Xiaohongshu Data Collection: Legal & Ethical Approaches to XHS Data
Date Published
Table Of Contents
• Why XHS Data Matters for International Brands
• What Types of Data Exist on Xiaohongshu
• The Legal Landscape: China's Three-Pillar Data Framework
• How PIPL Affects International Brands Collecting XHS Data
• Public Data vs. Private Data: Where the Line Is Drawn
• Ethical Principles for Responsible XHS Data Collection
• Legitimate Use Cases: What You Can and Should Do with XHS Data
• Common Compliance Mistakes to Avoid
• Practical Steps for a Compliant XHS Data Strategy
For international brands targeting Chinese consumers, Xiaohongshu (XHS) — also known as RedNote or Little Red Book — is no longer optional intelligence. With over 300 million monthly active users and a search-driven discovery model that shapes purchase decisions across beauty, fashion, food and beverage, and dozens of other categories, the platform generates a rich stream of consumer signals that savvy marketers are increasingly eager to tap. The question that stops most teams in their tracks, however, isn't strategic — it's legal: Can we actually collect this data, and how do we do it without crossing a line?
This guide answers that question directly. We'll walk through China's data protection framework, explain what it means specifically for brands collecting Xiaohongshu data, clarify the critical distinction between public and private data, and outline the ethical practices that keep your research program both compliant and credible. Whether you're building a trend-monitoring workflow, conducting KOL research, or benchmarking competitors, understanding these boundaries isn't just about legal risk management — it's about doing business in China the right way.
Why XHS Data Matters for International Brands {#why-xhs-data-matters}
Xiaohongshu occupies a unique position in the Chinese digital ecosystem. Unlike platforms that prioritize entertainment or social connection, XHS functions as a product discovery engine fueled by user-generated content — notes (posts combining images, short video, and text), reviews, and authentic community recommendations. For international brands, this makes it one of the most valuable listening environments available anywhere in China.
The platform's data reveals not just what consumers are buying, but why — the language they use, the concerns they raise, the aesthetics they respond to, and the influencers they trust. Brands that systematically analyze this data can reduce their content testing cycles, sharpen their KOL selection, and identify emerging trends before they saturate the market. It's the difference between guessing what Chinese consumers want and actually knowing.
But this intelligence only serves you if you collect and use it responsibly. Collecting XHS data carelessly — or ignoring the regulatory environment entirely — exposes your brand to legal liability in China and reputational damage that can be very difficult to recover from in a trust-driven community like Xiaohongshu.
---
What Types of Data Exist on Xiaohongshu {#types-of-xhs-data}
Before addressing what's legal, it helps to understand what kinds of data the platform actually contains. XHS data broadly falls into two categories: publicly visible content and non-public personal information.
Publicly visible data includes:
• Note content (titles, body text, hashtags, location tags)
• Engagement metrics (likes, collects/saves, comments, shares)
• Creator profile information (username, bio, follower count, following count)
• Comment threads on public notes
• Search trend data and keyword popularity signals
• Product tags and linked items
Non-public or private data includes:
• Direct messages and private conversations
• Phone numbers, email addresses, and contact details
• Account credentials or session-level data
• Any data that requires bypassing a login wall to access
• Behavioral data tied to individual user identities at scale
This distinction matters enormously from a legal standpoint, and most compliant data collection strategies for brand intelligence purposes operate entirely within the first category. The moment you venture into non-public data — regardless of how you obtain it — you're operating in territory that carries serious legal risk under multiple applicable laws.
---
The Legal Landscape: China's Three-Pillar Data Framework {#legal-landscape}
China's approach to data regulation is not a single law — it's a layered framework built on three major pieces of legislation, each addressing a different dimension of how data is collected, processed, and transferred.
