Mr. Zhiyi Ren
Partner

Zhiyi Ren is a leading regulatory lawyer in China, specializing in regulatory, financial markets, fund products, and M&A transactions in the financial sector. Since 2003, he has provided legal services to multinational financial/asset management companies in China, covering entity establishment, products, compliance, regulatory investigations, crisis management, and cross-border transactions. Prior to joining Fangda Partners, he worked as Head of Compliance in an internationally renowned investment bank’s domestic subsidiary on all its China investments, covering securities, futures, funds, commodities, trusts, guarantees, special opportunity group, and quant research. He gained abundant experience handling several financial enterprises’ legal and compliance affairs. He also worked in an international law firm for many years and is a member of the PRC Bar and the New York State Bar.

Mr. Blake Wang
Partner

Blake Wang specialises in financial regulation, asset management, and M&A. Blake advises renowned international financial institutions, asset managers and proprietary trading firms on establishing or investing in PRC entities, and investing in PRC financial markets. Blake has a rich experience in assisting foreign investors (e.g. QFIIs, PFMs) on product issuing and marketing, account opening, custody and advisory services, covering contract review and legal advice. Prior to joining Fangda, Blake worked for another leading PRC firm focusing on asset management and M&A practices. Blake also worked at the head office of Bank of China from 2010 to 2011. Blake holds degrees from Peking University and Zhejiang University.

FinTech Regulation in China

 I.Overview

From the perspective of financial licensing/regulatory rules, in the PRC the major types of FinTech businesses and their primary regulators include, among others:

From a historical perspective, during the earlier days of China’s FinTech industry, the concept “internet finance” emerged and was often mentioned by PRC financial regulators in relevant official documents issued in years such as around 2014 and 2015. As indicated by its name, internet finance refers to primarily the use of internet in financial activities, and used to be primarily associated with online financing platforms such as peer-to-peer (P2P) lending and crowdfunding. Since around 2016, as far as we are aware, major FinTech servicers gradually began to play a significant or even overwhelming role in many financial services. These years also have witnessed a massive jump in the AUM of China’s asset management industry, the growing power of large internet companies and their expansion to the financial sectors, and increased concerns over financial stability and data security. In recent years, the development of China’s FinTech regulation has been highlighted by key regulations and regulatory actions with respect to particularly the asset management industry (see Section II below), financial services of internet companies (see Section III below), and cyber security and data protection (see Section IV below).

II.FinTech for Asset Management

Generally there are no separate licenses for carrying out asset management via FinTech. Rather, asset managers, after obtaining the appropriate asset management license, may carry out their asset management via FinTech to the extent compliant with applicable regulatory rules. For the asset management industry broadly, related financial licenses may include mainly the investment management license, the investment advisory license, and the investment product sales license.

With respect to the investment management/advisory licenses, the Guiding Opinions on Regulating Asset Management Business of Financial Institutions ( 《关于规范 金融机构资产管理业务的指导意见》, commonly referred to as the “New Asset Management Rules”) promulgated in April 2018 requires that, among others:

– providing investment advisory services by making use of AI shall be subject to investment advisory licensing requirements;

– non-financial institutions may not engage in asset management businesses in a disguised form by making use of AI;

– when carrying out asset management by making use of AI, financial institutions still need to meet general regulatory requirements in respect of investor suitability, investment scope, information disclosure, and risk segregation; and

– to facilitate regulation over investment activities driven by AI, financial institutions shall report trading parameters and investment portfolio logic of AI model to financial regulators for record, and financial institutions shall also fully disclose to investors of the inherent defects and relevant risks of AI algorithms.

Meanwhile, PRC regulators have been watching over the application of AI and algorithmic trading in the asset management industry. For mutual funds investments, on 25 October 2019, the CSRC issued the Circular on Carrying Out the Pilot Work of Investment Advisory Business for Publicly Offered Securities Investment Funds (《关于做好公开募集证券投资基金投资顾问业务试点工作的通知》, the “Fund Investment Advisory Circular”), launching the pilot program of fund investment advisory business. Entities that have been approved to provide fund investment advisory services under the Fund Investment Advisory Circular include traditional fund management companies, securities companies, commercial banks, and also large internet companies. Among such entities, a mostly reported one is Vanguard Investment Advisors (Shanghai) Investment Consultancy Co., Ltd. (先锋领航投顾(上海)投资咨询有限公司, the “Ant-Vanguard JV”), a joint venture established by Ant Group and Vanguard. The Ant- Vanguard JV has launched its “Helping You to Invest” (帮你投) investment advisory service, which profiles and advises users by making use of AI, big data and cloud calculation.

