General · 通用.
117 entries. The economy-wide regime that applies across every sector — PIPL, the Data Security Law, the Cybersecurity Law, and the regulations, departmental rules, standards, and judicial interpretations built on them: personal information, data security and classification, cross-border transfer, and the data-element market.
Reference Handbooks .
权威实务手册 · institutional handbooks and joint guides
- § 01 · CN-SG Joint Guide
China–Singapore Joint Data Compliance Guide: Practical Handbook — China Chapter
中国—新加坡联合数据合规指引:实务手册(中国篇)
A 110-page bilingual practitioner handbook on Chinese data compliance, jointly compiled by the Shenzhen Data Exchange and Singapore's Asian Business Law Institute under the guidance of the Qianhai Authority. The China Chapter is structured around the Guide's two-axis compliance model: subject obligations (organizational structure, policy, classification & grading, partners, risk assessment, incident response) crossed with object types (general / important / personal / public / industry-specific data). Includes the regulator map, cross-border path selection trees, and worked examples. Current as of August 2025. This is the single most accessible authoritative reference DCC has identified for overseas counsel approaching the Chinese data regime.
- § 02 · CAC Data Export Q&A (Apr 2025)
Policy Q&A on Data Export Security Management (April 2025)
数据出境安全管理政策问答(2025年4月)
The first of the Cyberspace Administration of China's periodic data-export policy Q&A batches, published on cac.gov.cn and the 网信中国 WeChat channel on April 9, 2025. Its nine answers are the CAC's own gloss on the three-pathway regime: how the export system is designed and which instruments implement it; how pilot-FTZ negative lists are kept consistent (one list per field, later FTZs apply it by reference) and which FTZs have filed lists covering 17 fields; the four statutory factors for judging the 'necessity' of a personal information export; how important data is identified (Network Data Regulation Art. 62 and GB/T 43697-2024 Appendix G); the first published assessment statistics (298 assessments completed as of March 2025, 44 involving important data, a 15.9% non-pass rate, 325 of 509 important data items cleared); the role of foreign-invested enterprises in TC260 standard-setting; the group-company consolidated declaration and filing route and the then-forthcoming certification path for intra-group transfers; and the 3-year validity and 60-working-day extension window for assessment results. Overseas counsel will find it most useful for the necessity test and the confirmation that undeclared, un-notified data need not be treated as important data.
- § 03 · CAC Data Export Q&A (May 2025)
Policy Q&A on Data Export Security Management (May 2025)
数据出境安全管理政策问答(2025年5月)
Published by the Cyberspace Administration of China on May 30, 2025, this short second batch answers the two questions multinationals most often ask about important data. Q1 lays out the identification-and-declaration procedure under DSL Art. 21 and Network Data Regulation Art. 29 — sector catalogues and identification guides (industrial, telecommunications, geographic information, statistics), notification by meeting, document or one-to-one notice — and states in terms that where no sector rules have been published and no department has told a handler to identify important data, failure to identify, declare or specially protect it is not a violation and attracts no administrative penalty. Q2 confirms that important data collected and generated in China may be exported only after passing the CAC-organized security assessment, that un-notified data need not be declared as important data and its export will not be treated as unlawful, and fixes the deadline: once notified, or once the data is publicly released as important data, a handler wishing to continue exporting must declare a security assessment through the provincial cyberspace administration within 2 months. For overseas counsel this is the clearest official statement of the 'no liability until notified' position on important data.
- § 04 · CAC Data Export Q&A (Oct 2025)
Policy Q&A on Data Export Security Management (October 2025)
数据出境安全管理政策问答(2025年10月)
Published by the Cyberspace Administration of China on October 31, 2025, the third and longest batch (ten answers) works through the practical edges of the 2024 Cross-border Data Flows Provisions and the SCC Measures. It reads the 'etc.' in the Art. 5 contract-performance exemption as open-ended but subject to two cumulative conditions; rules that a domestic guest booking a domestic hotel is not an exempt scenario; explains that employee ID, passport and bank-account exports under the HR exemption must pass a scenario-specific necessity test; declines to extend the 2-month post-notification deadline for important-data assessments but suggests preparing materials in parallel; clarifies that 'abroad' in the Declaration Guidelines (Third Edition) means the access act occurs abroad, so overseas staff querying domestic data while in China is not an export; confirms that system upgrades alone do not trigger re-assessment under Art. 14; allows a single SCC filing per overseas recipient based on a reasonable annual volume forecast, with escalation to assessment once the January 1 cumulative thresholds are reached; explains when new scenarios require a fresh PIPIA and a supplementary or re-signed SCC; points to Appendix I (6) for onward transfers to overseas third parties; and names the November 2022 Certification Announcement and GB/T 46068-2025 as the reference bases for certification under the new Certification Measures.
- § 05 · CAC Data Export Q&A (Jan 2026)
Policy and Regulatory Q&A on Data Export Security Management (January 2026)
数据出境安全管理政策法规问答(2026年1月)
Published by the Cyberspace Administration of China on January 30, 2026 — the first batch retitled 'policy and regulatory' Q&A — this short release answers two questions overseas groups ask constantly. First, how the standard contract and certification routes interlock with the security assessment: a non-CIIO handler that has exported between 100,000 and 1 million individuals' non-sensitive personal information, or fewer than 10,000 individuals' sensitive personal information, since January 1 may use the SCC or certification; if it crosses 1 million (non-sensitive) or 10,000 (sensitive) it must declare a security assessment through the provincial cyberspace administration, and the declaration must fold in the personal information already exported that year under the SCC or certification — the assessment result then governs the whole flow. Second, a handler that has filed a Greater Bay Area standard contract may move personal information only within the GBA under the Hong Kong and Macao implementing guidelines; any provision to recipients outside the GBA falls back on the national routes (assessment, SCC or certification). The Q&A is a compact statement of the CAC's cumulative-counting logic and of the GBA contract's territorial ceiling.
- § 06 · CAC Data Export Q&A (Jul 2026)
Policy and Regulatory Q&A on Data Export Security Management (July 2026)
数据出境安全管理政策法规问答(2026年7月)
Published by the Cyberspace Administration of China on July 24, 2026, this batch answers three practitioner questions. On notice and separate consent for personal information exports, it restates PIPL Articles 39 and 30 (overseas recipient identity and contact details, purpose, method, categories, and how individuals exercise rights against the recipient; for sensitive personal information, also necessity and impact), rules that separate consent must be specific and unbundled — no blanket authorization — and points to GB/T 42574-2023 for signature, pop-up or email/SMS mechanics, while confirming that the Article 13(2)–(7) lawful bases dispense with consent but not with notice. On extending a security-assessment result, it lists the six cumulative conditions from the Declaration Guidelines (Third Edition): unchanged purpose and scope, unchanged parties, no more than a 20% increase in individuals or in important-data volume over the coming three years against the prior approval, compliant legal documents under Article 9 of the Assessment Measures, and three years of compliant operation without a major data security incident, with the application filed within 60 working days before expiry. On recruitment, it holds that sending domestic candidates' résumés to an overseas headquarters is not necessary unless the overseas entity actually participates in hiring decisions, and even then only for the minimum number of candidates and data fields, routed through assessment, SCC or certification with separate consent and a PIPIA.
