Key points are not available for this paper at this time.
: As data governance legislation proliferates globally, whether such regulation catalyzes operational upgrading within firms or merely imposes compliance costs remains an open question. We examine the micro-level behavioral consequences of China’s Data Security Law through corporate digital procurement, the operational domain where data exchange with upstream partners is most intensive and regulatory demands most directly binding. Because the law applies nationally but weighs more heavily on firms in provinces with weaker pre-existing data security infrastructure, we exploit this cross-regional variation in a difference-in-differences framework using Chinese A-share listed firms from 2016 to 2024. Firms facing stronger policy exposure raise their digital procurement intensity by about 24.4% of the sample mean, an effect robust to a comprehensive set of identification, measurement, and placebo checks. The response operates through three complementary channels: consolidation of the supplier portfolio, reallocation of managerial attention toward digitalization, and intensified external audit oversight. It is more pronounced among manufacturing firms and firms with dispersed ownership, and comparable across state and non-state enterprises. Because regimes such as the GDPR and U.S. cybersecurity disclosure rules impose similar obligations, the evidence identifies procurement digitalization as a margin of operational upgrading whose relevance reaches beyond the Chinese setting.
Lv et al. (Wed,) studied this question.