← Back to BZ filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
A. History and Development of the Company
We commenced operations by setting up Beijing Huapin Borui Network Technology Co., Ltd., which we refer to as the VIE, in December 2013. Our holding company, KANZHUN LIMITED, was incorporated in January 2014 to facilitate offshore financing.
In February 2014, KANZHUN LIMITED established a wholly owned subsidiary in Hong Kong, Techfish Limited. In May 2014, Techfish Limited established a wholly owned subsidiary in the Chinese mainland, Beijing Glorywolf Co., Ltd. In May 2014, we entered into a series of contractual arrangements with the VIE and its sole shareholder then to direct the activities of the VIE. The contractual arrangements with the VIE were subsequently replaced and superseded by updated agreements mainly as a result of change in the VIE’s shareholders from December 2014 through September 2022. In January 2024, the contractual arrangements were replaced by new contractual arrangements entered into among the VIE, its shareholders and another Techfish Limited’s wholly owned subsidiary in the Chinese mainland, Beijing Highland Wolf Technology Co., Ltd., through which our interests in the VIE remain unchanged.
In July 2014, we launched our “BOSS Zhipin” app.
In June 2021, we listed our ADSs on the Nasdaq Global Select Market under the symbol “BZ.”
In December 2022, our Class A ordinary shares commenced trading on the Main Board of the Hong Kong Stock Exchange under the stock code “2076.”
In July 2025, we completed a share offer of an aggregate of 34,500,000 Class A ordinary shares at an offer price of HK$66.00 per share (equivalent to approximately US$16.82 per ADS at an exchange rate of HK$7.8499 to US$1.00), comprising a Hong Kong public offering of 10,350,000 shares and an international offering of 24,150,000 shares. Net proceeds from this share offer, after deducting underwriting commissions and other offering expenses, were approximately HK$2.2 billion.
Our principal executive offices are located at 21/F, GrandyVic Building, Taiyanggong Middle Road, Chaoyang District, Beijing 100028, People’s Republic of China. Our telephone number at this address is + 86 10 8462 8340. Our registered office in the Cayman Islands is located at the offices of Maples Corporate Services Limited at PO Box 309, Ugland House, Grand Cayman, KY1-1104, Cayman Islands. Our agent for service of process in the United States is Cogency Global Inc., located at 122 East 42nd Street, 18th Floor, New York, NY 10168.
The SEC maintains an internet site that contains reports, proxy and information statements, and other information regarding issuers that file electronically with the SEC on www.sec.gov. You can also find information on our website https://ir.zhipin.com. The information contained on our website or available through our website is not incorporated by reference into and should not be considered a part of this annual report.
B. Business Overview
We are the leading online recruitment platform in China, reinventing how job seekers and enterprises connect and engage. As the go-to job seeking and recruiting platform in China, we provide job seekers with curated opportunities that open clear career pathways, and enable efficient, data-informed recruiting decisions for enterprises through streamlined talent sourcing, faster time-to-fill and greater hiring precision. Our average MAU grew from 42.3 million in 2023 to 53.0 million in 2024 and to 60.7 million in 2025. In 2025, our platform generated an average of 6.7 billion chat messages every month.
Our platform attracts a diverse and expanding pool of job seekers, including white- and gold-collar, blue-collar and college students. White- and gold-collar job seekers are typically professionals and skilled workers pursuing office-based or managerial roles, with a strong focus on career growth, skill enhancement and leadership opportunities. Blue-collar job seekers, which represent a growing segment, typically pursue roles in labor-intensive industries, where they value salary, welfare and proximity to work locations. College students often look for entry-level roles or internships with an eye on gaining experience and starting their careers. As of December 31, 2025, we served 252.6 million verified job seekers, with white- and gold-collar users, blue-collar job seekers and college students comprising 47.2%, 37.3% and 15.5% respectively, of our job seeker user base.
69
Table of Contents
We serve a broad spectrum of enterprise users, ranging from small businesses to large corporations across industries and geographic regions. A major constituent of our user base consists of Bosses (executives and middle-level managers from businesses of all sizes, as well as small business owners) who are the key decision-makers in hiring. Additionally, we support recruiting professionals such as human resource officers, headhunters and hiring specialists who rely on our platform to streamline their hiring processes. Our platform serves enterprises of all sizes, including all 2025 Fortune China 500 companies, as well as tens of millions of small businesses, with 89.4% of our verified enterprises employing fewer than 100 employees as of December 31, 2025. As of December 31, 2025, we served 36.8 million verified enterprise users and 20.3 million verified enterprises, with 62.5% of our verified enterprise users being Bosses. We recorded paid enterprise customers of 5.2 million in 2023, 6.1 million in 2024 and 6.8 million in 2025.
Built on a mobile-native foundation, our platform harnesses AI and big data to scale matching accuracy, hiring efficiency and engagement quality to new levels. At the heart of our platform is a powerful engine that processes massive static and dynamic data of daily interactions, including candidate and job post views, chat initiation, mutual consent and interview feedback, and transforms these fine-grained behavioral and structural signals into actionable insights on recruitment demand, talent mobility and preference. Our data intelligence is powered by a hybrid framework that combines two-way recommendations, deep learning algorithms, natural language processing, our proprietary large language model, Nanbeige and third-party foundation models to deliver precise, real-time job recommendations across professional, skilled worker and college student roles. We are also developing a suite of AI applications and tools to further optimize the candidate screening and communication process and reduce time-to-hire, advancing toward a results-driven recruitment ecosystem.
Our Platform
We connect job seekers and enterprise users in an efficient manner, mainly through a mobile-native, double-sided online recruitment platform that facilitates direct engagement between job seekers and enterprise users and delivers accurate matching results. Our data-powered experience for job seekers and enterprise users is built around four core innovations that drive engagement and generate measurable impact throughout the process:
● From web portal to tailored mobile platform. We were among the first to launch an online recruitment platform entirely based on a mobile application. The concept of creating a mobile-native recruitment platform is the foundation of our innovative business model that enables intelligent recommendation and two-way interactive communication and continues to shape key aspects of our offerings and user experience. Today, our platform has developed into a highly tailored platform where both job seekers and recruiters can manage their unique user profile on their own terms and with greater clarity. The level of adaptation deepens user engagement, increases time spent on our platform and fosters more meaningful interactions responsive to real-world needs and behaviors.
● From keyword search to dynamic, multimodal, and AI-curated recommendation. Our intelligent recommendation system acts as a “career assistant” evolving with each interaction. Rather than relying on keyword-based matching, our system taps into multi-dimensional features such as career development stages, skill trajectory and interaction history, to deliver intent-driven, high-fidelity job and candidate matches. AI-curated job recommendations connect the right candidates to the right jobs with growing accuracy over time. Our platform adapts to shifting user intent, filters out noise and keeps both job seekers and enterprises closely aligned with evolving opportunities.
● From one-way application to rich, real-time communication. Our direct-chat system enables job seekers and enterprise users to have real-time communication through text, voice and image, with features like read receipts and AI-facilitated quick-reply to reduce friction. Direct chatting allows users with real demands to stay active for job opportunities or candidates, and users can confirm each other’s intentions and their suitability before the interview, which makes their experience highly informative and efficient. Meanwhile, we are dedicated to protecting the job seekers’ privacy. Enterprise users are not allowed to access job seekers’ full resume or their contact information without job seekers’ consent.
● From fragmented data to insightful workforce intelligence. We translate vast volumes of raw interaction data into strategic insights across the recruitment and job-seeking chain. By analyzing how users engage and communicate, we build nuanced profiles that reflect both immediate intent and long-term potential. Our algorithms support ongoing talent development, candidate screening and workforce planning.
70
Table of Contents
Our platform accelerates growth through a self-reinforcing flywheel driven by the powerful interplay of user and data momentum.
● User momentum. The user flywheel is propelled by an exceptional user experience and a high density of opportunities. As more job seekers flock to our platform, enterprises seeking top talent follow, leading to an increase in quality job postings. A broader and more diverse job offering, as well as enhanced user engagement, can in turn improve job seeker satisfaction and expand the talent pool.
● Data momentum. The data flywheel focuses on the continuous accumulation and utilization of valuable user data. Every interaction, no matter from job seekers refining their profiles or enterprises posting jobs and reviewing candidates, adds to our vast data ecosystem. This data feeds algorithms, which in turn enhances matching accuracy and recommendation precision. As more data flows through our platform, our technology becomes increasingly sophisticated, creating even more relevant and accurate job and candidate matches.
These network effects compound into a virtuous cycle: better data drives smarter algorithms, which improve user experience and attract more users to accelerate scale. Our differentiated approach to blue- and white-collar segments further strengthens platform dynamics: blue-collar job seekers, with high-frequency job seeking activity, help meet core labor demand, while white-collar users contribute higher-value interactions, creating cross-segment synergies that power overall platform growth.
Our Services
Our offerings are designed to improve job hunting for job seekers and recruitment efficiency for enterprise users to elevate their experience. For job seekers, we provide job seeking services that allow job seekers to receive job recommendations, initiate direct chats and deliver resumes upon mutual consent. We also provide value-added tools that help them better prepare for their job hunt. For enterprise users, we provide direct recruitment services that allow enterprise users to post jobs, receive personalized candidate recommendations, engage in direct communication and receive resumes upon mutual consent. We also offer an expanding range of value-added tools to further enhance recruitment efficiency.
We provide online recruitment services through our main mobile app BOSS Zhipin (BOSS 直聘). BOSS Zhipin is a mobile app serving a wide range of job seekers and enterprises across industries and geographic regions. Its signature feature, “direct chat” between job seekers and enterprise users, enables both sides to quickly identify job-and-candidate fit.
Technology-driven Job Search and Hiring Experience
We deliver a job search and hiring experience through technology-driven interactions that lower barriers for users across a wide spectrum ranging from tech-savvy professionals to first-time mobile users in traditional industries, making it easy for them to navigate our platform quickly and intuitively. We integrate AI and big data analytics throughout the user journey, helping both job seekers and enterprise users access opportunities faster, make better decisions and act with less effort.
71
Table of Contents
● Informative and interactive user page. To start the journey on our platform, job seekers are required to provide basic personal and professional information, to create a mini resume which can be viewed by interested enterprise users. To help job seekers improve their profiles, we offer AI-powered resume polishing and personal information optimization tools that automatically highlight strengths and increase exposure to potential enterprise users. Meanwhile, enterprise users can set up their own accounts and provide background information about their company as well as reasons job seekers should consider joining.
● Matching the right person to the right role. Our typical user experience begins from the main feed where users scroll through curated job posts or candidate through our proprietary algorithms and machine learning technologies. We utilize vast amounts of data and machine learning to build and refine our proprietary algorithms that enable customized job recommendation for our users at a massive scale which makes it possible for us to serve a diverse user base on one platform. In addition to the recommendations, we leverage AI to further enhance job search and candidate matching accuracy. Through chat-based prompts, we gain a deeper understanding of users’ unique, personalized requirements—eliminating the need to rely solely on keywords or tags. Furthermore, AI provides explanations for its recommendations, ensuring transparency and better alignment with user needs.
● Direct communication facilitating user engagement. After reviewing job seeker’s profiles, enterprise users can initiate direct conversations with job seekers to tell them more about their companies or a specific opportunity. Similarly, job seekers can also reach out to enterprise users to express their interests in a role. Messaging is available through text and voice messages, emojis and images, which gives users a low-pressure, mobile-native way to connect and interact. Our instant messaging function ensures that users are active with real job hunting or recruiting needs and at the same time offers convenience and flexibility to users, which is especially beneficial to Bosses and blue-collar job seekers who are unable to make a major time commitment for recruitment and job-hunting activities.
● Resume delivery based on mutual consent. We firmly believe that recruiting is a two-way street. We are committed to transforming the recruiting process by empowering job seekers and giving them more say. We put job seekers back to the pilot seat by giving them more control in the job hunting process. Different from the traditional models where enterprises can directly purchase job seekers’ full resumes, enterprise users on our platforms can only see a job seeker’s mini resume that contains limited information. Enterprise users are not allowed to access job seekers’ full resume or their contact information without job seekers’ express consents. Enterprise users are thus motivated to engage in meaningful conversations with job seekers to confirm mutual interest before inviting them to deliver resumes. For example, to attract quality job seekers and gain access to their resumes, enterprise users may need to proactively reach out to these job seekers, demonstrate benefits of the job and answer their questions. Similarly, job seekers cannot submit their resumes to an enterprise user without the enterprise user’s consent. This function also showcases our commitment to safeguard job seeker’s information and protect their privacy.
Our personalized matching and connection features combined with effective communication between job seekers and enterprise, promote an efficient and results-driven job-hunting and recruiting experience.
Our offerings enable us to build a large and diverse user base coverage across white- and gold-collar users, blue-collar users and college students, and at the same time serve a full spectrum of enterprise users, large and small, in numerous industries and from diverse geographical areas. The breadth and depth of our user engagement have generated strong network effects that continue to reinforce the value of the platform.
Our Monetization Model
We provide recruitment and job hunting services to both enterprise users and job seekers and generate most of our revenue from paid services offered to enterprise users.
● For enterprise users, we offer direct recruitment services that allow them to post jobs and communicate with job seekers, which can be free or paid based on an innovative connection-oriented monetization strategy, supplemented by paid value-added tools to further enhance their recruitment efficiency as part of our overall recruitment services to the enterprise users.
72
Table of Contents
● Job seekers are able to communicate with enterprise users and apply for jobs free of charge. To improve job-matching results, we offer paid value-added services, such as resume exposure booster, competitive candidate analysis and AI interview training, to help job seekers improve visibility, better prepare for their job hunt and assess their candidacy. Job seekers pay directly for these tools based on feature selection and duration.
Our Technology
We have architected a vertically specialized infrastructure purpose-built to decode the complexity of double-sided recommendation and AI application. Grounded in deep research, platform-native behavioral and static datasets and adaptive models, our architecture is structured across three interlocking layers: foundation algorithms, data and scenario-based applications. This full-stack system is engineered to surface subtle, often hard-to-label hiring signals, structure them into actionable insights, deliver real-time recommendations at scale, and evolve continuously through placement and engagement feedback.
Algorithm Layer: Domain-Trained Industry Leading Recommendation and AI Models
Our algorithmic layer is designed to optimize not a single output, but a portfolio of competing goals encompassing long-term candidate satisfaction, enterprise user speed-to-hire and platform engagement. We apply advanced model to process, analyze and identify patterns in data and build models to analyze on job and candidate preferences of job seekers and enterprise users. This is especially useful considering the diverse, high-dimensional data we collect from our large and diverse user base. In 2024, we launched the Nanbeige Model, our vertically trained large language model built specifically for hiring use cases. Nanbeige powers core workflows across our platform, including search and recommendation, AI-facilitated communications and interviews. In February 2026, it once ranked first among HuggingFace’s trending text models.
Leveraging these data and technologies, we developed a more accurate portrait of each individual user and are able to understand user preferences to predict the likelihood of a successful job and candidate match indicated by the offering and acceptance of an interview invitation. This effectively addresses each individual’s different job or recruitment needs and their inability to identify suitable job positions due to information asymmetry and inexperience in job switching activities.
Data Layer: Granular, Live and Role-Aware Insights
We have the capability to gather massive multidimensional data in granular details, which helps capture the unique traits of each job seeker and enterprise user. This is made possible through customized and accurate job/candidate recommendation based on a multitude of factors, including, for example, career development goals, occupation inclination, job position preferences of job seekers and the recruiting needs of enterprises.
We have a large, granular and fast-growing dataset containing multidimensional behavioral and static information of job seekers and enterprise users. Each job seeker has a mini resume containing their basic information, which matches the information contained in each job post. The information in each mini-resume and job post forms our static user information database. We also capture how each user interacts with others and the content on its platform in granular detail, which contributes to valuable behavioral data insights. Our models process these behavioral data instantly and provide users with refined matching results.
Our strength in data technology is also characterized by our multi-label classification of data. Our data analytics technology takes into hundreds of elements of user features, which are growing over time and continue to optimize the algorithm model. For a single algorithm model, the more elements of data are collected and labeled, the more features that are included in the algorithm’s “decision-making” process, and the more efficiently and effectively the matching results can be delivered.
Application Layer: Embedded Intelligence Across the Hiring Funnel
Successful applications of our strong theoretical foundation and advanced technologies ensure accurate job and candidate matchings that are tailored to each individual’s preferences and account for bilateral compatibilities and suitability within user groups.
73
Table of Contents
We apply advanced algorithms to the recommendation system to reflect our key strategies, including (i) double-sided matching strategy: our recommendation algorithms consider not only the best recommendation to an individual, but also bilateral compatibilities and the suitability of the match within the user group, which result in a fairer distribution of the platform’s traffic; and (ii) personalized recommendation strategy: we make customized recommendations for users of different user groups, taking into account multiple factors, including the stages of career development, potential suitable positions not thought of by the job seeker but would match his/her skill set and the job seeker’s future career development opportunities. For example, we offer job recommendations to job seekers not only limited to positions based on their past employment history but also potential opportunities they may consider for their career development.
Innovation Layer: AI-Powered Integration Across Technology, Recommendation, Services and Products
Leveraging our self-developed Nanbeige model and third party models, we have made progress in comprehensively advancing the application and implementation of AI across all areas, including operations, management, recommendation technology, and user products.
With respect to the recommendation, we combined advanced large language models with its massive proprietary data to improve recommendation efficiency and matching accuracy. With respect to the product, the platform provided all job seekers with free tools such as AI job seeking assistant and AI interview coaching to enhance their job seeking experience and user engagement.
At the same time, AI capabilities were fully integrated into the commercialization products for enterprise users, and various AI recruitment functions were in different stages of application, gray-scale testing or exploration, and have received positive feedback from users. At the same time, we are actively leveraging AI capabilities in our existing products and services, such as bulk job seeking intention delivery and intent connect, and exploring the use of AI to expand into new business areas, such as closed-loop services.
Our team
Our technological capabilities are a unique advantage and critical to our business operations. As of December 31, 2025, we had a team of 1,131 research and development personnel dedicated to technology, data and related functions. Our research and development team is fully involved in all critical operational areas, with an in-depth understanding of our users’ needs.
Service innovation and excellence lie at the heart of our business. We also gather creative ideas from all of our teams, including service development team, sales team and big data and algorithm team who best understand user behavior and demand. Our massive user base and efficient product iteration process ensure our effective exploration of new possibilities and drive constant development of our services.
Sales and Marketing
We empower our sales team with our proprietary customer relationship management, or CRM system, by helping them identify employers with demand and a willingness to engage in bulk purchases or pay for more specialized services, which enables our sales team to effectively engage these enterprises. Our CRM system allows sales team to target high-potential customers more effectively and apply our data-driven strategies that improve conversion rates.
We pay to acquire user traffic from online third-party channels, mainly including app stores, search engines, info feeds and social networking platforms. We also benefit from organic traffic through word-of-mouth and brand recognition. We believe brand recognition is critical to our ability to continue to attract new users. To promote our brand image, we have launched various marketing initiatives, including outdoor advertising, TV advertising, video advertising, and marketing campaigns in major national and international events.
Vigorous User Verification & AI Powered Risk Assessment
We have implemented “platform user safety protection” program, which focuses on protecting our users’ interests. We emphasize the importance of ensuring the information presented on our platform is verified and authentic. We use a screening and monitoring system to examine and verify the authenticity of the job postings and leverage our advanced technology to detect and respond to threats and frauds incessantly. Our screening and monitoring system consists of user onboarding verification, continuous risk monitoring supported by our proprietary suite of risk identification models and offline risk assessment. Additionally, we adopt a comprehensive suite of procedures to verify the identity of job seekers. Authentic enterprises, enterprise users and job postings facilitate information transparency, enhance our service quality, cultivate trust inside our platform and strengthen our user stickiness.
74
Table of Contents
Enterprise users’ risk assessment
We implement a rigorous screening process to examine and verify the enterprise users’ identification information. To register an account with us, enterprise users are required to provide identification information and complete real name authentication and identify themselves with an enterprise. For enterprise users of a company that first joins our platform, we verify the identity and assess the risk of both the enterprise and the enterprise users. We require the company to go through a set of verification procedures during their onboarding process, including the uploading of the company’s business license and certificates of employment, which include, for example, business email, business address of the enterprise, and business address of the enterprise users to verify the relationship between the enterprise and the enterprise users. We also customize enterprise users’ registration policy based on our risk pre-determination mechanism. We require enterprises in high-risk industries, identified by the number of user complaints received or the number of misconducts within the industry, to provide additional materials, to go through additional steps to complete the verification process when such enterprise first joins our platform. For example, we require them to provide additional materials, including industry service licenses, video of their office environment or conduct an in-person meeting with our offline risk assessment team.
For enterprise users that identify themselves as employees of enterprises that have already been verified by us, we generally require the enterprise user to go through the same onboarding procedure. For enterprises with a large number of users, we also designate specific personnel within the enterprise to help us verify the identity information of new enterprise users that identify themselves as employees of the enterprise. Such enterprise users are generally not required to go through additional verification procedures designed for enterprises in high-risk industries as such verification process has already been completed when the company first joins our platform. We also constantly monitor enterprises who have been denied access to our platform to prevent them from potential future misconduct.
