Chinese Smart Devices Entering the U.S. Market: Key Data-Compliance Issues and Structural Planning
Introduction
Smart devices have become a leading category in the overseas expansion of Chinese companies. Voice interaction, physiological-vitals monitoring, environmental sensing, spatial positioning—these functions define a product’s competitiveness, and they also dictate the categories of data the product touches: communications content, voiceprints, health data, precise geolocation. Almost item for item, these fall within the data categories that U.S. law regulates most densely. Unlike traditional consumer electronics, a smart device’s data collection is embedded deep within the product’s core functionality. Data compliance is therefore no longer a paperwork matter to be cleaned up before launch; it is a structural problem inherent in how the product is defined, how the system is architected, and how the company is organized.
The more profound shift is occurring on the cross-border axis. Since 2025, the Final Rule on sensitive personal data issued by the U.S. Department of Justice under Executive Order 14117—officially the Data Security Program (DSP)—has entered a phase of full enforcement. This rule is not built around notice-and-consent; its logic is national security. It imposes outright prohibitions or restrictions on specified data transactions involving China, and the very arrangements it scrutinizes are precisely the ones Chinese companies most commonly use when expanding abroad: establishing a U.S. subsidiary to handle sales and operations, keeping the research-and-development team in China, and routing collected user data back into China for use. At the same time, China’s own rules on outbound transfer of personal information, geographic-information administration, and technology export controls impose constraints running in the opposite direction—on the repatriation of data and the outbound deployment of algorithms.
For companies expanding into the United States, the center of gravity in data compliance has shifted from the completeness of documents to the lawfulness of the architecture: whether data may be collected, whether it may cross borders, and who may access it—questions that must be settled before the product form and the corporate structure are fixed. This article therefore maps the data-compliance framework for smart devices entering the U.S. market, focusing on two levels: how the various categories of data a device collects are characterized under U.S. law and what liability mechanisms attach to each; and how data flows between a Chinese parent and a U.S. subsidiary should be structured under the DSP.
I. Data Categories Collected by Smart Devices and Their Characterization under U.S. Law
The United States has no unified, comprehensive federal privacy statute. Each category of data processing performed by a smart device must be located separately against federal sector-specific laws, state sector-specific laws, and state comprehensive privacy laws. A single product feature will often trigger multiple regulatory regimes at once. The principal data categories and their corresponding regulation are summarized below.
1. Biometric Information: State Sector-Specific Statutes and the Private Right of Action
Biometrics is the most active field of U.S. privacy class-action litigation, and the reason is the calculability of liability. Take BIPA as an example: before collecting a biometric identifier, a company must provide written notice and obtain written consent; a violator faces statutory damages of $1,000 per violation for negligent conduct and $5,000 per violation for intentional or reckless conduct (each measured as the greater of statutory damages or actual harm), and an individual may sue directly. In Cothron v. White Castle System, Inc., 2023 IL 128004, 216 N.E.3d 918, the Illinois Supreme Court confirmed a per-scan accrual rule, under which potential liability accumulates with each collection. Although a 2024 amendment narrowed repeated collection by the same method to a single recovery, the liability structure—user base multiplied by statutory damages—remains unchanged. The biometric statutes in Texas and Washington create no private right of action, but state attorneys general have grown markedly more aggressive in public enforcement in recent years, and Texas has already secured a large settlement for biometric violations (the 2024 Texas v. Meta facial-recognition matter, settled for $1.4 billion).
For device companies, the decisive factual question is the technical pathway. Plain speech-to-text transcription generally does not constitute biometric processing; but if the transcription relies on voiceprint features to distinguish and label different speakers, that voiceprint template may fall within the definition of a biometric identifier. Whether BIPA is triggered depends on how the algorithm actually handles the data, not on how the product markets the feature. The compliance analysis must begin with a factual investigation of the data flow and the processing logic.
2. Recording Functionality: State Recording-Consent Laws and the Third-Party Consent Problem
The second layer of risk facing devices with recording capability comes from state recording-consent laws. The federal wiretap statute (Electronic Communications Privacy Act of 1986, ECPA) follows a one-party consent rule, but more than ten states—including California, Florida, Illinois, Maryland, Massachusetts, and Washington—apply all-party consent, under which the recording of a confidential communication requires the consent of every party. California’s CIPA also carries a private right of action, with statutory damages of $5,000 per violation or three times actual damages.
What makes the smart-device setting distinctive is this: the consent a user gives through a registration agreement cannot extend to the other party to a communication or to third parties who are present. A device that can be carried on the person and can listen continuously, recording the conversation at the next table in a café, captures speakers who have neither registered an account nor clicked any terms. The third-party consent problem can be solved only through product design: a recording-indicator light, an audible alert, a perceptible physical marking, the recording trigger mechanism (continuous listening versus active wake-word), and the retention period for cached audio—each is a legal question and each is a design decision made at the hardware-definition stage. CIPA litigation targeting recording devices and website session-recording technologies has run high in recent years, and the plaintiffs’ bar keeps newly launched devices under close watch.
3. Health Data: MHMDA and Inferred Health Information
The heart rate, body movement, sleep architecture, and similar vitals data a device collects are, in most cases, not regulated by HIPAA (Health Insurance Portability and Accountability Act)—device manufacturers generally are not covered entities—but they do not sit in a regulatory vacuum. Washington’s MHMDA defines “consumer health data” broadly, sweeping in any information that identifies a consumer and is linked to that consumer’s physical or mental health status, and it expressly covers health status inferred from non-health data. This means that medical information indirectly disclosed through speech transcription or calendar entries, as well as medication reminders, may likewise constitute regulated health data. MHMDA requires a separate consent or necessity basis for the collection, use, and sharing of consumer health data: except where necessary to provide a product or service the consumer has requested, collection and sharing generally require express opt-in consent, sharing requires a further, independent consent, and the statute confers a private right of action. For a device marketed on health management, this law in practice sets the highest baseline for health-data compliance.
4. Children’s Data: COPPA and the Algorithmic-Deletion Remedy
If a device is directed to children under 13, or if the operator has actual knowledge that it has collected children’s data, the verifiable-parental-consent and related obligations under COPPA are triggered. In 2023, an FTC and DOJ enforcement action against a voice-assistant product settled for a $25 million civil penalty, with allegations including the unlawful retention of children’s voice and geolocation data. The remedy in the settlement order is especially noteworthy: beyond deletion of the data, it required deletion of the models and algorithms trained on that data. This pathway shows that a compliance defect at the data-collection stage can travel along the “data–model–product” chain to the algorithmic assets themselves. For companies that iterate their algorithms on user data, this means that core technology assets are equally exposed to data-compliance risk.
II. 28 C.F.R. Part 202: Reaching Data Transactions Between Parent and Subsidiary
28 C.F.R. Part 202 is the final rule issued by the U.S. Department of Justice to implement Executive Order 14117. It took effect on April 8, 2025; the good-faith compliance grace period set by the DOJ expired on July 8 of that year; and the due-diligence, audit, and reporting obligations applied in full beginning October 6 of that year. The rule is now in full enforcement. Its core is to regulate transactions between “U.S. persons” and countries of concern or covered persons that involve government-related data or bulk U.S. sensitive personal data—drawing the line between prohibited and restricted transactions and setting out exemptions, defining the scope of countries of concern and covered persons, establishing volume thresholds for bulk data, and attaching obligations such as license applications, recordkeeping, and reporting.
This rule’s relevance to Chinese smart-device companies can be observed against a typical overseas-expansion arrangement: a U.S. subsidiary is established to handle product sales, app operations, and collections, serving as the operating entity facing U.S. users; the R&D and algorithm team stays at the parent company in China; and the user data collected by the device and app is aggregated by the U.S. subsidiary and sent back into China, where the parent’s engineers retrieve, analyze, and use it to train models. Companies typically regard such an arrangement as an internal division of labor, yet what the DSP evaluates is precisely the “sent back into China” leg. The discussion below addresses, in turn, three questions: which transactions the rule reaches, which entities the rule reaches, and how the data flows in the arrangement above are characterized under the rule.
1. The Structure of the Rule: Prohibited, Restricted, and Exempt
The DSP divides transactions between U.S. persons and countries of concern or covered persons that involve government-related data or bulk U.S. sensitive personal data into two classes. Prohibited transactions may not be carried out at all; the archetype is data brokerage—the sale, licensing of access to, or similar commercial provision of data to a counterparty that did not collect that data directly from the data subjects. Restricted transactions include data-access arrangements under vendor agreements, employment agreements, and investment agreements; they may proceed only after the security requirements issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) are satisfied and the corresponding compliance obligations are performed. The rule also provides a list of exemptions, one of which—the one most closely bearing on the parent-subsidiary relationship—is taken up in Section 5 below.
The regulatory logic of the DSP differs fundamentally from that of state privacy laws. State privacy laws typically turn on notice, choice, sensitive-data consent, purpose limitation, data minimization, and consumer rights; once user consent is obtained, certain applicable statutory limits must still be met. The DSP is transaction control on a national-security dimension: for a transaction that falls into the prohibited class, user consent in any form produces no exempting effect. Technical processing likewise cannot change the characterization—the rule is explicit that data that has been anonymized, pseudonymized, de-identified, or encrypted does not lose its regulated character. The categories of regulated sensitive data include biometric identifiers, precise geolocation, personal health data, human genomic data, personal financial data, and certain combinations of identifiers—categories that overlap heavily with the data a smart device touches.
2. Who Is a “Covered Person,” What Counts as “Access,” and How Much Is “Bulk”
The scope of the covered person determines how deeply the rule penetrates. Under § 202.211, a covered person includes five categories: a foreign entity organized under the laws of a country of concern, with its principal place of business in a country of concern, or 50% or more owned, directly or indirectly, by a country-of-concern government; a foreign entity 50% or more owned, directly or indirectly, by a covered person; an individual primarily resident in a country of concern; an employee or contractor of a country of concern or a covered entity; and any person designated by the DOJ. The countries of concern currently include China (including Hong Kong and Macau), Russia, Iran, and three others.
Measured against the overseas-expansion arrangement described above, the conclusion is plain: a parent company organized under Chinese law is a covered person on the strength of “organized under the laws of a country of concern” alone, with no separate DOJ designation required; an affiliated entity that the parent holds through a third jurisdiction is likewise covered so long as it is 50% or more owned, directly or indirectly; and R&D engineers permanently resident in China, as “individuals primarily resident in a country of concern,” are covered persons as well.
The definition of access is equally broad: logical or physical access to data—including the ability to read, view, or receive the data—constitutes access. An engineer in China logging in remotely to a U.S. database over a VPN to troubleshoot is engaged in access; whether the data is physically transmitted back to a server in China is beside the point.
