Where Compliance Begins
Since China's Data Security Law (DSL) and Personal Information Protection Law (PIPL) took effect in 2021, and with the EU's General Data Protection Regulation (GDPR) in force since 2018, enterprises face unprecedented compliance scrutiny over how they process files. A contract, a financial report, a customer list—each can cross a legal red line during transmission, storage, compression, or conversion.
File compression and format conversion are routine operations, but legally they all qualify as "data processing activities." The moment data is created, edited, transmitted, or destroyed, it falls under the DSL's scope; the moment a file contains personal information, it also falls under the PIPL's scope (and the GDPR's scope if it concerns EU data subjects). So the answer to "is using an online compression tool a compliance violation?" does not depend on the tool itself. It depends on three variables: the classification level of the file, where the data flows during processing, and whether the enterprise has fulfilled its compliance obligations.
This article examines the legal requirements, maps out the compliance risks of enterprise file processing, and answers where the compliance boundary of online compression tools lies—across both the Chinese (DSL/PIPL) and international (GDPR) regulatory contexts.
I. Core Requirements of the DSL, PIPL, and GDPR
The Data Security Law: Two Core Obligations
China's Data Security Law, effective September 1, 2021, establishes the foundational framework for data security. For enterprise file processing, the core requirements concentrate on two levels:
The first is data classification and grading. The law requires the state to establish a data classification and grading protection system, and enterprises must classify and grade their own data accordingly. Files must be divided into different levels based on importance and the severity of harm if leaked. Public, internal, sensitive, and core classified information should each receive protection of different intensity. This directly affects tool selection—files of different levels must be matched with processing methods of corresponding security.
The second is full-lifecycle secure processing. File processing (creation, editing, compression, conversion, transmission, destruction) all constitute data processing activities and must be brought under compliance management. Enterprises must ensure tools themselves do not cause data leakage, and "whether the data flow is controllable" must be the primary evaluation factor.
The PIPL: Four Key Constraints
The Personal Information Protection Law, effective November 1, 2021, sets explicit requirements for the collection, storage, use, transmission, and deletion of personal information. Many files enterprises handle contain personal information: employee resumes with ID numbers, customer contracts with contact details, financial statements with bank accounts. The PIPL imposes four main constraints:
- Minimum necessity: Processing personal information shall be limited to the minimum scope necessary to achieve the processing purpose.
- Notice and consent: Collecting and using personal information requires informing the individual and obtaining consent.
- Cross-border transfer restrictions: Providing personal information overseas requires meeting statutory conditions such as security assessment, certification, or signing a standard contract.
- Deletion obligation: Once the processing purpose is achieved, personal information should be proactively deleted.
The GDPR: Parallel Obligations
For organizations subject to the GDPR, the obligations overlap significantly with the PIPL, though the legal mechanisms differ:
- Lawfulness, fairness, and transparency (Article 5) mirrors the PIPL's notice-and-consent framework.
- Data minimization (Article 5(1)(c)) is the GDPR equivalent of minimum necessity: collect only what is adequate and necessary.
- International data transfers (Chapter V) require safeguards such as Standard Contractual Clauses (SCCs), Binding Corporate Rules, or adequacy decisions—functionally similar to the PIPL's cross-border conditions.
- Records of processing activities (Article 30) require controllers and processors to maintain documentation of processing operations, analogous to the DSL's log retention requirement.
The practical takeaway is that an enterprise operating across jurisdictions faces a converging set of obligations: classify data, minimize collection, control cross-border flows, and keep auditable records. The most easily overlooked gap is uploading files containing personal information to online tools hosted on overseas servers. A seemingly ordinary "online compression" operation may already constitute a cross-border transfer, triggering statutory obligations under both the PIPL and the GDPR.
II. The Data Classification System and Its Impact on File Processing
Data classification is not only a legal requirement; it is the practical starting point for file processing compliance. Without classification there is no differentiated protection; without differentiated protection, there is no way to judge whether an online compression tool may be used.
Classification Logic
Drawing on industry practice, enterprise files can generally be divided into four levels:
- Public level: Information already published or that can be published, such as website announcements. Processing with online tools poses no compliance risk.
- Internal level: Information used internally and not disclosed externally, such as internal notices. Using online tools requires evaluating the provider's qualifications.
- Sensitive level: Files containing personal information, trade secrets, or important data, such as customer contracts and financial statements. These must be processed locally; uploading to public-network tools is prohibited.
- Core level: Files involving state secrets or core enterprise assets, such as classified documents. These must be processed in an isolated environment using tools that have passed specialized certification.
Data Classification Processing Flow
The diagram below shows the complete classification flow from file identification to selection of a processing method:
The core logic is: first determine whether the file falls within statutory regulation (personal information, important data, state secrets), then determine the level based on scale and cross-border status, and finally match the processing method. For "sensitive" and "core" level files, the processing method is a hard constraint—once the level is determined, local processing is mandatory with no room for debate about online tools.
III. The Three Major Compliance Risks
Risk 1: Cross-Border Data Transfer Risk
When using overseas online file processing tools, file data is transmitted to overseas servers, constituting a cross-border transfer. Under the DSL and PIPL, the export of important data requires passing a security assessment by the national cyberspace administration, and personal information export requires meeting one of the statutory conditions. Under the GDPR (Chapter V), transfers to third countries require appropriate safeguards such as SCCs or an adequacy decision.
Many employees habitually use foreign online tools to process contracts and reports, unaware that these operations may have triggered cross-border transfer obligations the enterprise never fulfilled. Even when using a domestic provider, if backend servers are deployed overseas or overseas CDN and cloud nodes are used, a cross-border transfer may still occur. The criterion is not "the server the user sees is in their country" but "which jurisdiction the data actually reaches."
Risk 2: Third-Party Processing Risk
Online tools typically upload files to third-party servers. Even if the provider promises "immediate deletion after processing," the enterprise still faces three categories of risk:
- Data leakage risk: If the provider's security defenses have vulnerabilities, files may be stolen during storage, transmission, or backup. Several well-known online tool providers have suffered data breaches in recent years.
- Retention and reuse risk: Some providers' privacy policies reserve the right to use uploaded content for service improvement or model training; file contents may be retained and repurposed.
- Lawful compulsion risk: The laws of the provider's jurisdiction may authorize local law enforcement to access server data, without the enterprise's knowledge.
For sensitive files, handing them to an uncontrollable third party inherently expands the attack surface. Even without an actual leak, the mere fact that "data has left the enterprise's controllable boundary" puts the enterprise on the defensive during a compliance audit.
Risk 3: Log Retention Risk
The DSL requires data processors to retain processing logs for no less than six months. The GDPR similarly requires records of processing activities (Article 30). Enterprises must record "who processed which file and when" to enable tracing if a security incident occurs.
If employees use personal online tools to process enterprise files, these operations fall outside the enterprise's logging scope, creating a compliance blind spot: the operation time cannot be recorded, the processing target cannot be identified, and the operator cannot be correlated. Once a leakage incident occurs, the enterprise cannot prove it fulfilled its security management obligations. The essence of this risk is "loss of controllability"—the processing occurs outside the enterprise boundary, and the enterprise can neither obtain the logs nor guarantee their authenticity.
Compliance Risk Assessment Flow
The diagram below shows the decision flow for a compliance risk assessment of file processing operations:
Risk level rises with file level, and for sensitive-level files and above, there is almost no room for "online tools." Enterprises should embed this flow into their tool selection and usage standards rather than relying on individual employees' judgment.
IV. Local vs Online Compression: A Compliance Comparison
From a compliance perspective, local and online compression differ fundamentally. The table below shows the differences across seven dimensions:
| Dimension | Local Compression | Online Compression |
|---|---|---|
| Data location | Stays on the local device; never leaves the enterprise boundary | Uploaded to third-party servers; leaves controllable scope |
| Cross-border transfer | Not involved; no export-filing obligation | May constitute a transfer; server location must be assessed |
| Third-party risk | No third-party involvement; no leakage or retention risk | Provider leakage, retention, and lawful-compulsion risks exist |
| Log controllability | Enterprise can fully record time, target, and operator | Operations fall outside enterprise logging; compliance blind spot |
| Network dependency | No network required; processing unaffected by network | Network required; the network link itself is a risk point |
| Approval & traceability | Can be incorporated into enterprise workflows; fully traceable | Hard to incorporate; poor traceability |
| Compliance fit | Suitable for all levels from public to core | Only suitable for public-level files; prohibited for sensitive and above |
Online compression has compliance shortfalls in four core dimensions—data location, cross-border transfer, third-party risk, and log controllability—while local compression naturally satisfies the legal requirements in all four. This does not mean online compression is entirely unusable; for public-level files, the convenience has value. But for internal-level files and above, local processing is the only reliable way to avoid compliance risk.
V. Industry Compliance Recommendations
Government and State-Owned Enterprises
Government agencies and state-owned enterprises often handle files involving state secrets, with the strictest compliance requirements. All file processing must be done on internal networks or locally; using any public-network online tool is prohibited. Classified files must be processed with tools that have passed national confidentiality certification. Electronic official documents should preferably use the OFD format and be compressed and converted through local tools.