A most recent development, which has been hotly discussed among China’s securities market participants in 2023, is the use of program trading/algorithm by asset managers. On 1 September 2023, each of the three major PRC stock exchanges issued notices to tighten oversight over program trading. Also on 1 September 2023, the CSRC disclosed on its website that it will further enhance relevant regulatory arrangements, and strengthen differentiated regulation over high-frequency trading.

III. Financial Services of Internet Companies

Internet companies in China overall have quickly caught up with or even overpassed their foreign peers in the aspect of leveraging FinTech to provide financial services, such as online payments, online lending and online distribution of asset management products. In the past around three years, PRC regulators appear to be concerned over the power of large internet companies and taking particular efforts to strengthen regulation over their financial services.

Among such efforts, the most well-known event might be the suspension of Ant Group’s IPO in November 2020. Meanwhile the market discussed whether to view and evaluate Ant Group as a technology company or as a financial institution1. From the PRC regulators’ perspective, the answer appears to be that regulation over financial activities of FinTech companies shall be strengthened. For example, also in November 2020, the CBIRC and the PBOC issued the Interim Measures on Internet Microloan Business Administration (Draft for Consultation) (《网络小额贷款业务管理暂行办法(征求意见稿) 》, the “Microloan Measures”). The Microloan Measures set out restrictions on microloan companies, such as:

– for a joint loan (which in practice may refer to a loan jointly extended by a FinTech company through its microloan company and a commercial bank), the fund contributed by the microloan company may not be less than 30%;

– the outstanding amount of funds obtained via issuing bonds or ABS may not be over 4 times of its net assets.

Such rules, once implemented, might substantially restrict the financial business scale of certain large internet companies which is achieved through the so-called “originate-to-distribute” business model.

A most recent example is the Regulation on Supervision and Administration of Non-Bank Payment Institutions (《非银行支付机构监督管理条例》, the “Non-Bank Payment Regulation”), which was issued on 9 December 2023 and will take effect on 1 May 2024. The Non-Bank Payment Regulation will strengthen regulation over the non-bank payment market as a whole, including payment services of internet companies such as WeChat Pay and Alipay.

More broadly, Chinese authorities appear to be concerned about the overall business risks of large internet companies and their strong presence in various business sectors. Such concern of Chinese authorities might be more serious than regulators in many other jurisdictions, since large Chinese internet companies are equipped with both big data and various financial licenses (lending, payments, credit rating, asset management, etc.). They are active across various types of financial services and have dominant market shares in areas such as online payments, making them more powerful than their foreign counterparties2.

Notably, the business form of large internet companies has been recognized by authorities as “platform economy” (平台经济), which requires coordinated regulation by various authorities. In December 2021, the Several Opinions on Promoting Compliant and Healthy Sustained Development of Platform Economy (《关于推动平台经济规范健康持续发展的若干意见》, the “Platform Economy Opinions”) was issued by nine authorities jointly, including among others the PBOC, the National Development and Reform Commission and the Cyberspace Administration of China. The Platform Economy Opinions provide that all financial

activities must be subject to financial regulation and be carried out by licensed entities. The Platform Economy Opinions also require regulating platform economy from such perspectives as data security, credit information and anti-monopoly. As such, the powerful internet platforms in China might face more stringent regulations in various aspects such as data security, anti-monopoly and anti-unfair-competition.

IV.Cyber Security Law and Data Protection

China has been strengthening regulation over cyber security and data protection in the recent years, with a particular attention to the financial sectors.

