top of page

XL INSIGHTS+
Legal Alerts and News Updates

China Fines Ctrip for Cross-Border Data Transfer Violation

Updated: 20 hours ago

  • The Shanghai municipal branch of the Cyberspace Administration of China (“CAC”) has fined the online travel agency Ctrip RMB 10 million, citing failure to fulfill cross-border data security assessment obligations and illegal outbound transfer of personal information. 

  • This action marks a new escalation in China's enforcement of its data protection laws, including one of the most substantial fines imposed under the PIPL to date.

 

On June 13, 2026, the Shanghai municipal branch of the Cyberspace Administration of China (“CAC”) announced a RMB 10 million fine against the online travel agency Shanghai Trip.com Commerce Co., Ltd. (“Ctrip”), citing (1) failure to fulfill cross-border data security assessment obligations and (2) illegal outbound transfer of personal information. As one of the most significant fines levied under the China’s Personal Information Protection Law (“PIPL”) to date, this action signals an emerging enforcement pattern under which regulators scrutinize organizations’ data management practices, perhaps issuing warnings and recommendations, and penalize noncompliance as a serious violation. 


This action marks a new escalation in China's enforcement of its data protection laws, including with one of the most substantial fines imposed under the PIPL to date. While Ctrip is a commercial entity, the regulatory reasoning and severity of the penalty carry profound implications for U.S. colleges and universities operating in or engaging with China, signaling that regulators are willing to impose significant financial penalties across all sectors, including education.


Background and Significance of the Fine


The Shanghai CAC fine stems from a marketing agreement Ctrip entered into with Cambodia’s Ministry of Tourism on September 1, 2025, under which the Cambodia’s Ministry of Tourism commissioned Ctrip to place advertisements on Ctrip’s affiliated channels. A company statement indicated that Ctrip had submitted the agreement for regulatory review, though the company asserted that the agreement did not involve data sharing or the disclosure of user privacy information. Under the PIPL, transfers of personal information of Chinese individuals outside of China must comply with the PIPL's cross-border data transfer mechanisms, which include CAC security assessments, standard contractual clauses, or certification. 


Unofficial sources suggest that the CAC may have identified compliance risks in certain Ctrip business lines as early as 2025 and offered recommendations for remediation.  More recently, Ctrip has also been the subject of more public regulatory scrutiny, including an antitrust investigation announced by the State Administration for Marget Regulation (“SAMR”) on January 14, 2026, and joint regulatory talks focusing on improper collection and use of personal information held on June 11, 2026, among SAMR, CAC, and the National Railway Administration and seven major third-party platforms, including Ctrip. 


Penalties Imposed by the Shanghai CAC


Though the Shanghai CAC’s announcement provided limited detail, two points merit attention.  First, the announcement cites a "failure to fulfill cross-border data security assessment obligations," not a "failure to pass." This indicates that Ctrip had likely undergone the required security assessment but failed to comply with the conditions or restrictions imposed by the CAC's decision. A failure to take substantive corrective action until enforcement began would suggest a pattern of negligence, which might have contributed to the severity of the final penalty. 


Second, the amount of the fine signals that the Shanghai CAC considers the violation to be serious.  Under Article 66 of the PIPL, penalties are tiered.  General violation may receive a corrector order, warning, and a fine of up to RMB 1 million.  Serious violations, by contrast, may receive a fine of up to RMB 50 million or 5% of the previous year’s turnover, alongside business suspension, confiscation of illegal gains, and potential liability for responsible individuals.  The RMB 10 million fine substantially exceeds the general violation cap, which places this case firmly in the "serious circumstances" category.


Implications for U.S. Higher Education Institutions


Under Article 3 of the PIPL, a U.S. higher education institution may be subject to the PIPL if it does any of the following: 


  • Handles personal information of Chinese students, scholars, or research participants for the purpose of providing educational products or services;

  • Analyzes or assesses the behavior of individuals in China; or

  • Engages in any other activities involving personal information of individuals located in China.


While no major enforcement action has yet been brought against a U.S. higher education institution, the Ctrip case demonstrates that regulators are increasingly willing to subject the data management practices of organizations to regulatory scrutiny and to penalize noncompliance as a serious violation.  


U.S. institutions that transfer personal information of Chinese individuals outside of China must navigate the PIPL's cross-border data transfer mechanisms, which include CAC security assessments, standard contractual clauses, or certification, unless statutory exemptions apply. Such U.S. higher education institutions should act now to audit their data flows, implement robust compliance mechanisms, and prepare for potential regulatory scrutiny.




© 2024 XL Law & Consulting PA. - A U.S. Corporation - Privacy Policy - Cookies Policy - Contact Us

The information provided on the XL Law & Consulting website is for educational purposes only. Nothing on this website should be construed as or relied upon as legal or other professional advice, nor does use of this website create an attorney-client relationship.

bottom of page