The bulk threshold is aggregated over a trailing 12-month window, and a single transaction or several transactions in the aggregate that reach the threshold will trigger it. The threshold figures are low for consumer-grade hardware: precise geolocation data on 1,000 U.S. devices, biometric identifiers on 1,000 U.S. persons, personal health data on 10,000 persons, and human genomic data on as few as 100 persons. A smart device’s first shipment can reach the threshold. For consumer-hardware companies, the compliance analysis should proceed on the premise that the bulk threshold has already been met, rather than treating non-attainment of the threshold as a basis for defense.
3. The Inversion of the Obligated Party: The U.S. Subsidiary Bears the Obligations, the Chinese Parent Is the Object of Concern
The obligated party under the rule is the “U.S. person,” which includes U.S. citizens and green-card holders (wherever located), any person located within the United States, and entities organized under U.S. law.
Parent and subsidiary therefore occupy two opposing positions in law: the subsidiary a Chinese company establishes in the United States is the “U.S. person” bearing compliance obligations under the DSP, while its Chinese parent is the “covered person” the rule guards against. When the U.S. subsidiary opens user data to the Chinese parent, the rule sees a restricted data transaction between the two. Companies habitually treat intra-group transactions as the allocation of resources within a single enterprise; that understanding does not hold here. Many companies regard the U.S. subsidiary as a barrier that insulates them from U.S. regulatory risk—under the DSP the position is the opposite, the subsidiary being precisely the entity that directly bears the compliance obligations.
This opposing legal posture extends to the individual level as well. Officers and directors who hold U.S. citizenship or a green card are themselves “U.S. persons,” and the rule prohibits a U.S. person from knowingly directing a prohibited transaction or a non-compliant restricted transaction. A U.S.-citizen executive who approves licensing the U.S. user database to the China-based algorithm team may personally commit a violation of that prohibition. The practice of Chinese-invested companies hiring U.S.-citizen executives to run their North American business is fairly common, and this layer of individual liability warrants a specific flag at the governance level.
4. The Characterization of Three Common Arrangements under the Rule
Arrangement One: the Chinese company operates directly, with no U.S. entity. The app is published under the China-based corporate entity, and both servers and operations are in China. Because the obligated party under the DSP is the U.S. person, a China-based company collecting data directly from U.S. consumers does not itself constitute a regulated transaction under the rule. That does not mean the arrangement is untouched by the rule. First, the U.S. service providers along the business chain (cloud services, ad attribution, data analytics, outsourced customer support) are each bound by the rule as “U.S. persons,” and their cooperative arrangements with the Chinese operating entity that involve data access fall within their own compliance review—a tightening of data interfaces being the natural extension of that obligation. Second, the “knowing direction” prohibition on U.S.-citizen executives described above does not lapse merely because the operating entity is in China. Third, this structure’s exposure under state privacy laws, FTC enforcement, and app-store governance is in no way reduced, and the very fact that “a Chinese entity directly holds U.S. users’ sensitive data” is, in the current regulatory climate, more apt to draw regulatory attention. The direct-operation structure saves on establishment costs, but its regulatory exposure is in fact more concentrated.
Arrangement Two: the U.S. subsidiary operates, and the Chinese parent provides R&D support. This is the most common structure and the focus of DSP analysis. The subsidiary collects data as the operating entity, and the parent carries out algorithm R&D and model training; every data flow between the two must be characterized item by item. The R&D-services arrangement between parent and subsidiary constitutes a vendor agreement under the rule, and the parent’s access to the bulk sensitive data the subsidiary holds, pursuant to that arrangement, is a restricted transaction. Where engineers in China obtain data privileges in the capacity of the subsidiary’s employees or consultants, the matter falls within the employment-agreement dimension and is likewise restricted. If the data flow is arranged as the subsidiary “licensing” or “granting” user data to the parent for its independent use, and it does not fall within a vendor, employment, or investment agreement, it may be characterized as data brokerage and held to be a “prohibited transaction”; if it is genuinely a vendor agreement under R&D services, it is more likely to be treated as a “restricted transaction.” It should also be noted that the rule sets no grandfather clause for existing arrangements—parent-subsidiary data-access arrangements already in place before the effective date fall within the regulation as continuing transactions and must be re-examined rather than carried forward by default.
Arrangement Three: localized isolation. U.S. users’ sensitive data is stored and processed locally in North America, and China-based entities (including personnel) have no access whatsoever, so that a regulated transaction never arises in the first place. The data feedback needed for R&D is replaced by synthetic data, aggregate statistical indicators, or item-by-item-assessed restricted channels. This arrangement offers the highest compliance certainty, at the cost of re-engineering the way R&D is organized: the default workflow in which the China-based team iterates algorithms directly on raw U.S. data must be reworked into a collaboration model in which data stays local and only compliance-processed results cross the border.
5. The Boundary of the Affiliate Exemption: Available for Administrative Matters, Unavailable for R&D Training
Faced with the characterizations above, a common question is whether, since parent and subsidiary belong to the same enterprise, the rule provides an exemption for internal transactions. Section 202.506 does provide a corporate-group-transaction exemption: a transaction between a U.S. person and its parent company, subsidiary, or affiliate located in a country of concern may be exempt if it is an “ordinary, incident-to arrangement of administrative or ancillary business operations.” But the exemption’s scope is narrower than the literal reading suggests. The examples the rule lists are corporate-function matters such as personnel compensation, tax filing, compliance audits, and risk management; official examples draw the line further—intra-group data access for the purpose of providing customer service may be exempt, while opening database access to a China-based affiliate in order to comply with a country-of-concern government’s demand for data is not, because it is not an ordinary, incident-to arrangement of administrative or ancillary matters.