- § 07 · CAC PI Protection Q&A (2026)
Policy and Regulatory Q&A on Personal Information Protection (2026 Batches)
个人信息保护政策法规问答(2026年)
A consolidated entry for the three 2026 batches of the Cyberspace Administration of China's personal information protection policy Q&A, published on cac.gov.cn on January 9, April 29 and August 12, 2026. The January batch defines personal information and sensitive personal information by category (with GB/T 45574-2025 Appendix A), sets out the four-part PIPIA required before facial recognition technology is applied, and explains who must designate a person in charge of personal information protection (1 million or more persons) and how to report through the online Personal Information Protection Business System. The April batch answers the counting question that runs through the whole regime — thresholds such as '10 million persons' are inclusive of the stated number, counted on the natural persons in the handler's current processing and excluding deleted data — and fixes compliance-audit frequency at every two years above 10 million, every three or four years between 1 million and 10 million, and every five years at 1 million or below, plus annual audits for any handler processing minors' personal information whether or not it identifies minors. The August batch elaborates the five unlawful patterns for processing publicly disclosed personal information and the four common causes of personal information leaks. Useful to overseas counsel as the CAC's own reading of thresholds and audit cadence.
- § 08 · SZDEX Cross-border Trading Guidelines
Guidelines for Compliance Assessment of Cross-border Data Transactions
跨境数据交易合规评估指引
A 53-page assessment guide from the Shenzhen Data Exchange covering the compliance review of cross-border data *transactions* — the sale or licensing of a data product for money across the PRC border, as distinct from the intra-group transfers the CAC export regime was built around. It classifies cross-border trading into six modes by data origin and counterparty location, rules four of them in and two out of scope, and then applies a three-stage assessment (subject → object → circulation) crossed with four dimensions (legality, security, integrity, rights protection). The value for overseas counsel is the offshore-counterparty checklist: what an offshore buyer or seller must itself demonstrate before a Chinese exchange or seller will clear the trade. Current as of 9 February 2026.
Laws .
法律 · National People's Congress
- § 01 · PIPL
Personal Information Protection Law of the People's Republic of China
中华人民共和国个人信息保护法
PIPL is China's comprehensive personal-information protection regime. It is structured around the concept of the personal information handler — a Chinese-law term that should not be flattened to GDPR's data controller. PIPL governs consent, sensitive personal information, cross-border transfer, and the rights of individuals, with extraterritorial reach to handlers outside China that target domestic natural persons.
- § 02 · DSL
Data Security Law of the People's Republic of China
中华人民共和国数据安全法
The Data Security Law is the second of China's three foundational data statutes (alongside CSL and PIPL). It governs all data processing activities — not just personal information — and establishes the data classification and grading regime, the 'important data' and 'national core data' categories, security obligations for data handlers, the cross-border transfer restrictions on important data, and the prohibition on providing data to foreign judicial or enforcement bodies without approval.
- § 03 · Export Control Law
Export Control Law of the People's Republic of China
中华人民共和国出口管制法
Adopted by the 13th National People's Congress Standing Committee at its 22nd session on October 17, 2020, promulgated the same day by Presidential Decree No. 58 and effective December 1, 2020, the Export Control Law is China's first unified export-control statute. Its 49 articles in five chapters cover dual-use items, military products, nuclear items and other goods, technologies and services tied to national security or non-proliferation obligations, administered through control lists, temporary controls of up to two years, export licensing, end-user and end-use certification, and a control list of blacklisted importers and end users. For data and technology counsel the law matters in four places. Article 2 defines controlled items to include data such as technical documentation related to the items, and extends export to any provision of controlled items by Chinese citizens, legal persons or unincorporated organizations to foreign organizations or individuals, which captures deemed exports that never cross a customs line. Article 32 makes the provision of export-control-related information abroad subject to law and prohibits it where national security may be harmed. Articles 44 and 48 assert jurisdiction over overseas actors and authorize reciprocal countermeasures. The pilot free trade zone data-export negative lists and the Network Data Security Regulations carve export-controlled technical data out of the ordinary data-export track and back into this regime.
- § 04 · Foreign Trade Law
Foreign Trade Law of the People's Republic of China (2025 Revision)
中华人民共和国对外贸易法(2025修订)
Revised in full by the 14th National People's Congress Standing Committee at its 19th session on December 27, 2025, promulgated by Presidential Decree No. 67 and effective March 1, 2026, the Foreign Trade Law is China's framework statute for trade in goods, technology and services. This is the law's second comprehensive revision: enacted in 1994, revised in 2004, and amended in 2016 and 2022, it now runs to eleven chapters and eighty-three articles. DCC tracks it for three reasons. Chapter III governs technology import and export, including contract filing for freely traded technology and licensing for restricted technology; Chapter IV codifies a negative-list regime for cross-border trade in services delivered by cross-border supply, consumption abroad and the movement of natural persons; and the trade-order and remedy chapters add a data-security compliance duty for foreign trade operators (Article 38), a mechanism to bar overseas persons who harm China's sovereignty, security or development interests (Article 40), an anti-circumvention clause reaching logistics, customs brokerage and platform services, and a financial-blocking provision (Article 77). Article 80 defers dual-use, military and nuclear items to the export control statutes. Officials who leak personal information or trade secrets learned in trade investigations face sanction (Articles 43 and 78). DCC summarizes the provisions relevant to technology and data flows rather than translating the full text.
- § 05 · CSL · AMENDED
Cybersecurity Law of the People's Republic of China (2025 Amendment)
中华人民共和国网络安全法(2025 修正)
The Cybersecurity Law is the earliest of the three foundational data-protection statutes. It establishes the Multi-Level Protection Scheme (MLPS), the Critical Information Infrastructure regime, network-operator obligations, and the cybersecurity review framework. The current text incorporates the 2025 amendment, which takes effect January 1, 2026.
- § 06 · Civil Code (PI Chapter)
Civil Code — Personality Rights Book, Chapter on Privacy and Protection of Personal Information
中华人民共和国民法典 · 人格权编 · 隐私权和个人信息保护章
Articles 1032–1039 of the Civil Code's Personality Rights Book establish the civil-law foundation for privacy and personal-information protection in China. The chapter defines the right of privacy, the scope of personal information, principles for handling, statutory defenses, individuals' rights of access and correction, processor obligations, and confidentiality duties of State organs. Civil-law remedies under this chapter operate alongside the public-law PIPL regime — neither displaces the other.
