As advised by our PRC Legal Adviser and U.S. Legal Adviser and based on the due diligence conducted by our U.S. Legal Adviser in connection with the [REDACTED], such collection and use of personal data comply with material applicable laws and regulations concerning data privacy and security in China and the United States during the Track Record Period and up to the Latest Practicable Date.
As to cross-border data transfer, we mainly transfer summary clinical trial data which does not contain personal information of enrolled patients for regulatory communications and filings and we have not conducted any cross-border transfer of personal data.
Business · 第 220 页
During the Track Record Period and up to the Latest Practicable Date, we had complied with all relevant laws and regulations concerning data privacy and security in the PRC and the United States in all material aspects and had not been subject to any material administrative penalty concerning data privacy and security.
In respect of our cross-border data transfer activities, as confirmed by our data compliance legal counsel, we are exempt from applying for the outbound data transfer security assessment, concluding a standard contract for the outbound transfer of personal information or obtaining personal information protection certification, for the reason set out as below.
Business · 第 203 页
Based on the foregoing, as of the Latest Practicable Date, our Directors and our data compliance legal counsel are of the view that we are not subject to a mandatory cybersecurity review pursuant to the Cybersecurity Review Measures.
Business · 第 203 页
As such, as of the Latest Practicable Date, our cross-border data transfers are in compliance with the requirements of the Personal Information Protection Law, the Regulation on Network Data Security Management, the Provisions on Promoting and Regulating Cross-Border Data Flows, and other relevant laws and regulations.
During the Track Record Period and up to the Latest Practicable Date, we had not transmitted any personal information collected or generated in the course of our operations in Chinese Mainland to any overseas entity, organization or individual.
Business · 第 208 页
As confirmed by our PRC Legal Advisor, during the Track Record Period and up to the Latest Practicable Date, we had not incurred any related administrative penalties.
None of such information constitutes sensitive personal information or involves any data identified, publicly announced or informed as important data by competent authorities.
Business · 第 136 页
Based on the foregoing, our PRC Legal Advisor is of the view that we have complied with applicable PRC laws and regulations relating to data privacy, cybersecurity and data security in all material respects.
征祥医药(南京)集团股份有限公司Zenshine Pharmaceuticals (Nanjing) Group Co., Ltd.
数据合规及数据出境确认
As advised by our PRC Data Compliance Counsel, during the Track Record Period and up to the Latest Practicable Date, we had been in compliance with applicable PRC laws and regulations relating to data privacy, cybersecurity, cross-border data transfer and data security in all material respects, and had not been subject to any administrative penalties or legal proceedings in relation thereto.
Business · 第 197 页
We were not required to undergo a security assessment, enter into the standard contract for the cross-border transfer of personal information, or obtain personal information protection certification.
Given the above, our PRC Data Compliance Legal Advisers are of the view that we have completed the self-assessment for outbound data transfer in the course of our business as required under the applicable PRC laws and regulations relating to outbound data transfer and that such outbound data transfer activities are compliant with the applicable PRC laws and regulations relating to outbound data transfer.
Business · 第 174 页
In addition, during the Track Record Period and up to the Latest Practicable Date, as advised by our PRC Data Compliance Legal Advisers and the Directors confirm that we have complied with the applicable PRC laws and regulations relating to data security, personal information protection and cyber security in all material respects.
Given that (i) CCRC has confirmed that listing in Hong Kong does not constitute a listing abroad; (ii) as of the Latest Practicable Date, we have not received any official notification from relevant regulatory authorities designating our network facilities and information systems as Critical Information Infrastructure (“CII”), and therefore we are not deemed as a CII operator; and (iii) as of the Latest Practicable Date, we had not received any notice that we are required to conduct a cybersecurity review or our data processing activity affects or may affect national security, therefore, our PRC Legal Advisor is of the view that as of the Latest Practicable Date, we were not required to file cybersecurity review under the Measures for Cybersecurity Review for our proposed listing.
Business · 第 190 页
As advised by our PRC Legal Advisor, we are not required to undergo a data export security assessment, on the basis that: (i) our business does not involve critical information infrastructure, we do not provide services to any critical information infrastructure operators, and we have not been designated as a critical information infrastructure operator by any relevant PRC authority; and (ii) the data involved in our sole cross-border data transmission scenario consists of hash values and device location information, which are not highly sensitive in nature, constitute general personal information only and do not fall within the definition of “important data” under the applicable PRC laws and regulations.
Business · 第 190 页
In line with our actual business operations, we have filed the Standard Contract for the Cross-Border Transfer of Personal Data (“個人信息出境標準合同”) and obtained the relevant certification.
In 2018, we became aware that certain personally identifiable information of our customers, including names, login credentials and credit card information, was stolen during a concerted criminal cyberattack on our computer network.
Risk Factors · 第 61 页
In October 2022, we reached a settlement agreement with the Office of the Attorney General, pursuant to which we paid US$1.9 million in settlement payment in the same month and have maintained a comprehensive information security programme that includes a series of cybersecurity measures to protect consumer information.
浙江荣泰电工器材股份有限公司Zhejiang Rongtai Electric Material Co., Ltd.
数据合规:非关键信息基础设施运营者
During the Track Record Period, we did not engage in cross-border data transactions and are not classified as a network platform operator processing personal information of over one million users or an operator of critical information infrastructure under the Cybersecurity Review Measures.
Risk Factors · 第 43 页
Based on the due diligence conducted and documents reviewed by our PRC data compliance legal advisers on information security and privacy, during the Track Record Period and up to the Latest Practicable Date, we were in material compliance with the PRC laws and regulations relating to cybersecurity, data security and privacy protection, and had not been involved in any material violations, including the unlawful collection, use or provision of data.
Our PRC Legal Advisor and legal advisors in other relevant jurisdictions are of the view that, during the Track Record Period and up to the Latest Practicable Date, we have been in compliance in all material respects with applicable laws and regulations relating to cybersecurity, data security and personal information protection in the PRC and other relevant jurisdictions.
Business · 第 201 页
Furthermore, our domestic official website has successfully obtained the Level II Multi-Level Protection Scheme filing (網絡 安全等級保護二級備案) with the local public security authority.
Within the business scope of cellular IoT chips research, development and commercialization, our PRC Legal Advisor as to data compliance, is of the view that, we had complied, in all material respects, with the applicable laws and regulations with respect to data privacy, cybersecurity, and personal data protection during the Track Record Period and up to the Latest Practicable Date.
Business · 第 190 页
All data collected by us within Chinese Mainland is stored domestically.
Subsequently, in September 2025, CNIL issued a fine of EUR 150 million against us in connection with our practices for obtaining user consent and cookie practices, though CNIL conceded that all alleged non-compliance had been remediated prior to the fine.
In April 2026, the Irish Data Protection Commission (the “DPC”) commenced a statutory inquiry into our transfers of certain EU personal data to China, following a complaint filed by a privacy advocacy group.
Business · 第 207 页
We are currently cooperating with this investigation and intend to vigorously defend our position that our transfers of EU personal data are compliant with the GDPR.
With respect to the matters disclosed in “Business — Legal Proceedings”, to the best of our knowledge, our practices are not materially non-compliant with applicable laws and regulations relating to data privacy and cybersecurity.