By this standard, providing U.S. users’ voiceprint, geolocation, and vitals data to a Chinese parent for the purpose of product R&D and algorithm training is a core-business data flow, far removed from anything “administrative or ancillary,” and cannot rely on the exemption. The more common misunderstanding in practice is precisely to treat data flows between parent and subsidiary as unregulated internal affairs by default. The foremost scenario the rule guards against is precisely data flowing to a covered person through an affiliate channel.
6. The Compliance Path for Restricted Transactions and Its Limits
In theory, a parent-subsidiary data arrangement that falls into the restricted class may continue if the CISA security requirements are satisfied, but the practical scope for this path is limited. The CISA security requirements operate on two levels: organizational- and system-level requirements (asset inventory, access governance, multi-factor authentication, log retention) and data-level requirements (encryption, minimization, data masking, and privacy-enhancing technologies). Their regulatory purpose is to effectively block a covered person’s access to the regulated data itself. In other words, what the compliance path permits is “access to the system but no contact with the regulated data,” whereas what the typical R&D scenario requires is precisely the raw data itself. There is a structural conflict between the purpose and the path, which means that most access arrangements aimed at training on raw data cannot be maintained in their existing form through this route.
The procedural costs are no lighter. Beginning October 6, 2025, a U.S. person engaged in a restricted transaction must establish a written data-compliance program, perform risk-based verification of data flows and counterparties, complete an annual independent audit, and retain records; a U.S. entity 25% or more owned by a country-of-concern person that engages in a restricted transaction involving cloud-computing services bears an additional annual reporting obligation, and a wholly Chinese-owned or Chinese-controlled U.S. subsidiary meets that ownership threshold. The rule provides a mechanism to apply for a specific license, but the DOJ has signaled a policy of strict construction, and a license should not be assumed as the default premise of a business plan. As to the consequences of a violation, the civil penalty is capped at the greater of more than $360,000 per violation (the base figure is adjusted annually for inflation) or twice the transaction amount; a willful violation may be prosecuted criminally under the International Emergency Economic Powers Act (IEEPA).
In sum, the practical conclusion the DSP delivers to smart-device companies is this: a core-business data flow between parent and subsidiary must either be eliminated through architectural redesign so that it never occurs, or be made to bear the full cost of the restricted-transaction requirements—and to accept the substantive limitation that the China-based team cannot touch the raw data. Neither the affiliate exemption nor user consent can serve as a basis for compliance.
III. The China-Side Rules: Outbound Data, Scene Data, and Technology Export
The other face of cross-border compliance is China’s outbound-transfer controls, and this is especially so for a business model in which both “algorithm and data” go abroad. On the personal-information side, if a device, during its operating phase in China, needs to transfer China-based users’ data abroad—including the easily overlooked scenario of calling an offshore large-model API—it must determine the applicable path among security assessment, standard-contract filing, or certification under Article 38 of the Personal Information Protection Law of the People’s Republic of China and the Provisions on Promoting and Regulating Cross-Border Data Flows; voiceprints, vitals, and movement trajectories are mostly sensitive personal information, and the volume thresholds that trigger outbound-transfer compliance obligations are markedly lower than for ordinary personal information. On the scene-data side, where data collected in real physical environments by embodied-intelligence and similar business models contains geographic-information elements such as geographic coordinates or spatial point clouds, the qualification requirements for collection and outbound transfer must further be assessed against the Surveying and Mapping Law of the People’s Republic of China and the geographic-information security administration rules. On the technology-export side, certain algorithm technologies are listed in the restricted-export portion of the Catalogue of Technologies Prohibited or Restricted from Export by China, and the outbound licensing, transfer, or provision of an algorithm through technical cooperation must first complete export-control screening and licensing procedures.
The resulting picture is this: U.S. law governs data flowing into China, China’s law governs data and technology flowing out of China, and the data channel between the Chinese parent and the U.S. subsidiary sits exactly at the intersection of the two sets of rules. The way to respond is to map fully the data flows inside and outside the parent-subsidiary structure, so that every cross-border data flow either has a clear, two-directional compliance basis or is avoided through architectural arrangement. Data-flow design thus turns from a technical decision into a legal one—and a legal decision that must be made before the system architecture and the parent-subsidiary division of labor are fixed.
IV. The Order of Building a Compliance Program: Facts, Architecture, Documents
Building on the analysis above, U.S.-market data compliance for a smart device is best approached through three ascending levels.
The first is the factual level. The force of every compliance document, privacy policy included, depends on an accurate depiction of the facts of data processing. A company should complete data mapping at the product-definition stage: what is collected, why it is collected, where it resides, who can access it, how long it is retained, and to whom it has been given. Of these, the “who can access it” item must, in the DSP context, be refined down to the privileges of each category of parent and subsidiary personnel and their nationality and residency attributes. Whether voiceprint processing constitutes biometrics, whether geolocation precision reaches the sensitive threshold, and which positions at the parent actually hold U.S.-database privileges are all questions in which factual determination precedes legal determination.
The second is the architectural level. The third-party recording-consent problem is solved through device-side notice mechanisms; DSP compliance is achieved through data localization and access isolation between parent and subsidiary; data minimization is implemented through on-device processing and de-identified uploads. The cost of retrofitting these matters after a product launches is several times the cost of building them in at the design stage, and the legal assessment should proceed in step with product definition and the parent-subsidiary division of labor rather than beginning after the product is fixed. The contractual arrangements with offshore large-model service providers belong to this level as well: voice content, transcribed text, and even geolocation and calendar information all enter the flow of prompts, and the data-processing agreement’s provisions on non-use of service data for training, subprocessor management, cross-border transfer, and security-incident notification must be negotiated at the outset of integration.