- § 07 · AUCL
Anti-Unfair Competition Law of the People's Republic of China
中华人民共和国反不正当竞争法
- § 08 · ATFL
Anti-Telecom and Online Fraud Law of the People's Republic of China
中华人民共和国反电信网络诈骗法
- § 09 · Minors Protection Law
Law on the Protection of Minors
中华人民共和国未成年人保护法
The umbrella statute for the protection of minors in China. Its 2020 revision added a dedicated 'Network Protection' chapter that anchors the entire minors-online-protection regime: internet-literacy education duties for the state, society, schools, and families (Art. 64); school management of smartphones and smart terminals (Art. 70); mandatory school bullying prevention-and-control systems with reporting duties for serious incidents (Art. 39); and school duties to notify parents and intervene when students show internet addiction (Art. 71). The Regulations on the Protection of Minors in Cyberspace (2024) implement the chapter at administrative-regulation level, and the MOE's Provisions on the Protection of Minors by Schools implement the school-facing duties.
Administrative Regulations .
行政法规 · State Council
- § 01 · CII Regulations
Security Protection Regulations for Critical Information Infrastructure
关键信息基础设施安全保护条例
These Regulations operationalize the Critical Information Infrastructure (CII) regime under CSL Articles 31–39. They define CII identification rules, set out CIIO obligations (specialized security body, annual testing and risk assessment, security review of network products, breach reporting), and establish the inter-agency coordination structure under CAC + Ministry of Public Security.
- § 02 · Data Twenty Opinions
Opinions of the CPC Central Committee and the State Council on Building a Basic Data System to Better Play the Role of Data Elements
中共中央 国务院关于构建数据基础制度更好发挥数据要素作用的意见
The foundational 20-article policy directive jointly issued by the CPC Central Committee and the State Council laying out China's national data basic system: data property rights structural subdivision (holding right / processing right / operation right), classified-and-graded right confirmation for public/enterprise/personal data, the on-floor + over-the-counter trading framework, the income distribution mechanism for data elements, and a multi-party governance model. This is the policy text that informs subsequent national-level legislation and rules on data assets, public data, and data property rights registration.
- § 03
Regulation on Network Data Security Management
网络数据安全管理条例
The Network Data Security Management Regulation is the State Council's overarching implementing regulation for the three foundational data-protection statutes (CSL, DSL, PIPL). It consolidates network-data security obligations, important-data identification and classification, cross-border transfer rules, security-incident reporting, and operator obligations for large data handlers and internet platforms. Promulgated as State Council Decree No. 790.
- § 04 · Dual-Use Items Export Control Regulations
Regulations of the People's Republic of China on the Export Control of Dual-Use Items
中华人民共和国两用物项出口管制条例
Adopted at the 41st executive meeting of the State Council on September 18, 2024, promulgated by Decree No. 792 of the State Council on September 30, 2024 and effective December 1, 2024, these Regulations are the principal implementing instrument under the Export Control Law for dual-use items. They replace the four item-specific regulations on nuclear, missile, biological and chemical dual-use exports with a single regime. Six chapters and fifty articles place the commerce department of the State Council (MOFCOM) in charge, define a three-track licensing regime (individual licenses of up to one year, general licenses of up to three years, and registration-based export certificates for listed low-risk scenarios), set a 45-working-day review clock, and build out end-user and end-use verification, a watch list and a control list. For data counsel the Regulations matter because Article 2 expressly folds technical documentation and other data into dual-use items and extends export to non-commercial transfers by gift, exhibition, cooperation or assistance; Article 38 requires immediate reporting of, and MOFCOM consent for, any foreign-government request for export-control-related access or on-site verification; Article 49 reaches dual-use items made abroad that contain, integrate or were produced with China-origin items or technology; and Article 27 imposes a five-year record-retention duty. The pilot free trade zone data-export negative lists route export-controlled technical data into this regime rather than the CAC data-export track.
- § 05
Regulations on the Protection of Minors in Cyberspace
未成年人网络保护条例
Implementing regulation for the protection of minors under PIPL and CSL. Covers age-appropriate content, online education, addiction-prevention regimes for video games and short videos, sensitive personal information of minors (under 14), parental consent mechanisms, and platform obligations for products targeting or accessible to minors.
- § 06 · Public Data Development and Utilization Opinions
Opinions of the General Office of the CPC Central Committee and the General Office of the State Council on Accelerating the Development and Utilization of Public Data Resources
中共中央办公厅、国务院办公厅关于加快公共数据资源开发利用的意见
Issued jointly by the General Office of the CPC Central Committee and the General Office of the State Council on September 21, 2024 (made public October 9, 2024), these Opinions are the central policy charter for China's public-data regime. They sit one level below the 2022 Data Twenty Opinions and above the NDRC/NDA implementing rules on authorized operation, registration and pricing that followed in January 2025. The seventeen numbered measures set targets for 2025 and 2030; organize public data into three channels — government data sharing, public data openness, and authorized operation (授权运营); require a registration system, a disclosure mechanism and a government-guided pricing regime under which public-governance and public-welfare uses are conditionally free; and permit public institutions that run data operations to convert into enterprises under state-asset supervision. Security duties (classification and grading, risk assessment, control of unpublished raw public data entering the market) run throughout. For overseas counsel, this is the text that explains why every provincial authorized-operation measure looks the way it does, and the document the later notices cite as their authority.
- § 07
Regulations on the Sharing of Government Data
政务数据共享条例
The first comprehensive State Council regulation specifically governing the sharing of government data across agencies. Establishes the unified national government-data sharing platform, defines responsibilities of the National Data Administration, sets data quality and security requirements, and addresses personal-information and important-data handling within the government-data context.
- § 08
Administrative Measures for Internet Information Services (2024 Revision)
互联网信息服务管理办法(2024 修订)
The foundational regulation of Internet Information Services (ICP) in China — the regulatory baseline beneath nearly every later data-protection rule. Establishes the ICP licensing regime (operational vs. non-operational), platform compliance obligations, content management, and the role of telecommunications and cyberspace administrative authorities. The 2024 revision aligns the regulation with CSL, DSL, PIPL, and the post-2022 platform rules.
- § 09 · PVISR
Administrative Regulation for Public Security Video Image Information Systems
公共安全视频图像信息系统管理条例
The State Council's overarching regulation for public security video image information systems (公共安全视频系统) in public places. Distinguishes three operator types: government-led, public-private partnership, and private-led, and applies graduated obligations depending on the operator type. Implements PIPL Article 26 for video-image capture in public places, including filing obligations, mandatory signage, retention, and security duties. Read with the 2025 FRT Measures (Decree No. 19) for facial-recognition deployments.
