Enterprise File Processing Compliance Guide Under the Data Security Law

Since the successive implementation of the Data Security Law and the Personal Information Protection Law in 2021, compliance requirements for enterprise file processing have increased significantly. A contract, a financial statement, a customer list—each may cross legal boundaries during transmission, storage, and compression. This article starts from legal requirements and systematically outlines the compliance risks and response methods for enterprise file processing.

This article is an expansion of the compliance section in the Complete File Compression Guide. We recommend reading them together for a comprehensive understanding of both the technical and compliance dimensions of file processing.

1. Core Requirements of the Data Security Law

The Data Security Law of the People's Republic of China took effect on September 1, 2021, establishing the basic framework for data security protection. For enterprise file processing, the core requirements are concentrated in two areas:

1.1 Data Classification and Grading

The Data Security Law requires the establishment of a data classification and grading protection system at the national level, and enterprises must accordingly classify and grade their own data. As an important carrier of data, files need to be categorized into different levels based on their importance and the severity of harm if leaked. For example, public information, internal information, sensitive information, and core classified information should be subject to different levels of protection measures.

In terms of file processing, this means: files of different classification levels should use different security levels of processing. Classified files must not be uploaded to public internet tools, and files containing sensitive information should be desensitized or encrypted before circulation. The first step for enterprises is to establish a file classification and grading registry, clearly identifying which files can be processed online and which must be processed locally.

1.2 Secure Processing

The Data Security Law requires that data processing activities comply with legal and regulatory requirements and establish comprehensive data security management systems. File processing (creation, editing, compression, conversion, transmission, destruction) all falls under data processing activities and must be incorporated into compliance management.

Enterprises need to ensure that file processing tools themselves do not cause data leakage—for example, when using online compression tools, files are uploaded to third-party servers, which may constitute data export or unauthorized data sharing. When selecting processing tools, "whether data flow is controllable" must be the primary evaluation factor.

2. Impact of the Personal Information Protection Law on File Processing

The Personal Information Protection Law took effect on November 1, 2021, setting clear requirements for the collection, storage, use, transmission, and deletion of personal information. Many files that enterprises process daily contain personal information: employee resumes contain ID numbers, customer contracts contain contact information, and financial statements contain bank account numbers.

The main impacts of this law on file processing include:

  • Minimum necessity principle: Processing personal information should be limited to the minimum scope necessary to achieve the processing purpose, without excessive collection.
  • Notice and consent: Collecting and using personal information requires informing the individual and obtaining consent. Personal information contained in files must also follow this principle.
  • Cross-border transmission restrictions: Providing personal information overseas requires meeting statutory conditions such as security assessment, certification, or signing standard contracts.
  • Deletion obligation: Personal information should be proactively deleted after the processing purpose is achieved. File archiving must also consider this requirement.

In practice, the most easily overlooked compliance gap for enterprises is: uploading files containing personal information to online tools provided by overseas servers for processing. A seemingly ordinary "online compression" operation may have already constituted personal information export, triggering statutory filing obligations.

3. Three Compliance Risks in Enterprise File Processing

3.1 Data Export Risk

When using overseas online file processing tools, file data is transmitted to overseas servers, constituting data export. Under the Data Security Law and Personal Information Protection Law, the export of important data requires passing a security assessment, and the export of personal information must meet statutory conditions. Many enterprise employees habitually use foreign online PDF tools to process contracts, statements, and other files, unaware that these operations may have triggered data export compliance obligations that the enterprise has not fulfilled through the corresponding filing procedures.

Recommendation: For files involving important data or personal information, use local processing tools to eliminate data export at the source.

3.2 Third-Party Processing Risk

Online file processing tools typically upload files to third-party servers. Even if the service provider promises immediate deletion after processing, enterprises still face the following risks: data leakage by the service provider leading to file exposure, the service provider retaining copies for other purposes, and legal compulsory data acquisition in the service provider's jurisdiction. For sensitive files such as contracts, financial data, and customer information, handing them over to uncontrollable third parties for processing inherently expands the attack surface for data leakage.

3.3 Log Retention Risk

The Data Security Law requires data processors to retain data processing logs for no less than six months. File processing is an important part of data processing, and enterprises need to record "who processed what file at what time." If employees use personal online tools to process enterprise files, these operations are often outside the enterprise's log scope, creating compliance blind spots that make tracing impossible in the event of a data leakage incident.