We leverage our advanced, AI-powered feature engineering, machine learning and decision engine to process user data and respond to threats and frauds. Relying on our advanced algorithms, we have built a proprietary suite of models to detect enterprise users’ misconduct and identify and continuously track high-risk job positions and employers. Our proprietary suite of risk identification models factor in multidimensional user information, including static and behavioral data gathered by our risk mining algorithms. Static data gathered includes business scope of an enterprise, its industry qualifications, registered address, records of illegal or unfaithful conduct, whether the enterprise is in good standing and other enterprise specific information. Behavioral data gathered includes user complaints and feedback and enterprise users’ engagement behavior with our platform and other users, such as the number of mini resumes viewed and chat messages sent by an enterprise user in a given period. Our risk mining algorithms process a wide spectrum of data features of enterprise users to assess and weigh individual factors about the trustworthiness of enterprise users. We track high risk behaviors such as false advertising, pyramid selling and private information extortion. We also take job seeker complaints into our data-driven risk assessment process. Job seekers play an important role in our comprehensive risk assessment network through reporting suspicious activities or false information in the company’s description or job postings. After we identify inappropriate behavior conducted by enterprise users whom we deem to pose high risks to our platform, we assign our offline team to conduct manual risk assessment. For example, we visit enterprises that are reported by users for providing fraudulent information and enterprises that we identify as of higher risks based on videos of their office environment.
Our dedicated offline risk assessment team visit employers in person to make sure the information presented on our platform is authentic and up-to-date. In particular, they verify the consistency of the employers’ business locations and enterprise users’ work locations. Our algorithms powered risk assessment system together with our offline verification efforts are necessary to manage the complexity of analysis at the scale and speed that is needed in light of our massive user base and the changing fraud landscape. We established the industry’s first integrated online and offline employer information verification system that adopts a combination of intelligent screening and security verification and on-site visit to verify enterprise information. The vigorous screening enables the provision of reliable job and employer information and addresses the misinformation that is prevalent in the online recruitment market, especially for blue-collar recruitment. After we discover misconduct of enterprise users, regardless of whether it took place on or outside of our platform, or identify false information, we take corresponding actions to address the issues identified, such as banning, blocking user accounts, requiring enterprises to provide additional verification materials, or prohibiting the information of the company and its enterprise users from being accessed by job seekers. For enterprise users suspected of serious misconduct or criminal activities, we report the case to local police department for further investigation. Our streamlined authentication process and ongoing risk assessment system foster a trustworthy and credible user platform. Before each onsite visit, we comprehensively assess the risk of the target company to ensure efficient offline verification of identified issues, which enables us to achieve high verification and risk assessment efficiency.
75
Table of Contents
Job seekers’ risk assessment
Job seekers are first required to complete our mobile phone verification process which requires users to register with their mobile phone numbers and provide the verification code we message to their phones for verification purpose. Our intelligence system detects suspicious user inputs that may undermine the integrity of our platform and will require those users to go through additional authentication procedures. For example, job seekers providing mobile numbers that are recorded in the phone number blacklist or using advertising language in their descriptions would be detected by our fraud prevention technology.
Data Privacy and Security
Data security is crucial to our business operations as it is the foundation of our competitive advantages. We have internal rules and policies that govern how we may collect and process data, as well as protocols, technologies and systems in place to ensure that data will not be accessed or disclosed improperly.
Data collection
For user information, our user privacy policies clearly describe our data collection, use, share and process practices and how users can exercise their rights in activities relating to the process of personal information. In particular, we provide users with prior notice and obtain their consent as to what data is being collected and undertake to manage and use the data collected in accordance with applicable laws before they use our services. Users can also change their privacy settings to change the scope of their information that we are able to access and use.
The types of user data we collect, store and use generally include: (i) user’s basic information, such as mobile phone number, name, gender, work experience related information; (ii) user’s identity information (most of them are enterprise users); (iii) user’s process information; and (iv) device feature information. The scope of usage is consistent with that being disclosed in privacy policies and does not exceed the scope authorized by users. The data is collected and used mainly for the purposes of user registration, identity authentication, online recruitment, personalized recommendation, content publishing, and user safety.
Data storage and information management
We back-up our user data and other forms of data on a daily basis in secured remote data back-up systems located in the Chinese mainland. We also conduct frequent reviews of our back-up systems to ensure that they function properly and are well maintained. We regularly conduct system-wise vulnerability scanning and prompt repairing to continually improve our data security measures. Our security system is capable of handling malicious attacks to safeguard the security of our platform and to protect the privacy of our users. We have also started using proprietary private cloud located in the Chinese mainland and maintained in-house to reduce the reliance on third-party cloud infrastructure provider, which allows us to better safeguard user data and address regulatory and compliance concerns.
To ensure the confidentiality and integrity of our data, we maintain a comprehensive and rigorous data security program. We de-identify and encrypt sensitive personal information and take other technological measures to ensure the secure storage, processing, transmission and usage of data. Specifically, we store business data in separate repositories and have detailed logical isolation and network policy segregation for business servers. Sensitive personal information is stored in encrypted form and sensitive information is de-identified and encrypted irreversibly before processing. To ensure the security of data transmission, we have adopted reasonable and feasible security measures in line with market standards to protect user information from unauthorized access, public disclosure, use, modification, damage or loss. For example, the exchange of data between the browser and the server is protected by SSL protocol encryption. We also provide HTTPS protocol for secure browsing on BOSS Zhipin website and for the transmission of sensitive information. In addition, we use trusted protection mechanism to prevent malicious attacks on user’s personal information. We have also formulated data destruction strategy and policy to standardize our data destruction procedures and adopted differentiated data deletion measures for different levels of data. We respond immediately once user submits account cancellation request, the cancelation process shall be completed if the cancellation requirements are met. Our deletion of data is automatically executed by system scripts, and we keep log records of the deletion operation. We store user personal information for the minimum amount of time necessary to process such data and delete user personal information or anonymize them in a timely manner after the purpose of processing such data has been achieved or as otherwise provided by laws and regulations.
76
Table of Contents
We have also established a standardized information management system. Our information security committee is a cross-disciplinary group comprised of personnel from multiple departments responsible for devising information security strategies and decision making regarding major information security issues. Our information security committee analyses industry trends, designs privacy protection protocols, conducts privacy trainings, assists in the formulation of feasible compliance work assessments and provides risk control suggestions. We have also set up a data security team that works closely with other departments to jointly establish and enforce procedures regarding the management of data security, including security with respect to data collection, storage and processing. Our compliance and legal teams will follow up with legal and regulatory updates to generate documented analysis for implementation of remedial measures with reference to compliance requirements.
Data access and sharing
All of our personnel are required to strictly follow our detailed internal rules, policies and protocols to ensure the privacy of our data. Our employees are granted access to the minimum extent that is necessary to fulfill their job responsibilities and within strictly defined and layered access authority, and are required to go through strict authorization and authentication procedures and policies before operating. At application level, we use privacy components to set up different approval processes based on data classification. Our online database is accessible only by database administrator with temporary password. R&D personnel are generally not permitted to access the database, if access is required on as-need basis, strict multi-level approval must be obtained. User personal information in the big data platform is desensitized and irreversibly encrypted. Even with authorized access, virtual desktops must be used to prevent from direct downloading of user privacy data to local devices. We also maintain data access logs and conduct automated assessment and routine manual verification. In addition, we conduct routine internal audit regarding the authority to access user data in order to ensure our authorizations are strictly followed. We provide regular trainings to our staff on internal policies and procedures for data security, on software technical skills to prevent data leakage, on cybersecurity and data protection related laws and regulations, and on other aspects that are relevant to their day-to-day work.
We do not share our user data with third parties, except for the limited purposes and under the following circumstances set forth in our strict privacy policies: (i) data sharing with affiliated platforms to facilitate user login and account management, and prevent fraud and minimize security risks; and (ii) data sharing with suppliers and business partners that provide certain services such as technical support, which are necessary for us to provide services to our users. Pursuant to our policies, we only grant authorization to third-party business partners to access our user data for legitimate, necessary, specific and clearly defined purposes. We have established internal policies for engaging with and managing suppliers and partners. We enter into security agreements with suppliers of network products and services, conduct regular audits to verify their compliance with obligations under these agreements, and perform additional data security capability assessments for those involved in data interchange to ensure continued alignment with our business security requirements.
Data breach and security incident management
We have established a comprehensive system to prevent and detect potential data breach risk, cyber threats, and other system vulnerabilities. We have adopted targeted, professional level security measures in different scenarios, such as network security, host security, application security, and data management, in response to different security risks. The network security protection measures include anti-DDOS attack platform, application firewall, network firewall, and threat intelligence analysis system. The host security protection measures include host security scanning, host security protection system, and anti-virus system. The application security protection measures include component scanning system, vulnerability scanning system, and code white box audit system. The data security protection measures include data classification and grading system, data leakage prevention system, and webpage watermarking. We have set up dedicated post for detecting data theft and leakage, which will be continuingly tested, followed up and rectified by dedicated security personnel. We use scanning tools to identify data or network defects/vulnerabilities on as-need basis and the defects/vulnerabilities identified will be followed up by dedicated personnel.
77
Table of Contents
For security incident management, emergency response plan and emergency drills, we have put in place security incident management procedures and response processes (emergency plan), which are improved each year to ensure day-to-day information security management and maintenance. We have developed contingency plans and response mechanisms to have different types and levels of security properly addressed within each stage from discovery, handling, closure, post-event tracking, investigation, correction, to evidence collection. We have established an emergency response team, and the handling of security incident will be documented and archived by the technology security center. We conduct major emergency drill once a year and the technical perform drills from time to time.
Security testing and assessment
Our business systems have received and maintained valid cybersecurity and information authentication. In June 2025, the VIE received ISO/IEC 27001 certification for its information security management system, confirming that its practices meet internationally recognized standards. In August 2025, BOSS Zhipin and Dianzhang Zhipin both passed their annual Level 3 cybersecurity classified protection assessments. Additionally, in 2025, we renewed our Personal Information Protection Certification from the China Cybersecurity Review Technology and Certification Center (CCRC) and maintained compliance with GB/T 35273-2020, the national standard for personal information security. These efforts reflect our ongoing commitment to keeping data protection policies and technical safeguards current and compliant. We have engaged a number of third-party security service providers to conduct security evaluation of our security systems, apps, and IT architecture, and cooperated with third-party testing and evaluation service providers to resolve issues identified.
In addition to third-party testing and assessments, we also conduct self-inspections and data security self-assessments. Since 2021 we have conducted annual data security assessment, and performed personal information security impact assessment. We use proprietary scanning tools, including component and vulnerability scanning systems, to generate data security assessment reports on a regular basis. Issues identified in the reports are closely analyzed and dealt with by our data security team.
Seasonality
Our quarterly operating results fluctuate due to seasonal patterns in recruitment demand and macroeconomic and labor market conditions. For example, traditionally, in the first quarters, recruitment activities generally slow down before the Chinese New Year. Our quarterly sales and marketing expenses are also generally the highest in the first quarter of every year as we increase our sales and branding activities during the Chinese New Year season. However, we have observed growing variability in these patterns as broader economic factors increasingly influence hiring cycles. Overall, the historical seasonality of our business has been relatively mild, but the seasonal trends that we have experienced in the past may not be indicative of our future operating results. See also “Item 3. Key Information—D. Risk Factors—Risks Relating to Our Business and Industry—Our results of operations are subject to fluctuations due to seasonality.”
Intellectual Properties
We regard our trademarks, copyrights, patents, domain names, know-how, proprietary technologies and similar intellectual property as critical to our success. As of December 31, 2025, we owned 360 patents including 164 inventive patents, 291 copyrights including 234 software programs, and 42 registered domain names in the Chinese mainland relating to various aspects of our operations and maintained approximately 1,189 trademark registrations in the Chinese mainland and 31 trademark registrations outside the Chinese mainland.
We seek to protect our technology and intellectual property rights through a combination of patent, copyright and trademark laws, as well as license agreements and other contractual protections. In addition, we enter into confidentiality and non-disclosure agreements with our employees, which require that all patents, software, inventions, developments, works of authorship and trade secrets created in connection with and during the course of their employment are our property.
78
Table of Contents
Competition
As a leading player in the online recruitment industry, we face competition from providers of similar services. Other online recruitment platforms compete directly with us for users, including both job seekers and enterprise users. We compete to attract, engage and retain users, to provide more accurate job and candidate matching and to improve and expand our product and service offerings in general. Our competitors may compete with us in a variety of ways, including by leveraging a large user base to engage more job seekers or enterprise users, investing in technologies to improve job and candidate matching efficiencies, conducting brand promotions and other marketing activities, and making acquisitions.
We believe that we can compete effectively with our competitors on the basis of our large and active user base, extensive high quality user data, advanced technological capabilities, high-quality user experience, ability to enhance efficiency and user satisfaction, as well as our brand recognition. For a discussion of risks relating to competition, see “Item 3. Key Information—D. Risk Factors—Risks Relating to Our Business and Industry—We face significant competition in China’s dynamic online recruitment service market, potential market entries by established players from other industries and new technology-driven startups may further intensify competition. Our market share, financial condition and results of operations may be materially and adversely affected if we are unable to compete effectively.”
Our Environment, Social and Governance (ESG) Initiatives
Our focus on corporate social responsibilities, environmental awareness, long-term sustainable development, and ethical conduct is core to our values. We believe our continued growth depends on our integration of ESG values into our corporate strategies and operations.
In April 2026, we released our 2025 ESG report, detailing our ESG achievements in 2025 and progress toward our longstanding ESG goals and commitments. The report provides additional transparency to our stakeholders, as well as details on our sustainability practices, social responsibility and corporate governance framework. Through the information disclosed in the report, we underscored our core strategies, including standardize corporate governance, product and service optimization, develop together with employees, practice green development, build a sustainable supply chain and deliver community care, which are the foundation of our ESG commitments. The information contained in our 2025 ESG report is not incorporated by reference into and should not be considered a part of this annual report.
Environmental and Social Initiatives
We are committed to bringing about positive changes to society, and we believe our long-standing commitment to social responsibility strengthens our brand reputation.
As a leading recruitment platform, we are dedicated to assisting disadvantaged groups with inclusive and tailored job seeking and recruiting services. Leveraging what we are best at, we have mainly centered our efforts in the recruitment industry:
● During the 2025 fall recruitment season, we hosted the Spirited Recruitment Festival. With the aim of providing greater “certainty” and “possibilities,” the event featured three online sections—Quick Q&A for Job Seekers, Resume Clinic, and Case Solutions—including 18 regional and industry-specific campus recruitment sessions, cumulatively offering hundreds of thousands of campus recruitment positions. During the 2025 spring recruitment season, we launched the “2025 Spirited Spring Recruitment Festival.” The platform brought together over 200,000 enterprises from various industries and regions across the country, offering millions of quality positions for fresh graduates. Themed recruitment events were organized, covering topics such as direct applications to state-owned and central enterprises, internet industry campus recruitment, internships in the Yangtze River Delta region, and internship opportunities for liberal arts students. The spring recruitment festival precisely reached over 6 million student users.
79
Table of Contents
● In July 2025, we organized the “Aspirations Reach Far—Youth Public Welfare Career Experience Camp”, which supported 100 teachers and students from Yunnan, Chongqing, Shanxi, and other regions to visit Shanghai. The activities centered around career enlightenment, technological exploration, and city experience. The teachers and students visited universities such as Shanghai Jiao Tong University, entered corporate R&D laboratories, and transformed scientific principles into practical experience through drone aerial photography, robot battles, precision instrument assembly, and documentary filming. This event broadened the horizons of young people, inspired their growth confidence and career aspirations, and was selected as a project funded by Shanghai’s counterpart support and cooperation exchange special funds, receiving government recognition and support.
● In December 2025, the International Day of Persons with Disabilities, our Company, in collaboration with the Employment Service Platform of the China Disabled Persons’ Federation, hosted a live-streamed job fair titled “Building Dreams in the Workplace·Moving Forward Without Barriers—2025 Online Recruitment Fair for College Students with Disabilities.” During the livestream, hosts provided detailed introductions to popular disability-friendly positions, while experts from the China Disabled Persons’ Federation offered in-depth interpretations of employment policies for persons with disabilities and provided career guidance. The livestream lasted approximately one and a half hours, featuring 254 positions from 229 enterprises, and attracted nearly 9,000 viewers and job applications.
Our efforts to empower local communities go beyond the recruitment industry.
● In 2025, we launched the “Ruyili” home-based elderly care service station initiative. Adopting a model that involves “government leadership, corporate funding, community operation, and collaboration between professionals and volunteers,” this initiative provides one-stop services such as “micro-day care, meal assistance, and health care” for elderly individuals living alone, those with severe disabilities, and those who are disabled in the community. The initiative also incorporates elements of traditional Chinese medicine for health preservation and art therapy, serving a cumulative total of over 5,000 individuals. This activity effectively addresses the gap in home-based elderly care services, establishes a “home-based health and wellness” pathway for high-density aging communities, and provides a replicable practical solution for megacities to cope with profound aging.
● In 2025, we institutionalized our “Warmth-to-Community” Welfare Initiative, aligned with traditional festivals such as the Spring Festival and Mid-Autumn Festival, and extended its support to the central and western regions through collaboration and counterpart assistance. By procuring local agricultural specialties as relief supplies, we directly benefited farmers through the “purchase instead of donation” approach, creating an integrated social impact model that combines welfare delivery with consumption-based poverty alleviation. By the end of the reporting period, the cumulative investment reached RMB 435 thousand, covering 2,000 households and providing practical care for vulnerable groups in the community.
● In 2025, we carried out disaster relief in 10 counties and cities across 6 provinces (autonomous regions) including Xizang, Guizhou, Beijing, Gansu, Hunan, Hebei, and Guangxi. It donated a total around RMB 4 million to areas affected by major natural disasters such as earthquakes and floods, effectively supporting emergency rescue, post-disaster reconstruction, and the restoration of people’s livelihood, and providing tangible assistance to local post-disaster recovery and the reestablishment of daily life order.
● In November 2025, a devastating fire broke out at Wang Fuk Court in Tai Po, New Territories, Hong Kong. Following the announcement of the “Tai Po Wang Fuk Court Relief Fund” by the Special Administrative Region government, we promptly responded by donating HK$3 million to the fund. This donation was specifically earmarked for emergency relief, transitional housing, and post-disaster reconstruction for the affected residents. Through this practical action, we stand united with the people of Hong Kong, helping them through this difficult time.
80
Table of Contents
We deeply value ecological preservation.
● In March and August 2025, we conducted two rounds of special ecological protection initiatives in the Indochinese gray langur habitat in Shidian County, Yunnan Province, and the Lanping Yunling Provincial Nature Reserve. Through actions such as constructing wildlife water stations points and laying water pipelines, we effectively ensured the drinking water safety of over 260 monkeys, significantly alleviating the pressure of water competition caused by seasonal drought. Additionally, we simultaneously launched a series of online and offline public welfare advocacy campaigns. These efforts not only garnered coverage of the drinking water situation of the Yunnan snub-nosed monkey by multiple CCTV platforms but also involved collaborations with numerous artists and bloggers. The related themed videos have garnered over 2.13 million views, and the total topic views has reached 160 million, effectively enhancing public awareness and concern for the survival status of the monkey population.
● In 2025, we carried out public welfare activities supporting the materials of frontline protection stations around three major event themes: “Guardian Season”, “Nest Building Season”, and “Life Tree Collaboration”. During the “Guardian Season”, we donated emergency supplies to the Zhuonai Lake Protection Station in Kekexili, Qinghai, to safeguard the migration route of Tibetan antelopes. In the “Nest Building Season” event, we built shelters to protect against the cold and equipped rangers in Bamei Village, Deqin County, Yunnan, improving their field work conditions. In the “Life Tree Collaboration” event, we donated kitchen equipment to five protection stations in Kekexili, effectively ensuring the logistical operation of the protection stations. We promoted this series of activities both online and offline, with topic views exceeding 62 million and theme videos and other content being played over 4.7 million times across the internet.
● In November 2025, we initiated the “Antelope Oasis Project” event, providing overwintering support for the endangered Przewalski’s gazelle by donating 25 tons of winter forage and 9 sets of intelligent monitoring equipment to relevant protected areas. The campaign not only ensured the basic survival needs of the Przewalski’s gazelle but also enhanced the scientific management level of conservation efforts. The campaign achieved over 82 million topic views and more than 1.2 million interactions.
Green Operation
We measured our greenhouse gas (“GHG”) emissions using the GHG Protocol Corporate Accounting and Reporting Standard developed by the World Resources Institute and the World Business Council for Sustainable Development.
Set forth below is a summary of key metrics we established to evaluate and guide our sustainable business operations.
For the
Year Ended
December 31, 2025(7)
Total GHG emission (1)(2) (Scopes 1 and 2) (Tons of CO2e) 2,345.84
GHG emission intensity(1)(2) (Scopes 1 and 2) (Tons of CO2e/person) 0.53
Total energy consumption(3) (MWh) 4,123.86
Energy consumption intensity(3) (MWh/person) 0.92
Total water consumption(4) (m3 ) 56,402.48
Water consumption intensity(4) (m3 /person) 12.63
Hazardous waste generated intensity(5) (Tons/person) 0.00004
Non-hazardous waste generated intensity(6) (Tons/person) 0.12
Notes:
(1) Due to the nature of the business, our material air emissions are GHG emissions arising from purchased electricity. The carbon footprint mainly includes leased offices that operate in China’s mainland.