Financial Services
Banks, insurance companies, and securities firms handle files containing large amounts of customer identity and financial information. Compression and conversion of customer data, loan contracts, and account statements should be done locally. Establish a file processing approval workflow recording the operator, time, target, and parameters of each operation, with logs retained for no less than six months. Use a DLP (data loss prevention) system to monitor whether sensitive files are being transmitted externally.
Healthcare
Medical institutions handle medical records and examination reports that constitute sensitive personal information. Compression and archiving of medical record files should be done locally within the hospital's system; using any third-party online tool to process patient information is prohibited. Electronic medical record transmission should use encrypted channels. Patient information files must not be uploaded to any third-party online tool, to avoid triggering cross-border transfer obligations.
VI. File Processing Tool Selection Compliance Checklist
When selecting a file processing tool, check each of the following compliance points:
- Does the tool upload data to a server? Prefer local processing tools that keep files on the device. This is the fundamental measure for avoiding cross-border transfer and third-party risk.
- Does processing require a network connection? Offline processing is safer; it eliminates the data transmission step.
- Is the service provider registered in your jurisdiction? This affects cross-border transfer assessment; overseas providers require verification of backend server location.
- Does the tool support file processing log recording? This satisfies the DSL's six-month log retention requirement (and the GDPR's Article 30 obligation). Logs should include time, filename, operator, and parameters.
- Has the tool passed relevant security certifications? Certifications such as ISO 27001 or national cybersecurity level protection assessments reflect the provider's security management capability.
- Is a data processing agreement signed? This clarifies the data security responsibilities of both parties, defining data usage, retention period, and deletion method.
- Does the tool support batch processing and access control? This meets enterprise management and audit needs, supporting role-based permissions and unified logging of batch operations.
Only a tool that passes all of the above checks may be added to an enterprise's whitelist. Any single item failing means the tool may only be used for public-level files.
VII. FAQ
Q1: The online compression tool says "files are deleted immediately after processing." Is there still a compliance risk?
Yes. Even if the provider promises deletion, the data has already left your device during transmission and may be intercepted, retained, or lawfully compelled. The transmission link, the provider's logging system, backup mechanisms, and disaster-recovery nodes can all leave traces. For sensitive files, "upload is risk"—once data leaves the enterprise's controllable boundary, there is no guarantee it will be completely deleted. Sensitive files should always be processed with a local compression tool.
Q2: Is it compliant for an employee to send files processed with an online compression tool via personal email?
Generally, no. Personal email is not managed by the enterprise, so the processing behavior cannot be recorded in enterprise logs, violating log retention requirements. The email may also transit through overseas servers, creating a cross-border transfer risk. Enterprises should explicitly prohibit such behavior through policy, provide enterprise email and local processing tools as alternatives, and use a DLP system to monitor whether sensitive files flow out through personal channels.
Q3: Does the Data Security Law have specific provisions for file compression?
No. The Data Security Law has no provisions specifically targeting file compression, but file compression constitutes a data processing activity and is subject to general requirements such as data classification, secure processing, and log retention. Whether it is compliant depends on three factors: the data level of the file, whether it involves personal information, and whether the processing involves a cross-border transfer. The law does not distinguish "compression" from other processing methods; it only looks at whether the processing meets general security requirements.
Q4: How can a local compression tool meet the log retention requirement?
Enterprises can require local compression tools to provide a processing log feature that records processing time, filename, operator, and compression parameters, with logs retained for no less than six months. A professional tool should support automatic recording and export of logs for security audits. Enterprises should also integrate logs into a unified log management platform, correlated with the identity authentication system to ensure operators are traceable. Note that logs themselves are data processing records and should be managed at the sensitive level to prevent log leakage from creating secondary risk.
Summary
The implementation of the DSL, PIPL, and GDPR has shifted enterprise file processing from "whatever is convenient" to "whatever is compliant." Returning to the original question—is using an online compression tool a compliance risk?—the answer depends on three variables: the file's classification level, the data's flow path, and whether processing is logged.
The core principles can be summarized as three: classify data, prioritize local processing, keep logs traceable.
- Data classification is the prerequisite. Without classification, there is no way to judge whether an online tool may be used. Enterprises must first build a file classification ledger.
- Local-first is the baseline. For sensitive-level files and above, local processing is the only reliable way to avoid cross-border transfer, third-party, and logging blind-spot risks. Online tools are acceptable only for public-level files.
- Traceable logs are the safeguard. All processing activities must be recordable and traceable, with logs retained for no less than six months. This is a necessary means for an enterprise to prove it has met its obligations.
Achieve these three, and the basic compliance framework for enterprise file processing is in place. File compression is just one link in the file processing chain, but it reflects the enterprise's overall data security governance maturity—compliant tool selection, a clear classification system, and a complete logging framework. All three are indispensable.
Related Reading: