Biomedical enterprises listing in Hong Kong: Data compliance has become a "must-answer" question for regulation.
Recently, the Hong Kong capital market has demonstrated strong financing vitality. Against the backdrop of the continuous growth of domestic enterprises going public in Hong Kong, biopharmaceutical companies are facing increasingly strict data compliance reviews due to the special nature of their business - the entire chain of research and development, clinical trials, registration, and commercialization deeply involves core sensitive data such as clinical trial data, patient personal information, and human genetic resources.
In 2025, the China Securities Regulatory Commission issued feedback opinions to 337 enterprises on overseas listing, with pharmaceutical companies accounting for 15% of the total. Currently, most mainland enterprises that successfully listed in Hong Kong have disclosed data compliance information to varying degrees in their prospectuses, and the biopharmaceutical and healthcare industries are among the most heavily disclosed areas. Thus, it can be seen that as capital activity increases, data compliance reviews have become increasingly strict. For biopharmaceutical companies, data compliance has shifted from being an "addition" to a "must-answer question".
1. Why is data compliance a core focus for listing on the Hong Kong stock market?
Biopharmaceutical companies involve highly sensitive data types at every stage: clinical trial data, patient personal health information, medical imaging data, human genetic resources information, etc. Once these data are leaked or improperly used, they can easily lead to the infringement of natural persons' dignity or personal property safety, which falls under the definition of "sensitive personal information" under the Personal Information Protection Law, and requires higher compliance requirements such as "explicit consent" and "impact assessment". At the same time, enterprises involving the collection and export of human genetic resources information must strictly comply with the compliance requirements of the "Regulations on the Management of Human Genetic Resources" and international cooperation approval/registration. For enterprises with business involving artificial intelligence drug research, they also need to pay attention to the obligations under the "Interim Measures for the Administration of Generative Artificial Intelligence Services", such as algorithm filing and security assessment.
In practice, both the overseas listing review by the China Securities Regulatory Commission and the inquiries by the Hong Kong Stock Exchange and the regulatory authorities have regarded data compliance as a key review subject. In recent years, the Hong Kong review authorities have used key laws and regulations such as the "Cybersecurity Review Measures" and the "Cyber Data Security Management Regulations" as the basis, requiring enterprises to assess and demonstrate from multiple dimensions such as applicability, whether the conditions trigger, whether it involves national security, and the overall compliance status and compliance capabilities, as well as future compliance commitments. The significant improvement in regulatory granularity has raised higher requirements for the depth of enterprises' compliance and the quality of their arguments.
2. Analysis of the core concerns of the regulatory feedback
In the overseas listing review process of pharmaceutical enterprises, the China Securities Regulatory Commission raised feedback opinions on data compliance issues for several enterprises. By reviewing the feedback opinions, it can be found that the regulatory review focus mainly lies in the following four aspects:
(1) Compliance of data collection and use
Over 80% of enterprises were asked about the data compliance situation of their websites, apps, mini-programs, and public accounts. This is one of the most frequently occurring issues in regulatory feedback. The regulatory focus is on whether the enterprise has developed and operated related products, whether it involves collecting and using personal information, and the scale of collected and used user information and data usage.
Typical inquiries include: Mindray Medical (2026) was required to explain "the situation of developing and operating APPs, mini-programs, public accounts, etc., whether it involves collecting and using personal information"; Anxiuyuan (2025) was required to explain "whether it involves developing, operating websites, mini-programs, APPs, public accounts, etc., whether it involves providing information content to third parties"; Da Yi Group (2025) was asked "whether it involves developing and operating APPs, mini-programs, public accounts, etc., whether it involves collecting and using personal information"; (II) Data Export Compliance Issues
As data export regulations become stricter, the proportion of inquiries regarding related issues has significantly increased. The regulatory focus is on whether enterprises have transmitted data to overseas entities or provided personal information to third parties, and whether they comply with relevant laws and regulations on personal data export.
Typical inquiries include: Fengjiang Management (2026) was required to explain "whether there is information provision to third parties, and whether it involves information data export and external provision"; Changfeng Pharmaceutical (2025) was asked "whether there is data transmission to overseas markets or personal information provision during the development of candidate products in markets such as the United States and Europe"; Zhuozheng Medical (2024) was required to explain "whether it involves providing personal data information of domestic individual users to third parties or to overseas entities, and whether it complies with relevant laws and regulations on personal data export".
(III) Data Protection Measures Before and After Listing
Most enterprises were required to explain the arrangements or measures for information data protection before and after listing. The regulatory aim is to confirm whether the enterprises have the ability to ensure continuous compliance and data security after listing and financing.
Typical inquiries include: Baiqiu Shangmei (2026) was required to "explain the arrangements or measures for personal information protection and data security before and after listing"; Kangzhe Pharmaceutical (2025) was required to "explain the arrangements or measures for personal information protection and data security before and after listing"; Baize Medical (2024) was required to "explain the arrangements or measures for domestic personal information protection and data security before and after listing"; Jiali Biotech (2023) was required to "explain the arrangements or measures for information data protection before and after listing".