The third is the documentary level. The privacy policy, user terms, and app-store privacy labels are built on the facts and architecture of the first two levels; for those engaged in restricted transactions, the written compliance program and audit arrangements under the DSP must be layered on top. A dynamic-review mechanism should also be reserved: U.S. state privacy legislation continues to expand year by year, the DSP’s interpretation and enforcement practice is still taking shape, and China’s outbound rules are continually adjusting between facilitation and security control. Compliance is an ongoing process that keeps pace with product iteration, not something completed upon a single delivery.
V. Conclusion
The practice of taking smart devices abroad is changing the place of data compliance in how a company operates: data collection and processing make up the product functionality itself, and the compliance requirements act directly on the design of the corporate structure and the data flows. The private rights of action and statutory-damages mechanisms under U.S. law in the fields of biometrics, recording consent, and health data make the cost of a violation highly actionable and highly calculable; the DSP, beyond traditional privacy law, adds a national-security dimension that is not exempted by user consent and that directly governs data movement between parent and subsidiary—the U.S. subsidiary is not a barrier insulating against regulatory risk but the entity that directly bears the compliance obligations. For a company planning to enter, or already in, the U.S. market, completing the data-compliance assessment before the product form and corporate structure are fixed is the lowest-cost, highest-certainty path.
This article is for general research and discussion only and does not constitute legal opinion or advice. For legal advice on a specific matter, please consult a qualified professional.
中国智能设备出海美国:数据合规的重点问题与架构安排
引言
智能设备正在成为中国企业出海的主力品类,语音交互、生理体征监测、环境感知、空间定位,这些功能定义了产品的竞争力,也同时决定了产品所涉的数据类别:通信内容、声纹、健康数据、精确地理位置,几乎逐项落在美国法律规制密度最高的数据类别上。与传统消费电子不同,智能设备的数据采集深嵌于产品功能本身。数据合规因此不再是上市前补办的文件事项,而是内生于产品定义、系统架构与公司组织方式的结构性问题。
更深刻的变化发生在跨境维度。自2025年起,美国司法部依据第14117号行政令制定的《敏感个人数据最终规则》(官方称为“数据安全计划”,即Data Security Program,下称DSP)进入全面执法阶段。这部规则不以“告知—同意”为中心,而是以国家安全为逻辑,对涉及中国的特定数据交易直接施加禁止或限制,并且评价的对象恰恰包括中国企业出海最常用的安排:在美国设立子公司负责销售运营,研发团队留在国内,用户数据收集后回传境内使用。与此同时,中国法项下的个人信息出境、地理信息管理与技术出口管制规则,也对数据回流和算法对外部署构成另一个方向的约束。
