LOréal

Cybersecurity Strategy for Global Consumer Products Company in China Market

The world is ever-changing; during the last 20 years, China has become the factory of the world for multiple industries, even for some high-technology industries, through the process of globalization. However, in the recent five years, China market has become more and more unique, even separated from the rest of the world, due to some geo-political reasons, high-tech competition, data sovereignty and localization requirement, and end-to-end supply chain security. Etc. 

But the only thing that has stayed the same is that China is one of the biggest consumer markets in the world due to the key factors: population, purchasing power and government policy support for the internal circulation of China's economy. No global consumer product company is willing to give up the Chinese market. The only thing we need to study is how to adapt our Chinese organization to this unique market and unique digital world, and the same to our Cybersecurity strategy in China, as a cybersecurity practitioner.

First of all, China has unique and comprehensive cybersecurity laws and regulations, including data security and privacy protection. What’s our strategy to comply with these requirements while keeping our global strategy and visibility? What kind of bottom line should we hold from either side? I believe this is the part where cybersecurity, legal, and even government affairs need to work very closely, and keep updated on the political climate, understand the government’s legislation and enforcement trends, and even benchmark with industry peers; then we can formulate our executable compliance strategy and plans. From a technical perspective, neither global centralization nor China localization technology and data residency strategy will be fitting for both side; we definitely need to source for an intermediate solution like a geographically partitioned or distributed solution to meet China data localization requirements while allowing only the necessary aggregated or pseudonymized data to be transferred cross-border to keep a consolidated global view. 

You must always pay attention to the major Chinese E-Commerce platforms for selling consumer products well in China market. Yes, we can have our own Direct-to-Consumer or loyalty programs, but it is crucial to embrace and integrate into China's major E-Commerce walled garden, and make use of China’s digital advertising channels by leveraging interesting marketing content and KOLs, even legitimately use 1st, 2nd and 3rd party data, social and search marketing touchpoint to target potential customers. That’s why operational risk on the E-Stores on E-Commerce platforms become critical to us; there is a high volume of operation accounts to be managed on those E-Stores, sometimes with high turnover and complex roles; our successful experience is in building an E-Commerce platform account management system to be integrated with our HR onboard/transfer/offboard process, automate the check-in/check-out/rotate process, enable the role-based authorization and entitlement review control, of course enabling audit logging to enable abnormal activity alert based on the pre-defined risk scenario rule. There will also be some privileged accounts for managing some key functionality of E-Stores; we have a success story of creating a secure and centralized environment for business to access their E-Stores via privileged accounts, and enable the visibility, accountability and traceability around the usage, completely avoid sharing credentials of privilege accounts.

"To protect all our loyalty members’ privacy information in  China with compliance with the China local cybersecurity and privacy regulations, we must build a comprehensive privacy protection program or system"

As you know, China Personal Information Protection Law (PIPL) took into effect on 1st Nov 2021, which is equivalent to Europe’s GDPR, even more, strict in some areas. But the biggest difference is still due to China’s unique digital ecosystems, which leads to the unique approach to privacy protection regulation’s enforcement and execution in China. After PIPL, all the major Chinese E-Commerce platforms have performed privacy revamp per the latest privacy requirements; after that, the interface between E-Commerce CRM, Order Management System and Logistic System changed, and it became more and more difficult for a merchant to acquire the personal information from customers, unless we successfully convince the customer to join our own membership program, legally speaking, this is the right thing to protect the lawful rights and interests of citizens and organizations, also serve the economic and social development of the whole digital ecology.

To protect all our loyalty members’ privacy information in China with compliance with the China local cybersecurity and privacy regulations, we must build a comprehensive privacy protection program or system, which includes:

• Privacy and Security by Design

• Supply Chain security management

• Personnel security governance

• Privacy regulation compliance

• China digital application compliance check

• China-specific target marketing rule 

• Chinese Data Subject Rights protection and appeal management

• Content management

One thing I need to highlight here is the last bullet item: content management, which is also a very special requirement in China's cybersecurity framework, this requires continuous checking and making sure all the content generated either by your company or your users are legally and politically right, this is not a small effort.

In a global company, there are always some debates between a global security solution and a local security solution; a global solution enables centralized management and operation and keeps global consistent configuration and rules, enabling global visibility. While the local solution is fitter to local consumer habits and experience, sometimes with high performance and even low cost. Again, China is a unique market; for some consumer-facing solutions, we definitely can consider local solutions with a global standardized risk assessment to be performed. Of course, we will prefer to choose a globally certified solution for the more backend solution; then, we can have a global view of the full picture. Again, there is no one-fit-all answer, we still need to dive deep into it case by case, but the risk assessment methodology and process should be consistent without any bias. One of the good examples is the NFT platform, which is also a very hot topic in China, to issue NFT in China, there are many potential legal risks, compliance requirements and industry practices in China, so we must choose a platform or key market player with all the license in China and contractual commitment to cooperate. However, we will still mitigate all the cybersecurity risks with global solutions based on the underneath blockchain technology. 

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.