In June 2017, the PRC Cyber Security Law (《中华人民共和国网络安全法》, the “CSL”) came into effect. Under the CSL, a critical information infrastructure operator (关键信息基础设施的运营者, “CIIO”) is subject to stringent obligations such as setting up and deploying specialised security management departments and security management responsible persons. Critical information infrastructure (“CII”) is defined under Article 31 of the CSL as information infrastructure in important industries/sectors including, among others, the financial industry, which, if damaged, disrupted or impacted by data breach, may materially impact national interest or public interest.

In particular, the CSL imposes stringent requirements on collection and use of personal information by network operators. When collecting and using personal information, network operators must comply with the principles of legality, justification and necessity, disclose rules for such collection and use, clearly indicate the purposes, methods and scope of information collection and use, and obtain the consent of those from whom the information is collected. Network operators are further subject to specific obligations such as:

– shall not collect personal information that is not related to the services they provide;

– shall not collect or use personal information in violation of applicable laws and regulations and the agreed methods;

– shall not disclose, falsify, or damage collected personal information, shall not disclose personal information to third parties without the consent of the person from whom the information is collected, unless after processing the information the specific person cannot be identified and the information cannot be recovered;

– shall take technical and other necessary measures to ensure the security of personal information and prevent leakage, damage or loss of such information. In the event that personal information has been or may be leaked, damaged or lost, remedial actions shall be taken immediately.

With respect to financial institutions specifically, on 13 February 2020, the PBOC released the Personal Financial Information Protection Technical Specification (《个人金融信息保护技术规范》, the “PBOC PFI Specification”, JR/T 0171—2020), which sets out detailed technical requirements on protection of personal financial information by financial industry institutions (金融业机构) through the process of providing financial products and services within the PRC. Financial industry institutions under the PBOC PFI Specification include, apart from licensed financial institutions, also relevant institutions that are involved in processing personal financial information.

V.RegTech

Regulatory technology (“RegTech”) is sometimes considered a subdivision of FinTech and refers to the use of technologies by financial institutions to more efficiently comply with regulatory compliance requirements. In China, RegTech does not have an official definition, and it appears to also refer to using technology by regulators to enhance regulatory efficiency.

Whilst public information on RegTech developments in China might not be very transparent and detailed, relevant media reports suggest that RegTech has been developing robustly and involves two major types of entities:

– Regulatory authorities: Each of the CSRC and the NFRA has established a Scientific and Technological Regulation Division (科技监管司). Particularly, for the Scientific and Technological Regulation Division under CSRC, its functions as officially announced include, among others, carrying out RegTech research;

– RegTech service providers: According to media reports, there are three types of RegTech service providers, including (1) large internet/FinTech companies, such as Alibaba and Tencent; (2) traditional FinTech companies which expands its business to RegTech, such as Hundsun; (3) specialised RegTech developers.

The advancement of technology enables PRC regulators to enhance their regulatory rules to supervise the market. For example, under the Measures for the Supervision and Administration of Anti-money Laundering and Counter-terrorism Financing of Financial Institutions (《金融机构反洗钱和反恐怖融资监督管理办法》) issued by the PBOC in April 2021, the PBOC expanded the applicable scope of AML and CFT obligations to entities such as internet micro lending companies and consumption finance companies. Other examples include the CBIRC’s regulation on IT outsourcing risks of banking and insurance institutions, and the CSRC’s regulation on IT management of securities and fund institutions.4

VI.Regulatory Trend

The FinTech industry in China has been facing a more stringent regulatory environment compared with the earlier stage of their development. Various regulators have strengthened regulation in aspects such as:

  • prohibiting unlicensed FinTech businesses: In the end of 2022, the CSRC announced that it contemplates requiring Futu and Tiger to cease illegally providing outbound securities investment brokerage services to PRC domestic investors;
  • strengthening cyber security and data protection regulation: PRC regulators issued various new regulations in this field, such as the Measures for Assessment of Data Offshoring Security Assessment ( 《数据出境安全评估办法》) and the Administrative Rules on Internet User Account Information (《互联网用户账号信息管理规定》);
  • enhancing financial consumer protection: New rules issued in this area include, e.g., the Administrative Measures for Protecting Rights and Interests of Consumers of Banking and Insurance Institutions (《银行保险机构消费者权益保护管理办法》).