Data And Regulation
Global Cross-border Data Governance Shifting Toward Access Control: The Institutional Innovation Experiment in Shanghai Lingang
Rules for cross-border data flows in the global digital economy are shifting from "whether data can leave the country" to "whether it can be accessed." This article analyzes this paradigm shift and explores how Shanghai's Lingang New Area can provide replicable solutions for enterprises through institutional innovation.
The infrastructure of the global digital economy is undergoing a quiet but profound power shift. Cross-border data flows are no longer merely a technical issue of data packets crossing national borders, but have become a critical battleground for data sovereignty games among nations and the global strategic layout of enterprises. While most multinational companies still focus on data export approval and localized storage, the pendulum of global regulation has swung toward a new dimension: who can access data, how they access it, and who controls access.
Event Background: From "Whether It Can Leave the Country" to "Whether It Can Be Accessed"
Traditionally, cross-border data governance revolved around "whether data leaves the country," "whether it is stored locally," and "whether it passes security assessments," forming a governance paradigm centered on physical movement and territorial jurisdiction. Under this framework, China established a management system centered on data export, with complete institutional tools, providing stable expectations for the secure and orderly flow of data.
However, a fundamental change is taking place: the core bottleneck encountered by multinational companies in global operations has shifted from "whether data can legally leave the country" to "whether overseas data, systems, services, and computing power can be continuously accessed, stably invoked, and used over the long term." Operations such as remote access, cloud-based operations and maintenance, API calls, and system control are becoming new regulatory focuses and restriction targets. Global cross-border data governance is shifting from "transmission control" to "permission-based access control." This is not just a technical adjustment, but a comprehensive restructuring of rule systems, jurisdictional logic, and risk assessment.
Three Major Paths in the U.S., Europe, and China: Intensifying Rule Competition
In response to this trend, the United States, the European Union, and China present distinctly different institutional logics.
The United States, based on Executive Order 14117 and relevant Department of Justice rules, has built a national security model centered on "access capability" and "control-chain penetration." Through "covered persons," it achieves full coverage of overseas affiliated parties, restricting not only the data itself but also access permissions and control rights, with a strong political overtone.
The European Union, based on the GDPR, together with the Data Governance Act, the Data Act, and the Cybersecurity Act 2.0, has formed the world's strictest and most influential rule system. Through the "high-risk suppliers" mechanism, the EU implements market access regulation, focuses on preventing non-technical risks such as "third-country influence," and continues to export regulatory standards globally.
China, based on the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law, has established a security order system centered on data export, incorporating overseas access to domestic data into unified regulation, emphasizing territorial boundaries and ex-ante supervision. However, its institutional response to restrictions on foreign entities targeting China and issues such as service interruptions still needs strengthening.
Digital Economy Analysis: Access Control Reshaping the Data Value Chain
As the regulatory focus shifts from "transmission boundaries" to "access boundaries," the composition of the data value chain is also changing. Traditionally, data stored, processed, and exported within a country followed a linear process. Under the new "access control" paradigm, data may still be stored within a country's borders, but it can be remotely invoked by systems in multiple locations around the world, forming a complex access network.For multinational enterprises, cloud platforms, APIs, keys, and update services have become the "lifeline" of digital operations. If these "access points" are restricted, even if data never leaves the country, a company's global business can grind to a halt. This means data governance is no longer just a compliance issue; it directly affects enterprise supply chain security and market access. For example, if a Chinese intelligent vehicle company relies on remote connections to overseas servers for global after-sales service, that connection itself may become the target of regulation.
At the same time, access control is also changing how the value of data is assessed. Traditionally, data value depended on data volume and quality; under access control, the "accessibility" of data and "inalienable control rights" become new value dimensions. For platform-based enterprises that control key data access points, their bargaining power further increases.
Business Model Observation: Compliance Capability Becomes a Core Competitive Advantage
In the new governance environment, compliance capability is becoming one of the most critical competitive barriers for multinational enterprises. A company that can simultaneously meet the access control requirements of multiple countries will gain lower operational risks and higher market trust than its competitors.