(2) Our greenhouse gas inventory mainly includes carbon dioxide. Greenhouse gas accounting is presented in carbon dioxide equivalent, calculated based on the 2022 Electricity Carbon Dioxide Emission Factors published by the Ministry of Ecology and Environment and the National Bureau of Statistics of the People’s Republic of China.
(3) Total energy consumption is calculated based upon the data of purchased electricity.
(4) Water supply mainly comes from the municipal water supply, and there is no issue in sourcing water. Water consumption for certain branches was calculated with reference to the 2024 China Water Resources Bulletin.
81
Table of Contents
(5) The hazardous waste generated in our office building primarily consists of used toner cartridges and ink cartridges from office printing equipment.
(6) The non-hazardous waste generated by our office buildings mainly includes domestic waste and electronic waste.
(7) Due to the nature of our business, data regarding packaging materials does not apply to us. Our current environmental performance metrics exclude data from subsidiary acquired in 2024 since it gained environmental data measurement capabilities only post-acquisition and integration.
Strengthening Environmental Management
We abide by environmental protection-related laws and regulations and we are committed to protecting the environment and natural resources in our operational area. We have developed an environmental management philosophy that encompasses our operations, employees, users, and partners, working with our stakeholders to jointly enhance the protection of the environment and efficient use of natural resources. In line with our environmental philosophy, we regularly assess the impact of our operations on the environment and natural resources, set environmental goals, and evaluate the achievement of these goals on an annual basis.
Promoting Green Offices
We are committed to embedding the concept of environmental protection in every aspect of our daily operations, and continually improving the standards and depth of environmental management by establishing systematic management and regular supervision mechanisms. We actively practice the concept of green and low-carbon operations, and Beijing Huapin Borui Network Technology Co., Ltd has obtained the ISO 14001 Environmental Management System Certification.
Energy Efficiency Improvement
We are dedicated to using energy responsibly. We continue to strengthen electricity management at office premises, establishing monthly and quarterly workplace electricity consumption tracking mechanisms, promptly identifying abnormal electricity usage through data analysis, and systematically reducing unnecessary energy consumption through electricity usage behavior optimization and equipment energy efficiency upgrades, driving deeper green and low-carbon operations.
Waste Management
We reduce waste generation at the source through promoting online office software and driving the recycling of office equipment, effectively reducing resource consumption. At the same time, we strictly implement waste classification and recycling systems, standardizing the disposal of various types of waste, with particular emphasis on hazardous waste management to prevent environmental risks. In terms of office paper procurement, we purchase FSC-certified paper products, actively supporting sustainable forest management, contributing to ecological protection and biodiversity conservation, and fulfilling our responsibilities in the green supply chain.
Water Resource Management
As part of our environmental commitment to water conservation, we have installed water-saving sanitary fixtures in additional office areas during the year, continuously increasing the proportion of sensor-based water-saving fixtures, and conducting regular inspections of water facilities to fulfill our water conservation commitment.
Building a Sustainable Supply Chain
We conduct thorough assessments of our suppliers to evaluate environmental and social risks concerning supplier engagement, evaluation, maintenance, and withdrawal. Our procurement practices prioritize the selection of environmentally friendly and sustainable products. Collaborating with partners, we explore eco-friendly business models to cultivate a responsible and enduring supply chain.
Employee Care, Diversity and Inclusion
We care about our team members and support them at work and beyond. We are continually creating an open, equal, inclusive and healthy work environment where everyone is able to thrive with a rewarding career path.
82
Table of Contents
We foster inclusion and equality among employees from all backgrounds. We believe that fairness and diversity, are important to us in thriving in the business environment. For instance, we offer leave benefits and special allowances for working mothers such as prenatal check-up leave, maternity leave, breastfeeding leave, and parental leave. We respect the religious beliefs and cultures of employees from ethnic minority groups and provide them with religious holiday leave.
Employee physical and mental health
We are committed to creating a comfortable working environment, and promoting a positive, healthy, and happy lifestyle. We have established a nationwide network of gyms as People Health Care Center (PHCC), which offers employees tailored health management courses including personal training, group class training, physiotherapy and rehabilitation. We have established our Psychological Service Care Center (PSCC), which offers high-quality psychosomatic health services to all employees, including individual counseling sessions, management consultancy, customized departmental programs, leadership development courses, experiential group counseling activities, and specialized thematic events.
Supporting employee career development
We continue to improve the training management mechanism and have constructed a talent training system that integrates the “curriculum system”, “internal trainer system”, and “internal learning platform”. This helps improve the quality of online and offline learning resources, forming a tiered training system that progresses from basic skills acquisition to advanced expertise mastery. We support employees to improve their professional skills and competitiveness, achieving common growth of employees and our Company.
Insurance
We believe we maintain insurance policies covering risks in line with industry standards. We do not maintain property insurance or business interruption insurance. We also do not maintain insurance policies covering damages to our network infrastructures or information technology systems. Any uninsured occurrence of business disruption, litigation or natural disaster, or significant damages to our uninsured equipment or facilities could have a material and adverse effect on our results of operations. See “Item 3. Key Information—D. Risk Factors—Risks Relating to Our Business and Industry—We may not have sufficient insurance to cover our business risks, so that any uninsured occurrence of business disruption may result in substantial costs to us and the diversion of our resources, which could have an adverse effect on our results of operations and financial condition.”
Regulation
This section sets forth a summary of the most significant rules and regulations that affect our business activities in the Chinese mainland or the rights of our shareholders to receive dividends and other distributions from us.
Regulations Relating to Talent Intermediary Services
The Employment Promotion Law of the PRC promulgated by the Standing Committee of the National People’s Congress on August 30, 2007 and last amended on April 24, 2015 stipulates that employment intermediary agencies shall register and seek approval from the competent labor administrative department after their incorporation. Any entity that has not obtained a license and registered in accordance with the law shall be prohibited from engaging in employment intermediary activities. No employment agency shall provide false employment information or provide recruitment services to any institution that is not legally incorporated or licensed (if applicable). Any unlicensed and unregistered institution that, in violation of the provisions aforementioned, engages in unauthorized employment intermediary services, may be subject to the closure of business. Any illegal gains shall be confiscated and a fine from RMB10,000 to RMB50,000 may be imposed.
83
Table of Contents
Talent intermediary services agencies including us in the Chinese mainland are mainly regulated by the Ministry of Human Resources and Social Security of the PRC, or the MOHRSS. Pursuant to the Provisions on Talent Market Administration, jointly promulgated by the PRC Ministry of Personnel (one of the predecessors to the MOHRSS) and the State Administration of Industry and Commerce (currently known as the SAMR), on September 11, 2001 and last amended on December 31, 2019, any entity providing talent intermediary services in the Chinese mainland must obtain a human resource services license from the local branch of the MOHRSS. In addition, this regulation also reiterates the requirements under the Employment Promotion Law of the PRC that as a talent intermediary service agency, we are prohibited from providing fake information, making false promises and publishing fake recruitment advertisement.
On June 29, 2018, the State Council issued the Interim Regulations for the Human Resources Market, effective on October 1, 2018, according to which, the human resources or HR services providers include public HR services providers established by the PRC governmental authorities and commercial HR services providers. Commercial HR services providers engaging in employment agency activities are required to obtain a human resource services license, when such HR services are provided through the Internet, laws and regulations relating to network security and the management of Internet information services shall also be complied. For any commercial HR services providers engaging in the services such as collection and release of HR supply and demand information, HR management consulting, HR assessment, or HR training, it shall file with the competent department of the MOHRSS within 15 days of the date it starts the operation. The HR services providers providing recruitment or other HR services as entrusted by an employer shall not resort to fraud, violence, coercion or other improper means, shall not seek improper interests in the name of recruitment or introduce entities or individuals to engage in illegal activities. Commercial HR services providers shall expressly specify certain matters, among others, including the business license, charging standards, and human resource services licenses in their premises, which are subject to the supervision and inspection by the PRC governmental authorities such as the SAMR.
The MOHRSS promulgated the Administrative Regulations on Online Recruitment Services on December 18, 2020, which came into effect on March 1, 2021. These regulations reiterate the requirement that commercial HR services providers engaging in online recruitment services shall obtain a human resource service license with the service scope of “providing online recruitment services,” in addition, those involved in the telecommunications services shall also obtain the telecommunication business operating license required by law.
According to the Administrative Regulations on Online Recruitment Services, a HR service agency engaging in online recruitment services shall establish a complete online recruitment information management system and review the authenticity and legality of the materials and documents provided by employers in accordance with the PRC laws, including (i) recruitment brochures of the employer; (ii) the business license of the employer or the approval document for its establishment issued by the authorities; and (iii) the identity certificate of the person handling the release of recruitment information and the power of attorney of the employer. If the HR service agency fails to fulfill the above review obligations, it may be ordered to make rectifications and the failure to do so will subject it to an administrative penalty of (i) less than RMB10,000, if there are no illegal gains, or (ii) a fine of more than RMB10,000 but less than RMB30,000 and the confiscation of any illegal gains. As of the date of this annual report, we have not been subject to any administrative penalties imposed by the government authorities in relation to fraudulent recruitment.
The MOHRSS promulgated the Administrative Regulations on Human Resources Service Agencies on June 29, 2023, which came into effect on August 1, 2023, according to which, the commercial HR service agency engaging in employment agency activities shall obtain a human resource services license. The commercial HR service agency engaging in online recruitment services shall also obtain a telecommunications operation permit pursuant to the law. “Employment agency activities” refers to the intermediary services provided for employers to recruit persons and workers to seek employment, including recommending workers to employers, introducing employers to workers, organizing job fairs, carrying out online recruitment services, conducting senior talent search (headhunting) services and other commercial activities. For any commercial HR service agencies engaged in collection and release of HR supply and demand information, employment and entrepreneurship guidance, HR management consulting, HR assessment, HR training, HR service outsourcing and other HR service businesses, it shall file with the competent department of the MOHRSS within 15 days of commencing business. Commercial HR service agencies engaging in labor dispatch and overseas labor cooperation shall comply with the relevant provisions of the labor dispatch and overseas labor cooperation. Any unlicensed and unregistered institution that, in violation of the provisions aforementioned, engages in unauthorized employment intermediary services, may be subject to the closure of business. Any illegal gains shall be confiscated and a fine from RMB10,000 to RMB50,000 may be imposed. Any commercial HR service agency providing HR services without completing filing formalities shall be ordered by the HR and social security administrative authorities to make correction. Where correction is not made, a fine ranging from RMB5,000 to RMB10,000 shall be imposed.
84
Table of Contents
On August 23, 2024, the MOHRSS and the Office of the Central Cyberspace Affairs Commission jointly issued the Notice on Further Strengthening the Standardized Administration of the Human Resources Market, aiming to strengthen the supervision of the HR market, regulate HR market activities, and protect the legitimate rights and interests of workers and employers. The main contents of such Notice include: strengthening HR market access administration, strictly regulating online recruitment services, enhancing supervision over employment discrimination, strengthening the safety management of on-site recruitment, regulating market service charging practices, improving the comprehensive supervision of market activities, and strengthening the education and guidance for job seekers.
On December 25, 2025, the General Office of the MOHRSS, the General Office of the Central Cyberspace Affairs Commission, the General Office of the MIIT, the General Office of the Ministry of Public Security, and the General Office of the State Administration of Financial Regulation jointly issued the Notice on Regulating the Release of Recruitment Information on Online Platforms. The Notice mainly stipulates the following seven aspects: (i) strengthening supervision of online recruitment service licensing, requiring commercial human resources service agencies and online platforms to obtain human resources service licenses and take corresponding regulatory measures against illegal recruitment information publication; (ii) enhancing account registration management, requiring online platforms to implement real-name identity verification and prohibit providing services to users with false identities; (iii) classifying and verifying account qualifications, requiring online platforms to verify recruitment service accounts at least once every six months and prohibit unverified accounts from publishing recruitment information; (iv) disclosing account qualification information, requiring online platforms to set “recruitment service” labels and display relevant qualification information, with suspension of service for non-compliant accounts; (v) standardizing recruitment information format, requiring recruitment information to include essential elements and validity periods, and strictly prohibiting forwarding recruitment information without source attribution; (vi) strictly prohibiting illegal traffic attraction under the guise of recruitment information, banning the use of false recruitment to induce job seekers into “recruitment-to-training” or “training loan” agreements or illegal activities; (vii) seriously dealing with illegal and non-compliant accounts, requiring the establishment of risk identification models and rapid complaint handling mechanisms, and creating abnormal lists to prevent related entities from republishing recruitment information.
According to the Contract Law of the PRC promulgated by the National People’s Congress on March 15, 1999 and nullified since January 1, 2021, and the Civil Code of the PRC promulgated by the National People’s Congress on May 28, 2020 and effective on January 1, 2021, an intermediation contract is defined as a contract whereby an intermediary presents to its client an opportunity for entering into a contract or provides the client with other intermediary services in connection with the conclusion of a contract, and the client pays the intermediary service fees. Pursuant to the Contract Law and the Civil Code of the PRC, an intermediary must provide authentic information relating to the proposed contract. If an intermediary intentionally conceals any material fact or provides false information in connection with the performance of the proposed contract, which results in harm to the client’s interests, the intermediary may not claim service fees and is liable for the damages caused. Our business of connecting individual users with business customers on our online platform constitutes an intermediary service, and our contracts with business customers are intermediation contracts under the Contract Law and the Civil Code of the PRC, as a result, the performances, explanation and disputes under such contacts shall be regulated by these two bodies of law.
We have obtained a human resource service license with the service scope of “providing online recruitment services,” which remains in full force and effect as of the date of this annual report.
85
Table of Contents
Regulations Relating to Incorporation and Foreign Investment
The establishment, operation, and management of corporate entities in the Chinese mainland is governed by the PRC Company Law, which was promulgated by the Standing Committee of the National People’s Congress, on December 29, 1993, effective from July 1, 1994 and last amended on December 29, 2023 and became effective on July 1, 2024. The PRC Company Law generally governs two types of companies, namely limited liability companies and joint-stock limited companies, both entitled with the status of legal persons. The liability of shareholders of a limited liability company or a joint-stock limited company is limited to the amount of registered capital they have contributed. The PRC Company Law shall also apply to foreign-invested companies unless laws on foreign investment have stipulated otherwise. The PRC Company Law which became effective on July 1, 2024 imposes greater personal liability for directors, supervisors and management. Shareholders of a company must fully pay in their subscribed registered capital within five years from the date of establishment of this company, and companies established before July 1, 2024 shall gradually adjust their capital contribution to meet this new requirement. Violation of this law could lead to sanctions and penalties, including fines, orders to correct and public announcements of violations. On December 20, 2024, the SAMR promulgated the Measures for the Implementation of the Administration of Company Registration, which came into effect on February 10, 2025, pursuant to which, for a limited liability company registered and established before June 30, 2024, if the remaining term for subscribed capital contribution exceeds five years as of July 1, 2027, the company shall adjust such remaining term to less than five years by June 30, 2027; if the remaining term for subscribed capital contribution is less than five years as of July 1, 2027 or the registered capital has been paid in full, no adjustment to the term for subscribed capital contribution is required. The Measures for the Implementation of the Administration of Company Registration shall also apply to foreign-invested companies unless laws on foreign investment have stipulated otherwise.
On March 15, 2019, the National People’s Congress promulgated the PRC Foreign Investment Law, which came into effect on January 1, 2020 and replaced the previous laws regulating foreign investment in the Chinese mainland, namely, the Sino-foreign Equity Joint Venture Enterprise Law, the Sino-foreign Cooperative Joint Venture Enterprise Law and the Wholly Foreign-invested Enterprise Law, together with their implementation rules and the ancillary regulations. The PRC Foreign Investment Law sets out the definition of foreign investment and the framework for promotion, protection and administration of foreign investment activities. On December 30, 2019, the Ministry of Commerce and SAMR jointly promulgated the Measures for Reporting of Information on Foreign Investment, which came into effect on January 1, 2020, pursuant to which, the establishment of the foreign invested enterprises, including establishment through purchasing the equities of a domestic enterprise or subscribing to the increased registered capital of a domestic enterprise, and its subsequent changes are required to submit an initial or change report through the Enterprise Registration System.
Investment activities in the Chinese mainland by foreign investors are principally governed by the Negative List, and Catalogue of Industries for Encouraging Foreign Investment (2025 version). The former which came into effect on November 1, 2024, sets out special administrative measures in respect of the access of foreign investments in a centralized manner, and the latter, which came into effect on February 1, 2026, sets out the encouraged industries for foreign investment. Our business in providing value-added telecommunication service falls within the restricted categories of the Negative List. Our business in providing internet culture business and radio and television program services falls within the prohibited categories of the Negative List.
Regulations Relating to Value-Added Telecommunication Services
Value-added Telecommunications Services
An extensive regulatory scheme governing telecommunication services, including value-added telecommunication services and infrastructure telecommunications services, is promulgated by the State Council, the MIIT, and other government authorities. Value-added telecommunication service operators may be required to obtain additional licenses and permits in addition to those that they currently have given new laws and regulations may be adopted from time to time. In addition, substantial uncertainties exist regarding the interpretation and implementation of current and any future laws and regulations of the Chinese mainland applicable to the telecommunication activities.
86
Table of Contents
On September 25, 2000, the State Council promulgated the Telecommunication Regulations of the PRC, as last amended on February 6, 2016, to regulate telecommunications activities in the Chinese mainland. On December 28, 2015, the MIIT promulgated the Classification Catalogue of Telecommunications Services (2015 version), which was amended on June 6, 2019. According to the Telecommunications Regulations and the Classification Catalogue of Telecommunications Services, there are two categories of telecommunication activities, namely “infrastructure telecommunications services” and “value-added telecommunications services.” Pursuant to the Telecommunications Regulations, operators of value-added telecommunications services shall be approved by the MIIT, or its provincial level counterparts, and obtain a license for value-added telecommunications business. The Measures for the Administration of Telecommunications Business Licensing, issued by the MIIT on March 1, 2009 and last amended on July 3, 2017 for the purpose of strengthening the administration of telecommunications business licensing set forth more specific provisions regarding the types of licenses required to operate value-added telecommunications services and the application for and the approval, use and administration of a telecommunications business permit.
Internet Information Services
The Administrative Measures on Internet Information Services, which were promulgated by the State Council on September 25, 2000, last amended on December 6, 2024 and became effective on January 20, 2025, set out guidelines on the provision of Internet information services. These measures classified Internet information services into commercial Internet information services and noncommercial Internet information services and a commercial operator of Internet content provision services must obtain a value-added telecommunications business operating license, or the ICP License, for the provision of Internet information services from the appropriate telecommunications authorities. As of the date of this annual report, we have obtained an ICP License for provision of internet information services.
According to the Administrative Measures on Internet Information Services, violators may be subject to penalties, including criminal sanctions, for providing Internet content that: opposes the fundamental principles stated in the PRC Constitution; compromises national security, divulges national secrets, subverts national power or damages national unity; harms national dignity or interest; incites ethnic hatred or racial discrimination or damages inter-ethnic unity; undermines the PRC’s religious policy or propagates superstition; disseminates rumors, disturbs social order or disrupts social stability; disseminates obscenity or pornography, encourages gambling, violence, murder or fear or incites the commission of a crime; insults or slanders a third party or infringes upon the lawful rights and interests of a third party; or is otherwise prohibited by law or administrative regulations. An Internet information service provider may not post or disseminate any content that falls within prohibited categories and must stop providing any such content on their websites. The PRC government may order ICP License holders that violate any of the abovementioned content restrictions to correct those violations and revoke their ICP Licenses under serious conditions.
In addition to the Telecommunications Regulations and other regulations above, apps and app stores are specifically regulated by the Administrative Provisions on Mobile Internet Applications Information Services, which were promulgated by the CAC on June 28, 2016, amended on June 14, 2022 and became effective on August 1, 2022. These provisions regulate app information service providers and app store service providers and the CAC and local offices of cyberspace administration shall be responsible for the supervision and administration of nationwide or local APP information respectively.
App information service providers shall acquire the qualifications required by the laws and regulations and implement the information security management responsibilities strictly and fulfill their obligations, including real-name system, protection of users’ information, examination and management of information content, etc.
87
Table of Contents
The Provisions on Ecological Governance of Network Information Content, which were promulgated by the CAC on December 15, 2019 and became effective on March 1, 2020, clarify the scope of content to be encouraged, prohibited or prevented from production, reproduction and release. Producers of network information contents shall take measures to prevent and resist the production, reproduction and release of any adverse information with the following contents: (i) those using an exaggerated title, with the content seriously inconsistent with the title; (ii) those speculating in gossip, scandal or notoriety, etc.; (iii) those improperly commenting on natural disasters, major accidents or other disasters; (iv) those containing sexual cues or sexual teasing or others that are easily suggestive of sex; (v) those causing physical or mental discomfort such as bloodiness, horror and cruelty; (vi) those inciting mass discrimination or regional discrimination, etc.; (vii) those preaching tasteless, vulgar and kitsch contents; (viii) those probably inducing minors to imitate unsafe acts or acts violating social morality, or inducing minors to have unhealthy hobbies; and (ix) any other content that has an adverse impact on cyber ecology. A network information content service platform shall establish a mechanism for ecological governance of network information content, formulate detailed rules for ecological governance of network information content of its own platform, and improve systems for user registration, account management, information release review, thread comment review, page ecological management, real-time inspection, emergency response, and disposal of network rumors and black industry chain information. Users of network information content services, producers of network information contents and network information content service platforms shall not tamper with or hijack traffic, falsely register accounts or illegally trade accounts, or manipulate user accounts, manually or by technical means, thereby disrupting the order of cyber ecology.