- § 10 · Shenzhen Data Regulations
Shenzhen Special Economic Zone Data Regulations
深圳经济特区数据条例
China's first comprehensive local data law, adopted by the Standing Committee of the Shenzhen Municipal People's Congress on 29 June 2021 and effective 1 January 2022. The Regulations pioneered express recognition of 'data rights and interests' (数据权益) — conferring personality-rights interests on individuals over their personal data and property-rights interests on lawful data processors over their data products — and introduced China's most detailed consent-and-notice regime for personal data at the time, including an explicit prohibition on big-data price discrimination against existing users (大数据杀熟). It established a public data sharing-as-default framework, a data factor market chapter with fair-competition rules, and comprehensive data security obligations including mandatory cross-border transfer security assessments. As the first sub-national regulation to span personal data, public data, the data factor market, and data security in a single instrument, Shenzhen's Regulations served as an influential drafting model ahead of PIPL (2021) and the Data Security Law (2021) and remain directly applicable to businesses operating in Shenzhen; overseas counsel should note that penalties for unlawful data trading can reach RMB 1 million, and anticompetitive data-market conduct can attract fines of up to 5% of prior-year revenue or RMB 50 million.
Departmental Rules .
部门规章 · CAC, MIIT, MPS and others
- § 01
Measures for the Security Assessment of Data Export
数据出境安全评估办法
The first of CAC's three cross-border transfer pathways. Required for CIIOs transferring any personal information or important data abroad, and for non-CIIO handlers above certain thresholds. Establishes the application procedure, evaluation factors, validity period, and self-assessment requirements. Read together with the 2024 Cross-border Data Flow Provisions, which relaxed thresholds.
- § 02
Provisions on Promoting and Regulating Cross-border Data Flows
促进和规范数据跨境流动规定
The 2024 Cross-border Data Flow Provisions are CAC's relaxation package on outbound data transfer. They introduce thresholds and exemptions for the security assessment, standard contract, and certification pathways, plus a free trade zone (FTZ) negative-list mechanism. For overseas counsel, this is the regulation that practically determines whether a routine cross-border transfer needs to clear formal CAC review or not.
- § 03
Data Property Rights Registration Work Guide (Trial)
数据产权登记工作指引(试行)
NDA's first national framework for the registration of Data Property Rights — the rights to hold, use, and operate data established under the Data 20 Articles policy. Issued by the NDA Comprehensive Department on July 1, 2026 as the Trial Work Guide, it sets out registration institutions, the registration procedure (application, acceptance, review, public announcement, objection handling, evidence preservation, certificate issuance), the ownership-clarity rules that determine who can register which right over which data, the five registration types (initial, transfer, change, renewal, deregistration), and liability for institutions and applicants. Compared with the April 2026 consultation draft, the final text tightens security/public-interest gates, adds a definition of derived data, shifts the national platform terminology to a service system, strengthens provincial management and institution-exit rules, narrows public-data registration from mandatory to conditional/voluntary wording, and moves certificate validity from issuance to evidence-preservation completion.
- § 04 · SCC Measures
Measures on the Standard Contract for the Outbound Transfer of Personal Information
个人信息出境标准合同办法
The second of CAC's three cross-border transfer pathways: signing a CAC-prescribed Standard Contract with the overseas recipient and filing it with the provincial CAC. Used by handlers below the Security Assessment thresholds. The Measures establish eligibility criteria, the filing procedure, ongoing obligations after filing, and the CAC's right to invalidate the contract on the recipient side. The Standard Contract template itself is annexed.
- § 05 · Network Data Risk Assessment Measures
Measures for Network Data Security Risk Assessment
网络数据安全风险评估办法
The first dedicated, cross-sector implementing rule for the annual network-data risk-assessment obligation created by the Network Data Security Management Regulation (State Council Decree No. 790). Jointly issued by the CAC, MIIT and the Ministry of Public Security as Order No. 24, it requires every important-data handler to conduct a risk assessment each year — and again whenever a material change in the security status of important data may adversely affect security — to retain the report for at least three years, and to submit it to the competent authority within 20 working days; general-data handlers are encouraged to assess at least once every three years. It builds the regime for third-party assessment institutions: voluntary certification, a ban on sub-entrustment, a no-more-than-three-consecutive-years rotation rule, and confidentiality and deletion duties. Regulators may compel a certified-institution assessment after a high-risk finding or a breach involving important data or large-scale personal information, and may order an important-data handler to stop processing important data where activities endanger national security or the public interest. Adopted June 1, 2026; promulgated June 18, 2026; effective August 20, 2026.
- § 06
Guide to the Filing of the Standard Contract for Outbound Transfer of Personal Information (First Edition)
个人信息出境标准合同备案指南(第一版)
CAC's procedural guide accompanying the SCC Measures. Specifies the filing materials required, where to file (provincial CAC), online filing system mechanics, materials acceptance and review timeline, and standardized templates for the power of attorney, the letter of commitment, the Standard Contract itself, and the Personal Information Protection Impact Assessment Report. Read together with the SCC Measures for the operational filing path.
- § 07 · Data Terms Batch 1
Explanation of Common Terms in the Field of Data (First Batch)
数据领域常用名词解释(第一批)
The first installment of official terminology explanations issued by the National Data Administration. Establishes authoritative Chinese government definitions for 40 foundational data-field concepts including data, primary data, data resources, data elements, data products and services, data assets, data handling, data handler, commissioned data handler, data circulation, data transaction, data governance, data security, public data, digital industrialization, industrial digitalization, metadata, structured/semi-structured/unstructured data, privacy-protective computation (secure multi-party computing, federated learning, trusted execution environment, cryptographic computing), and blockchain.
- § 08 · Data Terms Batch 2
Explanation of Common Terms in the Field of Data (Second Batch)
数据领域常用名词解释(第二批)
The second installment of official terminology explanations issued by the National Data Administration, continuing the consensus-building effort that began with the First Batch in December 2024. The 20 terms in this batch focus on data property rights vocabulary (Data Property Rights, Data Property Rights Registration, Right to Hold Data, Right to Use Data, Right to Operate Data, derived data, enterprise data); data trading institutions and market structure (data trading institution, on-exchange data trading, off-exchange data trading, data trading matching, data third-party professional service institution); the data industry and data labeling sub-industry; trusted data space and data use control; data infrastructure; and computing-power scheduling and pooling. DCC translation, cross-checked against the glossary for consistency with the public-data property-rights registration documents.
