cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted
Viewer

China and laptop encryption

Hello all,

 

I'm reaching out to this knowledgeable group for direction.  My current company is about to expand it's business into China and I'm not having much luck tracking down the current China law on bringing encrypted devices into China. 

 

Any pointers on where I can find current information?

 

Thanks,

 

Robert

5 Replies
Highlighted
Viewer II

Re: China and laptop encryption

Try the Chinese Consulate.

Highlighted
Viewer III

Re: China and laptop encryption

What specific encrypted devices and what scenario you are talking about? Generally, the national cybersecurity law and OSCCA does care about any crypto products to be used in China.

 
Highlighted
Viewer III

Re: China and laptop encryption

better reach out to USITO.

 
Highlighted
Newcomer I

Re: China and laptop encryption

I am not a lawyer, but I've been on multiple big projects launching into China with enormous investment $$$ floating around, so have a bit of experience.  Consider this advice, and not authoritative.

 

There aren't hard and fast rules. It's all geo-political, and risk-based decisions.

 

 

If you're a technology company, the answers might be different, particularly if your corporation is on unfriendly terms with China (I'm looking at you Google) or if Snowden papers showed your firm colluded w/ the NSA.  But, let's presume you're not on that small list.

 

Basically, they're not going to care what laptop OS or crypto your team members are carrying flying into China, doing business, and flying home.  Could they?  Absolutely, your guys could be back-roomed at the border.  Will they?  Almost certainly not.  The dreaded, "They're going to ask for our keys" seems an exception rather than the rule, and is more common to network infrastructure than executive laptops.  I think the better questions are, "What should {execs/privileged account holders} carry into China? What contingency & OpSec plans should be utilized while there?  What should happen upon return?"

 

For deployment into China, you're not going to want to import anyway, because that gets you into import/export restrictions, tariffs, and all kinds of headaches.  Buy equipment local, software local, install local and you'll be fine.  Will your supply chain be secure? Nope.  But, are you going to frisk the cleaning crew every night?

 

This is a very complex field full of land mines... and I don't want to write a book on here because part of my consulting practice is supply chain security assessment, and helping firms make entry into new markets, China in particular, navigating privacy & security concerns. As I said, there aren't hard & fast rules, so I can't provide absolutes that, "if you do this, then XYZ will be true".

 

Happy to chat over a coffee. 🙂

 

-ddh