虎嗅

"Sensitive Data Regulations and America's Decade-Long Strategy: The Practice of Bans on Kaspersky and Huawei Has Shaped America's Systematic Regulatory Framework"

原文:敏感数据规则与美国十年布局​:卡巴斯基、华为禁令的实践塑造美国系统性监管框架

Summary of Key Points

This article highlights the policy continuity between the two major political parties in the United States regarding technology products and data security. Despite Trump repealing most of the regulations established by the Biden administration, he retained the "Sensitive Data Rules" aimed at preventing foreign entities (especially China) from accessing sensitive American information, classifying them as "critical national security projects." By examining three case studies—Kaspersky, Huawei/ZTE, and TikTok—the article outlines how the U.S. has developed a policy framework over the past decade to address geopolitical risks. It highlights the consensus between both parties, judicial support, the establishment of systematic tools, and the trend towards expanded restrictions, providing guidance for Chinese companies on how to respond.

Detailed Analysis

1. Rare Consensus Between the Two Parties: Cross-Governmental Continuity in Data Security Policy

Why did Trump retain the Biden-era sensitive data rules? The core reason is that national security is non-partisan. Both Democrats and Republicans agree that foreign entities (particularly China) obtaining sensitive American data, such as biometric information, medical records, and financial details, poses a threat to U.S. security. This consensus ensures that policies remain stable across administrations, meaning restrictions on Chinese technology companies and data will only tighten, not loosen.

For example, although Trump largely overturned Biden's domestic policies (such as climate and healthcare), he exceptionally kept the sensitive data rules and even elevated them to the status of "critical projects." This indicates a mutual understanding between the parties on the need for strong measures in the field of technology security.

2. Three Case Studies: How the U.S. Weaves a Tighter Security Net

U.S. policies are not developed out of thin air but are refined through specific cases:

  • Kaspersky (Russian antivirus software): In 2017, the Department of Homeland Security ordered federal agencies to remove Kaspersky's software, citing concerns that it was subject to Russian law and could be exploited by intelligence services. This was the first time the U.S. used a "Binding Operational Directive" (BOD) against a particular company. When Kaspersky sued, the court ruled in favor of the government, stating that the decision was based on security considerations rather than punishment.
  • Huawei/ZTE (Chinese telecommunications equipment): In 2018, Congress passed legislation prohibiting federal agencies from purchasing or collaborating with companies that use Huawei or ZTE equipment. The FCC classified these companies as "security risks" and banned them from receiving federal subsidies. When Huawei sued, the court again supported the government, arguing that the measures were necessary for espionage prevention.
  • TikTok (Chinese short-video app): Trump attempted to ban TikTok, but Biden retained the requirement for its forced sale. Congress followed up with legislation, and when TikTok appealed to the Supreme Court, it lost. However, after Trump took office again, the enforcement was suspended. These cases show that while it is difficult for the U.S. to ban widely used consumer products, the overall policy direction remains unchanged: either sell the companies or impose strict regulations.

These three cases demonstrate how the U.S. uses legal, administrative orders, and subsidies to gradually exclude foreign technology companies from the market.

3. A Systematic Toolkit: The U.S. Government's Standardized Approach

The U.S. now has a set of replicable tools for enforcing its policies:

  • FASC Committee: Responsible for assessing security risks in federal procurement and ordering the removal of risky products.
  • Executive Order 13873: The Secretary of Commerce can designate any technology product as a "threat to national security" and ban it directly.
  • FCC Risk List: Lists products with security issues, prohibiting their purchase with federal funds.
  • Sensitive Data Rules: Do not target specific companies but regulate categories of sensitive data to restrict foreign access.

These tools work together to create a comprehensive approach that could be applied to more Chinese products in the future, such as the recently passed "Routers Act" in the House of Representatives, which aims to ban certain Chinese routers.

4. Judicial Support: Companies Have Little Chance of Overriding Policies

Companies like Kaspersky, Huawei, and TikTok that have sued the government have lost their cases, with courts consistently ruling in favor of national security. For example, when Kaspersky argued that the government's actions were based on its Russian background, the court acknowledged the risk and deemed the government's actions reasonable. When TikTok claimed a violation of free speech rights, the Supreme Court upheld the government's authority to regulate for national security reasons.

This indicates that it is almost impossible for Chinese companies to overturn U.S. restrictions through litigation. They must accept these measures and prepare in advance.

5. Guidance for Chinese Companies

Based on these trends, Chinese companies should take the following steps:

  • Recognize Policy Continuity: Avoid assuming that restrictions will ease with a change of administration and consider them as a long-term risk.
  • Prioritize Compliance: For example, under the sensitive data rules, some transactions can be compliant by meeting auditable security requirements. Establish compliance systems in advance.
  • Conduct Risk Assessments: Regularly assess whether your products or services could be listed as risky (e.g., if they handle sensitive data or critical infrastructure).
  • Diversify Markets: Reduce dependence on the U.S. market and expand into other regions, such as Southeast Asia and Europe.
  • Promote Technological Independence: For example, by developing their own chips to reduce reliance on supply chain vulnerabilities.

In summary, the U.S. has entered a new era where technology security takes precedence. Chinese companies need to proactively adapt and adopt strategies for compliance, diversification, and technological autonomy to stay competitive in this context.

Final Conclusion

The U.S.'s restrictions on foreign technology companies are **long-term, systematic, and based on bipartisan consensus.* Chinese companies must plan ahead by focusing on compliance, diversifying their markets, and enhancing their technological independence to remain competitive.