对出海企业而言,数据合规的重心已从文件的完备性转向架构的合法性:数据能否采集、能否跨境、由谁访问,需要在产品形态与公司架构定型之前作出安排。因此,文章梳理智能设备进入美国市场的数据合规框架,重点讨论两个层面:设备采集的各类数据在美国法下如何定性、对应何种责任机制;以及在DSP之下,中国母公司与美国子公司之间的数据流动应当如何安排。
一、智能设备的数据类别与美国法定性
美国没有统一的联邦综合性隐私立法,智能设备的每一类数据处理活动,需要分别对照联邦专门法、州专门法与州综合性隐私法定位。同一项产品功能,往往同时触发多重规制。主要数据类别与对应规制概况如下:
1. 生物识别信息:州专门立法与私人诉权
生物识别是美国隐私集体诉讼最活跃的领域,原因在于责任的可计算性。以BIPA为例,采集生物识别标识符前须履行书面告知并取得书面同意;违反者,过失情形下每次违规可主张1,000美元法定赔偿,故意或重大过失情形下每次5,000美元(均以法定赔偿与实际损失孰高者为准),个人可直接起诉。伊利诺伊州最高法院在Cothron v. White Castle System, Inc., 2023 IL 128004, 216 N.E.3d 918 案中确认了逐次累积的计算规则,潜在责任随采集次数不断累积。2024年修正案虽将同一方式的重复采集限缩为单次救济,但用户基数乘以法定赔偿额的责任结构并未改变。德州、华盛顿州的生物识别立法不设私人诉权,州总检察长的公共执法近年来明显积极,德州已就生物识别违规取得高额和解(2024年德州总检察长诉Meta人脸识别案,和解金额达14亿美元)。
对设备企业而言,关键的事实问题在于技术路径。单纯的语音转写一般不构成生物识别处理;但如果转写依赖声纹特征对不同说话人作区分标识,该等声纹模板即可能落入生物识别标识符的定义。是否触发BIPA,取决于算法实际如何处理数据,而非产品如何宣传功能。合规分析必须从数据流与处理逻辑的事实核查做起。
2. 录音功能:州录音同意法与第三人同意问题
具备录音功能的设备面临的第二重风险来自州录音同意法。联邦窃听法(Electronic Communications Privacy Act of 1986, ECPA)采用单方同意规则,但加州、佛罗里达州、伊利诺伊州、马里兰州、马萨诸塞州、华盛顿州等十余个州实行全员同意,录制秘密性通信须经各方同意。加州CIPA同时设有私人诉权,每次违规法定赔偿5,000美元或实际损失的三倍。
智能设备场景的特殊性在于:用户通过注册协议作出的同意,无法延及通信相对方与在场第三人。一台可随身携带、可持续拾音的设备在咖啡馆录下邻座对话,被录制者既未注册账户,也未点击任何条款。第三人同意的问题只能依靠产品设计来解决:录音指示灯、提示音、可感知的物理标识、录音触发机制(持续拾音还是主动唤醒)、缓存音频的留存期限,每一项都是法律问题,也都是硬件定义阶段的设计决策。近年来针对录音设备与网站会话记录技术的CIPA诉讼持续高发,原告律师群体对新上市设备保持密切关注。
3. 健康数据:MHMDA与健康推断信息
设备采集的心率、体动、睡眠结构等体征数据,多数情形下不受HIPAA(Health Insurance Portability and Accountability Act)规制(设备厂商通常不构成covered entity),但并非处于规制的真空状态。华盛顿州MHMDA对“消费者健康数据”的界定很宽,凡可识别消费者并与其身心健康状态相关联的信息均在其列,且明确涵盖从非健康数据中推断出的健康状态。这意味着语音转写、日程记录中间接透露的就医信息、用药提醒,同样可能构成受规制的健康数据。MHMDA要求对消费者健康数据的收集、使用和共享建立单独的同意或必要性基础,除为提供消费者请求的产品或服务所必要外,收集和共享通常需要明确的opt-in consent,共享还需另行取得独立同意,并赋予了私人诉权。对以健康管理为卖点的设备而言,这部法律实际上构成健康数据合规的最高基准线。
4. 儿童数据:COPPA与算法删除救济
若设备面向13岁以下儿童,或经营者实际知悉收集了儿童数据,将触发COPPA项下的可核实家长同意等义务。2023年FTC与司法部针对某语音助手产品的执法行动以2,500万美元民事罚款和解,指控包括违规留存儿童语音与定位数据。和解令的救济方式尤其值得注意,除删除数据外,还要求删除据此训练的模型与算法。这一路径表明,数据采集环节的合规瑕疵,会沿着“数据—模型—产品”的链条传导至算法资产本身。对于依靠用户数据迭代算法的企业,这意味着核心技术资产同样暴露在数据合规风险之下。
二、28 C.F.R. Part 202:管到母子公司之间的数据交易
28 C.F.R. Part 202是美国司法部为实施第14117号行政令制定的最终规则,于2025年4月8日生效,司法部设置的善意合规缓冲期同年7月8日届满,尽职调查、审计与报告义务自同年10月6日起全面适用,目前已处于全面执法阶段。规则的主要内容,是对“美国人”与受关注国家或受管辖主体之间、涉及政府相关数据或批量美国敏感个人数据的交易实施管制,划定禁止类与受限制类交易并列明豁免情形,界定受关注国家与受管辖主体的范围,设定批量数据的数量门槛,并配套许可申请、记录保存与报告等义务。
这部规则与中国智能设备企业的关联,可以放在一种典型的出海安排中进行观察:在美国设立子公司,负责产品销售、App运营和收款,作为面向美国用户的经营主体;研发与算法团队留在境内母公司;设备和App收集的用户数据,由美国子公司汇集后回传境内,供母公司工程师调取、分析、训练模型。此类安排通常被企业理解为内部分工,而DSP恰恰评价的是其中“回传境内”的一段。以下将依次讨论规则管什么交易、管到哪些主体、上述安排中的数据流动在规则下如何定性这三大问题。

1. 规则结构:禁止、限制与豁免
DSP将美国人与受关注国家或受管辖主体之间、涉及政府相关数据或批量美国敏感个人数据的交易分为两类。禁止类交易一律不得进行,典型是数据经纪,即向未直接从数据主体处采集该数据的相对方出售、许可或以类似商业方式提供数据。受限制交易包括供应商协议、雇佣协议、投资协议项下的数据访问安排,须满足美国网络安全与基础设施安全局(CISA)发布的安全要求并履行相应合规义务后方可进行。此外规则设有豁免清单,下文第5节专门讨论其中与母子公司关系最密切的一项。