1. The Personal Information Protection Law (PIPL) — Effective November 1, 2021, PIPL is China's comprehensive personal data privacy law. It governs the collection, use, storage, sharing, and transfer of personal information of individuals in mainland China. In structure and spirit it resembles the EU's GDPR, but it has its own distinct requirements, consent standards, and enforcement mechanisms. Crucially, PIPL does not recognize "legitimate interest" as a lawful basis for data processing the way GDPR does — a distinction that has significant implications for marketing-related data collection.
2. The Cybersecurity Law (CSL) — Effective since June 2017, China's Cybersecurity Law focuses on network security, data protection, and the obligations of network operators. It requires organizations operating in China to implement technical measures to prevent data leaks and unauthorized access, and it establishes data localization requirements for operators of critical information infrastructure.
3. The Data Security Law (DSL) — Effective September 2021, the DSL sits alongside PIPL and the CSL to govern data security across a broad category of data, not just personal information. It introduces classifications for "important data" that carry additional cross-border transfer restrictions.
For international brands collecting XHS data, all three layers are potentially relevant, though PIPL is the one most directly applicable to the kinds of user-generated data available on the platform.
---
How PIPL Affects International Brands Collecting XHS Data {#pipl-international-brands}
One of the most important — and frequently misunderstood — features of PIPL is its extraterritorial reach. The law applies not only to organizations processing data inside mainland China, but also to foreign entities outside China that process personal information of individuals located in China for the purpose of providing products or services, or for analyzing or evaluating their behaviors. This means a brand headquartered in London, New York, or Sydney that collects and processes data from Chinese consumers on XHS falls within PIPL's scope.
Under PIPL, personal information is defined broadly: any data — recorded electronically or otherwise — that can identify a natural person, either directly or indirectly. This covers names, usernames, contact information, location data, biometric data, and even behavioral patterns when they can be linked to an identifiable individual. Importantly, anonymized data that cannot be reversed to identify an individual is excluded from PIPL's scope, which creates a legitimate pathway for aggregated, de-identified trend research.
The law's core requirements for international brands to keep in mind include:
• Purpose limitation: Data collected must be used only for the specific, clearly stated purpose for which it was collected. Using XHS data gathered for competitor benchmarking to build a consumer targeting database, for example, would require fresh consent.
• Data minimization: Only the data actually necessary for the stated purpose should be collected and retained.
• Consent requirements: In most cases, PIPL requires explicit, informed consent before personal information is processed. Unlike GDPR, there is no general "legitimate interest" exception for commercial marketing activities.
• Cross-border transfer restrictions: If personal data collected from Chinese individuals is transferred outside mainland China, specific compliance mechanisms must be followed, including standard contractual clauses or passing a security assessment by Chinese regulators.
• Retention limits: Data should be retained only for as long as necessary, with clear deletion cycles.
Violations carry serious consequences. PIPL penalties can reach RMB 50 million or 5% of the previous year's annual revenues, and individuals found directly liable may face fines of up to RMB 1 million. Enforcement has become progressively more active — in 2025, Chinese regulators took formal legal action against a European luxury brand's Shanghai subsidiary for illegally transferring personal information overseas following a data breach.
For international brands operating on or monitoring Xiaohongshu, the takeaway is clear: PIPL compliance isn't theoretical risk management. It's a live regulatory obligation.
---
Public Data vs. Private Data: Where the Line Is Drawn {#public-vs-private}
A common source of confusion — and genuine legal risk — is the assumption that because data is publicly visible, it can be freely collected, redistributed, or commercially exploited without restriction. This is incorrect under both Chinese law and global best practice.
"Publicly visible" means anyone with platform access can see the content. It does not mean the creator has consented to that content being systematically harvested, aggregated, republished, or used in ways they never anticipated. Under PIPL, the obligation to notify data subjects applies broadly, and the law's purpose limitation principle means that data voluntarily shared in a social context cannot simply be repurposed for commercial data products without further legal basis.
Social media posts fall within PIPL's definition of personal information when they can be linked to an identifiable individual. This is why the distinction between aggregated, anonymized insights and individually-identifiable data collection is so important in practice. Collecting engagement trends across a category, analyzing which hashtags are gaining traction, or studying what types of content formats perform best — these activities involve aggregated signals that carry substantially lower legal risk than building a database of individual user profiles with linked behavioral histories.
Non-public data — direct messages, phone numbers, contact details, or any data sitting behind authentication walls — is firmly off-limits. Collecting this type of information carries significant legal risk under both PIPL and China's Cybersecurity Law, regardless of the technical method used to obtain it.
---
Ethical Principles for Responsible XHS Data Collection {#ethical-principles}
Legal compliance sets the floor, but ethical practice is what builds sustainable, trustworthy research operations — and protects your brand's standing in a community where authenticity is everything. The following principles should guide any XHS data program:
• Collect only what you need. Define your research question before you define your data set. If you're trying to understand trending skincare ingredients, you don't need individual user profiles — you need content signals.
• Don't circumvent platform protections. Bypassing authentication walls, using fake credentials, or deploying methods designed to defeat Xiaohongshu's anti-scraping measures is both a terms-of-service violation and a legal risk.
• Respect creators and their content. XHS creators are real people who have built genuine audiences. Don't republish their content without permission, and don't use their personal likenesses or detailed profile data in ways they would not sanction.
• Limit data retention. Set clear timelines for how long you keep data and build deletion into your workflow. This aligns with PIPL's minimization requirements and reduces your ongoing liability exposure.
• Keep personal and aggregated data clearly separated. If your research process touches any individually identifiable data, ensure it is either properly consented or promptly anonymized before analysis.
• Be transparent internally. Document your data collection methods, purposes, and retention policies. This positions you well for any internal audit or external regulatory inquiry.
---
Legitimate Use Cases: What You Can and Should Do with XHS Data {#legitimate-use-cases}
Within a compliant, ethically grounded framework, Xiaohongshu data is enormously valuable for international brands. Here are the primary use cases that are both legitimate and strategically high-value:
Trend and Category Intelligence. Monitoring which keywords, hashtags, and content themes are gaining traction within your product category gives you real-time consumer insight that no annual survey can match. This kind of aggregated trend analysis involves publicly visible signals and does not require collecting individual-level personal data.
Competitor Content Benchmarking. Analyzing publicly visible competitor brand accounts — their posting frequency, content formats, engagement rates, and KOL partnerships — is standard competitive research practice. Brands that do this systematically can identify content gaps, understand what messaging resonates, and avoid duplicating approaches that aren't working in the market.
KOL and Creator Discovery. Evaluating creator profiles — their audience size, engagement quality, content themes, and category fit — based on publicly available profile data and note performance metrics is a core part of influencer marketing on XHS. The key compliance consideration here is using this data to make partnership decisions, not to build and sell detailed personal dossiers.
Consumer Sentiment and Reputation Monitoring. Tracking how your own brand is being discussed, reviewed, and tagged across public notes and comment sections gives you early warning on reputation issues and a continuous feedback loop on product performance. This is one of the clearest cases where the research purpose (monitoring your own brand) closely aligns with data minimization principles.
Content Strategy Development. Understanding what visual formats, narrative styles, and key messages drive high engagement in your category informs content creation without requiring any personal data collection at all.
For brands wanting to develop a data-informed XHS strategy grounded in these use cases, AllXHS's industry-specific Xiaohongshu marketing strategies cover how these insights translate into platform-specific execution across 20+ verticals.
---
Common Compliance Mistakes to Avoid {#common-mistakes}
Even well-intentioned teams make compliance errors when they haven't thought through their XHS data practices carefully. These are the most common mistakes to watch for:
Treating "public" as "free to use for anything." Public visibility is not informed consent. Using publicly visible data for purposes far removed from its original context — particularly at scale and for commercial gain — is where many compliance violations begin.