- § 09
Measures for the Certification of the Cross-border Provision of Personal Information
个人信息出境认证办法
The third of CAC's three cross-border transfer pathways — PI Protection Certification — finally given its own dedicated rules effective January 1, 2026. Joint issuance with SAMR (which administers the certification body accreditation regime). Establishes who can be certified, eligibility thresholds, what certification covers, and the relationship to the Security Assessment and Standard Contract pathways.
- § 10
Cybersecurity Review Measures
网络安全审查办法
The 2021 update to the cybersecurity review regime, expanded after the Didi enforcement action. Applies to (i) CIIO procurement of network products/services that may affect national security, and (ii) network platforms holding personal information of more than one million users when seeking an overseas listing. Sets the procedure, factors considered, and outcomes (no-action, conditional approval, prohibition).
- § 11
Administrative Measures for Personal Information Protection Compliance Audits
个人信息保护合规审计管理办法
These Measures implement the compliance-audit obligation in PIPL Article 54. Self-audit is required at least every two years for handlers of more than 10 million people's personal information; CAC-directed audits by a third-party specialized agency are triggered by significant risk, large-scale infringement, or major security incidents. The Measures are accompanied by a 27-section Guidelines annex that lays out exactly what auditors should examine — effectively a regulator-issued checklist for personal-information compliance.
- § 12 · Small Handler Simplified Measures
Provisions on Simplified Personal Information Protection Measures for Small Personal Information Handlers
小型个人信息处理者个人信息保护简化措施规定
CAC and MPS Order No. 25, issued 22 July 2026 and effective 1 September 2026, is the long-promised implementation of PIPL Article 62's mandate to write dedicated personal-information rules for small handlers. It defines a small personal information handler as one processing the personal information of fewer than 100,000 people, and then scales down almost every PIPL obligation for that population: a three-item minimum content list for processing rules published by posted notice or pop-up; notice discharged through the published rules alone where processing is necessary to the product or service and nothing is provided onward; consent inferred from an individual's voluntary, informed provision of necessary information; a full exemption from drafting rules and giving notice where the handler operates only through a network platform whose own rules, audit and impact assessment already cover it; compliance audit once every five years using an annexed self-check table, waived entirely during the validity of a Personal Information Protection Certification; a one-page impact-assessment form; and simplified breach notification. Article 10 carries the cross-border payload — six conditions exempting a small handler from the Data Export Security Assessment, the Standard Contract and certification, with important data carved out. Articles 18 and 19 add mandatory no-penalty and mitigated-penalty circumstances. Two annexes supply the audit self-check table and the impact-assessment form.
- § 13 · Incident Reporting Measures
Measures for the Administration of National Cybersecurity Incident Reporting
国家网络安全事件报告管理办法
Issued by the CAC on September 11, 2025 and effective November 1, 2025, these Measures establish a unified national workflow for cybersecurity incident reporting, triggered whenever an incident is graded 'relatively significant' or above under the annexed Classification Guidelines (which track GB/T 20986-2023). Reporting clocks are calibrated by operator type: critical information infrastructure (CII) operators must report within one hour, central and state organs within two hours, and all other network operators within four hours, with tighter escalation windows for major and especially major incidents. Each report must cover eight specified elements — including, for ransomware, the ransom amount and payment deadline — and a comprehensive 30-day summary report is required after incident handling concludes; the 12387 hotline serves as the central intake. Article 11 creates an explicit safe harbour for operators that prepared adequately, responded under their emergency plan, and reported in good time, while Article 10 subjects late, false, or concealed reporting that causes serious harm to heavier penalties for both the entity and responsible individuals — a combination that overseas counsel should factor into incident-response playbooks for any China-nexus operation.
- § 14 · Network Identity Authentication Measures (MPS Order No. 173)
Measures for the Administration of National Network Identity Authentication Public Services
国家网络身份认证公共服务管理办法
MPS Order No. 173 — the departmental rule establishing China's state-run network identity authentication scheme, built on two new credentials: the 网号 ('network number'), a letters-and-digits identity symbol carrying no plaintext identity information, and the 网证 ('network credential'), which carries the network number plus the holder's non-plaintext identity data. Adopted at the 1st MPS executive meeting on 27 February 2025, promulgated 19 May 2025 with the concurrence of five other departments, effective 15 July 2025. In 16 articles it makes application voluntary for natural persons holding a valid legal identity document (with parental consent below 14), and — the provision that matters most for platforms — bars a platform that has authenticated a user through the scheme from requiring that user to supply plaintext identity information separately, while requiring equal service for users who decline it. It also confines the public-service platform to authentication-necessary data, requires separate consent for sensitive personal information, mandates domestic storage of important data and personal information with a security assessment for any outbound transfer, and routes penalties through the CSL, DSL and PIPL.
- § 15 · Public Data Authorized Operation Disclosure Notice
Notice of the General Affairs Department of the National Data Administration on Properly Carrying Out Information Disclosure for the Authorized Operation of Public Data Resources
国家数据局综合司关于做好公共数据资源授权运营信息披露工作的通知
Issued by the General Affairs Department of the National Data Administration on January 28, 2026 as 国数综资源〔2026〕2号, this Notice operationalizes the disclosure duties that Articles 18 and 19 of the Authorized Operation Implementation Specifications impose on implementing institutions and operating institutions. It fixes who discloses what: implementing institutions publish their own particulars, the public data resources they have authorized and the ceiling fee standards for the public data operation service fee; operating institutions publish their particulars, the resources they hold under authorization, their product and service list and their specific fee standards (the indicator sets are in two annexes). Disclosure is annual, due by the end of March for the preceding year, and must go through the public data resource registration platforms — the national platform for central organs and central enterprises, provincial platforms interconnected with it for localities — with parallel publication on official websites and media encouraged. Local data administration authorities and sectoral data administration bodies supervise, correct non-registration, late or false disclosure through on-site guidance, regulatory interviews, correction orders and public notification, and share disclosed information with audit bodies. For overseas counsel, this is the first public, platform-based window into who holds Chinese public-data licenses and on what commercial terms.
- § 16 · Public Data Authorized Operation Pricing Notice
Notice of the National Development and Reform Commission and the National Data Administration on Establishing a Price Formation Mechanism for the Authorized Operation of Public Data Resources
国家发展改革委、国家数据局关于建立公共数据资源授权运营价格形成机制的通知
Issued by the NDRC and the National Data Administration on January 16, 2025 as 发改价格〔2025〕65号 and effective March 1, 2025, this Notice is the pricing leg of the January 2025 public-data package that also produced the Authorized Operation Specifications and the Registration Interim Measures. It gives operational form to the central Opinions' rule that public data products used for public governance and public welfare are free while those used for industrial and sectoral development may carry a 'public data operation service fee' under government-guided pricing. The mechanism is three-tiered: the development-and-reform authority, together with the data administration authority, fixes an operating institution's maximum permitted revenue on a cost-recovery-plus-reasonable-profit basis (permitted profit margin capped at the ten-year treasury yield plus six percentage points); the authorizing entity sets ceiling fee standards by product and reports them in writing; the operating institution prices below the ceiling. Revenue is re-evaluated at least every three years, with over-collection clawed back, plus an annual adjustment rule keyed to a ten-percent deviation. Operators must keep separate accounts and publish their fee lists. For overseas counsel, this is the document that defines what a licensed public-data product may lawfully cost in China.