On September 15, 2021, the CAC promulgated the Opinions on Further Enforcing Responsibilities on Website Platforms as the Main Responsible Party for Information Content Management, effective on the same date. The opinions stipulate that website platforms shall perform specific responsibilities as the main responsible party for information content management, including, among others, enhancing the platform community rules, strengthening the regulation and management of accounts, improving the content vetting mechanism and the quality of information content, managing the dissemination of information content, and strengthening the management of key functions.
The Administrative Provisions on the Account Information of Internet Users, which were promulgated by the CAC on June 27, 2022 and became effective on August 1, 2022, set out guidelines on the provision the account information of Internet users. Internet-based information service providers shall perform their responsibilities as the administrative subjects of the account information of internet users, have in place professionals and technical capacity appropriate to the scale of services, and establish, improve and strictly implement the authentication of real identity information, verification of account information, security of information content, ecological governance, emergency responses, protection of personal information and other management systems.
On September 17, 2021, the CAC, the MIIT, the SAMR, the Ministry of Public Security, the Ministry of Culture and Tourism and several other governmental authorities, jointly issued the Guidelines on Strengthening the Comprehensive Regulation of Algorithm for Internet Information Services, effective on the same date, which stipulate that the regulators shall carry out daily monitoring of data use, application scenarios and effects of algorithms, and conduct security assessments of algorithm, and that an algorithm filing system shall be established and classification and hierarchical security management of algorithms shall be adopted. On December 31, 2021, the CAC, the MIIT, the Ministry of Public Security and the SMAR jointly issued the Administrative Provisions on Algorithm Recommendation for Internet Information Service, which took effect on March 1, 2022. These provisions provide the classification and hierarchical management of algorithm recommendation service providers based on various criteria, and stipulates that algorithm recommendation service providers shall clearly inform users of their provision of algorithm recommendation services, and properly disclose the basic principles, intentions, and main operating mechanisms of algorithm recommendation services, and that algorithm recommendation service providers shall perform their responsibilities as subjects for algorithm security, establish and improve the management systems and technical measures for algorithm mechanism and principle review, scientific and technological ethics review, user registration, information release review, data security and personal information protection, anti-telecommunications and Internet fraud, security assessment and monitoring, and security incident emergency response, formulate and publicize the rules for algorithm recommendation services, and be equipped with professional staff and technical support appropriate to the scale of the algorithm recommendation service. An algorithm recommendation service provider with public opinion attribute or social mobilization ability shall fill in such information as the service provider’s name, service form, application field, algorithm type, algorithm self-assessment report and content to be disclosed via the internet information service algorithm record-filing system to go through record-filing formalities.
88
Table of Contents
Foreign Investment in Value-Added Telecommunications Industry
Pursuant to the Negative List and the Administrative Regulations on Foreign-Invested Telecommunications Enterprises, which were promulgated by the State Council on December 11, 2001 and last amended on March 29, 2022 by the State Council, the ultimate capital contribution percentage by foreign investor(s) in a foreign-invested value-added telecommunications services (except for e-commerce, domestic multi-party communications, storage-forwarding and call centers) is up to 50%. As of the date of this annual report, the VIE has obtained an ICP License for providing internet information services.
Regulations Relating to Online Transmission of Audio-Visual Programs
According to the Administrative Regulations on Internet Audio-Visual Program Service, promulgated by the State Administration of Press, Publication, Radio, Film and Television, or the SAPPRFT, and the Ministry of Information Industry (currently known as the MIIT) on December 20, 2007 and were last amended on August 28, 2015, “internet audio-visual program services” means producing, editing and integrating of audio-visual programs, supplying audio-visual programs to the public via the internet, and providing audio-visual programs uploading and transmission services to a third party. Entities providing internet audio-visual programs services must obtain a License for Online Transmission of Audio-Visual Programs or make the filing for providing internet audio-visual program services and content. Entities engaged in internet audio-visual program services without approval may be subject to warning, order to rectify, and a fine of no more than RMB30,000. Under serious conditions, the equipment used for such activities shall be confiscated and a fine of one but no more than two times of the investment amount may be imposed.
According to an Q&A session for reporters’ questions on the Administrative Provisions on Internet-based Audio-Visual Program Services issued by the SAPPRFT on its official website on February 3, 2008, units that legally provide internet audio-visual program services before the issuance of the Administrative Provisions on Internet-based Audio-Visual Program Services, as long as the operators do not violate laws and regulations, have the right to re-register their businesses and continue to operate internet audio-visual program services. This exemption will not be granted to internet audio-visual program service units established after the release of the Administrative Provisions on Internet-based Audio-Visual Program Services. These policies were later reflected in the Notice on Issues Related to the Application and Examination of the Permit for Spreading Audio-Visual Programs via Information Network issued by the SAPPRFT on April 8, 2008 and last amended on August 28, 2015.
However, according to the Certain Decisions on the Entry of the Non-state-owned Capital into the Cultural Industry promulgated by the State Council and became effective on April 13, 2005, and the Several Opinions on Canvassing Foreign Investment into the Culture Sector promulgated by the Ministry of Culture (currently known as the Ministry of Culture and Tourism), the SAPPRFT, the NDRC and the Ministry of Commerce and became effective on July 6, 2005, non-state-owned enterprises and foreign investors are not allowed to conduct the business of transmitting audio-visual programs via an information network. In addition, in the current practice of governmental authorities in the PRC, only companies with 30 million or more daily active users and 100 or more program inspectors, personnel within a company that is responsible for reviewing and vetting the content of the internet audio-visual program, are eligible to make the filing with the National Internet Audio-Visual Platforms Information Registration Management System.
As of the date of this annual report, we have not obtained a License for Online Transmission of Audio-Visual Programs or made the filing for providing internet audio-visual program services and content through our online recruitment platform in the Chinese mainland, and we have not been subject to any administrative penalties imposed by, or any investigations initiated by, the governmental authorities due to lack of the license or failure to complete the filing. See “Item 3. Key Information—D. Risk Factors—Risks Relating to Our Business and Industry—Any lack of or failure to maintain requisite approvals, licenses or permits applicable to our business may have a material and adverse impact on our business, financial condition and results of operations, and compliance with applicable laws or regulations may require us to obtain additional approvals or licenses or change our business model.”
On March 30, 2009, the SAPPRFT promulgated the Notice on Strengthening the Administration of the Content of Internet Audio-Visual Programs, which reiterates the pre-approval requirements for the internet audio-visual programs, including those on mobile network (if applicable), and prohibits internet audio-visual programs containing violence, pornography, gambling, terrorism, superstition, or other prohibited elements.
89
Table of Contents
On January 2, 2014, the SAPPRFT promulgated the Supplementary Notice on Further Improving the Management of Internet Audio-Visual Programs such as Online Dramas and Micro Movies, which requires institutions engaged in the production of internet audio-visual programs such as online dramas and micro films shall obtain a Radio and Television Program Production and Operation Permit. An internet-based audio-visual program service entity shall not broadcast online dramas, micro films and other internet audio-visual programs produced by institutions that have not obtained the Radio and Television Program Production and Operation Permit. An internet-based audio-visual program service entity can only forward programs uploaded by individuals who have verified their true identity information, and the programs must comply with the content management regulations. Internet audio-visual programs (including online dramas and micro films) shall be filed with the competent authorities before broadcasting.
On March 16, 2018, the SAPPRFT promulgated the Notice on Further Standardizing the Communication Order of Internet Audio-Visual Programs, which stipulates (including) audio-visual platforms shall not: (i) produce and disseminate programs that spoof and vilify classic literary and artistic works; (ii) re-edit, re-dub, re-subtitle or otherwise spoof classic literary and artistic works, radio, film and television programs, and network original audio-visual programs without authorization; and(iii)spread programs that have been edited and tampered with the original intention.
According to the Administrative Provisions on Network Audio and Video Information Services promulgated by the CAC, the Ministry of Culture and Tourism, and the National Radio and Television Administration on November 18, 2019, which took into effect on January 1, 2020, network audio and video information service providers shall, in accordance with the provisions of the PRC Cyber Security Law, authenticate users’ real identity information based on organization code, identity card number, mobile phone number, etc. Network audio and video information service providers shall not provide information release services for users who fail to provide their real identity information. Network audio and video information service providers shall fulfill their responsibilities as subjects of information content security management, have in place professionals commensurate with their service scale, establish and improve their systems in respect of user registration, information release review, information security management, emergency response, education and training of practitioners, protection of minors, and protection of intellectual property rights. Network audio and video information service providers shall strengthen the management of the audio and video information released by network audio and video information service users, deploy and apply illegal and non-real audio and video identification technologies; if any audio and video information service user is found to produce, release or disseminate the information content prohibited by laws and regulations, the transmission of such information shall be ceased in accordance with the law or as agreed, and disposal measures such as deletion shall be taken to prevent the information from spreading, save records, and report to administrations of cyberspace, culture and tourism, radio and television, etc.
On January 9, 2019, the China Netcasting Services Association promulgated the Network Short Video Platform Management Specification and the Detailed Rules for the Censorship Standards for Online Short Video Content, as last amended on December 15, 2021, which clarifies that the network short video platform implements the program content review before broadcasting system, all short videos broadcast on the platform should be reviewed before broadcasting and the program shall not contain illegal or immoral content.
Regulation Relating to Production and Distribution of Radio and Television Programs
On August 11, 1997, the State Council promulgated Administrative Regulations on Radio and Television, which came into effect on September 1, 1997 and were last amended on December 6, 2024 and became effective on January 20, 2025. The establishment of the entities engaging in the production and management of radio television programs shall be subject to the approval of radio stations, television stations and the radio and television administrative department of the people’s government at provincial level or above.
According to the Provisions for the Administration of the Production and Distribution of Radio and Television Programs promulgated by the SAPPRFT on July 19, 2004, which took into effect on August 20, 2004 and were last amended on June 3, 2025, any entity that produces or operates radio or television programs must obtain a Radio and Television Program Production and Operation Permit. Entities holding such permits shall conduct their business within the permitted scope as provided in their permits. Entities engaging in the producing or operating radio or television programs without such permit are subject to the closure of business, confiscation of used tools, equipment and carriers, as well as a fine between RMB10,000 and RMB50,000.
In addition, under the Provisions for the Administration of the Production and Distribution of Radio and Television Programs and the Negative List, foreign-invested enterprises are not allowed to engage in the above-mentioned services.
The VIE has obtained a Radio and Television Program Production and Operation Permit for the production of radio and television programs, which remains in full force and effect as of the date of this annual report.
90
Table of Contents
Regulations Relating to Online Live Streaming Services
On November 4, 2016, the CAC promulgated the Regulations for the Administration of Online Live Streaming Services, which became effective on December 1, 2016. The regulations require providers of online live streaming services taking multiple measures when operating live streaming services, which includes (i) establishing a platform for censoring contents for live streaming, managing such contents based on category and level of user scale thereof, adding or broadcasting identification information of the platform for contents in the form of images/texts, video, and audio, and censoring news and information for live streaming and the interactions thereof prior to releasing them; (ii) authenticating real identity information of each user of online live streaming services based on mobile phone number in the principle of “real name in background, and willingness in foreground”; (iii) verifying real identity information of each online live-stream releaser, filing such information with local CAC branches in provinces, autonomous regions and centrally- administered municipalities on a classification basis, and providing law enforcement authorities with such information upon lawful request thereby; (iv) concluding a service agreement with any user of online live streaming services, defining rights and obligations of both sides, and requiring the user to comply with the laws, regulations and the platform convention; and (v) establishing a blacklist management system to prohibit any online live streaming services user included on the blacklist from registering another account, and reporting the blacklist to the CAC branch in the province, autonomous region or centrally- administered municipality where it is located.
According to the regulations, where a provider of online live streaming services or an online live-stream releaser provides Internet-based news and information service without or beyond permission, the CAC branches in provinces, autonomous regions and centrally-administered municipalities shall impose punishment on the provider or the releaser in accordance with the Regulations for the Administration of Internet-based News and Information Services. The CAC and its local branches shall, ex officio, impose punishment according to law on offenders otherwise violating the regulations, and such offenders shall be prosecuted for criminal liability according to law if such violation constitutes a crime. Where online live streaming services, which are provided through online performances and online audio-visual programs, violate laws and regulations, the authorities concerned shall impose punishment in accordance with the laws. On September 2, 2016, the SAPPRFT promulgated the Notice of Issues Related to Strengthening the Management of Live Streaming Service of Online Audio-Visual Programs, which requires that the online audio-visual live streaming of cultural activities, sports, major political, military, economic, social and cultural activities of general social groups must hold a License for Online Transmission of Audio-Visual Programs and that the information about the special activities to be live stream must be filed with the Provincial Department of the SAPPRFT in advance.
According to the Measures for the Administration of Cyber Performance Business Operations, promulgated by the Ministry of Culture (currently known as the Ministry of Culture and Tourism), on December 2, 2016 and became effective on January 1, 2017, a cyber-performance business entity engaging in cyber performance business operations shall, in accordance with the Interim Administrative Provisions on Internet Culture, apply to the cultural administrative department at the provincial level for an Internet Culture Business License, and the license shall specify the scope of its cyber performance. A cyber-performance business entity shall indicate the number of its Internet Culture Business License in a conspicuous position on its homepage.
According to the Notice on Tightening the Administration of Online Live-streaming Services jointly promulgated by the MIIT and other five promulgation authorities on August 1, 2018, online live-streaming services providers shall fulfill the website ICP filing formalities with the competent department for telecommunications according to the law. Online live-streaming services providers involved in the operation of telecommunications services and Internet-based news information, online performances, live broadcast of internet audio-visual programs and other services shall apply to the authorities for licenses for the operation of telecommunications services, Internet-based news information services, network cultural operations, and dissemination of audio-visual programs through information networks and shall complete record-filing formalities with the local public security authorities in accordance with the regulations within 30 days of their live-streaming services being launched.
According to the Notice on Strengthening the Administration of the Online Show Live Streaming and E-commerce Live Streaming issued by the National Radio and Television Administration on November 12, 2020, with respect to platforms providing online show live streaming services or e-commerce live streaming services, the overall ratio of front-line content reviewers to online live streaming rooms shall be 1:50 or higher. A platform shall report the number of its live streaming rooms, streamers and content reviewers to the provincial branch of the National Radio and Television Administration on a quarterly basis. Online show live streaming platforms shall tag content and streamers by category. A streamer cannot change the category of the programs offered in his or her live streaming room without prior approval from the platform. Users that are minors or without real-name registration are forbidden from virtual gifting, and platforms shall limit the maximum amount of virtual gifting per time, per day, and per month. When the virtual gifting by a user reaches half of the daily/monthly limit, a consumption reminder from the platform and a confirmation from the user by text messages or other means are required before the next transaction. When the amount of virtual gifting by a user reaches the daily/monthly limit, the platform shall suspend the virtual gifting function for such user for that day or month.
91
Table of Contents
In addition, on February 9, 2021, the MIIT, the Ministry of Public Security, the Ministry of Culture and Tourism and the National Radio and Television Administration and other three promulgation authorities jointly promulgated the Guiding Opinions on Strengthening the Standardized Administration of Online Live-streaming, which require that Live-streaming platforms carrying out profit-making online performances shall hold the Permit for Network Culture Business and go through ICP record-filing; live-streaming platforms carrying out online audio-visual program services shall hold the License for Online Transmission of Audio-Visual Programs (or complete registration with the national information registration management system for online audio-visual platforms) and go through ICP record-filing; and live-streaming platforms carrying out Internet news information services shall hold the Permit for Internet News Information Services. Online live-streaming platforms shall timely go through the enterprise record-filing formalities with local competent Governmental Authorities such as the cyberspace administration authorities, and platforms ceasing to provide live-streaming services shall timely cancel their record-filing.
On September 4, 1991, the Standing Committee of the National People’s Congress promulgated the Law of the PRC on the Protection of Minors, which came into effect on January 1, 1992 and were last amended on April 26, 2024. According to this Law, online live-streaming service providers shall not provide minors under the age of 16 with the account registration service of online live-streaming publishers; when providing account registration service of online live-streaming publishers for minors reaching the age of 16, the service providers shall verify the identity information of the minors and obtain the consent of their parents or other guardians.
Regulations Relating to Internet Culture Activities
On May 10, 2003, the Ministry of Culture (currently known as the Ministry of Culture and Tourism) promulgated the Interim Administrative Provisions on Internet Culture, which became effective on July 1, 2003 and were last amended on December 15, 2017. The provisions require Internet information services providers engaging in commercial “Internet culture activities” to file an application for establishment to the competent culture administration authorities for approval and obtain an Internet Culture Business Operating License from the Ministry of Culture. “Internet cultural activity” is defined under the provisions as an act of provision of internet cultural products and related services, which includes (i) the production, duplication, importation, and broadcasting of the internet cultural products; (ii) the online dissemination whereby cultural products are posted on the internet or transmitted via the internet to end-users, such as computers, fixed-line telephones, mobile phones, television sets and games machines, for online users’ browsing, use or downloading; and (iii) the exhibition and competition of the internet cultural products. For any organization that engages in commercial Internet culture activities without approval, the cultural administration authorities or the cultural market enforcement authorities of the people’s government above county level with jurisdiction shall order it to cease the commercial Internet culture activities, give it a warning and impose concurrently a fine less than RMB30,000 against it; if it refuses to cease the commercial Internet culture activities, it shall be blacklisted in the cultural market and be subject to punishment for dishonesty in accordance with the law.
In addition, according to the Negative List and Several Opinions on the Introduction of Foreign Investment in the Cultural Field, promulgated by the Ministry of Culture and other four government authorities, foreign-invested enterprises are not allowed to engage in the above-mentioned Internet cultural activity.
On August 12, 2013, the Ministry of Culture promulgated the Measures for the Administration of Content Self-Examination of Internet Culture Organizations, which became effective on December 1, 2013. Before providing services to the public, Internet culture organizations shall examine the contents of Internet culture products and services. An Internet culture organization shall establish a content management system, clarify the responsibilities, standards, processes and accountability methods of content audit, and report to the administrative department of culture at the provincial level for record.
Regulations Relating to Information Security and Censorship
Internet content in the Chinese mainland is regulated and restricted from a state security standpoint. The Standing Committee of the National People’s Congress enacted the Decisions on the Maintenance of Internet Security on December 28, 2000, which were last amended on August 27, 2009, providing that the following activities conducted through the internet are subject to criminal liabilities: (i) gaining improper entry into any of the computer information networks relating to state affairs, national defensive affairs, or cutting-edge science and technology; (ii) violation of relevant provisions of the State in the form of unauthorized interruption of any computer network or communication service, as a result of which the computer network or communication system cannot function normally; (iii) spreading rumor, slander or other harmful information via the internet for the purpose of inciting subversion of the state political power; (iv) stealing or divulging state secrets, intelligence or military secrets via internet; (v) spreading false or inappropriate commercial information; or (vi) infringing on the intellectual property.
92
Table of Contents
On November 7, 2016, the Standing Committee of the National People’s Congress promulgated the PRC Cyber Security Law, which became effective on June 1, 2017, and was last amended on October 28, 2025 and became effective on January 1, 2026, pursuant to which, network operators shall comply with laws and regulations and fulfill their obligations to safeguard security of the network when conducting business and providing services. Those who provide services through networks including us shall take technical measures and other necessary measures pursuant to laws, regulations and compulsory national requirements to safeguard the safe and stable operation of the networks, respond to network security incidents effectively, prevent illegal and criminal activities, and maintain the integrity, confidentiality and usability of network data, and the network operator shall prevent network data from being divulged, stolen or falsified. In addition, any network operator to collect personal information shall follow the principles of legitimacy, rationality and necessity and shall not collect or use any personal information without due authorization of the person whose personal information is collected, and network operators of key information infrastructure shall store within the territory of the Chinese mainland all the personal information and important data collected and produced within the territory of the Chinese mainland. The last amended PRC Cyber Security Law introduces a dedicated provision on artificial intelligence, explicitly supporting AI fundamental research, algorithm development, and computing infrastructure construction, while requiring the establishment of ethics standards, strengthened risk monitoring, and safety supervision. It also imposes more stringent legal liabilities for the violation of the security protection obligations of network operation, network information, critical information infrastructure and personal information under the PRC Cyber Security Law, and raises the upper limit of monetary fines for entities causing particularly severe consequences (such as complete dysfunction of critical information infrastructure) from RMB1 million to RMB10 million, and for individuals from RMB100,000 to RMB1 million.