Ignoring PIPL because you're based outside China. PIPL's extraterritorial scope is explicit. Foreign brands processing the personal information of Chinese residents are subject to the law regardless of where their servers sit. "We're not a Chinese company" is not a compliance defense.
Collecting more data than the use case requires. Broad, undifferentiated data harvesting creates storage liabilities, increases PIPL exposure, and rarely delivers better insights than targeted, purpose-defined collection. Define your question first.
Redistributing copyrighted creator content. Even if a note is publicly visible, its text, images, and video are the creator's intellectual property. Reproducing or republishing this content — in reports, marketing materials, or data products — without permission infringes copyright separate from any personal data concerns.
Not documenting your data practices. If you can't articulate what data you collected, why, how long you kept it, and how you protected it, you're not in a position to demonstrate compliance under PIPL's requirements.
---
Practical Steps for a Compliant XHS Data Strategy {#practical-steps}
Putting these principles into practice doesn't require a legal team on permanent standby — it requires clear process design from the start.
1. Define your research purpose before collection begins. Every data collection activity should begin with a documented statement of purpose. What question are you trying to answer? What decision will the data inform? This step drives everything else.
1. Audit what data types you actually need. Once your purpose is clear, map the minimum data required to answer it. For most brand intelligence use cases, aggregated signals (engagement rates, trending keywords, content format performance) are sufficient — individual user-level data is not required.
1. Use compliant data access methods. Whether you're working with a third-party data provider, a purpose-built API, or a manual monitoring workflow, ensure your data access method respects Xiaohongshu's terms of service and does not bypass platform authentication or anti-scraping measures.
1. Establish a retention and deletion policy. Decide at the outset how long your data will be kept and build deletion or anonymization into your workflow at that point. This is a PIPL requirement, not just a best practice.
1. Separate individual-level data from aggregated analysis. If your workflow touches any individually identifiable information, ensure it is anonymized or pseudonymized before it moves into analysis. Store it separately and limit access.
1. Get legal review for cross-border data transfers. If data collected from XHS users is being transferred outside mainland China — including to your headquarters or cloud storage — this requires compliance with one of PIPL's approved cross-border transfer mechanisms. Consult qualified legal counsel for your specific situation.
1. Keep documentation. Maintain internal records of your data sources, collection methods, purposes, and retention policies. This documentation becomes your first line of defense in any compliance inquiry.
For brands building more comprehensive XHS intelligence programs, AllXHS's free Xiaohongshu resources include research frameworks and tools designed specifically for international brands navigating the platform's unique landscape.
Final Thoughts {#final-thoughts}
Xiaohongshu data is genuinely valuable — for trend intelligence, competitor benchmarking, KOL research, and brand sentiment monitoring. International brands that build systematic, data-informed XHS strategies consistently outperform those that rely on intuition alone. But the value of that intelligence is only realized when the collection practices behind it are legally sound and ethically grounded.
China's data regulatory framework — anchored by PIPL, the Cybersecurity Law, and the Data Security Law — is comprehensive, actively enforced, and explicitly extends to foreign entities that handle Chinese consumer data. The line between public visibility and free commercial use is not as clear as many teams assume, and the distinction between aggregated trend signals and individually identifiable personal data is where most compliance risk actually lives.
The good news is that the most strategically valuable XHS data use cases — trend analysis, content benchmarking, sentiment monitoring, KOL discovery — operate comfortably within the bounds of responsible, compliant practice. You don't have to choose between useful intelligence and responsible data collection. You just have to design your approach thoughtfully from the start.
Important Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Data privacy laws are complex and jurisdiction-specific. Always consult a qualified legal professional for guidance on your organization's specific compliance obligations.
---
Ready to Build a Smarter XHS Strategy?
AllXHS is the #1 English-language resource hub for international brands marketing on Xiaohongshu. From data-driven industry reports to expert consultation, we help you navigate platform nuances, cultural context, and strategic execution — compliantly and effectively.
Or explore our expert Xiaohongshu marketing services to see how we support brands from market entry through scale.