- § 17 · Public Data Governance Cost Pooling Pilot Notice
Notice of the Ministry of Finance on Launching Pilot Work on the Pooling of Public Data Resource Governance Costs
财政部关于开展公共数据资源治理成本归集试点工作的通知
Issued by the Ministry of Finance on April 23, 2026 as 财会〔2026〕5号, this Notice launches a pilot in ten regions — Beijing, Hebei, Liaoning, Shanghai, Zhejiang, Anhui, Fujian, Qingdao, Chongqing and Sichuan — in which administrative and public institutions that apply the Government Accounting Standards System will inventory their public data resources and pool the costs of governing them. It is the first MOF instrument to treat public data held by government bodies as an object of cost accounting, and it adopts the definition of public data resources from the NDRC/NDA Registration Interim Measures. Pilot units take governance as a stand-alone business line, pool costs across collection, processing, storage and maintenance and security (personnel, purchased data sets, technical services, depreciation, amortization, utilities), and may choose the manufacturing-cost or full-cost method. The timetable runs from unit selection by July 31, 2026 through a cost-pooling window of January to June 2027 to provincial summaries by September 30, 2027. For overseas counsel advising on data-asset accounting, valuation or the pricing of licensed public data, this is the upstream cost base that future accounting rules — and government-guided prices — will rest on.
- § 18 · Cultural Relics Data Measures
Measures for the Administration of State-Owned Cultural Relics Resource Data
国有文物资源数据管理办法
Issued by the National Cultural Heritage Administration as 文物科发〔2026〕17号 on June 9, 2026 and effective November 1, 2026, these 33-article Measures are the first sector-wide data rule for China's museums, heritage-protection bodies and other state institutions that hold state-owned cultural relics. They declare state ownership of all cultural-relics resource data — raw, processed and derived — and place day-to-day custody with the holding institution, while the NCHA Data Center builds national and regional storage centers and a registration platform. The Measures then walk the full lifecycle: digitization must be done on-site for movable relics by vetted personnel under confidentiality undertakings and may not be duplicated; processing contractors must work in controlled premises and delete temporary files; every institution must back up to a national or regional center; transfers go through certified online platforms or, for very large volumes, encrypted physical media; and every dataset must be registered (initial, change and cancellation registration) before it can be served. The data-service chapter is what matters commercially: processed data may be released only on a 'raw data stays in-domain, data controllable and measurable' basis, with six exclusion grounds (state secrets, public morals, third-party rights, unclear provenance, donor restrictions, other legal bars), three service channels — proactive publication, non-profit licensing at cost or free, and negotiated commercial licensing for exhibitions, cultural-creative products, film and animation, advertising and games — and mandatory licensee vetting, written agreements and unique traceability identifiers. Derived data produced by licensees may be allocated to the institution by agreement. For overseas publishers, game studios and museums seeking Chinese heritage imagery, this is the licensing rulebook.
- § 19 · Children's PI Provisions
Provisions on the Online Protection of Children's Personal Information
儿童个人信息网络保护规定
China's first dedicated rule for children's personal information online, issued by the CAC in 2019 and effective October 1, 2019. It fixes 14 as the age of childhood, requires verifiable guardian consent before a network operator collects, stores, uses, transfers, or discloses a child's personal information, and imposes a guardian-facing notice-and-refusal regime, data-minimization and storage-limitation duties, encrypted storage, minimum-authorization access controls, entrustment and transfer safeguards, deletion and correction rights, and breach notification to guardians. It predates PIPL but is read together with PIPL Article 28 (which treats the personal information of minors under 14 as sensitive personal information) and the Regulations on the Protection of Minors in Cyberspace.
- § 20 · App PI Identification Method
Method for Identifying the Unlawful Collection and Use of Personal Information by Apps
App违法违规收集使用个人信息行为认定方法
Issued jointly in November 2019 by the CAC Secretariat, MIIT, MPS, and SAMR under Document No. 国信办秘字〔2019〕191号, this instrument provides the operational six-category test that regulators use to determine whether an app's collection and use of personal information is unlawful or excessive: (1) failure to publicly disclose collection and use rules; (2) failure to clearly state the purpose, method, and scope of collection; (3) collection without user consent; (4) collection beyond what is necessary for the service; (5) sharing personal information with third parties without consent; and (6) failure to provide deletion or correction functions or complaint channels. The method underpins the national App special-governance campaign and is the direct basis for app-store removal orders issued by regulators. Overseas counsel advising Chinese-market apps or cross-border data-sharing arrangements must treat compliance with each of the six categories as a threshold checklist, as a single identified violation can trigger mandatory rectification and removal.
- § 21 · Necessary PI Scope Provisions
Provisions on the Scope of Necessary Personal Information for Common Types of Mobile Internet Applications
常见类型移动互联网应用程序必要个人信息范围规定
These Provisions, issued jointly by the CAC, MIIT, MPS, and SAMR in March 2021 and effective May 1, 2021, define 'necessary personal information' as the minimum data indispensable for an app's basic functional service to operate — and expressly prohibit operators from refusing basic service to users who decline to provide non-necessary personal information. The Provisions enumerate 39 common mobile app categories (including map navigation, ride-hailing, instant messaging, online shopping, mobile banking, and more), specifying the precise personal information each category may require; 12 of the 39 categories — including browsers, input methods, news apps, and short-video apps — require no personal information at all for basic use. Overseas counsel advise on these Provisions when auditing the data-collection practices of apps distributed in China, assessing whether consent gates or account-wall practices are lawful, and preparing for MIIT or CAC enforcement inspections targeting excessive or non-necessary data collection.
- § 22 · Platform Rules Measures
Measures for the Supervision and Administration of Online Trading Platform Rules
网络交易平台规则监督管理办法
Departmental rule (SAMR/CAC Order No. 116) governing how online trading platform operators formulate, amend and enforce their platform rules (service agreements, in-platform management rules, dispute-handling rules, personal-information protection rules, IP rules, etc.). It requires conspicuous publication, comment solicitation, advance notice before changes take effect, retention of historical versions, and an appeals channel including human review where decisions are made solely by AI. Separate chapters address information/network/data security (including minors' protection and personal-information allocation between platforms and in-platform operators), protection of in-platform operators against unreasonable restrictions and fees, and consumer protection against discriminatory pricing and unilateral membership changes. Effective February 1, 2026.
