Summary of Key Points
The enforcement of the U.S. Department of Justice's Bulk Sensitive Data Rules (BSD) is about to celebrate its first anniversary. Although there have been no official fines yet, a recent private lawsuit in Illinois (Baker v. Index Exchange) has posed significant compliance risks for Chinese companies operating overseas, such as Temu. For the first time, the court allowed the use of the BSD rules to override the Electronic Communications Privacy Act (ECPA)'s "consent defense." This means that individuals can sue Chinese companies based on the BSD regulations without waiting for the government to determine a violation, potentially leading to a wave of class actions and substantial damages. Chinese companies must not only deal with government enforcement but also guard against lawsuits filed by private plaintiffs' attorneys.
Why is this case a "landmark"? — The BSD has become a new weapon for private lawsuits
Previously, companies that collected user data had complied with the ECPA as long as they obtained users' consent (for example, through a "privacy policy" pop-up when accessing their website). However, in the Baker case, the court ruled that consent from the website was ineffective if the data was transferred to a Chinese company that violated the BSD.
Specifically, the plaintiff Baker alleged that Index Exchange, an advertising platform, had shared his browsing data with Temu, a Pinduoduo-affiliated company. Index Exchange argued that the website's consent allowed data tracking, but the court dismissed this argument, stating that if Temu was considered a "controlled entity" under the BSD, the data transfer violated the regulations, rendering the previous consent invalid.
This is the first time a court has recognized a violation of the BSD as grounds for a private lawsuit, potentially opening the door for class actions where plaintiffs can sue advertising platforms and e-commerce companies together, with potential claims involving thousands of users.
Why are Chinese companies particularly vulnerable? — The broad definition of "controlled entities"
The BSD defines "controlled entities" as companies or individuals associated with countries of interest to the U.S. (such as China and Russia). Two provisions are particularly problematic for Chinese companies:
1. A 50% stake requirement: Whether you hold a direct stake or an indirect one (e.g., through Cayman or Irish shell companies), if Chinese shareholders collectively hold more than 50%, the company is considered a "controlled entity."
2. Penetration of VIE structures: The U.S. Department of Justice can easily penetrate such structures (as seen in CFIUS reviews). Although Temu's parent company, PDD Holdings, is registered in Ireland, the plaintiff argued that at least 50% of Temu was owned by Chinese individuals. The court left this issue open for trial, indicating that overseas shells are not effective in avoiding compliance.
Therefore, any Chinese company operating overseas, such as Temu or SHEIN, could become a target for lawsuits if plaintiffs' attorneys can prove it is a "controlled entity."
The BSD's hidden pitfalls are more severe than you think
The BSD is intended to protect sensitive national security data, but its scope is incredibly broad:
- Common advertising data is considered sensitive: IP addresses, cookies, ad IDs, browsing history, and approximate locations are all classified as "sensitive personal data" under the BSD.
- Encryption and anonymization do not exempt you: Encrypting or removing names does not qualify the data as non-sensitive; the BSD explicitly states these measures do not exempt violations.
- Cumulative data counts: It is not based on a single excessive transfer but on the total amount of data transferred to the same Chinese company within 12 months. A mid-sized e-commerce company could easily accumulate enough data from 100,000 Americans to trigger the rules.
- Low threshold for comprehensive data: Even if only a small portion of users are government employees or located near government facilities (which is likely the case with Temu's large user base), the rule applies. In other words, as long as you have a significant number of users, you could be affected.
In summary, routine data transfers by Chinese companies conducting advertising activities may violate the BSD.
What companies need to do next? — Prepare for class actions and dual compliance pressures
Following this ruling, in the next 12-24 months, Illinois (the most active jurisdiction for class actions in the U.S.) is likely to see a surge of lawsuits against Chinese e-commerce and advertising platforms. Plaintiffs' attorneys will use the Baker case as a template, starting with lawsuits against advertising platforms before targeting Chinese companies.
Chinese companies must now focus on both government compliance inspections and private litigation:
1. Reevaluate data processes: Identify which data is transferred to Chinese entities and check for cumulative violations.
2. Adjust transaction structures: Transfer data through non-Chinese third parties or split the data to avoid triggering the BSD.
3. Prepare evidence in advance: Prove that you are not a "controlled entity" (e.g., by showing your stakeholding percentage or control structure) or that data transfers do not violate the BSD.
In conclusion, the BSD is no longer just a government-related compliance issue; it has become a real risk that can be triggered at any time by private lawsuits. Chinese companies operating overseas must prioritize addressing this threat.
(End of translation)