The practice of Shanghai Lingang New Area in this field is of typical significance. As a frontier of national-level institutional opening-up, Lingang took the lead nationwide in 2024 by establishing a cross-border data service center, providing one-stop services such as policy consultation, business guidance, document submission, and ecosystem matchmaking, covering the entire chain from security compliance, data technology, infrastructure, and industry applications to foreign-related compliance.
Lingang has also developed multiple benchmark scenarios: cross-border green trade carbon data, global supply chain logistics visualization, international shipping vessel inspection, global after-sales service for intelligent connected vehicles, cross-border asset management internal control coordination, and biopharmaceutical pharmacovigilance. These scenarios are not simple data transmission but deeply involve remote access, system control, and interface invocation—typical applications under the "access control" paradigm.
Through this exploration, Lingang has proven that security and openness can both be achieved, and that regulation and convenience can develop in coordination. More importantly, it provides China with a practical "toolbox" for reshaping global data rules, moving policy from macro narrative to micro-level implementation.
Market Competition Analysis: Who Benefits, Who Bears the Pressure?
From the perspective of the global competitive landscape, the biggest beneficiaries of the access control era may be tech giants and cloud service providers with global compliance infrastructure. For example, AWS, Azure, and Google Cloud are already accustomed to multi-jurisdictional compliance and can adapt more quickly to flexible new rules. Conversely, companies that rely on a single market and lack cross-jurisdictional compliance capabilities will face higher barriers.
Chinese tech companies going global will also come under greater pressure. The U.S. "entities of concern" mechanism directly targets companies with Chinese backgrounds, and the EU's high-risk supplier assessments will also adversely affect Chinese enterprises. However, if Lingang's "cross-border data service" model can be promoted, it will become a "compliance foundation" for Chinese enterprises, helping them respond to overseas regulation in a more systematic way and even, in turn, influence the formation of international rules.## Data and Regulatory Impact: China Needs a Dual-Track Institutional System
For a long time, China's data outbound transfer regulation has focused solely on "outbound," but the global trend has shifted toward "inbound" and "access." This means that China needs to build a governance system driven by both "outbound transfer" and "access." On the one hand, it should continue to refine rules for data outbound transfer; on the other hand, it should establish a corresponding management framework for foreign access to data within China, while providing legal response tools for "restricted" domestic enterprises.
The practical experience of Lingang shows that piloting in specific regions can generate innovations that go beyond traditional frameworks. In the future, China can build on Lingang's experience to accelerate the formulation of cross-border access governance rules, develop national-level digital compliance infrastructure, and provide public goods such as unified standards, certification, and evidence storage, thereby reducing enterprises' global compliance costs. At the same time, by actively participating in multilateral and regional rule negotiations, China can propose its own solutions to cope with the pressure of control-chain jurisdictional penetration.
Global Trend Watch: Data Sovereignty and Digital Globalization in Parallel
In the long run, global data governance will not become completely fragmented, but "conditional openness" will become the mainstream. Data sovereignty and digital globalization will proceed in parallel, and multinational enterprises must find a dynamic balance between the two.
As a new governance tool, access control essentially extends state "power" to the "use" rather than "ownership" of data. This is accelerating the evolution of global digital trade rules. In the future, cross-border data governance may form a multilateral framework similar to WTO rules, and pioneers—such as Shanghai Lingang—can provide important references for such a framework.
DigitalEcoNews Insight
The paradigm shift in global cross-border data governance essentially reflects the conflict between the public and commodity attributes of data as a factor of production. As data shifts from "flow" to "access," the competitive focus of enterprises will shift from "owning data" to "being permitted to use data." The exploration of the Shanghai Lingang Special Area reminds us that institutional innovation can become an important competitive lever. Rather than passively adapting to other countries' rules, it is better to proactively provide replicable solutions and strive for discourse power while the rules are not yet solidified. For Chinese enterprises, compliance capability is no longer just about reducing risk, but also a differentiating capability for expanding into global markets. The key to winning the future digital economy may lie in who can more smartly build a channel between security and openness.
Use note · digitalecononews
digitalecononews frames this note through Digital Markets / AI Economy / Platforms & Apps (Source URLs should be opened before the summary is reused). Digital Markets / AI Economy / Platforms & Apps explains the local editorial angle; dates, names and status changes still need checking.