(IV) Compliance Management of Special Data Types
Some enterprises have received targeted inquiries due to the involvement of special data types. Biomedical enterprises, in particular, have focused on the management of human genetic resources. The regulatory authorities are no longer satisfied with enterprises providing a conclusive opinion of "having obtained administrative permission", but are conducting substantive reviews to determine whether foreign entities have illegally utilized China's human genetic resources for scientific research or have provided data/samples to overseas entities without fulfilling the filing procedures.
Typical inquiries include: Hua昊 Zhongtian (2024) was required to explain "the situation of the company and its subsidiaries' possession, collection, and storage of human genetic resources, and whether corresponding control and compliance measures have been taken"; Pagel Bio (2024) was required to explain "the types, scale, sources, and usage of data information collected and stored during the research process".
In addition, as AI technology is increasingly applied in the field of drug research and development, biomedical enterprises involving AI have been explicitly asked about the implementation of the "Interim Measures for the Management of Generative Artificial Intelligence Services", and algorithm filing and security assessment have become one of the substantive entry conditions for overseas listings in specific industries.
Typical inquiries include: Lvmi Lianchuang (2026) was asked "whether the company's business involves AI large models and other artificial intelligence fields, and if so, whether it complies with the provisions of the 'Interim Measures for the Management of Generative Artificial Intelligence Services'"; Baiqiu Shangmei (2026) was required to explain "whether the company's business involves AI large models and other artificial intelligence fields, and whether it complies with the 'Interim Measures for the Management of Generative Artificial Intelligence Services'".
III. Unique Challenges for Biomedical Enterprises: When Industry Characteristics Encounter Regulatory Red Lines
From the four feedback dimensions mentioned above, it can be seen that the regulatory authorities' review of biopharmaceutical enterprises is not a "one-size-fits-all" general inquiry, but precisely targets the specific data risks unique to the industry. When the four review frameworks - compliance of data sources, compliance of data export, protection measures before and after listing, and management of special data types - meet the business nature of biopharmaceutical enterprises, which deeply rely on clinical trial data, human genetic resources, and patient personal information, the following three unique challenges emerge:
(1) The paradox of data cross-border in multi-center clinical trials
The research activities of biopharmaceutical enterprises inherently have a transnational attribute - to accelerate the launch of new drugs, multi-center clinical trials are often conducted simultaneously in China, the United States, Europe, etc. Clinical data needs to be circulated among domestic sponsors, CROs, and research centers. However, a large amount of health and medical big data is likely to be classified as "important data", and is generally required to be stored domestically. The "Regulations on the Management of Human Genetic Resources" sets strict approval thresholds for the export of information involving Chinese human genetic resources; the "Personal Information Protection Law" requires multiple preconditions such as separate consent, security assessment, standard contract or certification for the cross-border provision of sensitive personal information. The efficiency and global layout of clinical trials require data flow, while the regulatory framework takes the principle of "restricting flow and strict approval" as the basic rule. If enterprises fail to clarify their data flow before listing and complete the establishment of an exit compliance path, they are likely to encounter data compliance risks.
(2) The challenge of handling sensitive personal information in clinical trials
Compared to other industries, biopharmaceutical enterprises handle personal information in clinical trials with a high degree of particularity: the medical records, test results, genetic information, imaging materials, etc. of the subjects all belong to "sensitive personal information" as defined by the "Personal Information Protection Law". The handling of such information requires obtaining the "separate consent" of the subjects, conducting an impact assessment on personal information protection, and taking more stringent protection measures.
However, in practice, the signing of informed consent forms is often carried out by research institutions or CROs, and enterprises lack direct control over whether the notification to the subjects is sufficient and whether the consent is "separate and clear"; at the same time, the preservation rights and responsibilities of source documents for clinical trials (such as hospital medical records, laboratory records) are stipulated in the contract between the research institution and the sponsor, and the compliance management of enterprises in terms of data storage period, access rights, etc. is extremely difficult.
(3) The "high-voltage line" of human genetic resources management
Human genetic resources information is an important strategic resource of our country, and its collection, preservation, utilization, and external provision are strictly regulated by the "Regulations on the Management of Human Genetic Resources" and its supporting rules. For biopharmaceutical enterprises, as long as it involves genetic testing, biological sample analysis, or genetic information research with the population of our country as the object, it may fall within the regulatory scope. Especially when enterprises have foreign capital components (commonly seen in VIE structures), the violation of collection or export may more likely touch the red line of "prohibiting foreign organizations and their controlling institutions from collecting, preserving human genetic resources within China".
In this field, regulation has shifted from "formal review" to "substantive penetration". In the feedback from companies such as Huayao Zhongtian and Pai Ge Biology, the regulatory authorities require explanations of "the situation and control measures of human genetic resources that the enterprise masters, collects, and preserves", and the underlying logic is that if the research pipeline of the enterprise heavily relies on genetic resource data of the Chinese population but fails to establish a standardized internal management system, it will not only face administrative penalty risks, but also may undermine the business legitimacy foundation of the listing entity.