On June 22, 2007, the Ministry of Public Security, the National Administration of State Secrets Protection, the State Cipher Code Administration and the Information Office of the State Council (absorbed into the MIIT) promulgated the Administrative Measures for the Graded Protection of Information Security, effective from June 22, 2007, pursuant to which, graded protection of the state information security shall follow the principle of “independent grading and independent protection,” and the security protection grade of an information system shall be determined according to such factors as its level of importance in national security, economic development and social livelihood as well as its level of damage to national security, social order, public interests and the legitimate rights and interests of citizens, legal persons and other organizations in case it is destroyed, accordingly the security protection grade of an information system may be classified into five grades. The entities operating the information systems shall determine the security protection grade of the information system pursuant to these measures and the Guidelines for Grading of Classified Protection of Cyber Security, and report the grade to the relevant department for examination and approval.
On April 13, 2020, the CAC, the NDRC, MIIT and other nine promulgation authorities issued the Cybersecurity Review Measures, effective on June 1, 2020, which stipulate that the cybersecurity review shall focus on the evaluation of possible risks to national security caused by the purchase of the network product or service, also provide for more detailed rules regarding cybersecurity review requirements. On December 28, 2021, the CAC, together with certain other PRC governmental authorities, jointly released the Revised Cybersecurity Review Measures, which took effect on February 15, 2022. Pursuant to the Revised Cybersecurity Review Measures, critical information infrastructure operators procuring network products and services and online platform operators conducting data processing activities that affect or may affect national security shall conduct a cybersecurity review. In particular, if operators of critical information infrastructure anticipate that its procurement of network products and services affect or may affect national security after the network products and services being put into use, it shall apply for cybersecurity review to the Cybersecurity Review Office. In addition, online platform operators possessing personal information of more than one million users seeking to be listed on a foreign stock exchange must apply for a cybersecurity review. If the authorities believe that the network products or services or the data processing activities of the operators affect or may affect national security, they may initiate the cybersecurity review against such operators. Given the Revised Cybersecurity Review Measures were relatively new, there are substantial uncertainties as to the interpretation, application and enforcement of the Revised Cybersecurity Review Measures.
On June 10, 2021, the Standing Committee of the National People’s Congress promulgated the PRC Data Security Law which came into effect on September 1, 2021 and provides for a security review procedure for the data activities that may affect national security. The PRC Data Security Law requires data processing, which includes the collection, storage, use, processing, transmission, provision and publication of data, to be conducted in a legitimate and proper manner. It also introduces a data classification and hierarchical protection system based on the importance of data to economic and social development, as well as the degree of harm it will cause to national security, public interests, or legitimate rights and interests of individuals or organizations when such data is tampered with, destroyed, leaked, or illegally acquired or used. The appropriate level of protection measures is required to be taken for each respective category of data. In addition, the PRC Data Security Law also provides that any organization or individual within the territory of the Chinese mainland shall not provide any foreign judicial body and law enforcement body with any data stored within the territory of the Chinese mainland without the approval of the competent PRC governmental authorities. Violation of the PRC Data Security Law may subject the entities or individuals to warning, fines, and business suspension, revocation of permits or business licenses, or even criminal liabilities.
93
Table of Contents
On July 30, 2021, the PRC State Council promulgated the Regulations on Security Protection of Critical Information Infrastructure, which became effective on September 1, 2021. Pursuant to such regulations, “critical information infrastructure” shall mean any important network facilities or information systems of important industries or fields such as public communication and information service, energy, transportation, water conservation, finance, public services, government digital services and national defense science, and any other important network facilities or information systems which may seriously endanger national security, national economy, people’s livelihood and public interest in case of damage, function loss or data leakage. In addition, the administration departments for each critical industry and sector shall be responsible for formulating identification rules and determining the critical information infrastructure in the respective industry or field. The operators shall be informed about the final determination. As of the date of this annual report, the Ministry of Transport has promulgated the Administrative Measures for the Security Protection of Railway Critical Information Infrastructure on December 17, 2023, which came into effect on February 1, 2024, and the Administrative Measures for the Security Protection of Highway and Waterway Critical Information Infrastructure on April 24, 2023, which came into effect on June 1, 2023, and the State Post Bureau of the PRC has promulgated the Administrative Measures for the Security Protection of Critical Information Infrastructure in the Postal Industry (Trial) on December 31, 2025, which came into effect on February 1, 2026. No other detailed implementation rules have been issued by governmental authorities, and we have not been informed by any governmental authority that we are a critical information infrastructure operator.
On September 24, 2024, the State Council promulgated Regulations on the Administration of Network Data Security, which came into effect on January 1, 2025, and provides that network data processors who carry out online data processing activities that impact or might impact national security, shall conduct a national security review in accordance with relevant national regulations. The Regulations on the Administration of Network Data Security also requires data processors processing over 10 million users’ personal information to comply with the regulations on important data processors, including, among others, appointing a person in charge of data security and establishing a data security management organization, conducting risk assessments before providing, entrusting processing, and jointly processing important data ; when important data security is impacted due to merger, division, dissolution, bankruptcy, or so forth, measures shall be taken to ensure network data security, and the important data disposition plan, the name or contact information of the recipient shall be reported to the relevant competent departments at the provincial level or above. The regulations also provide that important data processors shall carry out a risk assessment of their network data processing activities every year and submit a risk assessment report to the relevant competent authorities at or above the provincial level, who shall promptly inform the cyberspace administration and public security authorities at the same level. In addition, large network platform service providers, i.e. services providers of a network platform with more than 50 million registered users or more than 10 million monthly active users, complex business types, and network data handling activities having a significant impact on national security, economic operation, national welfare and people’s livelihood, shall release annual social responsibility reports on personal information protection, and the contents of such reports shall include but not be limited to the measures for personal information protection and the effects thereof, the acceptance of applications for the exercise of rights by individuals, and the performance of duties by the supervision body for personal information protection which is mainly composed of external members.
In addition, the Administrative Regulations on Online Recruitment Services provide that HR services agencies engaging in online recruitment services shall, in accordance with the requirements under the laws and regulations of the Chinese mainland related to national cybersecurity and cybersecurity graded protection systems, strengthen cybersecurity management, perform cybersecurity protection obligations, and adopt technical or other necessary measures to ensure the security of recruitment service network, information system and users’ information. Moreover, HR services agencies shall establish and improve their users’ information protection system for online recruitment services, and shall not disclose, divulge, damage or illegally sell or provide to any person, such information as the citizen identification number, age, gender, address, contact information of an individual or any information on business situations of an employer. If such agencies provide any personal information or important data collected or generated within the Chinese mainland to any overseas party due to their business operation, such provision shall abide by applicable laws and regulations of the Chinese mainland.
94
Table of Contents
On July 7, 2022, the CAC issued the Measures for the Security Assessment of Cross-border Transfer of Data, which became effective on September 1, 2022. These measures require the data processor providing data overseas and falling under any of the following circumstances to apply for the security assessment of cross-border transfer of data with the local provincial-level counterparts of the national cybersecurity authority: (i) where the data processor intends to provide important data overseas; (ii) where a critical information infrastructure operator and a data processor who has processed personal information of more than 1,000,000 individuals intends to provide personal information overseas; (iii) where a data processor who has provided personal information of 100,000 individuals or sensitive personal information of 10,000 individuals to overseas recipients, in each case as calculated cumulatively, since 1 January of the last year intends to provide personal information overseas; and (iv) other circumstances where the security assessment of data cross-border transfer is required as prescribed by the CAC. Furthermore, the data processor shall conduct a self-assessment on the risk of data cross-border transfer prior to applying for the foregoing security assessment, under which the data processor shall focus on certain factors including, among others, the legitimacy, fairness and necessity of the purpose, scope and method of data cross-border transfer and the data processing of overseas recipients, the scale, scope, type and sensitivity of the data to be transferred abroad, the risks that the cross-border data transfer may bring to national security, public interests and the legitimate rights and interests of individuals or organizations as well as whether the cross-border data transfer related contracts or the other legally binding documents to be entered with overseas recipients have fully included the data security protection responsibilities and obligations.
On March 22, 2024, the CAC issued the Provisions on Promoting and Regulating Cross-border Data Flows, which became effective on the same day, requiring security assessment for the following types of cross-border data transfers: (i) for critical information infrastructure operators, the outbound transfer of personal information or important data, and (ii) for data processors that are not critical information infrastructure operators, the outbound transfer of important data or the cumulative outbound transfer within one calendar year of the personal information of over one million people or the sensitive personal information of over 10,000 people. These provisions also stipulated that, when data processors that are not critical information infrastructure operators engage in the cumulative outbound transfer within one calendar year of the personal information of over 10,000 people but less than one million people or the sensitive personal information of less than 10,000 people, the data processors must enter into a standard contract for cross-border transfer of personal information with the data recipient or obtain a certification for the protection of personal information. Furthermore, these provisions clarified that data processors do not need to treat any data as “important data” the outbound transfer of which requires security assessments, if government authorities have not declared or notified them that the data are “important data.” The Provisions on Promoting and Regulating Cross-border Data Flows stipulates that a data handler providing personal information abroad may be exempted from declaring security assessment for data to be provided abroad, concluding a standard contract for personal information to be provided abroad or passing authentication for protection of personal information if it satisfies certain conditions. In addition, the provision of data collected and generated from activities such as international trade, cross-border transport, academic cooperation, and transnational manufacturing and marketing—provided such data does not contain personal information or important data—is exempt from the aforementioned procedures when shared with overseas parties.
On December 8, 2022, the MIIT issued the Measures for the Administration of Data Security in the Field of Industry and Information Technology (for Trial Implementation), which became effective on January 1, 2023. The measures are aimed to regulate the processing activities of data in the field of industry and information technology field conducted by data processors in the PRC. The measures apply to industrial enterprises, software and information technology service companies, and companies holding licenses for operation of telecommunication services that independently determine the purposes and methods of data processing in the course of data processing activities. Data processing activities include, among others, the collection, storage, use, processing, transmission, provision, and disclosure of data. Pursuant to the measures, data in the field of industry and information technology includes industrial data, telecommunication data and radio data generated and collected during the operation of the services. The measures provide for the classification of data in the field of industry and information technology as general, important, or core data, and provide specific requirements for the management of data classifications and data protection measures, including, among others, data collection, storage, processing, transmission, disclosure, and destruction for data processors in the field of industry and information technology. In particular, data processors processing important data and core data are required to complete filings with the authorities for the catalogue of important data and core data. The filing information includes basic information on the data, such as category, classification, quantity, processing purposes and methods of data processing, scope of use, liable entities, data sharing, cross-border transfer of data and data security protection measures. If over 30% of the quantity (i.e., number of data items or amount of data stored) of important and core data changes or there is any material change to other filing information, data processors must update the filing information with the authorities within three months after such change. Furthermore, the measures provide data security requirements for cross-border and data transfers for data processors. If a data processor needs to transfer data in cases of merger, restructuring, or bankruptcy, it shall establish a data transfer plan and notify users affected. In addition, the measures indicate that the legal representative or principal of the data processor should be the primary person held accountable for data security and the person in charge of data security should take direct responsibility for the security of data processing activities.
95
Table of Contents
On June 12, 2024, the CAC, the Ministry of Public Security, the Ministry of Culture and Tourism and the National Radio and Television Administration jointly promulgated the Provisions on the Governance of Cyberviolence Information, which came into effect on August 1, 2024. Pursuant to the provisions, the network information service providers shall perform their responsibilities as subjects of network information content administration, establish and improve a mechanism for governing cyberviolence information, and improve the systems for user registration, account management, personal information protection, information release review, monitoring and early warning, and identification and handling. The network information service providers shall also formulate and disclose management rules and platform conventions, enter into service agreements with users, specify the rights and obligations related to cyberviolence information governance, and fulfill governance responsibilities in accordance with the law and the agreement. Under the provisions, “cyberviolence information” refers to the illegal and harmful information that is released to individuals in a centralized manner in the form of texts, images, audio, videos, etc., and contains insults, verbal abuse, slanderous rumors, inciting hatred, coercion, privacy violations, accusations, mockery, depreciation, discrimination, and other contents that affect physical and mental health.
On September 11, 2025, the CAC promulgated the Measures for the Administration of National Cybersecurity Incident Reporting, which came into effect on November 1, 2025. The measures establish a tiered and categorized cybersecurity incident reporting system, specifying reporting obligations and time limits for network operators when “relatively large” or above incidents occur: critical information infrastructure operators must report to protection departments and public security organs within one hour; central and state organs and their subordinate units must report to their own cybersecurity work institutions within two hours; other network operators must report to provincial cyberspace administration departments within four hours; and for major or particularly serious incidents, hierarchical reporting to national cyberspace authorities is required within 30 minutes to one hour. The exhibit to the measures explicitly classify cybersecurity incidents into four tiers: (i) Extra‑significant cybersecurity incidents (e.g., those causing direct economic losses of more than RMB100 million, leakage of personal information of more than 100 million individuals, or attacks and tampering targeting ultra‑large online platforms resulting in the large‑scale spread of illegal and harmful information); (ii) Significant cybersecurity incidents (e.g., those causing direct economic losses of more than RMB20 million, leakage of personal information of more than 10 million individuals, or attacks and tampering targeting large online platforms resulting in the widespread spread of illegal and harmful information); (iii) Relatively large cybersecurity incidents (e.g., those causing direct economic losses of more than RMB5 million, leakage of personal information of more than 1 million individuals, or attacks and tampering targeting online platforms resulting in the relatively widespread spread of illegal and harmful information); and (iv) General cybersecurity incidents (all other cybersecurity incidents that pose a certain threat to and cause a certain impact on national security, social order, economic development and public interests, and do not fall under the preceding three tiers).
On December 6, 2025, the CAC released the Measures for Network Data Security Risk Assessment (Draft for Comments), which mainly stipulates the scope of application for risk assessment activities concerning network data and data processing activities within China’s territory, requires important data processors to conduct annual risk assessments and submit reports while general data processors assess at least once every three years, permits self-assessment or third-party assessment with priority given to certified institutions, mandates delegated assessment by certified institutions when significant risks, security incidents or national security threats are identified, and sets forth supporting systems for risk information sharing, collaborative response and legal liability, while providing for mutual recognition of assessment results with classified protection testing, compliance audits and other evaluations to avoid duplication.
Regulations Relating to Privacy Protection
Pursuant to the Civil Code of the PRC, the personal information of a natural person shall be protected by the law. Any organization or individual that need to obtain personal information of others shall obtain such information legally and ensure the safety of such information, and shall not illegally collect, use, process or transmit personal information of others, or illegally purchase or sell, provide or make public personal information of others.
On December 13, 2005, the Ministry of Public Security issued the Regulations on Technological Measures for Internet Security Protection, which took effect on March 1, 2006. These measures require Internet service providers including us to take proper measures including anti-virus, data back-up and other related measures, and to keep records of certain information about their users (including user registration information, log-in and log-out time, IP address, content and time of posts by users) for at least 60 days, and detect illegal information, stop transmission of such information, and keep records. Internet services providers including us are prohibited from unauthorized disclosure of users’ information to any third parties unless such disclosure is required by the laws and regulations. They are further required to establish management systems and take technological measures to safeguard the freedom and secrecy of the users’ correspondences.
96
Table of Contents
On December 28, 2012, the Standing Committee of the National People’s Congress promulgated the Decision on Strengthening Network Information Protection to enhance the legal protection of information security and privacy on the internet. On July 16, 2013, the MIIT promulgated the Provisions on Protection of Personal Information of Telecommunication and Internet Users, effective on September 1, 2013, to regulate the collection and use of users’ personal information in the provision of telecommunication services and Internet information services in the Chinese mainland and the personal information includes a user’s name, birth date, identification card number, address, phone number, account name, password and other information that can be used for identifying a user. Telecommunication business operators and Internet service providers are required to constitute their own rules for the collecting and use of users’ information and they cannot collect or use of user’s information without users’ consent. Telecommunication business operators and Internet service providers must specify the purposes, manners and scopes of information collection and uses, obtain the consent of the relevant individuals, and keep the collected personal information confidential. Telecommunication business operators and Internet service providers are prohibited from disclosing, tampering with, damaging, selling or illegally providing others with, collected personal information. Telecommunication business operators and Internet service providers are required to take technical and other measures to prevent the collected personal information from any unauthorized disclosure, damage or loss.
On December 29, 2011, the MIIT promulgated the Several Provisions on Regulation of the Order of Internet Information Service Market, which became effective on March 15, 2012. The provisions stipulate that without the consent of users, Internet information service providers shall not collect information relevant to the users that can lead to the recognition of the identity of the users independently or in combination with other information, nor shall they provide this kind of information to others, unless otherwise provided by laws and administrative regulations. The provisions also require that Internet information service providers properly store this information; if it is divulged or may possibly be divulged, Internet information service providers shall immediately take remedial measures; where such incident causes or may cause serious consequences, they shall immediately report the same to the telecommunications administration authorities that grant them with the Internet information service license or filing and cooperate in the investigation and disposal carried out by the competent government authorities. Failure to comply with such requirements may result in a fine between RMB10,000 and RMB30,000 and an announcement to the public. According to the PRC Cyber Security Law, a network operator shall not collect personal information irrelevant to the services it provides or collect or use personal information in violation of the provisions of laws or agreements between both parties.
On May 8, 2017, the Supreme People’s Court and the Supreme People’s Procuratorate released the Interpretations of the Supreme People’s Court and the Supreme People’s Procuratorate on Several Issues Concerning the Application of Law in the Handling of Criminal Cases Involving Infringement of Citizens’ Personal Information, effective from June 1, 2017. These interpretations clarify several concepts regarding the crime of “infringement of citizens’ personal information” stipulated by Article 253A of the Criminal Law of the PRC, including “citizen’s personal information,” “provision,” and “unlawful acquisition.” Also, they specify the standards for determining “serious circumstances” and “particularly serious circumstances” of this crime.
On January 23, 2019, the Office of the Central Cyberspace Affairs Commission, the MIIT, the Ministry of Public Security, and the SAMR jointly issued an Announcement of Launching Special Crackdown Against Illegal Collection and Use of Personal Information by Apps to implement special rectification works against mobile Apps that collect and use personal information in violation of applicable laws and regulations, where business operators are prohibited from collecting personal information irrelevant to their services, or forcing users to give authorization in disguised manner.
On November 28, 2019, the CAC, the MIIT, the Ministry of Public Security and the SAMR jointly issued the Methods of Identifying Illegal Acts of Apps to Collect and Use Personal Information, effective on the same date. This regulation further specifies certain illegal practices of Apps operators in terms of personal information protection, including “failure to publicize rules for collecting and using personal information,” “failure to expressly state the purpose, manner and scope of collecting and using personal information,” “collection and use of personal information without consent of users of such App,” “collecting personal information irrelevant to the services provided by such App in violation of the principle of necessity,” “provision of personal information to others without users’ consent,” “failure to provide the function of deleting or correcting personal information in accordance with the law” and “failure to disclose information for complaints and reporting.”
On March 12, 2021, the MIIT, the CAC, the Ministry of Public Security and the SAMR jointly promulgated the Rules on the Scope of Necessary Personal Information for Common Types of Mobile Internet Applications, effective on May 1, 2021, which specify that the scope of necessary personal information for job hunting and recruitment applications includes mobile phone numbers of registered users and resume provided by job seekers. On April 26, 2021, the MIIT promulgated Interim Provisions on the Administration of Personal Information Protection for Apps (Draft for Comments), which further stipulate the protection and management of the personal information on the Apps. As of the date of this annual report, the Interim Provisions on the Administration of Personal Information Protection for Apps (Draft for Comments) has not been formally adopted.
97
Table of Contents
The PRC Data Security Law specifies that the scope of the data almost includes all information records generated from every aspect of production, operation and management during the process of digital transformation of government affairs and enterprises, and requires that data shall be collected legally and properly and shall not be acquired by theft or other illegal means. An entity conducting data processing activities shall establish a sound data security management system throughout the whole process, organize data security education and training and take technical measures and other necessary measures to ensure the security of the information. In addition, data processing activities carried out through the Internet or any other information network shall be conducted on the basis of the graded protection system for cybersecurity. Risk monitoring shall be strengthened when data processing activities are conducted, and remedial measures shall be taken immediately upon discovery of any data security defect or bug. In case of data security incidents, disposal measures shall be taken immediately, users shall be timely notified in accordance with the provisions and reports shall be made to the competent authorities.
On August 20, 2021, the PRC Personal Information Protection Law was passed by the Standing Committee of the National People’s Congress and became effective on November 1, 2021. This law consolidates rules with respect to personal information rights and privacy protection and specifies the protection requirements for processing personal information, and specifies the rules for processing sensitive personal information. The personal information of an individual shall be processed on the basis of having the consent of the data subject concerned or on some other legitimate basis. Only where there is a specific purpose and sufficient necessity, and under circumstances where strict protection measures are taken, may personal information processors process sensitive personal information. The processing of sensitive personal information of an individual shall be subject to the individual’s separate consent. Personal information processors shall be subject to the liability for personal information processing activities, and adopt necessary measures to safeguard the security of the personal information. Otherwise, the personal information processors will be subject to orders of the regulatory authorities to rectify their operations, suspend or terminate the provision of services, or confiscation of illegal income, fines or other penalties.
