B BROCENT

compliance

Cover image for Brocent IT blog post: Delivering IT in Mainland China Without a Local Entity: Hardware Routes, Partner Structure, and What Changed in 2026

October 01, 2026 | 20 min

Delivering IT in Mainland China Without a Local Entity: Hardware Routes, Partner Structure, and What Changed in 2026

A research briefing for overseas and Hong Kong IT prime contractors — and the multinationals that buy from them — that have to deliver onsite IT in mainland China without a local entity. It explains the four exposures an informal partner arrangement creates, walks through the customs routes that actually fit IT hardware (ATA Carnet, temporary entry 2600, repair goods 1300, free-of-charge goods 3339, no-cost replacement 3100, and a third-party importer of record), sets out the four documents that make the partner relationship legible, and corrects three claims still circulating: there is no customs code 1318, the postal limit from Hong Kong is RMB 800, and since 1 January 2026 free services are no longer a deemed VAT sale.

Cover image for Brocent IT blog post: One ITAD Policy, Three Countries: The Certificate an Auditor Will Actually Accept

September 29, 2026 | 16 min

One ITAD Policy, Three Countries: The Certificate an Auditor Will Actually Accept

For the regional IT asset owner or facilities lead retiring three or four years of devices across Singapore, Taiwan and Vietnam in one programme — usually triggered by an audit or a lease event. What an erasure or destruction certificate actually has to show before an auditor will accept it, where chain of custody breaks between three countries, what genuinely differs by jurisdiction versus what should never be assumed, and how to write one group ITAD policy that survives three different sets of local logistics.

Cover image for Brocent IT blog post: Who Withholds the Tax on Your Engineer in Shanghai? China's New VAT Measures and the Contractor Delivery Model

September 19, 2026 | 17 min

Who Withholds the Tax on Your Engineer in Shanghai? China's New VAT Measures and the Contractor Delivery Model

A policy briefing for global IT prime contractors and the enterprises that buy from them. China's Administrative Measures for the Withholding and Remittance of VAT on Natural Persons take effect on 1 November 2026 and move the collection point from the individual to the domestic entity that pays them — with monthly filing, identity record-keeping, and a filing obligation even in months when no tax is due. This report reads the fifteen articles, explains why a delivery model built on freelancers paid from offshore now leaves a visible gap where a monthly record should be, separates the exposure that belongs to the prime contractor from the exposure that belongs to the client, and supplies a nine-question due-diligence checklist you can send to a provider tomorrow.

Cover image for Brocent IT blog post: What a Failed Vulnerability Scan Cost a Hong Kong Law Firm's Cyber Policy

September 04, 2026 | 15 min

What a Failed Vulnerability Scan Cost a Hong Kong Law Firm's Cyber Policy

A composite scenario from Hong Kong: a law firm's cyber-insurance broker returns the renewal questionnaire with one line highlighted — a forgotten, internet-facing service with a known vulnerability. What insurers and clients are actually asking for, and what a real scanning practice looks like.

Cover image for Brocent IT blog post: The Pen-Test Requirement a Hong Kong Payments Firm Didn't See Coming

September 04, 2026 | 15 min

The Pen-Test Requirement a Hong Kong Payments Firm Didn't See Coming

A composite scenario from Hong Kong: a licensed payments firm faces a routine regulatory review asking for evidence of penetration testing, and finds a two-year-old PDF isn't evidence of anything current. What a maintained testing cadence changes, and where an IT partner's role stops.

Cover image for Brocent IT blog post: Forty Old Laptops and No Paper Trail

September 04, 2026 | 15 min

Forty Old Laptops and No Paper Trail

A composite scenario from Hong Kong: a professional-services firm downsizing offices opens a storeroom during the move and finds forty retired laptops with no wipe log and no destruction record. What a certified IT asset disposal process actually proves, and why it belongs inside an ongoing managed IT plan rather than a one-off clean-out.

Cover image for Brocent IT blog post: Why Hong Kong Companies Are Bundling MSP, MSSP, and HKMA/C-RAF Support Into One Contract

August 28, 2026 | 22 min

Why Hong Kong Companies Are Bundling MSP, MSSP, and HKMA/C-RAF Support Into One Contract

A research report on why Hong Kong companies — especially HKMA-regulated authorized institutions and their vendors — are bundling managed IT (MSP), managed security (MSSP), and HKMA cybersecurity/C-RAF regulatory support into a single RFP, what C-RAF's three components actually require, and where a vendor's honest role ends and the institution's own non-delegable regulatory accountability begins.

Cover image for Brocent IT blog post: China Employment Law for Foreign-Invested Enterprises: What IT and Ops Leaders Actually Need to Know

August 26, 2026 | 23 min

China Employment Law for Foreign-Invested Enterprises: What IT and Ops Leaders Actually Need to Know

A research report on the employment-law exposure a foreign-invested enterprise carries when it employs its own IT staff in mainland China — the September 2025 judicial interpretation, non-competes and trade secrets for technical staff, and what actually has to happen when a systems administrator leaves.

Cover image for Brocent IT blog post: How to Use Gemini to Draft Client Security Questionnaire and RFP Responses

August 13, 2026 | 11 min

How to Use Gemini to Draft Client Security Questionnaire and RFP Responses

How to answer 200-row security questionnaires in a day and a half instead of two weeks — building an answer library from real policies and audit output, and the verification step no AI can take over.

Cover image for Brocent IT blog post: PDPA Compliance Checklist for IT Outsourcing in Singapore

July 31, 2026 | 12 min

PDPA Compliance Checklist for IT Outsourcing in Singapore

A PDPA compliance checklist for IT outsourcing in Singapore - data protection obligations, breach notification timelines, DPO requirements, and vendor vetting.

Cover image for Brocent IT blog post: Choosing a Data Center Provider in Singapore: Cost Guide

July 30, 2026 | 14 min

Choosing a Data Center Provider in Singapore: Cost Guide

A benchmark-based guide to what drives data center and colocation costs in Singapore, how hyperscale, enterprise colocation, and public cloud compare, and what to check before you sign.

Cover image for Brocent IT blog post: Vulnerability Management vs. Penetration Testing: What APAC SMEs Actually Need

July 14, 2026 | 14 min

Vulnerability Management vs. Penetration Testing: What APAC SMEs Actually Need

A practical guide for APAC SMEs on the difference between continuous vulnerability management and point-in-time penetration testing, when each is required by SFC, MAS, HKMA, or PCI-DSS, and how to decide which to invest in first.

Cover image for Brocent IT blog post: ICP Licensing in China: What Foreign Enterprises Need to Know

May 20, 2025 | 6 min

ICP Licensing in China: What Foreign Enterprises Need to Know

Operating a website or internet service in mainland China requires an ICP licence. Getting it wrong can mean your site is blocked. Here is what you need to know before you launch.