V. Compliance Response Framework under the Dual Regulatory Landscape
After understanding these challenges, enterprises also need to face the "dual regulatory landscape" formed by the Hong Kong Stock Exchange and the China Securities Regulatory Commission. Regarding the Hong Kong Stock Exchange, they are more concerned about whether the data compliance risks are adequately disclosed in the prospectus, as well as whether the enterprises possess the "continuous compliance" institutional capabilities - this is reflected in their repeated inquiries about the information and data protection measures before and after listing. On the other hand, the China Securities Regulatory Commission focuses on verifying whether the enterprises' data activities during their historical operations comply with the substantive requirements of domestic regulations, especially in dimensions such as digital product operation, data export, and human genetic resources management, and conducting item-by-item verification.
Therefore, enterprises need to "explain the past clearly" - making complete and accurate disclosures and arguments regarding their past data processing activities; and also "manage the future well" - establishing sound data security management systems, organizational structures, and emergency response plans to ensure that they can continue to meet regulatory requirements after listing.
Therefore, enterprises need to establish a compliance system: including a clearly defined data security officer and management institution, data classification and grading system, operational procedures for impact assessment of personal information protection, records of data export security assessment or standard contract filing, and user exercise response mechanisms, etc.
V. The Value of Professional Services: Full-chain Support from Risk Identification to Regulatory Clearance
Facing the aforementioned challenges and dual regulatory pressure, biopharmaceutical enterprises no longer need single-point legal consultation, but a full-chain professional support covering "pre-event screening - mid-event rectification - post-event response". Based on practical experience assisting multiple enterprises in successfully listing in Hong Kong, we believe that the following service modules constitute the core closed loop of data compliance escort:
The first step: Precise assessment of business models and data flow characteristics. Each biopharmaceutical enterprise has different R&D pipelines, trial designs, CRO cooperation models, and data flows. Professional teams need to deeply analyze the specific business scenarios of the enterprises - which clinical trials involve multi-country data flow? Which studies involve the collection of human genetic resources? Which apps and mini-programs collect patient data? The "data map" drawn based on this is the cornerstone of all subsequent compliance work.
The second step: Conduct data compliance due diligence. Conduct a comprehensive "check-up" of the enterprise's data processing activities: data types and scales, storage locations and retention periods, transmission methods and third-party sharing situations, fulfillment of informed consent and notification obligations, etc., and form detailed compliance records.
The third step: Conduct compliance gap analysis and promote implementation of rectification. Compare with the item-by-item requirements of laws such as the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, the Regulations on Human Genetic Resources Management, and the Network Data Security Management Regulations, identify gaps, formulate rectification plans, and assist the enterprises in establishing systems, optimizing processes, and deploying technologies to ensure that the rectification results are verifiable and traceable.
The fourth step: Issue a data compliance legal opinion. Provide professional legal endorsement for the disclosure in the prospectus, covering aspects such as cybersecurity level protection, data classification and grading, personal information protection mechanisms, human genetic resources management, and data export compliance, presenting the full picture of the enterprise's data compliance to the regulatory authorities.
The fifth step: Assist in responding to regulatory inquiries from both China Securities Regulatory Commission and Hong Kong Stock Exchange. Whether it is the filing feedback from the China Securities Regulatory Commission or the supplementary inquiries from the Hong Kong Stock Exchange, it can be based on solid due diligence records and rectification results to accurately respond to regulatory concerns.
VI. Forward-looking Layout: Compliance is not only the "knock-on brick" for listing, but also the "moat" for business
For biopharmaceutical enterprises planning to list in Hong Kong, the significance of data compliance goes beyond the superficial goal of "meeting the review requirements". From the trend, the feedback questions from the China Securities Regulatory Commission are moving from general inquiries to scenario-based and data-driven in-depth verification - if enterprises have established a complete compliance system before listing, they can not only significantly shorten the inquiry cycle, reduce listing uncertainty, but also gain the trust of counterparties in future international cooperation transactions by virtue of standardized data governance.
Conversely, if compliance is regarded as a phased task "to meet audits", it is possible that one may encounter repeated inquiries during the filing stage, and even the listing window may be missed due to historical violations (such as data security penalties). Data compliance rectification involves system design, technical deployment, process reengineering and personnel training, and it is by no means a task that can be accomplished in a short period of time. It is essential to initiate the compliance planning as early as possible and integrate professional legal support into every key node of product development, clinical trial design and listing preparation. Only in this way can one move steadily and far in the competition for capital markets - making compliance truly become an "addition" to the enterprise's value, rather than just a "required answer" for regulatory reviews.
Attachment: Summary Table of Regulatory Queries for Hong Kong Stock Market Listed Companies in Recent Years