DSP与州隐私法的规制逻辑存在本质差异。州隐私法通常围绕告知、选择权、敏感数据同意、目的限制、数据最小化与消费者权利展开,取得用户同意后,需满足适用的部分法定限制。DSP是国家安全维度的交易管制,对落入禁止类的交易,任何形式的用户同意均不产生豁免效果。技术处理亦不能改变定性:规则明确,数据经匿名化、假名化、去标识化或加密,不改变其受规制属性。受规制的敏感数据类别包括生物识别标识符、精确地理位置、个人健康数据、人类基因组数据、个人金融数据及特定标识符组合,与智能设备所涉的数据类别高度重合。
2. 谁是“受管辖主体”,什么算“访问”,多少算“批量”
受管辖主体(covered person)的范围决定了规则的穿透深度。依规则第202.211条,受管辖主体包括五类:依受关注国家法律设立、主要营业地位于受关注国家或受关注国家政府直接或间接持股50%以上的外国实体;被受管辖主体直接间接持股50%以上的外国实体;主要居住于受关注国家境内的个人;受关注国家或受管辖实体的雇员与承包商;以及司法部指定的任何主体。受关注国家目前包括中国(含香港、澳门)、俄罗斯、伊朗等六国。
对照前述出海安排,结论很明确:依中国法设立的母公司,单凭“依受关注国家法律设立”这一项,即构成受管辖主体,无需司法部另行指定;母公司在第三地控股的关联实体,只要被直接或间接持股50%以上,同样受管辖;常驻中国境内的研发工程师,属于“主要居住于受关注国家的个人”,亦属受管辖主体。
“访问”(access)的定义同样宽泛:对数据的逻辑或物理接触,包括读取、查看、接收数据的能力,均构成访问。境内工程师通过VPN远程登录美国数据库排查问题,即为访问,数据是否物理传输回境内服务器在所不问。
批量门槛按前12个月窗口聚合计算,单笔或多笔交易累计达标即触发。门槛数值对消费级硬件而言很低:精确地理位置数据为1000台美国设备,生物识别标识符为1000名美国人,个人健康数据为10000人,人类基因组数据低至100人。一款智能设备的首批出货即可达到门槛。对消费硬件企业,合规分析应当以批量门槛已经满足为前提,而不是以未达门槛作为抗辩基础。
3. 义务主体的倒置:美国子公司负担义务,中国母公司是防范对象
规则的义务主体是“美国人”,包括美国公民与绿卡持有人(无论身处何地)、位于美国境内的任何人,以及依美国法设立的实体。
母子公司由此在法律上处于两个相反的位置:中国企业在美国设立的子公司,是DSP项下负担合规义务的“美国人”;而它的中国母公司,是规则所防范的“受管辖主体”。美国子公司向中国母公司开放用户数据,在规则眼中即构成两者之间的一笔受限制数据交易。企业惯常将集团内交易视为同一家企业内部的资源调配,这一理解在此并不成立。很多企业把美国子公司理解为隔离美国监管风险的屏障,DSP之下情况恰恰相反,子公司正是直接负担合规义务的主体。
这种相反的法律地位还延伸到个人层面。公司高管、董事中持有美国国籍或绿卡的人员,本人即“美国人”,规则禁止美国人明知地指示禁止类交易或不合规的受限制交易。一位美籍高管批准将美国用户数据库授权给境内算法团队使用,其个人即可能构成对该禁令的违反。中资企业聘用美籍高管管理北美业务的安排相当普遍,这一层个人责任值得在治理层面专门提示。
4. 三种常见安排在规则下的定性
安排一:中国公司直接运营,不设美国实体。App以境内公司主体上架,服务器与运营均在境内。由于DSP的义务主体是美国人,境内公司直接面向美国消费者收集数据,本身并不构成规则项下的受规制交易。但这并不意味着该安排不受规则影响。其一,业务链条上的美国服务商(云服务、广告归因、数据分析、客服外包)各自作为“美国人”受规则拘束,它们与中国运营主体之间涉及数据访问的合作安排,落入其自身的合规审查范围,数据接口收紧是这一义务的自然延伸;其二,前述美籍高管的“明知指示”禁令不因运营主体在境内而失效;其三,该架构在州隐私法、FTC执法及应用商店治理层面的暴露没有任何减少,而“中国主体直接持有美国用户敏感数据”这一事实本身,在当前监管环境下也更容易引起监管关注。直营架构虽然省去了设立成本,监管层面的暴露反而更为集中。
安排二:美国子公司运营,中国母公司提供研发支持。这是最常见的架构,也是DSP分析的重心。子公司作为运营主体收集数据,母公司承担算法研发与模型训练,两者之间的每一条数据流都需要逐项定性。母子公司之间的研发服务安排,构成规则项下的供应商协议,母公司基于该安排访问子公司持有的批量敏感数据,属于受限制交易。境内工程师以子公司雇员或顾问身份取得数据权限的,落入雇佣协议维度,同样受限。如果数据流被安排为子公司向母公司“授权”或“许可”用户数据供其独立使用,且不落入供应商、雇佣或投资协议,则可能被定性为数据经纪并认定为“禁止类交易”;若确属研发服务项下的供应商协议,则更可能按“受限制交易”处理。还应注意,规则没有为既存安排设置不追溯条款,生效前已经存在的母子公司数据访问安排,作为持续性交易同样落入规制,需要重新检视而非默认延续。
安排三:本地化隔离。美国用户敏感数据在北美本地存储与处理,境内主体(包括人员)不具备任何访问权限,受规制交易自始不发生。研发所需的数据反馈,以合成数据、聚合统计指标或经逐项评估的受限通道替代。这一安排的合规确定性最高,代价是研发组织方式的重构:境内团队直接使用美国原始数据迭代算法的默认工作流,必须改造为数据留在当地、只有合规处理后的结果跨境流动的协作模式。

5. 关联公司豁免的边界:行政事务可用,研发训练不可用
