Didi to delist from New York and go public in Hong Kong
Source: | Author: Asia Compliance Forum | Publish time: 2021-12-03 | 501 Views | 🔊 Click to read aloud ❚❚ | Share:


Chinese ride-hailing giant Didi Chuxing, which was listed in New York in late June but triggered a cybersecurity probe two days later, announced today that it would start the process to delist from the New York Stock Exchange and prepare for a Hong Kong initial public offering (IPO).

Didi said on its official Weibo account that, “After careful study, the company will start the work of delisting from NYSE and initiate preparation for listing in Hong Kong with immediate effect.”


Timeline

  • June 11, 2021 - Didi makes public the filing for its U.S. listing, setting the stage for what is expected to be the world's biggest initial public offering of 2021.

  • June 30,2021 - Didi raises $4.4 billion in its IPO.

  • July 2, 2021 – Cyberspace Administration of China (CAC) announced that it would implement a network security review of Did, citing as authority the Cybersecurity Review Measures, National Security Law and Cybersecurity Law. Didi is ordered to stop all new user registration during the security review period to prevent the expansion of risk.

  • July 4, 2021 –The CAC announced that “after testing and verification, the Didi App has been found to have serious problems regarding the illegal and irregular use of personal information collection”. The CAC ordered Didi’s apps to be taken down from app stores.

  • July 5, 2021 – The CAC announced that it also launched cybersecurity investigations into three other companies (Yunmanman, Huochebang, and Boss Zhipin) that recently debuted on the U.S. stock exchanges and asked them to stop registering new users.

  • July 9, 2021 – Chinese authorities ordered app stores in China to remove 25 apps owned and operated by DiDi, including Didi Chuxing Enterprise Edition, Uber China, and D-Chat.

  • July 10, 2021 – The CAC proposed to revise the Cybersecurity Review Measures, which came into effect in June 2020, adding, among other things, a new security assessment requirement for certain overseas IPOs.

  • July 16, 2021 – The CAC, Ministry of Public Security (in charge of domestic security), Ministry of State Security (civilian arm for intelligence gathering and counterespionage), Ministry of Natural Resources (in charge of mapping and road surveying), the Ministry of Transport (regulates the ride-hailing industry) as well as the tax and antitrust regulators (SAMR) launched an investigation into Didi’s data security. Didi is the first major internet company to be publicly subject to the cybersecurity review.

  • December 3, 2021 - Didi announced that it would start the process to delist from the New York Stock Exchange and prepare for a Hong Kong IPO.


Data Security Assessment for Overseas Listing

Following the Didi investigation, China immediately issued the draft revised Cybersecurity Review Measures requiring network operators that possess personal information of more than 1,000,000 users to go through a mandatory cybersecurity review with the CAC before listing overseas.

The Cybersecurity Review Measures are initially intended to safeguard cybersecurity and supply chain security among critical information infrastructure operators (CIIOs) by requiring that CIIOs undergo a cybersecurity review when procuring network products and services that may implicate national security concerns. The draft revised Cybersecurity Review Measures significantly expand the security assessment requirement from CIIOs’ procurement of network products and services to certain overseas listings and data processing activities of CIIOs and non-CIIOs. In assessing the potential national security risks posed by an proposed overseas listing, the CAC would considers factors such as the risks of CII, core data, important data and massive personal information being influenced, controlled or maliciously exploited by a foreign government following the overseas listing of a Chinese company.

The draft revised Cybersecurity Review Measures, if promulgated in their current form, would potentially subject a variety of Chinese companies that process massive personal information, core data or important data, not just CIIOs, contemplating overseas listings, to the cybersecurity review by the CAC.

On November 14, 2021, the CAC issued the draft Network Data Security Regulations which reiterate the security assessment for overseas listing by network operators that process personal information of more than 1,000,000 individuals. In addition, the draft Network Data Security Regulations also clarify that companies that seek Hong Kong listing would also be subject to the security assessment if it affects or may affect China’s national security. That said, delisting from Nasdaq and relisting in Hong Kong may not exempt Didi from the security assessment requirement given the volume and sensitivity of data processing by the company.


Enhanced Regulations on Provisions of Data to Foreign Judicial or Enforcement Authorities

China recently issued a series of new laws, such as the Data Security Law and Personal Information Protection Law, that prohibit companies from providing data stored in China to foreign judicial or enforcement agencies without first obtaining the approval from competent Chinese authorities.  

Such restrictions on cross-border data transfers could create tensions over data sovereignty when companies list overseas and subject themselves to foreign securities or other regulatory requirements. For instance, companies listed in the U.S. may be required to reveal audit documents that contain sensitive information on operations in order to comply with the U.S. accounting standards. The interim final rule of the Holding Foreign Companies Accountable Act directs the US Securities and Exchange Commission (SEC) to prohibit exchanges in the U.S. from trading the securities of certain identified foreign issuers whose financial statements have not been audited by accounting firms subject to inspection by the Public Company Accounting Oversight Board for three consecutive years.

The PRC Data Security Law and Personal Information Protection Law could be invoked by the Chinese authorities to prevent these listed companies from handing over important or sensitive data to the SEC.


Possible Policy Changes related to the VIE Structure

Variable interest entity (VIE) is a complicated contractual control structure that commonly used by Chinese technology companies. Recently, there are reports that China may ban variable interest entities (VIEs) from listing overseas. (https://www.reuters.com/markets/asia/chinas-vie-problem-is-resolving-itself-2021-12-02/) However, China's securities regulator denied such speculations on December 1, 2021 (https://www.channelnewsasia.com/business/china-regulator-denies-media-report-china-will-ban-vies-listing-overseas-2351101). There are concerns that VIEs may encounter more stringent scrutiny with respect to cybersecurity, including with respect to the transfer of data overseas by the onshore companies. Companies would need to closely monitor the developments in this respect and adjust their financing structure and strategies accordingly if any changes occur.