In addition, the PRC Personal Information Protection Law strengthens the supervision of automatic decision making to protect the rights of individuals to obtain fair transaction terms and to strengthen the supervision of mobile applications, including: (i) requiring transparency, fairness and impartiality; (ii) banning automatic decision making that impose unreasonable preferential treatment on individuals in terms of transaction prices and other transaction conditions; (iii) setting forth individuals’ right to opt out of automatic decision making; (iv) setting forth individuals’ right to receive explanation of the process which could have significant impact on individuals’ rights and interests and the right to not be subject to decisions based solely on automated processing when such decisions have significant impact on the individual. The processors using personal information for automatic decision making must ensure the transparency of the decision making and fairness and impartiality of the results, and the automatic decision making must not be used to impose unreasonable differential treatment on individuals in terms of transaction prices and other transaction conditions. If the automatic decision making is used for information pushing or commercial marketing to individuals, processors must provide individuals with options that are not based on the individuals’ personal characteristics, or convenient methods for the individuals to refuse such commercial marketing or information pushing. Such options may include, for example, providing a tab on the user interface to disable information pushing with one click, so that users do not have to receive information feed customized based on his or her personal characteristic features. In addition, if such decisions significantly affect the rights and interests of an individual, the individual can request processors to give explanations or refuse to accept the processors making decisions solely based on automatic decision making.
98
Table of Contents
On February 12, 2025, the CAC promulgated the Measures for the Administration of Personal Information Protection Compliance Audit, which became effective from May 1, 2025. The measures mainly stipulate the scope of application for reviewing and evaluating personal information processing activities’ compliance with laws and regulations, establish a two-tier mechanism requiring processors handling over 10 million individuals’ personal information to conduct audits at least every two years while permitting protection departments to mandate delegated professional audits upon discovering serious risks or large-scale breaches, and require that a personal information processor that processes personal information of more than 1 million individuals shall appoint a personal information protection officer who shall be responsible for conducting compliance audits on the personal information protection activities of the processor.
On July 18, 2025, the CAC issued the Announcement on Conducting Information Submission for Personal Information Protection Officers, which provided that where a personal information processor handles personal information of 1 million individuals or more, it shall complete the formalities for submitting information on its personal information protection officer to the cyberspace administration of the prefecture-level city where it is located within 30 working days from the date on which the number reaches 1 million, and for personal information processors that already handled personal information of 1 million individuals or more before the issuance of the announcement, they shall complete the information submission by August 29, 2025.
On October 14, 2025, the CAC and the SAMR jointly issued the Measures for the Certification of Outbound Transfer of Personal Information, which became effective from January 1, 2026, stipulating that before applying for certification for the outbound provision of personal information, a personal information processor shall perform its obligations in accordance with the provisions of laws and administrative regulations, including notification, obtaining separate consent from individuals, and conducting a personal information protection impact assessment. Where a personal information processor provides personal information overseas by way of certification, it shall apply to a professional certification body for personal information outbound transfer certification.
On September 12, 2025, the CAC issued the Provisions on the Establishment of a Personal Information Protection Supervision Committee by Large‑scale Online Platforms (Draft for Comments), stipulating that a personal information protection supervision committee established by a personal information processor that provides critical Internet platform services within the PRC, has a huge user base, and operates complex business types shall have a number of members commensurate with the business scale and user volume of the large‑scale online platform, generally no fewer than seven members, of which no less than two‑thirds shall be external members. A large‑scale online platform service provider may, in accordance with state regulations, grant external members remuneration commensurate with their duties based on their full‑time or part‑time duties, working hours, workload and other relevant factors. Except for the aforementioned remuneration, external members shall not obtain any other interests from the large‑scale online platform service provider, its shareholders holding 5% or more of the shares, controlling shareholders, actual controllers, or any affiliated entities or personnel.
On November 22, 2025, the CAC and the Ministry of Public Security issued the Provisions on the Protection of Personal Information on Large‑scale Online Platforms (Draft for Comments). The provisions stipulate that network data processors providing large‑scale online platform services shall appoint a personal information protection officer in accordance with the provisions of laws and regulations, publicly disclose the contact information of such officer, and establish a dedicated department for personal information protection. They shall store personal information collected and generated in the course of operations within the territory of the PRC. Where it is truly necessary to provide such information overseas, they shall comply with the relevant provisions of the State on the security administration of outbound data transfers. The identification of large-scale online platforms shall mainly take into account the following factors: (i) having more than 50 million registered users or more than 10 million monthly active users; (ii) providing critical network services or operating a business scope covering multiple types of services; (iii) handling data whose leakage, tampering or damage would have a material impact on national security, economic operation, national economy and people’s livelihood; and (iv) other circumstances specified by the national cyberspace administration and the public security department of the State Council.
99
Table of Contents
On January 10, 2026, the CAC issued the Provisions on the Collection and Use of Personal Information by Internet Applications (Draft for Comments), which stipulate that Operators of internet applications and software development kits shall bear primary responsibility respectively for the collection, use and security protection of personal information in connection with the mobile applications and software development kits they operate. Internet application operators shall perform statutory review obligations with respect to embedded software development kits; distribution platform operators shall perform statutory review obligations with respect to distributed internet applications; and smart device manufacturers shall perform statutory review obligations with respect to pre-installed mobile applications. Where an internet application with more than 50 million registered users or more than 10 million monthly active users and with complex business types revises or updates its personal information collection and use rules, it shall simultaneously solicit public opinions through its homepage, official website, official WeChat account and other channels, for a period of not less than seven working days.
The Administrative Measures for the Application Security of Facial Recognition Technology jointly issued by the CAC and the Ministry of Public Security on March 13, 2025 and effective from June 1, 2025, regulate activities involving the handling of facial information through facial recognition technology within the territory of China. The measures establish comprehensive obligations for personal information handlers, including regulatory filing requirements, security standards, and operational rules for the use of facial recognition technology, aiming to protect personal information rights and public security.
Regulations Relating to Generative AI
On August 29, 2019, the Ministry of Science and Technology issued the Guidelines for the Construction of the National New Generation Artificial Intelligence Innovation and Development Pilot Zone, which were amended on September 29, 2020 and came into effect on the same date. The guidelines aim to establish a conducive environment for the innovation and development of AI, promote the establishment of AI infrastructure and enhance the conditional support for the innovation and development of AI.
On March 12, 2021, the National People’s Congress promulgated the Outline of the 14th Five-Year Plan for the National Economic and Social Development of the People’s Republic of China and the Outlines of Objectives in Perspective for the Year 2035. The outlines emphasize key focus areas including essential algorithms for AI, and underscore the nurturing of emerging digital industries such as AI.
On December 31, 2021, the CAC, the MIIT, the Ministry of Public Security and the SAMR jointly issued the Administration Provisions on Algorithmic Recommendation of Internet Information Services, which became effective on March 1, 2022. These provisions stipulates that algorithmic recommendation service providers must (i) fulfill their responsibilities for algorithm security, (ii) establish and strengthen management systems for algorithm mechanism examination, ethical review in technology, user registration, information release examination, protection of data security and personal information, anti-telecom and network fraud, security assessment and monitoring, emergency response to security incidents, etc., and (iii) formulate and publish rules governing algorithmic recommendation related service. The provider of algorithmic recommendation services should not use the services to (i) carry out any illegal activity which may endanger national security and social public interest, disturb economic order and social order, or infringe third parties’ legal interest, or (ii) spread any information prohibited by laws or regulations. Besides, it should not take advantage of algorithms to impose unreasonable restrictions on other information service providers, or hinder or obstruct the normal operation of their legal services. The providers of algorithmic recommendation services with the characteristics of public opinion or capacity of social mobilization must complete the filing with the CAC’s filing system within ten business days after the launch of its service.
On November 25, 2022, the CAC, the MIIT and the Ministry of Public Security promulgated the Administrative Provisions on Deep Synthesis of Internet Information Services, which became effective on January 10, 2023. Pursuant to these provisions, deep synthesis service providers are required to fulfill their primary responsibilities for information security, establish and improve management systems for various aspects including user registration, algorithm mechanism review, scientific and technological ethics review, information release review, data security, personal information protection, combating telecom and online fraud, and emergency response and implement secure and controllable technical support measures.
100
Table of Contents
On July 10, 2023, the CAC, the NDRC, the Ministry of Education, the Ministry of Science and Technology, the MIIT, the Ministry of Public Security and the National Radio and Television Administration promulgated the Interim Measures for the Administration of Generative Artificial Intelligence Services, which became effective on August 15, 2023. These measures outline compliance requirements for providers of generative AI services to the public within the territory of PRC. Providers are required to conduct data processing training activities in accordance with PRC laws and regulations and assume responsibility as producers of network information contents, as well as fulfill network information security obligations. Any provider of Generative AI services with attribute of public opinions or of social mobilization ability shall conduct security assessment in accordance with the relevant provisions, and complete the formalities for algorithm filing, change or deregistration in accordance with the Administrative Provisions on Algorithm Recommendation for Internet Information Service. Other requirements under these measures include the use of legitimate data sources, no infringement on others’ legitimate intellectual property rights, and obtaining consent for personal information usage. Violations may result in punishment specified under the PRC data and cybersecurity legal regime, including the PRC Cyber Security Law, the PRC Data Security Law, the PRC Personal Information Protection Law, and the PRC Science and Technology Progress Law. In the absence of any specific provisions, violations may result in warnings, orders to correct, and orders to suspend the provision of services determined by competent governmental authorities.
On March 7, 2025, the CAC, the MIIT, the Ministry of Public Security and the National Radio and Television Administration jointly issued the Measures for the Identification of Artificial Intelligence Generated and Synthesized Content, which became effective from September 1, 2025. These measures mainly stipulate the scope of application for network information service providers subject to algorithm recommendation, deep synthesis, and generative AI service management regulations, establishes a dual identification system combining explicit and implicit identifiers requiring service providers to add user-perceptible explicit identifiers (text, sound, graphics) to generated synthetic content including text, images, audio, video, and virtual scenes, as well as implicit identifiers containing content attributes and service provider information in file metadata, standardizes dissemination platforms’ obligations to verify implicit identifiers, add prominent warning labels, and retain dissemination element information.
Regulations Relating to Advertisement
All commercial advertising activities for direct or indirect introduction of products or services promoted by product business operators or service providers via a certain medium and in a certain form within the territory of the PRC are applied to the PRC Advertising Law, promulgated by the Standing Committee of the National People’s Congress on October 27, 1994 and as last amended and effective on April 29, 2021, which requires advertisers, advertising operators and advertising distributors to ensure that the content of the advertisements they produce or distribute are true and in full compliance with applicable laws and regulations and the content of the advertisement shall not contains the prohibited information including but not limited to (i) information harm the dignity or interests of the State or divulge the secrets of the State, (ii) information contain wordings such as “national level,” “highest level” and “best,” (iii) information contain ethnic, racial, religious, sexual discrimination. In addition, where a special government review is required for certain categories of advertisements before publishing, the advertisers, advertising operators and advertising distributors are obligated to confirm that such review has been duly performed and that the approval has been obtained. Without prior consent or request, the advertisers, advertising operators and advertising distributors shall not deliver advertisement to any person’s accommodation or transportation. If the advertisers, advertising operators and advertising distributors display any pop-up advertisement, they shall show the close button clearly to make sure that the viewers can close the advertisement upon one-click.
Violations of these regulations may result in penalties, including fines, confiscation of advertising income, orders to cease dissemination of the advertisements and orders to publish an advertisement correcting the misleading information. For serious violations, the SAMR, or its local branches may order the violator to terminate its advertising operations or even revoke its business license. Furthermore, advertisers, advertising operators or advertising distributors may be subject to civil liabilities if they infringe on the legal rights and interests of third parties.
On February 25, 2023, the SAMR promulgated the Measures for the Administration of Internet Advertisement, effective from May 1, 2023. These measures are applicable to the usage of internet media such as websites, web pages, and internet applications, whether directly or indirectly, to promote commercial advertisement activities for products or services via text, images, videos or other forms, in the territory of the PRC. Under the new measures, when publishing internet advertisements in the form of pop-ups or other forms, the advertiser or the publisher should prominently mark a close button to ensure that the advertisement can be closed with one click. Furthermore, operators of live broadcasting rooms who are commissioned to provide advertisement design, production, agency and publishing services shall assume legal responsibility and obligations as the advertisement operator and advertiser.
101
Table of Contents
In addition, according to the Provisions on Talent Market Administration, the Talent Intermediary Services agencies are prohibited from publishing fake recruitment advertisement and violations would lead to penalties under the PRC Advertising Law, which includes fines, prohibition from advertising for a period of time or revocation of business licenses.
Regulations Relating to Intellectual Property
Regulations on Patents
Pursuant to the Patent Law of the PRC, which was issued by the Standing Committee of the National People’s Congress on March 12, 1984, and last revised on October 17, 2020 and became effective as of June 1, 2021, the State Intellectual Property Office is responsible for managing patent work of the whole nation. The patent management departments of the people’s governments of each province, autonomous region and municipality directly under the central government are responsible for the patent management in their respective administrative regions. Chinese patent system adopts the principle of “prior application,” i.e., where two or more applicants file applications for patent for the identical invention or creation respectively, the patent right shall be granted to the applicant whose application was filed first. If one wishes to file application for patent for invention or utility models, the following three standards must be met: novelty, creativity and practicability. The validity period of a patent for invention is 20 years, the validity period of utility models is 10 years, and the validity period of the design is 15 years. Others may use the patent after obtaining the permit or proper authorization of the patent holder, otherwise such behavior will constitute an infringing act of the patent right.
Regulations on Trademarks
Pursuant to the Trademark Law of the PRC, which was promulgated by the Standing Committee of the National People’s Congress on August 23, 1982 and last amended on April 23, 2019 and came into effect on November 1, 2019, the Implementation Regulations of the Trademark Law of the PRC which were issued by the State Council on August 3, 2002 and last amended on April 29, 2014, and went into effect on May 1, 2014. The Trademark Office under the China National Intellectual Property Administration shall handle trademark registrations and grant a term of ten years to registered trademarks, which may be renewed for additional ten-year period upon request from the trademark owner. The Trademark Law of the PRC has adopted a “first-to-file” principle with respect to trademark registration. Where an application for trademark for which application for registration has been made is identical or similar to another trademark which has already been registered or is under preliminary examination and approval for use on the same kind of or similar commodities or services, the application for registration of such trademark may be rejected. Any person applying for the registration of a trademark may not prejudice the existing right of others, nor may any person register in advance a trademark that has already been used by another party and has already gained a “sufficient degree of reputation” through such party’s use. A trademark registrant may, by entering into a trademark licensing contract, license another party to use its registered trademark. Where another party is licensed to use a registered trademark, the licenser shall report the license to the Trademark Office under the China National Intellectual Property Administration for recordation, and the office shall publish it. An unrecorded license may not be used as a defense against a third party in good faith.
Regulations on Copyrights
Pursuant to the Copyright Law of the PRC promulgated by the Standing Committee of the National People’s Congress on September 7, 1990, last amended on November 11, 2020 and became effective as of June 1, 2021, Chinese citizens, legal persons or other entities shall, whether published or not, enjoy copyright in their works, which include, among others, works of literature, art, natural science, social science, engineering technology and computer software created in writing or oral or other forms. Copyright holders can enjoy multiple rights, including the right of publication, the right of authorship and the right of reproduction.
Pursuant to the Regulation on Computers Software Protection promulgated on June 4, 1991 by the State Council and last amended on January 30, 2013 and the Measures for the Registration of Computer Software Copyright promulgated in 1992 and last amended by the National Copyright Administration on February 20, 2002, the National Copyright Administration is mainly responsible for the registration and management of software copyright in the Chinese mainland and recognizes the China Copyright Protection Center as the software registration organization. The China Copyright Protection Center shall grant certificates of registration to computer software copyright applicants in compliance with the regulations of the Measures for the Registration of Computer Software Copyright and the Regulation on Computers Software Protection.
102
Table of Contents
Regulations on Domain Names
Pursuant to the Measures for the Administration of Internet Domain Names promulgated by MIIT on August 24, 2017 and became effective on November 1, 2017, domain name shall refer to the character mark of hierarchical structure, which identifies and locates a computer on the internet and corresponds to the Internet Protocol address of that computer. The MIIT supervises and administers the domain name services in the Chinese mainland. The registration for domain names such as the first-tier domain name “.cn” follows the principle of “first application, first registration.” An applicant for registration of domain name shall provide information for the registration of domain name such as the true, accurate and complete information on the identity of the domain name holder to the domain name registration service authority. After completion of the registration procedures, the applicant will become the holder of the domain name. Any registration and use of domain names by organizations and individuals shall abide by the requirements of the Measures for the Administration of Internet Domain Names, and any registrations and uses of domain names in breach of the said Measures constitutes an offense and is subject to criminal liability.
Regulations Relating to Foreign Exchange
Regulations on Foreign Currency Exchange
The principal regulations governing foreign currency exchange in the Chinese mainland are the Foreign Exchange Administration Regulations, as last amended on August 5, 2008. Pursuant to the regulations, international payments in foreign exchange and the transfer of foreign exchange under the current account items shall not be subject to any state control or restriction when complying with certain procedural requirements. In contrast, the conversion of RMB into foreign currencies and remittance of the converted foreign currency outside the Chinese mainland for the purpose of capital account items, such as direct equity investments, loans and repatriation of investment, requires prior approval from SAFE or its local branches.
According to the Circular of SAFE on Further Improving and Adjusting the Foreign Exchange Policies on Direct Investment, promulgated by the SAFE on November 19, 2012 and last amended on December 30, 2019, foreign exchange control measures related to foreign direct investment are improved, such as (i) the open of and payment into the foreign exchange account related to direct investment are no longer subject to approval by SAFE; (ii) reinvestment with legal income of foreign investors in the Chinese mainland is no longer subject to approval by SAFE; (iii) purchase and external payment of foreign exchange related to foreign direct investment are no longer subject to approval by SAFE. Later, on February 13, 2015, SAFE issued SAFE Circular 13, effective from June 1, 2015 and last amended on December 30, 2019, providing that the bank, instead of SAFE, can directly handle the foreign exchange registration and approval for foreign direct investment and SAFE and its branches.
SAFE released SAFE Circular 19, on March 30, 2015, which came into force on June 1, 2015 and last amended on March 23, 2023. Under SAFE Circular 19, a foreign invested enterprise, within the registered scope of business, may settle their foreign exchange capital following a principal of authenticity on a discretionary basis according to the actual needs of their business operation, and the RMB capital so converted can be used for equity investments within the Chinese mainland, which will be regarded as the reinvestment of foreign-invested enterprise, provided that such foreign invested enterprises are not registered as an enterprises mainly engaged in investment business, including foreign investment companies, foreign funded venture capital enterprises and foreign funded equity investment enterprises. The RMB converted from the foreign exchange capital will be kept in a designated account and is not allowed to be used directly or indirectly for purposes beyond its business scope or used to provide RMB entrusted loans (unless permitted within its registered business scope), repayment of inter-company loans (including third-party advances), and repayment of bank RMB loans that have been re-loaned to third parties, and other uses expressly forbidden under SAFE Circular 19.
The Circular of the SAFE on Reforming and Regulating Policies on the Control over Foreign Exchange Settlement of Capital Accounts, or SAFE Circular 16, was promulgated and became effective on June 9, 2016 and last amended on December 4, 2023. According to SAFE Circular 16, enterprises registered in the Chinese mainland may also convert their foreign debts from foreign currency into RMB on self-discretionary basis. SAFE Circular 16 provides an integrated standard for conversion of foreign exchange under capital account items (including but not limited to foreign currency capital and foreign debts) on self-discretionary basis, which applies to all enterprises registered in the Chinese mainland. SAFE Circular 16 reiterates the principle that RMB converted from foreign currency-denominated capital of a company may not be directly or indirectly used for purposes beyond its business scope and may not be used for investments in securities or other investment excluding financial products and structured deposits with risk rating results not higher than Grade II within the Chinese mainland unless otherwise specifically provided. Besides, the converted RMB shall not be used to make loans for non-affiliated enterprises unless it is permitted within the business scope or to purchase any residential real estate that is not for the enterprise’s own use unless it is an enterprise engaging in real estate development and leasing.
103
Table of Contents
On October 23, 2019, SAFE issued the SAFE Circular 28, last amended on December 4, 2023, which cancels the restrictions on domestic equity investments by capital fund of non-investment foreign invested enterprises and allows non-investment foreign invested enterprises to use their capital funds to lawfully make equity investments in the Chinese mainland, provided that such investments do not violate the Negative List and the target investment projects are genuine and in compliance with laws.
According to the SAFE Circular 8 issued by the SAFE on April 10, 2020, eligible enterprises are allowed to make domestic payments by using their capital funds, foreign credits and the income under capital accounts of overseas listing, with no need to provide the evidentiary materials concerning authenticity of such capital for banks in advance, provided that their capital use shall be authentic and in line with provisions, and conform to the prevailing administrative regulations on the use of income under capital accounts. The concerned bank shall conduct spot checking in accordance with the requirements.
