WorldPrivacyAtlas
Laws by country

Sector-Specific Law

Cybersecurity Law and Data Security Law of the People's Republic of China

China CSL / DSL

China · June 1, 2017 (CSL); September 1, 2021 (DSL and the CII Regulations)

Verify details

The PIPL is only one leg of China's data regime, and for many businesses it is not the binding one. The Cybersecurity Law imposes security, real-name registration, incident-reporting and cooperation duties on 'network operators' — a definition broad enough in practice to reach almost any business that owns or administers its own network in mainland China — and imposes markedly heavier obligations on operators of critical information infrastructure, including annual security evaluations, procurement security reviews for products affecting national security, and domestic storage of personal information and important data. The Data Security Law adds a classification-and-grading regime across ALL data, not just personal data, with the heaviest duties attaching to 'important data' and to data with a bearing on national security, plus a rule against providing data stored in China to foreign judicial or law-enforcement authorities without Chinese approval. Marked 'check': sectoral 'important data' catalogues are issued by individual regulators and the CII identification rules are set sector by sector, so whether either regime binds a given business is a fact-specific question this atlas cannot answer.

Cybersecurity Law of the PRC (2016); Data Security Law of the PRC (2021); Regulations on the Security and Protection of Critical Information Infrastructure (2021)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.