4. Compliance Differences: Local vs. Online Compression

From a compliance perspective, there are fundamental differences between local compression and online compression:

DimensionLocal CompressionOnline Compression
Data locationStays on local device throughoutUploaded to third-party servers
Data exportNot involvedMay constitute data export
Third-party riskNoneLeakage and retention risks
Log controllabilityEnterprise can record processing activitiesOperations outside enterprise log scope
Network dependencyNo network requiredMust be connected
Compliance fitSuitable for all types of sensitive filesOnly suitable for public information

SmartSlim uses a purely local compression mode, with files processed entirely on the user's device, uploading no data and requiring no network, naturally complying with the Data Security Law and Personal Information Protection Law requirements for sensitive file processing. For enterprises that need to process contracts, financial statements, customer data, and other sensitive files, local compression is an effective way to avoid compliance risks.

5. Industry-Specific Compliance Recommendations

Government and State-Owned Enterprises

Government agencies and state-owned enterprises handle files that often involve state secrets and internal sensitive information, with the strictest compliance requirements. Recommendations: all file processing should be completed on internal networks or locally, with the use of public internet online tools prohibited; classified files should be processed using tools that have passed national confidentiality certification; electronic documents should preferably use the OFD format and be compressed through local tools. For related content, see OFD vs PDF: Differences and Compression Methods.

Financial Industry

Banks, insurance companies, and securities firms process files containing large amounts of customer identity and financial information, subject to strict regulatory oversight. Recommendations: compression and conversion of customer documents, loan contracts, and similar files should be done locally; establish a file processing approval workflow recording every processing operation; regularly audit the use of file processing tools to ensure no sensitive files are transmitted externally.

Healthcare Industry

Medical institutions process medical records, test reports, and other files classified as sensitive personal information, subject to regulations such as the Medical Institution Medical Records Management Regulations. Recommendations: compression and archiving of medical record files should be completed within the institution's local system; electronic medical record transmission should use encrypted channels; patient information files must not be uploaded to any third-party online tools to avoid triggering personal information export obligations.

6. File Processing Tool Selection Compliance Checklist

When selecting file processing tools, we recommend checking the following compliance points item by item:

  • Whether data is uploaded to servers: Prioritize local processing tools where files do not leave the device.
  • Whether processing requires network connectivity: Offline processing is more secure and does not depend on external networks.
  • Whether the tool provider is registered in China: Relevant to data export determination; overseas providers require extra caution.
  • Whether file processing log recording is supported: To meet the Data Security Law's requirement of retaining logs for no less than six months.
  • Whether relevant security certifications have been obtained: Such as classified protection assessment, ISO 27001, and other security qualifications.
  • Whether a data processing agreement has been signed: To clarify the data security responsibilities and obligations of both parties.
  • Whether batch processing and permission management are supported: To meet enterprise management and audit needs.

Only tools that pass the above checks can be included in the enterprise's file processing tool whitelist. Taking compression as an example, SmartSlim's local compression mode meets requirements across dimensions such as data location, network dependency, and log controllability, making it suitable as the enterprise's standard file compression tool.

7. Frequently Asked Questions (FAQ)

If an online compression tool says it deletes files immediately after processing, is there still a compliance risk?

There is still risk. Even if the service provider promises deletion, the data has already left your device during transmission and may be intercepted, retained, or legally compelled for disclosure. The transmission link itself, the service provider's logging system, and backup mechanisms may all leave traces of the file. For sensitive files, "uploading is itself a risk." We recommend using local compression tools.

Is it compliant for employees to send online-compressed files using personal email?

Generally no. Personal email is not managed by the enterprise, processing activities cannot be recorded in enterprise logs, and emails may transit through overseas servers, creating data export risks. Enterprises should explicitly prohibit such behavior through policy and provide enterprise email and local processing tools as alternatives.

Does the Data Security Law have specific provisions for file compression?

The Data Security Law does not have specific provisions for file compression, but file compression is a data processing activity subject to general requirements such as data classification and grading, secure processing, and log retention. The key factors for compliance are the data level of the files being processed, whether personal information is involved, and whether data export occurs during processing.

How do local compression tools meet log retention requirements?

Enterprises can require local compression tools to provide processing log functionality, recording processing time, file names, operators, compression parameters, and other information, with logs retained for no less than six months. Professional tools like SmartSlim support local processing log recording and can export logs for security auditing, helping enterprises meet the Data Security Law's log retention requirements.

Conclusion

The implementation of the Data Security Law and Personal Information Protection Law has shifted enterprise file processing from "whatever is convenient" to "whatever is compliant." The core principles are threefold: data classification, local priority, and traceable logs. Classify and grade files for management, process all sensitive files locally, and ensure all processing activities are recorded and traceable—achieving these three points essentially establishes the compliance framework for enterprise file processing.

Choosing a file compression tool that supports local processing and provides traceable logs is the most direct starting point for implementing compliance requirements. For more on the technical principles and methods of file compression, read the Complete File Compression Guide.

Related Reading: