measures to safeguard Canadian data against the provisions of the US Patriot Act, which grant US authorities access to data stored within the US, irrespective of its source or origin (Treasury Board of Canada Government of Canada 2006). This shared concern highlights the importance of avoiding an oversimplified dichotomy between China's approach and the "Western approach" (Gao 2004) rejects ahistorical conclusions, emphasizing that the absence of a directly corresponding term for "privacy" in the English language should not lead us to dismissing the existence of indigenous concepts related to privacy throughout Chinese history. While the term yinsi may have different origins, the associated notion does not emerge from nothing.

In traditional Chinese culture, yinsi possesses a collective dimension that prioritizes public and communal interests (Zhai and Li 2008). In the Chinese context, the privacy of the collective often takes precedence over that of individuals, with everything pertaining to an individual being subordinate to the collective to varying degrees (Zhai and Li 2008). The traditional idea of "yinsi protection" in China reflects a collectivist and instrumentalist mindset, the purpose of which is to maintain the harmony and stability of society as a whole, in contrast to the Western emphasis on preserving individuality and human rights (Zhai and Li 2008).

Some other studies emphasize how cultural inclinations shape individuals' attitudes toward privacy. In collectivist societies, trust tends to be higher within in-groups where significant social relationships are formed, whereas in individualist societies, social relationships are not confined to specific in-groups (Hamamura 2012). The distinctions between individualist and collectivist orientations manifest in various aspects of privacy concerns. Information privacy concerns revolve around the protection of personal data and online information, while psychological privacy pertains to feeling comfortable expressing oneself without concern about how others may judge their disclosed information (Li et al. 2022). Prior research indicates that Chinese and Koreans tend to be more concerned about psychological privacy, specifically the fear of being judged, in contrast to users in the United States, who are more inclined to express worry regarding the security of their personal information when using social media (Li et al. 2022). A 2011 study shows that Chinese users exhibited a higher level of trust in both the social network site system and its operator compared to their American counterparts (Wang, Norice, and Cranor 2011). These studies seem to suggest a distinctive cultural inclination among Chinese people in their privacy concerns.

Nevertheless, this cultural determinist approach certainly has its limitations. Some studies suggest that individuals' privacy concerns are primarily linked to the prevalence of internet usage rather than cultural distinctions such as individualism or collectivism (Engström et al. 2023). In other words, greater internet utilization is correlated with reduced levels of privacy concerns. From a Weberian perspective, the swift emergence and expansion of major technology corporations in China are bound to precipitate a heightened sense of individualism within Chinese society.

The emphasis on collectivism in Chinese culture partly explains why some citizens were willing to compromise their privacy rights during the COVID-19 pandemic. This cultural penchant is compounded by the socializing role of social media, which has cultivated more relaxed attitudes toward privacy (Tsay-Vogel et al. 2018). Despite this predisposition, the COVID-19 pandemic was a shock to Chinese society in the sense that it exacerbated the tensions between human security and state security (Zhang 2022). During the COVID-19 pandemic, China instituted a nationwide telecom data analysis platform overseen by the Ministry of Information Industry Technology (Norton Rose Fulbright 2021), which collected data even before the risks to public health and safety had been fully substantiated (Liu 2022). Nonetheless, despite individual concerns about privacy, the dissatisfaction with tracking did not result in any legal actions or lawsuits against local governments, as they retain discretionary authority to balance the interests of individuals and the collective well-being (Liu 2022). The "crisis mode" triggered by COVID-19 normalized the use of tracking technology and facial recognition.

The heightened public awareness of individual privacy prompts scholars to scrutinize the extensive use of health codes for governance, which has emboldened local governments to extend their authority into other areas, including gathering information not only on individuals' health conditions but also to monitor their behavior as responsible citizens (Zou 2023). With 900 million internet users, a thriving digital economy, and the prevalence of data theft and fraud, Chinese consumers are increasingly uneasy about unrestricted data collection by private firms (Pyo 2020). An example of this heightened awareness is the lawsuit filed by a university professor named Guo Bing, who took legal action against Hangzhou Safari Park over the use of facial recognition technology. Guo Bing accused the park of infringing upon consumer protection laws by forcibly gathering visitors' facial characteristics (BBC 2019). On 9 April 2021, this landmark case reached its long-awaited final verdict. Hangzhou Safari Park, the defendant, was mandated by the court to expunge all facial feature data collected from Guo Bing. Guo's plea against the compulsory collection of biometrics resulted in Hangzhou becoming the first city to outlaw mandatory facial recognition practices (Mo 2021).

Corroborating the growing awareness of individual privacy is the survey conducted by the Nandu Personal Information Protection Research Center, a think tank affiliated with Southern Metropolis Daily. It published the Public Survey Report on Facial Recognition in 2020. The findings revealed a significant sentiment among respondents, with 60% expressing concerns about the excessive use of facial recognition technology. Alarmingly, over 30% of those surveyed reported experiencing privacy breaches or property losses attributed to the unauthorized dissemination and misappropriation of their facial information (Fu 2020). Concerns have also emerged in relation to AI technologies, such as those used for self-driving, which rely on facial data for training purposes. Linking individual privacy concerns around facial data with national security, Zhang ** responsibilities among different governmental departments. For example, since the Cyberspace Administration of China (CAC)'s establishment in 2014, it has been engaged in a continuous turf war with the Ministry of Public Security concerning critical infrastructure protection and various other issues (Lee 2021; Creemers 2022). While the Personal Information Protection Law (PIPL) was established as the main authority overseeing personal information protection, the Ministry of Public Security was involved in the punitive actions against Didi (Hu 2021).

Expanding upon the discussion on yinsi in the previous section, the notion of "privacy" carries a somewhat distinct connotation in China, lacking the same constitutional status linked to liberal principles of the rule of law and economic values, as seen in Europe or the US (Creemers 2022). As Creemers notes, while PIPL primarily centers on regulating the relationship between individuals and data controllers, the Data Security Law (DSL) places a greater emphasis on assessing and managing the risks emanating from data held in China. The former is primarily concerned with balancing domestic interests and mitigating tensions between individual rights and collective economic growth, while the latter primarily focuses on safeguarding Chinese interests against deliberate hostile threats originating from foreign sources. As domestic scam cases and deteriorating relations with the US fed into the policy-making processes on digital governance, the distinction between safeguarding personal information for individual interests and its potential significance for national security began to blur (Creemers 2022).

Bearing in mind the caveat regarding cultural determinism, it appears that the Sinicized concept of human security does indeed take on an added dimension of collectivism. In the context of privacy protection, this dimension becomes evident in the guidelines that determine the threshold at which the volume of data raises national security concerns. As clarified in the Cybersecurity Review Measures, operators in possession of personal information from over 1 million users are mandated to undergo a cybersecurity review before proceeding with their overseas initial public offering (Cyberspace Administration of China et al. 2022). The focus on determining the threshold at which individual privacy transitions into a national security concern reflects an implicit assumption that individual privacy protection can only be provided by a capable state that can safeguard its sovereign rights.

From the perspective of governance, the expansion of state power over data heightens the risk of abuse, which could in turn undermine the government's credibility. The massive amount of data collected is vulnerable to cyberattacks, and if leaked, could potentially threaten both individual privacy and national security (Zou 2023). A case in point is the Shanghai National Police Database breach, involving data from 1 billion Chinese residents, including sensitive information like ID numbers and criminal records (Goh et al. 2022; Ni 2022; Hurst 2022).

The commitment to protecting individual privacy helps the Chinese state to bolster its legitimacy in the face of widespread digital abuse (Jia 2023). This motivation is exemplified by recent efforts against telecom scams and fraudulent activities. According to the Supreme People's Procuratorate of China, during the initial ten months of 2023, procuratorates across the country have taken legal action against more than 34,000 individuals involved in telecom and online fraud cases, representing a substantial 52 percent year-on-year increase (** the boundaries and norms associated with the concept of freedom of expression (Afina 2023).

As such, "governance by platforms" and "governance of platforms" work together to shape the regulatory landscape. Research on the distinction between these two modes of governance highlights the increasing influence of platforms in decision-making in data governance (Gorwa 2019; Poell, Nieborg, and Duffy 2021). The vast amount of data facilitates smart city development and digital governance, but also shifts the power dynamic in favor of the authorities and capital, which hide behind algorithms to discipline the public and foster acceptance of injustice (Zhang 2023).

Didi's development trajectory along with China's evolving regulatory landscape highlights how government policies can both shape and incentivize data-driven innovation and vice versa. Established in 2012, Didi swiftly ascended to the pinnacle of the ride-sharing industry in China, solidifying its position as the largest platform in the country following its acquisition of Uber's operations in China. By the time it prepared an initial public offering in the US, Didi had extended its services to 14 countries beyond China, amassing an estimated 50 million users in overseas markets (Chen 2021).

Didi’s personalized algorithms, powered by vast datasets of user behavior, pose potential challenges regarding data-driven innovation in the service industry to both individual privacy and national security. Holding an extensive repository of consumer data, Didi's operations fall under the purview of various Chinese laws and regulations, including the DSL, Cybersecurity Law, PIPL, and Cybersecurity Review Measures (People’s Daily 2022). The concern around national security was significantly amplified when Didi chose to list on the NYSE, as this move raised concerns about the potential exposure of sensitive data collected in China to foreign entities (Wang et al. 2024).

After taking down the Didi Chuxing app, on 5 July 2021, the Chinese Cyberspace Administration announced inquiries into other companies, including Full Truck Alliance and Boss Zhipin, citing concerns regarding national data security risks (Kharpal 2021). This marks the start of the government's endeavors to regain control and reshape the power dynamics in the digital governance landscape, which had long been dominated by major technology corporations.

In July 2022, CAC announced the penalties on Didi in accordance with the Cybersecurity Law, DSL, and PIPL (People’s Daily 2022). This breach resulted in a substantial fine of 8.026 billion yuan, surpassing even the 743 million euros fine imposed on Amazon for its GDPR violation, setting a record as the highest fine in the global history of data protection (Goh et al. 2022).

However, it is worth noting that despite the ongoing tension between state authorities and major tech companies, their relationship has not always been contentious. In the past, Didi's data collection had been used to assist the government in matters related to security governance. As of 2017, Didi had initiated collaborations with the local governments of more than 20 cities across China on smart transportation (China Net 2017). In September 2017, Didi initiated a strategic partnership with the Traffic Police of the Guangzhou Municipal Public Security Bureau. Synergizing Didi's extensive big data and analytical capabilities with the rich traffic data reservoir of the Guangzhou Traffic Police, this collaboration helps the government understand risky driving behaviors, crack down on drunk driving, and mitigate traffic congestion (China Net 2017). In 2020, Didi bolstered its collaboration with national law enforcement agencies to enhance background checks of drivers (Didi Global 2020). By August 2020, Didi had established partnerships with more than 50 local police departments to bolster crime deterrence on its platform (Didi Global 2020). As part of its Safe Driving System, Didi employs cameras for monitoring of both the road ahead and behind the vehicle while recording GPS data (** countries abstained from participation due to concerns that data flows might potentially disrupt their development (Aaronson 2021, 5). Data governance conducted hastily risks evolving into another dimension of capitalist mechanisms that reinforce inequalities between the Global North and Global South.

At the outset of 2021, data privacy laws were in place in 145 countries, a number that had risen to 157 by mid-March 2022 (Greenleaf 2022). The fragmentation of data privacy laws across the globe results in overlap** sovereignty claims concerning the control and ownership of data. Similarly, the current regulatory landscape concerning digital platforms is also complex and fragmented (Afina 2023). The competition for discourse power in data sovereignty, with cross-border data flow governance as a key element, is emerging as a central focus in future international competition (Shen 2023).

With these advancements in legal and regulatory frameworks, various interpretations of data sovereignty are being promoted and diffused (He 2021). The EU’s concept of data sovereignty aligns with its strategic autonomy and human rights agenda, whereas the US places greater emphasis on harnessing the economic potential of information and communication technology companies, accommodating the data collection and algorithm training requirements of technology giants (Broeders, Cristiano, and Kaminska 2023; Que and Wang 2022). Despite differences in the normative foundations of their respective approaches to data sovereignty, both parties share a growing concern about the location of data storage due to its implications for data sovereignty (Wang et al. 2024).

As China emerges as a frontrunner in sha** norms and regulations concerning cyberspace governance, its strategies for privacy and data protection also carry global ramifications (Gao 2021). Collectively, these legal and regulatory barriers may lead to increased fragmentation in global business operations. After a period of tightening control over data generated in China, recent efforts to expedite approvals for foreign companies awaiting data transfer clearance offshore (Yu and Tham

Conclusion

This paper offered an analytical perspective to understand the concept of yinsi and the intricate relationship between the individual, the community, and the state within the discourse of security and data privacy. Drawing a novel theoretical approach building on the Sinicized concept of human security and the indigenous concept of yinsi, this paper argues that China’s regulatory framework for privacy protection has evolved alongside technological innovations and key events that raised public concerns about the widespread use of technology that encroaches upon individual privacy.

Given that it is still in the early stages of development, China's regulatory framework sometimes appears fragmented, with overlap** responsibilities among various government departments. Due to its emphasis on state sovereignty over individual privacy, China's approach to privacy protection tends to downplay the perspective that societies could benefit from the use, sharing, and transfer of large quantities of data.

This paper complements Chen and Gao's (Forthcoming) observation regarding a shift in China's official narratives on cyber governance concerning the transition from a primary focus on national security to an increased emphasis on the protection of digital infrastructure and the control over data flows. This paper further demonstrates that this shift has incentivized the Chinese government to regulate cross-border data flows, especially when such flows involve the data of a significant number of users.

China's approach to privacy protection carries several global implications. Firstly, it presents challenges for multinational corporations engaged in global operations, as they must incur increased operational costs to ensure compliance. The state control over the movement of data may contribute to the fragmentation of digital businesses and slow down global digital trade. Secondly, it exacerbates preexisting geopolitical tensions with other major rule-making powers such as the US and EU, as their differing normative expectations become evident in their respective approaches. Thirdly, as other countries endeavor to strike a balance between data-driven economic opportunities and privacy concerns, China's approach may be seen as a potential model for governments looking to maintain significant state control over data.