- § 23 · CII Commercial Cryptography Provisions
Provisions on the Administration of the Use of Commercial Cryptography in Critical Information Infrastructure
关键信息基础设施商用密码使用管理规定
Departmental rule (State Cryptography Administration / CAC / Ministry of Public Security Order No. 5) requiring operators of critical information infrastructure (CII) to use commercial cryptography to protect their CII, and to plan, build and operate commercial-cryptography assurance systems concurrently with the CII itself. It mandates commercial-cryptography application security assessments at the planning, construction and operation stages (at least annually once in operation), requires the use of certified commercial-cryptography products and State-vetted algorithms, sets staffing and funding requirements (key administrators, cipher operators, security auditors), imposes annual reporting duties, and provides penalties of up to RMB 1,000,000. Effective August 1, 2025.
- § 24 · PI Certification Rules
Implementation Rules for Personal Information Protection Certification
个人信息保护认证实施规则
The Implementation Rules for Personal Information Protection Certification, issued as the annex to SAMR and CAC Joint Announcement No. 37 of 2022 on November 18, 2022, operationalize the certification pathway that PIPL Article 38(2) authorizes for cross-border transfers of personal information and that simultaneously governs domestic personal information protection certification. The Rules establish a three-stage certification model — technical verification, on-site audit, and post-certification supervision — grounded in GB/T 35273 (Personal Information Security Specification) for all personal information handlers, with the additional requirement that handlers engaged in cross-border processing activities comply with TC260-PG-20222A (Security Certification Specification for Cross-border Personal Information Processing Activities). Certification certificates are valid for three years, subject to ongoing supervisory audits, and may be suspended or revoked for non-compliance; certified handlers may display the corresponding certification mark (with a distinct cross-border variant). The Rules were subsequently supplemented by the Measures for the Certification of the Cross-border Provision of Personal Information (effective January 1, 2026), which specifically governs the cross-border certification route; overseas counsel advising on cross-border transfers should read the two instruments together, as the Implementation Rules set the foundational procedural framework that the 2026 Measures build upon.
- § 25 · PI Certification Announcement
Announcement on the Implementation of Personal Information Protection Certification
关于实施个人信息保护认证的公告
The November 2022 joint announcement by SAMR and CAC (Announcement No. 37 of 2022) formally launched the Personal Information Protection Certification scheme, designating approved certification bodies to conduct certification activities in accordance with the Implementation Rules for Personal Information Protection Certification and, for cross-border processing activities, the TC260 standard TC260-PG-20222A. Participation is voluntary: the announcement encourages personal information handlers to obtain certification as a means of demonstrating and improving their personal information protection capabilities. The announcement is short — one operative paragraph — and works in tandem with the accompanying Implementation Rules (attached to the announcement) and the subsequently issued Measures for the Certification of the Cross-border Provision of Personal Information (2026). For overseas counsel, the scheme provides a third compliance pathway alongside the Security Assessment and the Standard Contract for cross-border transfers of personal information.
- § 26 · Telecom & Internet User PI Provisions
Provisions on Protecting the Personal Information of Telecommunications and Internet Users
电信和互联网用户个人信息保护规定
Issued by the Ministry of Industry and Information Technology (MIIT) in July 2013 and effective 1 September 2013, these Provisions are the principal sector-specific rule governing the collection and use of users' personal information by telecommunications business operators and internet information service providers operating in China. They establish consent and notice requirements before collection, data-minimisation and purpose-limitation duties, strict confidentiality obligations, mandatory security safeguards (including access controls, breach reporting, annual self-audits, and staff training), and a two-tier penalty regime enforced by MIIT and its provincial communications-administration bureaus. Predating the Personal Information Protection Law (PIPL) by eight years, the Provisions remain in force as a sectoral antecedent and continue to bind telecom and ISP licensees directly through the licence-review process; overseas counsel advising clients who hold or apply for Chinese ICP or telecom value-added service licences must treat these Provisions as the operative data-protection floor alongside PIPL.
- § 27 · Changchun Public Data Authorized Operation Measures
Changchun Municipality Measures for the Administration of Authorized Operation of Public Data Resources
长春市公共数据资源授权运营管理办法
Issued by the Changchun Municipal People's Government as 长府规〔2025〕5号 on September 19, 2025 and effective the same day, these 29-article Measures replace the city's 2023 authorized-operation rules (长府规〔2023〕3号) and realign Changchun — the capital of Jilin Province — with the NDRC/NDA Implementing Specifications and the Jilin provincial measures. Changchun combines whole authorization with authorization by field; the Municipal Government leads through its digital-government leading group, a cross-departmental coordination working group (data, cyberspace, development and reform, public security, state security, finance, market regulation and state-owned assets) handles major issues and builds value, security, quality and compliance assessment systems, the Municipal Government Affairs and Data Bureau administers, and the Municipal Information Center acts as the municipal implementing institution by delegation. All operation takes place in a single citywide 'authorized operation domain': raw data is invisible to processing staff and may not be exported, and models are trained only on sampled, de-identified data. Plans are filed with the provincial data authority, agreements with both provincial and municipal authorities. Pricing follows the national free-for-public-use, government-guided-for-commercial split; revenue is shared on 'who invests, contributes, benefits,' and operators are encouraged to reinvest in departmental and county data governance. Business entities re-develop delivered products after scenario compliance assessment; personal information must be anonymized or authorized; and counties and development zones apply the Measures by reference.
- § 28 · Children in Distress PI Measures
Working Measures for the Protection of the Personal Information of Children in Distress
困境儿童个人信息保护工作办法
Working measures (Min Fa [2024] No. 67) jointly issued by the Ministry of Civil Affairs and seventeen other central authorities and mass organizations to regulate the use and protection of the personal information of children in distress. Following the principle of 'whoever is in charge / whoever processes is responsible', the measures assign protection duties across the civil-affairs, education, health, judicial, publicity, cyberspace, culture-and-tourism and broadcasting systems, as well as trade unions, the Communist Youth League, women's federations and disabled persons' federations. They require consent of parents or guardians for processing the information of children under 14 (and consent of the child plus notice to guardians for those 14 and over), prohibit labeling, traffic-chasing and using such information for fundraising or live-stream commerce, and grant children and their guardians a right to inquire about and object to processing. Effective November 18, 2024.