面对上述定性,常见的疑问是:母子公司同属一家企业,规则是否设有内部交易的豁免。规则第202.506条确实规定了公司集团交易豁免:美国人与其位于受关注国家的母公司、子公司或关联方之间的交易,如属“行政性或辅助性经营事项的通常附随安排”,可以豁免。但该豁免的适用范围较字面理解的更窄。规则列举的适例是人事薪酬、税务申报、合规审计、风险管理等公司职能性事务;官方示例进一步划界,集团内为提供客户服务而发生的数据访问可以豁免,而为配合受关注国家政府调取数据而向境内关联方开放数据库访问的,因不属于行政辅助事项的通常附随安排,不得豁免。
照此标准,以产品研发、算法训练为目的将美国用户的声纹、定位、体征数据提供给中国母公司,属于核心业务数据流,与“行政性或辅助性”相去甚远,不能依赖该豁免。实务中较常见的误解,正是把母子公司之间的数据流动默认为不受规制的内部事务。规则防范的首要场景,恰恰是数据经由关联公司通道流向受管辖主体。
6. 受限制交易的合规路径及其局限
理论上,落入受限制交易的母子公司数据安排,可以通过满足CISA安全要求继续进行,但该路径的实际适用空间有限。CISA安全要求分为两个层面:组织与系统级要求(资产清单、访问治理、多因素认证、日志留存),以及数据级要求(加密、最小化、数据遮蔽及隐私增强技术)。其规范目的是有效阻断受管辖主体对受规制数据本身的接触。换言之,合规路径允许的是“访问系统但接触不到受规制数据”,而典型研发场景需要的恰恰是原始数据本身。目的与路径之间存在结构性冲突,这决定了多数以原始数据训练为目的的访问安排,无法通过该路径维持原状。
程序成本同样不轻。自2025年10月6日起,从事受限制交易的美国人须建立书面数据合规计划、执行基于风险的数据流与交易对手核验、完成年度独立审计并留存记录;受关注国家主体持股25%以上的美国实体,从事涉及云计算服务的受限制交易的,另负年度报告义务,中资全资或控股的美国子公司均满足该持股标准。规则设有特定许可的申请机制,但司法部已释放从严把握的政策信号,许可不宜作为商业计划的默认假设。违规的后果方面,民事处罚上限为每次违规逾36万美元(基准额按通胀逐年调整)或交易金额的两倍,以较高者为准;故意违反可依《国际紧急经济权力法》(International Emergency Economic Powers Act) 追究刑事责任。
归纳起来,DSP给智能设备企业的实务结论是:母子公司之间的核心业务数据流,要么通过架构改造使其不发生,要么按受限制交易的全套要求支付合规成本,并接受境内团队接触不到原始数据的实质限制。以关联公司豁免或用户同意作为合规基础,均难以成立。
三、中国侧规则:数据出境、场景数据与技术出口
跨境合规的另一面是中国法上的出境管制,对“算法+数据”双出海的业态尤其如此。个人信息出境方面,设备在境内运营阶段如需将境内用户数据传输出境,包括调用境外大模型API这一容易被忽略的场景,应依照《中华人民共和国个人信息保护法》第三十八条及《促进和规范数据跨境流动规定》确定适用安全评估、标准合同备案或认证路径;声纹、体征、行踪轨迹多属敏感个人信息,触发出境合规义务的数量门槛显著低于一般个人信息。场景数据方面,具身智能等业态在真实物理环境中采集的数据如包含地理坐标、空间点云等地理信息要素,还需对照《中华人民共和国测绘法》及地理信息安全管理规定评估采集与出境的资质要求。技术出口方面,部分算法技术列入《中国禁止出口限制出口技术目录》限制出口部分,算法对外许可、转让或以技术合作形式向境外提供的,应事先完成出口管制筛查与许可程序。
由此形成的格局是:美国法管的是数据流入中国,中国法管的是数据与技术流出中国,中国母公司与美国子公司之间的数据通道,恰好处在两套规则的交汇点上。应对思路在于完整梳理母子公司内外的数据流向,使每一条跨境数据流要么具备明确的双向合规依据,要么通过架构安排避免发生。数据流向设计因此从技术决策变成法律决策,而且是需要在系统架构与母子公司分工定型之前完成的法律决策。

四、合规体系的搭建顺序:事实、架构、文件
基于前述分析,智能设备的美国市场数据合规宜按三个层次递进。
首先是事实层面。包括隐私政策在内的全部合规文件,效力取决于对数据处理事实的准确刻画。企业应在产品定义阶段完成数据映射:采集什么、为何采集、存在哪里、谁能访问、留存多久、给了谁。其中“谁能访问”一项,在DSP语境下需要细化到母子公司每一类人员的权限及其国籍、居住地属性。声纹处理是否构成生物识别、定位精度是否达到敏感标准、母公司哪些岗位实际持有美国数据库权限,都是事实判断先于法律判断的问题。
其次是架构层面。第三人录音的同意问题靠设备端告知机制解决,DSP合规靠数据本地化与母子公司之间的访问隔离实现,数据最小化靠端侧处理、脱敏上传落地。这些问题在产品上市后的改造成本,数倍于设计阶段的嵌入成本,法律评估应当与产品定义、母子公司分工同步进行,而不是在产品定型之后才开始。与境外大模型服务商的合同安排同属此层:语音内容、转写文本乃至定位与日程信息都会进入提示词流转,数据处理协议中关于服务数据不用于训练、子处理者管理、跨境传输与安全事件通知的约定,需要在接入之初谈定。
最后是文件层面。隐私政策、用户条款、应用商店隐私标签,建立在前两层的事实与架构之上;从事受限制交易的,还需叠加DSP项下的书面合规计划与审计安排。同时应预留动态复核机制:美国州隐私立法仍在逐年扩张,DSP的解释与执法实践处于形成期,中国出境规则在便利化与安全管控之间持续调整,合规是与产品迭代同节奏的持续过程,非一次交付即告完成。
五、结语
智能设备的出海实践正在改变数据合规在企业经营中的位置:数据采集与处理构成产品功能本身,合规要求则直接作用于公司架构与数据流向的设计。美国法下生物识别、录音同意、健康数据领域的私人诉权与法定赔偿机制,使违规成本具有高度的可诉性与可计算性;DSP则在传统隐私法之外增加了一个不因用户同意而豁免、直接约束母子公司数据往来的国家安全维度,美国子公司不是隔离监管风险的屏障,而是直接负担合规义务的主体。对计划进入或已经进入美国市场的企业而言,在产品形态与公司架构定型之前完成数据合规评估,是成本最低、确定性最高的路径。
本文仅为一般性研究探讨,不构成任何法律意见或建议。如需就具体事项获取法律意见,请咨询专业人士。