On December 4, 2023, SAFE issued the Notice by the State Administration of Foreign Exchange of Further Deepening Reforms to Facilitating Cross-border Trade and Investment, providing that qualified “high and new technology enterprises,” “specialized, featured and new enterprises” and “small and medium-sized high-tech enterprises” in Tianjin, Shanghai, Jiangsu, Shandong (including Qingdao), Hubei, Guangdong (including Shenzhen), Sichuan, Shaanxi, Beijing, Chongqing, Zhejiang (including Ningbo), Anhui, Hunan, and Hainan may borrow foreign debts freely within the limit of the equivalent of US$10 million, and qualified “high and new technology enterprises,” “specialized, featured and new enterprises” and “small and medium-sized high-tech enterprises” in other regions may borrow foreign debts freely within the limit of the equivalent of US$5 million. The interpretation and implementation in practice of this notice, Circular 28 and Circular 8 are still subject to substantial uncertainties given they are newly issued regulations.
Regulations on Foreign Exchange Registration of Overseas Investment by PRC Residents
On July 4, 2014, SAFE issued SAFE Circular 37, to regulate foreign exchange matters in relation to the use of Special Purpose Vehicles, or SPVs, by residents in the Chinese mainland or entities to seek offshore investment and financing or conduct round trip investment in the Chinese mainland.
Pursuant to SAFE Circular 37, a SPV refers to an overseas enterprise directly formed or indirectly controlled for investment or financing purposes by a domestic resident (domestic institution or domestic individual resident) with the assets or interests it legally holds overseas or in a domestic enterprise, while “round trip investment” refers to the direct investments made in the Chinese mainland by domestic residents directly or indirectly through SPVs, namely, the behavior of establishing foreign invested enterprises or projects in the Chinese mainland by formation, acquisition, merger, or any other means, and acquiring interests, such as ownership, control, or operating right, in them. SAFE Circular 37 provides that, before making contribution into an SPV, residents in the Chinese mainland are required to complete foreign exchange registration with SAFE or its local branch according to SAFE Circular 37 and applicable currently effective SAFE regulations. According to Circular 13, local banks, instead of SAFE, will examine and handle foreign exchange registration for overseas direct investment, including the initial foreign exchange registration and amendment registration.
Failure to comply with the registration procedures set forth in SAFE Circular 37 and the subsequent notice, or making misrepresentation on or failure to disclose controllers of the foreign invested enterprise that is established through round-trip investment, may result in restrictions imposed on the foreign exchange activities of the foreign invested enterprise, including payment of dividends and other distributions, such as proceeds from any reduction in capital, share transfer or liquidation, to its offshore parent or affiliate, and the capital inflow from the offshore parent, and may also subject residents in the Chinese mainland or entities to penalties under PRC foreign exchange administration regulations.
We have used our best efforts to notify residents in the Chinese mainland (domestic institution or domestic individual resident) who directly or indirectly hold shares in our Cayman Islands holding company and who are known to us as being residents in the Chinese mainland to complete the foreign exchange registrations. However, we may not at all times be fully aware or informed of the identities of all our shareholders or beneficial owners, and we cannot compel them to comply with SAFE registration requirements. See “Item 3. Key Information—D. Risk Factors—Risks Relating to Doing Business in China—PRC regulations relating to offshore investment activities by residents in the Chinese mainland may limit the ability of our subsidiaries in the Chinese mainland to increase their registered capital or distribute profits to us or otherwise expose us or our PRC resident beneficial owners to liability and penalties under laws of the Chinese mainland.”
104
Table of Contents
Regulations on Stock Incentive Plans
Pursuant to the Notice on Issues Concerning the Foreign Exchange Administration for Domestic Individuals Participating in Stock Incentive Plan of Overseas Publicly Listed Company, issued by SAFE on February 15, 2012, employees, directors, supervisors and other senior management participating in any stock incentive plan of an overseas publicly listed company who are PRC citizens or who are non PRC citizens residing in the Chinese mainland for a continuous period of not less than one year, subject to a few exceptions, are required to register with SAFE through a domestic qualified agent, which could be a subsidiary in the Chinese mainland of such overseas listed company, and complete certain other procedures. Failure to complete the SAFE registrations may subject them to fines and legal sanctions and may also limit their ability to contribute additional capital into their wholly foreign owned subsidiaries in the Chinese mainland and limit these subsidiaries’ ability to distribute dividends to them. The domestic agents shall, on behalf of the residents in the Chinese mainland who have the right to exercise the employee share options, apply to SAFE or its local branches for an annual quota for the payment of foreign currencies in connection with the exercise of residents in the Chinese mainland of the employee share options. The foreign exchange proceeds received by the residents in the Chinese mainland from the sale of shares under the stock incentive plans granted and dividends distributed by the overseas listed companies must be remitted into the bank accounts in the Chinese mainland established by the domestic agents before distribution to such residents in the Chinese mainland. In addition, the domestic agents shall quarterly submit the form for record-filing of information of the Domestic Individuals Participating in the Stock Incentive Plans of Overseas Listed Companies with SAFE or its local branches. In addition, the domestic agents are required to amend the SAFE registration with respect to the stock incentive plan if there is any material change to the stock incentive plan.
In addition, the State Administration of Taxation has issued circulars concerning stock incentive plan including share option and restricted shares, under which the income derived from such stock incentive plan by our employees who are resident individuals in the Chinese mainland under the PRC Individual Income Tax Law (2018 Revision) will be subject to PRC individual income tax. Our subsidiaries in the Chinese mainland and VIE have obligations to file documents related to such stock incentive plan with the tax authorities and to withhold individual income taxes of those employees for their income derived from the stock incentive plan. If our employees fail to pay or if we fail to withhold their income taxes as required by the laws and regulations, we may face sanctions imposed by the PRC tax authorities or other PRC government authorities.
Regulations Relating to Dividend Distributions
The principal laws, rules and regulations governing dividend distributions by foreign-invested enterprises in the Chinese mainland are the PRC Company Law which was last amended in 2023 and became effective in July 2024 and the PRC Foreign Investment Law and its Implementing Regulations. Under these requirements, foreign-invested enterprises may pay dividends only out of their accumulated profit, if any, as determined in accordance with PRC accounting standards and regulations. A Chinese mainland company is required to allocate at least 10% of their respective accumulated after-tax profits each year, if any, to fund certain capital reserve funds until the aggregate amount of these reserve funds have reached 50% of the registered capital of the enterprises. A Chinese mainland company is not permitted to distribute any profits until any losses from prior fiscal years have been offset. Profits retained from prior fiscal years may be distributed together with distributable profits from the current fiscal year.
Regulations Relating to Overseas Securities Offerings
On July 6, 2021, the PRC government authorities issued Opinions on Strictly Cracking Down Illegal Securities Activities in Accordance with the Law. These opinions emphasized the need to strengthen the administration over illegal securities activities and the supervision on overseas listings by China-based companies and proposed to take effective measures, such as promoting the construction of regulatory systems to deal with the risks and incidents faced by China-based overseas-listed companies.
On February 17, 2023, the CSRC issued the Overseas Listing Regulations and five supporting guidelines, which became effective on March 31, 2023. On May 16, 2023, the CSRC promulgated another supporting guideline, which came into effect on the same date. As a company that is listed outside of China whose main business operations are in the Chinese mainland, we must file with the CSRC within three business days after any offering of securities we make.
On February 24, 2023, the CSRC issued the Provisions on Strengthening the Confidentiality and Archive Management Work Relating to the Overseas Securities Offering and Listing by Domestic Companies, which became effective on March 31, 2023. These provisions aim to expand the applicable scope of the regulation to indirect overseas offerings and listings by PRC domestic companies and emphasize the confidentiality and archive management duties of PRC domestic companies during the process of overseas offerings and listings. Given these provisions were relatively new, there are substantial uncertainties as to their interpretation, application, and enforcement.
105
Table of Contents
On December 24, 2025, the People’s Bank of China and the SAFE jointly issued the Notice on Issues Concerning Fund Administration for Domestic Enterprises’ Overseas Listing, which stipulates that this Notice shall only apply to the fund administration relating to direct overseas issuance and listing or issuance of overseas depositary receipts by a joint stock limited company registered in the Chinese mainland that has completed filing with the CSRC.
Regulations Relating to Employment and Social Welfare
Regulations on Employment
The major laws and regulations of the Chinese mainland that govern employment relationship are the PRC Labor Law, promulgated by the Standing Committee of the National People’s Congress on July 5, 1994, effective on January 1, 1995 and last amended on December 29, 2018, and the PRC Labor Contract Law, promulgated by the Standing Committee of the National People’s Congress on June 29, 2007, effective on January 1, 2008 and last amended on December 28, 2012, and the Implementation Rules of the PRC Labor Contract Law, issued by the State Council on September 18, 2008 and effective on the same day. According to the aforementioned laws and regulations, labor relationships between employers and employees must be executed in written form. The laws and regulations above impose stringent requirements on the employers in relation to entering into fixed-term employment contracts, hiring of temporary employees and dismissal of employees. As prescribed under the laws and regulations, employers shall ensure its employees have the right to rest and the right to receive wages no lower than the local minimum wages. Employers must establish a system for labor safety and sanitation that strictly abide by state standards and provide relevant education to its employees. Violations of the PRC Labor Contract Law and the PRC Labor Law may result in the imposition of fines and other administrative liabilities and/or incur criminal liabilities in the case of serious violations.
Regulations on Social Insurance and Housing Fund
According to the Social Insurance Law of the PRC, which was issued by the Standing Committee of the National People’s Congress on October 28, 2010 and came into effect on July 1, 2011 and was last revised on December 29, 2018, enterprises and institutions in the Chinese mainland shall provide their employees with welfare schemes covering pension insurance, unemployment insurance, maternity insurance, occupational injury insurance, medical insurance and other welfare plans. The employer shall apply to the local social insurance agency for social insurance registration within 30 days from the date of its formation. And it shall, within 30 days from the date of employment, apply to the social insurance agency for social insurance registration for the employee. Any employer who violates the regulations above shall be ordered to make correction within a prescribed time limit; if the employer fails to rectify within the time limit, the employer and its directly liable person will be fined. Meanwhile, the Interim Regulation on the Collection and Payment of Social Insurance Premiums, issued by the State Council on January 22, 1999, effective on the same day and was last revised on March 24, 2019, prescribes the details concerning the social securities.
Apart from the general provisions about social insurance, specific provisions on various types of insurance are set out in the Regulation on Work-Related Injury Insurance, issued by the State Council on April 27, 2003, effective on January 1, 2004, and revised on December 20, 2010, the Regulations on Unemployment Insurance, issued by the State Council on January 22, 1999 and effective on the same day, the Trial Measures on Employee Maternity Insurance of Enterprises, issued by the Ministry of Labor (one of the predecessors to the MOHRSS) on December 14, 1994 and effective on January 1, 1995. Enterprises subject to these regulations shall provide their employees with the corresponding insurance.
According to the Regulations on the Administration of Housing Provident Fund, implemented since April 3, 1999 and last amended on March 24, 2019, any newly established entity shall make deposit registration at the housing accumulation fund management center within 30 days as of its establishment. After that, the entity shall open a housing accumulation fund account for its employees in an entrusted bank. Within 30 days as of the date an employee is recruited, the entity shall make deposit registration at the housing accumulation fund management center and seal up the employee’s housing accumulation fund account in the bank mentioned above within 30 days from termination of the employment relationship.
Any entity that fails to make deposit registration of the housing accumulation fund or fails to open a housing accumulation fund account for its employees shall be ordered to complete the procedures within a prescribed time limit. Any entity failing to complete the procedure within the time limit will be fined RMB10,000 to RMB50,000. Any entity fails to make payment of housing provident fund within the time limit or has shortfall in payment of housing provident fund will be ordered to make the payment or make up the shortfall within the prescribed time limit, otherwise, the housing provident management center is entitled to apply for compulsory enforcement with the People’s Court.
106
Table of Contents
Regulations Relating to Tax
Regulations on Dividend Withholding Tax
The PRC Enterprise Income Tax Law was promulgated by the National People’s Congress on March 16, 2007, became effective on January 1, 2008 and was last amended on December 29, 2018. According to this law and the Regulation on the Implementation of the Enterprise Income Tax Law of the PRC, which was issued on December 6, 2007, became effective on January 1, 2008 and was last amended on December 6, 2024 and became effective on January 20, 2025, dividends generated after January 1, 2008 and payable by a foreign-invested enterprise in the Chinese mainland to its foreign enterprise investors are subject to a 10% withholding tax, unless any such foreign enterprise investor’s jurisdiction of incorporation has a tax treaty with the Chinese mainland that provides for a preferential withholding arrangement. According to the Arrangement between the Chinese mainland and the Hong Kong Special Administrative Region for the Avoidance of Double Taxation and Prevention of Fiscal Evasion with Respect to Taxes on Income, which was issued by the State Administration of Taxation on August 21, 2006 and was subsequently amended in 2008, 2011, 2016 and 2019, the withholding tax rate in respect of the payment of dividends by a Chinese mainland enterprise to a Hong Kong enterprise may be reduced to 5% from a standard rate of 10% if the Hong Kong enterprise directly holds at least 25% of the Chinese mainland enterprise and certain other conditions are met, including: (i) the Hong Kong enterprise must directly own the required percentage of equity interests and voting rights in the Chinese mainland resident enterprise; and (ii) the Hong Kong enterprise must have directly owned such required percentage in the Chinese mainland resident enterprise throughout the 12 months prior to receiving the dividends. However, based on the Circular on Certain Issues with Respect to the Enforcement of Dividend Provisions in Tax Treaties issued and became effective on February 20, 2009 by the State Administration of Taxation, if the PRC tax authorities determine, in their discretion, that a company benefits from such reduced income tax rate due to a structure or arrangement that is primarily tax-driven, such PRC tax authorities may adjust the preferential tax treatment; and based on the Announcement on Certain Issues with Respect to the “Beneficial Owner” in Tax Treaties issued by the State Administration of Taxation on February 3, 2018 and effective from April 1, 2018, if an applicant’s business activities do not constitute substantive business activities, it could result in the negative determination of the applicant’s status as a “beneficial owner,” and consequently, the applicant could be precluded from enjoying the above-mentioned reduced income tax rate of 5%.
Regulations on Enterprise Income Tax
The PRC Enterprise Income Tax Law and the Regulation on the Implementation of the Enterprise Income Tax Law of the PRC impose a uniform 25% enterprise income tax rate to both foreign invested and domestic enterprises, except where tax incentives are granted to special industries and projects. Among other tax incentives, the preferential tax treatment continues as long as an enterprise can retain its “High and New Technology Enterprise” status.
Under the PRC Enterprise Income Tax Law, an enterprise established outside the Chinese mainland with “de facto management bodies” within the Chinese mainland is considered a “resident enterprise” for Chinese mainland enterprise income tax purposes and is generally subject to a uniform 25% enterprise income tax rate on its worldwide income. Circular 82 promulgated by the State Administration of Taxation on April 22, 2009 and last amended on December 29, 2017 and the Announcement of the State Administration of Taxation on Issues concerning the Determination of Resident Enterprises Based on the Standards of Actual Management Institutions promulgated by the State Administration of Taxation on January 29, 2014 set out the standards used to classify certain Chinese invested enterprises controlled by Chinese enterprises or Chinese enterprise groups and established outside of the Chinese mainland as “resident enterprises,” which also clarified that dividends and other income paid by such Chinese mainland “resident enterprises” will be considered PRC source income and subject to PRC withholding tax, currently at a rate of 10%, when paid to non-Chinese mainland enterprise shareholders. This notice also subjects such Chinese mainland “resident enterprises” to various reporting requirements with the PRC tax authorities. Under the Regulation on the Implementation of the Enterprise Income Tax Law of the PRC, a “de facto management body” is defined as a body that has material and overall management and control over the manufacturing and business operations, personnel and HR, finances and properties of an enterprise.
107
Table of Contents
On October 17, 2017, the State Administration of Taxation issued SAT Bulletin 37, last amended on June 15, 2018, which replaced the Notice on Strengthening Administration of Enterprise Income Tax for Share Transfers by Non-Chinese mainland Resident Enterprises, issued by the State Administration of Taxation, on December 10, 2009, and partially replaced and supplemented the rules under SAT Bulletin 7, issued by the State Administration of Taxation, on February 3, 2015. Under SAT Bulletin 7, an “indirect transfer” of assets, including equity interests in a Chinese mainland resident enterprise, by non-Chinese mainland resident enterprises may be re-characterized and treated as a direct transfer of PRC taxable assets, if such arrangement does not have a reasonable commercial purpose and was established for the purpose of avoiding payment of Chinese mainland enterprise income tax. As a result, gains derived from such indirect transfer may be subject to Chinese mainland enterprise income tax. In respect of an indirect offshore transfer of assets of a mainland establishment, the gain is to be regarded as effectively connected with the Chinese mainland establishment and therefore included in its enterprise income tax filing, and would consequently be subject to Chinese mainland enterprise income tax at a rate of 25%. Where the underlying transfer relates to the immoveable properties in the Chinese mainland or to equity investments in a Chinese mainland resident enterprise, which is not effectively connected to a mainland establishment of a non-resident enterprise, a Chinese mainland enterprise income tax at 10% would apply, subject to available preferential tax treatment under applicable tax treaties or similar arrangements, and the party who is obligated to make the transfer payments bears the withholding obligation. Pursuant to SAT Bulletin 37, the withholding party shall declare and pay the withheld tax to the competent tax authority in the place where such withholding party is located within seven days from the date of occurrence of the withholding obligation. Both SAT Bulletin 37 and SAT Bulletin 7 do not apply to transactions of sale of shares by investors through a public stock exchange where such shares were acquired from a transaction through a public stock exchange.
The Organization for Economic Cooperation and Development, or the OECD, introduced a framework for the implementation of a 15% global minimum tax (Pillar Two). Various OECD member countries have either enacted or are in the process of enacting Pillar Two legislation. This legislation has not yet enacted in the Chinese mainland while was enacted in Hong Kong and became effective for the year ended December 31, 2025.
Regulations on Value-added Tax
The Provisional Regulations of the PRC on Value-added Tax were promulgated by the State Council on December 13, 1993 and came into effect on January 1, 1994 and were subsequently amended in 2008, 2016 and 2017, and were repealed by the PRC Value-added Tax Law promulgated by the National People’s Congress on December 25, 2024, and came into effective on January 1, 2026. The Detailed Rules for the Implementation of the Provisional Regulations of the PRC on Value-added Tax (Revised in 2011) were promulgated by the Ministry of Finance on December 25, 1993 and subsequently amended on December 15, 2008 and October 28, 2011. On November 19, 2017, the State Council promulgated the Decisions on Abolishing the Provisional Regulations of the PRC on Business Tax and Amending the Provisional Regulations of the PRC on Value-added Tax, or Order 691. According to the Provisional Regulations of the PRC on Value-added Tax, the Detailed Rules for the Implementation of the Provisional Regulations of the PRC on Value-added Tax and Order 691, all enterprises and individuals engaged in the sales of goods, the provision of processing, repair and replacement services, sales of services, intangible assets and real properties and the importation of goods within the territory of the Chinese mainland are subject to value-added tax. The value-added tax rates generally applicable are simplified as 17%, 11%, 6% and 0%, and the value-added tax rate applicable to the small-scale taxpayers is 3%.
On April 4, 2018, Adjustment to Value-added Tax Rates, or Bulletin 32, was promulgated by the Ministry of Finance and the State Administration of Taxation, which came into effect on May 1, 2018. According to Bulletin 32, the value-added tax rates of 17% and 11% are changed to 16% and 10%, respectively. On March 20, 2019, the Ministry of Finance, the State Administration of Taxation and the General Administration of Customs jointly promulgated the Announcement on Policies for Deepening the Value-added Tax Reform or Notice 39, which came into effect on April 1, 2019 and were amended on September 1, 2025. Notice 39 further changes the value-added tax rates of 16% and 10% to 13% and 9%, respectively.
Under the PRC Value-added Tax Law, all the enterprises and individuals engaged in the sales of goods, services, intangible assets, real properties and importation of goods within the territory of the Chinese mainland are subject to value-added tax. The general value-added tax rates remain at 13%, 9%, 6% and 0%, and the value-added tax rate applicable to small-scale taxpayers remains at 3%. In addition, the PRC Value-added Tax Law clarifies that when overseas entities and individuals conduct taxable transactions within the Chinese mainland, the purchasers shall act as the withholding agents, unless a domestic agent is appointed to file a tax return and pay tax in accordance with the provisions of the State Council.
108
Table of Contents
Regulations Relating to Anti-Monopoly
The Standing Committee of the National People’s Congress promulgated the Anti-Monopoly Law of the PRC on August 30, 2007, which came into effect on August 1, 2008 and last amended on June 24, 2022, reiterates that monopolistic conduct such as entering into monopoly agreements, abuse of such position and concentration of undertakings that have the effect of eliminating or restricting competition are prohibited. Furthermore, a business operator with a dominant market position may not abuse its dominant market position to conduct acts such as selling commodities at unfairly high prices or purchasing commodities at unfairly low prices, selling products at prices below cost without any justifiable cause, and refusing to trade with a trading party without any justifiable cause. Sanctions for the violations of the prohibition on the abuse of dominant market position include an order to cease the relevant activities, confiscation of the illegal gains and fines (from 1% to 10% of sales revenue from the previous year).
