Why Data Catalogs Miss the Real Risks in Data Security Assessment
The article argues that data security risk assessment must shift from static data catalogs to analyzing dynamic processing activities—who uses data, for what purpose, via which channels, and with what accountability—citing China's new Network Data Security Risk Assessment Measures and providing a four-question framework to evaluate whether assessments truly capture risk in scenarios like AI-driven data flows.