On August 3, 2008, the State Council issued the Provisions of the State Council on the Thresholds for Declaring Concentration of Business Operators, and last amended and took effective on January 22, 2024. Pursuant to the Anti-Monopoly Law of the PRC and such provisions, when a concentration of undertakings occurs and reaches any of the following thresholds, the undertakings concerned shall file a prior notification with the Anti-Monopoly agency (i) the total global turnover of all operators participating in the transaction exceeded RMB12 billion in the preceding fiscal year and at least two of these operators each had a turnover of more than RMB800 million within the Chinese mainland in the preceding fiscal year, or (ii) the total turnover within the Chinese mainland of all the operators participating in the concentration exceeded RMB4 billion in the preceding fiscal year, and at least two of these operators each had a turnover of more than RMB800 million within the Chinese mainland in the preceding fiscal year are triggered, and no concentration shall be implemented until the Anti-Monopoly agency clears the Anti-Monopoly filing. If a concentration of business operators does not satisfy the threshold for declaration as prescribed, but there is evidence proving that the concentration has or may have the effect of eliminating or restricting competition, the anti-monopoly law of the PRC enforcement authorities of the State Council may request the business operators to make a concentration declaration. “Concentration of undertakings” means any of the following: (i) merger of undertakings; (ii) acquisition of control over another undertaking by acquiring equity or assets; or (iii) acquisition of control over, or exercising decisive influence on, another undertaking by contract or by any other means.
On February 7, 2021, the Anti-monopoly Commission of the State Council published the Guidelines on Anti-Monopoly Issues in Platform Economy, which took effect on the same date. These guidelines set out detailed standards and rules in respect of definition of relevant markets, typical types of cartel activity and abusive behavior by the operators of Internet platform with market dominance, as well as merger control review procedures, which provide further guidelines for enforcement of Anti-Monopoly laws regarding online platform operators.
On January 28, 2026, the SAMR released the Anti-monopoly Compliance Guidelines for Internet Platforms, which took effect on the same date. According to the Anti-monopoly Compliance Guidelines for Internet Platforms, platform operators shall strengthen anti-monopoly compliance management to maintain fair market competition and promote the healthy development of the platform economy. Platform operators shall not use data, algorithms, technology, capital advantages, platform rules or other methods, to engage in monopolistic conduct prohibited by the Anti-monopoly Law of the PRC. Platform operators shall avoid engaging in monopolistic agreements and abusing a dominant market position, and shall not organize or substantively help other operators to reach monopolistic agreements. Furthermore, platforms with significant market share or market power are encouraged to periodically assess whether they hold a dominant market position, and an operator with a dominant market position shall refrain from abusive practices including unfair pricing, predatory pricing without justifiable grounds, refusing to trade, restricting transactions, tying or imposing unreasonable conditions and applying differential treatment.
109
Table of Contents
The Anti-Unfair Competition Law were promulgated by the State Council on September 2, 1993 and came into effect on December 1, 1993 and were subsequently amended in 2017 and 2019, and last amended on June 27, 2025, with effect from October 15, 2025. According to the Anti-Unfair Competition Law, unfair competition refers to that the operator disrupts the market competition order and damages the legitimate rights and interests of other operators or consumers in violation of the provisions of the Anti-Unfair Competition Law in the production and operating activities. Pursuant to the Anti- Unfair Competition Law, operators must abide by the principle of voluntariness, equality, impartiality, integrity and adhere to laws and business ethics during market transactions. Operators in violation of the Anti-Unfair Competition Law should bear corresponding civil, administrative or criminal liabilities depending on the specific circumstances.
On May 6, 2024, the SAMR promulgated the Interim Provisions Against Unfair Competition in Cyberspace, which became effective on September 1, 2024. This regulation aims to maintain the market order of fair competition, encourage innovation, protect the legitimate rights and interests of business operators and consumers and promote the standardized, sustainable and sound development of the digital economy. This regulation specified the specific behaviors of online unfair competition that should be prohibited, for example, the business operator shall not (i) make use of the Internet, big data, algorithms and other technical means to commit traffic hijacking, interference, malicious incompatibility and other acts by influencing users’ choices or otherwise to impede or disrupt the normal operation of cyber goods or services legally provided by other business operators; (ii) intercept or block the information content and webpages legally provided by specific business operators, impede, or disrupt the normal operation of cyber goods or services legally provided by other business operators, and disrupt the fair competition order of the market; and (iii) make use of technical means to unreasonably provide different transaction conditions for its counterparties with identical conditions, infringe upon the right to option and fair transactions of the counterparties, impede or disrupt the normal operation of cyber goods or services legally provided by other business operators, and disrupt the fair transaction order of the market. Any business operator engaging in monopolistic conduct by excluding or restricting competition in cyberspace will be subject to penalties under the Anti-Monopoly Law of the PRC.
On March 10, 2023, the SAMR issued the Provisions on the Review of Concentration of Undertakings and the Provisions on the Prohibition of Acts of Abuse of Dominant Market Position, which came into effect on April 15, 2023. The SAMR issued the Provisions on the Prohibition of Monopoly Agreements on March 10, 2023, which was amended on December 9, 2025, with effect from February 1, 2026. The SAMR also issued the Provisions on the Prohibition of Acts of Abuse of Administrative Power to Exclude or Restrict Competition on March 10, 2023, which was amended on December 18, 2025, with effect from February 1, 2026. These provisions provide detailed rules for the implementation of the Anti-Monopoly Law of the PRC.
110
Table of Contents
C. Organizational Structure
The following diagram illustrates our corporate structure, including our significant subsidiaries and the VIE, as of the date of this annual report:
Notes:
(1) “Our WFOE” refers to Beijing Glorywolf Co., Ltd. from May 2014 to December 2023 and Beijing Highland Wolf Technology Co., Ltd. from January 2024 onwards.
(2) Shareholders of the VIE and their respective shareholdings in the VIE and relationships with our company are (i) Mr. Peng Zhao 99.5%, our Founder, Chairman and Chief Executive Officer; and (ii) Ms. Xu Yue 0.5%, our financial director. See “Item 3. Key Information—D. Risk Factors—Risks Relating to Our Corporate Structure—The shareholders of the VIE may have actual or potential conflicts of interest with us.”
Contractual Arrangements with the VIE and Its Shareholders
Current laws and regulations of the Chinese mainland impose certain restrictions or prohibitions on foreign ownership of companies that engage in value-added telecommunication services and certain other businesses. We are an exempted company incorporated in the Cayman Islands. Our WFOE is our subsidiary in the Chinese mainland and is a foreign-invested enterprise under PRC Laws. To comply with laws and regulations of the Chinese mainland, we conduct certain of our business in the Chinese mainland through the VIE based on a series of contractual arrangements by and among our WFOE, the VIE and its shareholders.
111
Table of Contents
Our contractual arrangements with the VIE and its shareholders allow us to (i) direct the activities of the VIE, (ii) receive substantially all of the economic benefits of the VIE, (iii) have the pledge right over the equity interests in the VIE as the pledgee, and (iv) have an exclusive call option to purchase all or part of the equity interests and/or assets in the VIE when and to the extent permitted by laws of the Chinese mainland.
As a result of our direct ownership in our WFOE and the contractual arrangements with the VIE, we are regarded as the primary beneficiary of the VIE, and we treat the VIE as our consolidated entities under U.S. GAAP. We have consolidated the financial results of the VIE in our consolidated financial statements in accordance with U.S. GAAP.
The following is a summary of the currently effective VIE contractual agreements by and among our WFOE, the VIE and its shareholders.
Agreements that allow us to direct the activities of the VIE
Powers of Attorney. Pursuant to the powers of attorney entered into by the VIE, its shareholders and our WFOE, each of the VIE shareholders unconditionally and irrevocably agrees to appoint our WFOE and/or its designee as their sole and exclusive agent to act on their behalf on all matters concerning the VIE and to exercise all of their rights as shareholder of the VIE, including but not limited to: (i) to propose, convene and attend shareholders’ meetings of the VIE and sign minutes and resolutions of the shareholders’ meeting on their behalf; (ii) to exercise all shareholder rights that they are entitled to under PRC laws and the articles of association of the VIE, including, but not limited to, the right to vote as a shareholder, and the right to sell or transfer or pledge or dispose of all or any part of their shareholding; and (iii) acting as their authorized representative to elect, designate and appoint the legal representative, chairman, directors, supervisors, general manager and other senior executives of the VIE. The powers of attorney will be terminated, among other things, under certain conditions when our WFOE or its designee is duly registered as the sole shareholder of the VIE on the premise that PRC laws permit our WFOE, or its offshore parent company or any subsidiary directly or indirectly controlled by it, to directly hold equity interest in and legally engage in the business conducted by the VIE.
Equity Pledge Agreement. Under the equity pledge agreement among our WFOE, the VIE and its shareholders dated January 1, 2024, each of the VIE shareholders agreed to pledge all of their respective equity interests in the VIE to our WFOE as a security interest to guarantee performance of their contractual obligations under the VIE contractual agreements and all liabilities, monetary debts or other payment obligations arising out of or in relation with the VIE contractual agreements.
Among other things, the VIE shareholders have undertaken that without our WFOE’s prior written consent, they shall not directly or indirectly transfer the equity interests in any way, create or permit the existence of any pledge or other form of security which might affect the rights and interests of our WFOE, other than the transfer of such equity interests to our WFOE or its designee pursuant to the exclusive purchase option agreement discussed below.
Upon the occurrence of an event of default (as defined in the equity pledge agreement), our WFOE may, at any time thereafter, serve a default notice to the VIE shareholders, upon which our WFOE may (1) demand all the outstanding payment due according to the exclusive technology and service co-operation agreement discussed below, and/or (2) exercise its right of pledge according to the equity pledge agreement, or otherwise dispose of the pledged equity interest in accordance with applicable Laws, unless the event of default has been resolved in the satisfactory of our WFOE within 30 days after the default notice has been served. Our WFOE may exercise such right of pledge based on its own independent judgment. The shareholders of the VIE and the VIE have covenanted to unconditionally collaborate with our WFOE when our WFOE exercises such right of pledge. Our WFOE shall bear no responsibilities for any direct or indirect loss incurred consequent upon its exercise of such right of pledge.
The equity pledge agreement shall remain effective until, among others, the VIE and its shareholders have recorded the release of such pledged equity interests in the register of members of the VIE and completed the deregistration procedure.
We have completed the registration of the equity interest pledge under the equity pledge agreement in relation to the VIE with the relevant office of the SAMR in accordance with applicable laws and regulations of the Chinese mainland.
112
Table of Contents
Agreements that allow us to receive economic benefits from the VIE
Exclusive Technology and Service Co-operation Agreement. Pursuant to the exclusive technology and service co-operation agreement among our WFOE, the VIE and its shareholders dated January 1, 2024, our WFOE has the exclusive right to provide technical consultancy, technical support, and other services, which may include (i) provision of advices on business management; (ii) provision of advices on IT system and other technical support; (iii) provision of business support, marketing and promotion; (iv) provision of development, maintenance and upgrade of software; (v) provision of human resources support; (vi) provision of leasing services to equipment; and (vii) other services requested from time to time.
Without our WFOE’s prior written consent, the VIE shall not, and shall procure its subsidiaries not to, receive services which are identical or similar to the services covered by the exclusive technology and service co-operation agreement from any third party (as defined in the exclusive technology and service co-operation agreement).
In consideration of the services provided by our WFOE, the VIE shall pay service fee to our WFOE. Pursuant to the exclusive technology and service co-operation agreement, the service fees shall be equivalent to the total consolidated profit of the VIE and its subsidiaries, after offsetting the prior-year loss (if any), operating costs, expenses, taxes and other statutory contributions. Notwithstanding the foregoing, our WFOE shall have the right to adjust the level of the service fees by taking into account such factors as (a) the complexity and difficulty of the services involved, (b) the time taken for the services, (c) the scope of management and technical consulting and other services and their commercial value, (d) the scope of intellectual property licensing and leasing services and their commercial value, and (e) the market reference price for services of similar kinds. The VIE shall pay the service fees to our WFOE within 30 business days after given payment instructions by our WFOE.
Our WFOE has the exclusive and proprietary rights and interest to all intellectual properties, irrespective of being developed by the VIE or by our WFOE. Without the prior written consent of our WFOE, the VIE shall not, and shall procure its subsidiaries not to, transfer, assign, pledge, or by any other means dispose of any of such intellectual properties.
The exclusive technology and service co-operation agreement shall remain effective until, among others, the date on which our WFOE or the party designated by our WFOE is formally registered as the shareholder of the VIE, in the case where our WFOE is permitted by the PRC laws to directly hold the shares of the VIE and our WFOE and its subsidiaries and affiliates are allowed to engage in the Relevant Businesses being currently operated by the VIE.
Agreements that provide us with the option to purchase the equity interests in the VIE
Exclusive Purchase Option Agreement. Under the exclusive call option agreement among our WFOE, the VIE and its shareholders dated January 1, 2024, our WFOE, or its offshore parent company or its directly or indirectly owned subsidiaries was granted an irrevocable and exclusive right by the VIE shareholders to purchase from each of the VIE shareholders all or any part of their respective equity interest in the VIE.
The VIE and its shareholders irrevocably covenanted that they shall procure each of the subsidiaries of the VIE to observe the same covenants as those made by the VIE under the corresponding provisions in the exclusive purchase option agreement that, among others, (i) unless with prior written consent by our WFOE, the VIE shall not sell, transfer, pledge, or otherwise dispose all or any part of its assets (other than the assets necessary for its ordinary course of business); (ii) without the prior consent by our WFOE, no actions or omissions would be taken that would adversely affect the operation status and asset value of the VIE; and (iii) upon the request of our WFOE, the VIE shareholders and the VIE shall appoint the party designated by our WFOE as the director, supervisor and/or senior officer of the VIE and/or remove the incumbent directors, supervisors and/or senior officers of the VIE and implement all applicable resolutions and filing procedures. In addition, the VIE shareholders irrevocably covenanted that they shall not sell, transfer, pledge, or otherwise dispose all or any part of its equity interest in the VIE, other than the creation of the pledge of the VIE’s equity interest pursuant to the VIE contractual agreements.
The purchase price payable by our WFOE or its designee in respect of the transfer of the entire equity interest and/or the total assets of the VIE shall be the nominal price, or the minimum price required by competent PRC authorities or PRC laws. However, in any event, subject to the provisions and requirements of PRC laws, the price paid by our WFOE and/or its designee to the VIE and/or VIE shareholders at any such price shall be returned by the VIE and/or VIE shareholders to our WFOE at the time and in the form requested by our WFOE.
113
Table of Contents
The exclusive purchase option agreement shall remain effective for ten years with our WFOE having the option to renew it until all the equity interest in and/or all assets of the VIE has been transferred to our WFOE and/or its designee (registration has been completed for the change of members) and our WFOE and its subsidiaries and branches can legally engage in the business of the VIE.
The VIE and its shareholders, among other things, have covenanted that: (i) without the prior written consent of our WFOE, they shall not supplement, alter or modify the articles of association of the VIE, or change its registered capital or capital structure in any way; (ii) they shall maintain the VIE’s corporate existence and conduct its business and affairs prudently and efficiently; (iii) without the prior written consent of our WFOE, the VIE will not sell, transfer, pledge or otherwise dispose of any of its assets (except for what is required for daily business operations), business or revenue; (iv) without the prior written consent of our WFOE, the VIE will not incur, inherit, guarantee or permit any debt except for: debts arising in the ordinary or usual course of business other than by means of loans; and debts that have been disclosed to and agreed in writing by our WFOE; (v) they shall maintain the ordinary business operations of the VIE so as to maintain the value of the VIE’s assets, and shall not perform any act/omission which would be sufficient to affect its business condition and the value of its assets; (vi) without the prior written consent of our WFOE, the VIE shall not enter into any material contract other than contracts entered into in the ordinary and normal course of business and contracts entered into by the VIE and our WFOE’s overseas parent company and/or the subsidiaries directly or indirectly controlled by such parent company; (vii) without the prior written consent of our WFOE, the VIE shall not provide any loan or security to any person; (viii) upon the request of our WFOE, the VIE will provide to our WFOE all the information concerning its operating and financial status; (ix) without the prior written consent of our WFOE, they shall not procure or consent the VIE to merge or form a joint venture with any entities, or acquire or make investment in any entity; (x) they shall immediately notify our WFOE and take all necessary actions pursuant to the reasonable requirements of our WFOE when there is any litigation, arbitration or administrative proceedings that would occur or might occur in connection with the VIE’s assets, business and revenue; (xi) to protect the VIE’s ownership of all its assets, they shall execute all necessary or appropriate documents, take all necessary or appropriate actions and file all necessary or appropriate claims or take necessary and appropriate defense against all claims; (xii) without the prior written consent of our WFOE, the VIE shall not distribute dividends in any form to its shareholders, but shall, upon the request of our WFOE, immediately distribute all distributable profits to its respective shareholders; and (xiii) the VIE shall, upon the request of our WFOE, appoint or terminate the appointment of any person designated by our WFOE to act as a director of the VIE.
The VIE shareholders, among other things, have further covenanted that: (i) without the prior written consent of our WFOE, they shall not sell, transfer, pledge or dispose legal or beneficial interest in the VIE, or impose any encumbrances on such rights and interests, other than the creation of the pledge of the VIE’s equity interest pursuant to the VIE contractual agreements; (ii) shall not engage in any business operation or conduct in any manner which may impose an adverse impact on the reputation of the VIE; (iii) without our WFOE’s prior written consent, they shall procure board of directors and/or shareholders’ meetings of the VIE not to approve the sale, transfer, pledge, or disposal of legal or beneficial interest of any equity interest or assets, or allow creation of any encumbrances thereon, other than the creation of the pledge of the VIE’s shares pursuant to the VIE contractual agreements; (iv) without our WFOE’s prior written consent, they shall not procure board of directors and/or shareholders’ meetings of the VIE to approve a merger, or consolidation, or acquisition in any person, or divestment of the VIE, revision of its articles of associations, or change in registered capital or its corporate status; (v) the VIE shareholders shall not instruct the VIE to pay any dividends or bonus or to convene a shareholders’ meeting in relation thereto, or to vote in favour of such matter at such meeting; and (vi) they shall abide strictly by the VIE contractual agreements, perform the obligations under such agreements effectively, and not take any actions or omissions which may adversely affect the validity and enforceability of such agreements.
Spousal Consent. Pursuant to the spousal consent letter executed by the spouses of both shareholders of the VIE on January 1, 2024, the signing spouse unconditionally and irrevocably consents to the execution of the exclusive technology and service co-operation agreement, the equity pledge agreement, the exclusive purchase option agreement, and the powers of attorney executed by Mr. Zhao or Ms. Yue (as the case may be) and to the disposal in accordance therewith of the equity interest in the VIE held by Mr. Zhao or Ms. Yue (as the case may be). Each of the spouses also undertook (i) not to make any claim with respect to the equity interest in the VIE; (ii) to execute all documents and take all actions necessary to ensure that the exclusive technology and service co-operation agreement, the equity pledge agreement, the exclusive purchase option agreement and the powers of attorney (as amended from time to time) are properly performed; and (iii) if for any reason the spouses acquire any of the equity held by the VIE shareholder in the VIE, to be bound by the aforementioned documents and execute any required written documents for such purpose.
In the opinion of Tian Yuan Law Firm, our PRC legal counsel:
● the ownership structures of the VIE and our WFOE in China are not in violation of applicable mandatory laws and regulations of the Chinese mainland currently in effect; and
● each of the agreements under the contractual arrangements among our WFOE, the VIE and its shareholders governed by PRC law currently is valid and binding, and do not violate applicable PRC laws or regulations currently in effect.
114
Table of Contents
However, our PRC legal counsel has also advised us that there are substantial uncertainties regarding the interpretation and application of current and future laws of the Chinese mainland, regulations and rules. Accordingly, the PRC regulatory authorities may take a view that is contrary to the opinion of our PRC legal counsel. It is uncertain whether any new laws or regulations of the Chinese mainland relating to VIE structures will be adopted or if adopted, what they would provide. If we or the VIE are found to be in violation of any existing or future laws or regulations of the Chinese mainland, or fail to obtain or maintain any of the required permits, approvals, or filings, the PRC regulatory authorities would have broad discretion to take action in dealing with such violations or failures. See “Item 3. Key Information—D. Risk Factors—Risks relating to Our Corporate Structure—If the PRC government finds that the agreements that establish the structure for operating some of our operations in the Chinese mainland do not comply with laws and regulations of the Chinese mainland relating to the relevant industries, or if these laws and regulations or the interpretation of existing laws and regulations change in the future, we could be subject to severe penalties or be forced to relinquish our interests in those operations,” “Item 3. Key Information—D. Risk Factors—Risks Relating to Our Corporate Structure—Our current corporate structure and business operations may be substantially affected by the Foreign Investment Law” and “Item 3. Key Information—D. Risk Factors—Risks Relating to Doing Business in China—Uncertainties in the interpretation and enforcement of PRC laws and regulations could adversely affect us.”
D. Property, Plants and Equipment
Our headquarters are based in Beijing and we have offices in 32 cities in the Chinese mainland. We leased properties in the Chinese mainland with a total gross floor area of approximately 86,292.91 square meters as of the date of this annual report. Our leased properties are mainly used as offices. They mainly include premises for our headquarters and offices. We believe that our existing facilities are generally adequate to meet our current needs, but we expect to seek additional space as needed to accommodate future growth.