- § 29 · Guangxi FTZ Negative List (2025)
China (Guangxi) Pilot Free Trade Zone Data Export Management List (Negative List) (2025 Edition)
中国(广西)自由贸易试验区数据出境管理清单(负面清单)(2025版)
Issued in August 2025 as Annex 2 to the joint notice of the Guangxi commerce, FTZ, cyberspace and big-data authorities and filed with the CAC and NDA, the Guangxi negative list is built sector by sector rather than economy-wide, and its 2025 batch covers four industries chosen for the FTZ's ASEAN-facing economy: geographic-information and meteorological data services, enterprise credit-information services, live-streaming cross-border e-commerce, and overseas audio-visual production and distribution. For each sector it lists the important data requiring a security assessment (with scenario descriptions and express exclusions — for example, geographic and meteorological data not depicting Chinese territory is out) and the personal-information volumes requiring assessment or, below that, a standard contract or certification. Two design choices matter for practitioners. First, scenario-specific relaxation: in defined scenarios and for enumerated data fields — corporate officers' and shareholders' details in due-diligence work, shipper and host details in live-commerce logistics, cast-and-crew details in film production — the assessment threshold rises from 1 million to 2 million individuals and the standard-contract band runs from 100,000 (or 500,000 for credit data) to 2 million; outside those scenarios the national 1 million / 10,000-sensitive thresholds apply. Second, counting rules: individuals are de-duplicated, and transfers exempt under Articles 3, 4, 5(1)(1)–(3) and 6 of the 2024 Provisions are not counted. Thirteen explanatory clauses restate the self-assessment mechanism, the export-control carve-out, and the notice, separate-consent and PIPIA duties that continue to apply.
- § 30 · Guangxi FTZ Negative List Measures
China (Guangxi) Pilot Free Trade Zone Measures for the Administration of the Data Export Negative List (Trial)
中国(广西)自由贸易试验区数据出境负面清单管理办法(试行)
Issued in August 2025 (Annex 1 to the joint notice of the Guangxi Department of Commerce, the Guangxi FTZ Work Office, the Guangxi Cyberspace Administration and the Guangxi Big Data Development Bureau, filed with the CAC and the NDA) and effective on publication for a two-year trial, these 18-clause Measures are the procedural framework behind Guangxi's sector-by-sector negative lists — the first FTZ to publish a stand-alone rulebook rather than a list alone. They fix who does what (a cross-border data flow coordination working group of the cyberspace, data, commerce, FTZ, public security and state security authorities plus sector regulators; sector regulators own classification and grading and co-draft their lists), how lists are made (demand research, important-data identification under the regional data-security coordination mechanism, scenario analysis, expert review, approval by the regional Cybersecurity and Informatization Commission and filing with the CAC and NDA), what a list must contain (an assessment list and an SCC/certification list), and how it operates: a processor registered in the FTZ self-assesses whether its export falls within a listed sector and within the list; if within, it uses the national route; if the sector is listed but the data is not, it may export freely; if the sector is not yet listed, general national rules apply. Clause 7 confirms the Article 5 exemption for international trade, cross-border transport, academic cooperation, transnational manufacturing and marketing data containing no personal information or important data; Clause 8 carves out core data, unauthorized government-sourced important data, and export-controlled technical data. An annexed Reference Rules table sets five unified important-data thresholds for FTZ enterprises — including personal information of 10 million or more individuals, or 1 million sensitive, or 100,000 with bank, insurance, account or medical data — and maps 40 sub-categories across 13 sectors to example identification rules.
- § 31 · Hebei Public Data Authorized Operation Measures
Hebei Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial)
河北省公共数据资源授权运营管理办法(试行)
Issued by the Hebei Provincial Data and Government Services Bureau on December 30, 2024 and effective February 1, 2025 for a two-year trial, these 40-article Measures were among the first provincial rules to follow the October 2024 central Opinions on public data. Hebei's model is the most market-procedural of the provincial texts. It mandates scenario-based authorization only — 'one scenario, one authorization' — with operators selected through the public resources trading center by open tender, invited tender or negotiation, and the list of authorizable resources and primary-processed products published there; third-party cleansing, de-identification and pre-processing is procured on a 'whoever commissions pays' basis. Terms are capped at three years in principle, renewal must be sought three months before expiry, and plans and agreements pass the 'three majors and one large' mechanism and are filed upward within 10 working days. A single provincial public data platform is the trusted space for all operations; operators may import lawfully obtained enterprise and personal data for fusion computing with the implementing institution's approval, must train models only on sampled, de-identified data, and may not export raw data or anything reversibly derived from it. Pricing is government-guided; revenue is shared on 'who invests, contributes, benefits.' The Measures spell out five unilateral-termination grounds, require irreversible destruction of raw data on exit with six months of log retention, and bar any indirect acquisition of public-data rights through system co-development or data-governance service contracts.
- § 32 · Jiangxi Public Data Authorized Operation Measures
Jiangxi Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial)
江西省公共数据资源授权运营管理办法(试行)
Issued by the General Office of the Jiangxi Provincial People's Government as 赣府厅发〔2025〕26号 on November 11, 2025, effective December 15, 2025 for a two-year trial period, these 25-article Measures implement the 2024 central Opinions and the NDRC/NDA Implementing Specifications in Jiangxi. Three features distinguish the Jiangxi text. It uses a negative-list mechanism for supply: every government department must bring its lawfully held public data into authorized operation unless it justifies an exclusion, which the data authority reviews and the government approves as a negative list; public data obtained via government sharing may be used only with the providing unit's consent. It fixes governance by level: the Provincial Big Data Center is the provincial implementing institution, cities and counties choose their own, plans and operating agreements must pass the 'three majors and one large' collective decision mechanism and be filed with the provincial data authority within 20 working days, and a single provincial authorized-operation platform is the default, with municipal platforms only by provincial consent and on unified catalogue, identity and interface standards. And it treats revenue as public finance: income from the use of administrative and public-institution data resources is managed as government non-tax revenue under the centralized treasury system, with a stated aim of feeding proceeds back into public services. Operators may not sublicense, exceed scope or re-develop delivered products; on termination the implementing institution must cut platform access and retain the operator's full work logs for at least three years. A due-diligence exemption clause and a clause on managing data-asset securitization risk round out the text.
- § 33 · Jilin Public Data Authorized Operation Measures
Jilin Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial)
吉林省公共数据资源授权运营管理办法(试行)
Issued by the Jilin Provincial Government Services and Digital Development Administration on April 24, 2026 as a local normative document (吉政数发〔2026〕4号) and effective the same day for a two-year trial period, these 29-article Measures localize the NDRC/NDA Implementation Specifications for Authorized Operation of Public Data Resources within Jilin. They track the national template closely — implementation plans approved under the 'three majors and one large' mechanism, operators selected by public bidding, invited bidding or negotiation, a five-year cap on operating terms, and a ban on operators re-developing their own delivered products — but add several provincial features: a defined 'data-source unit' with its own duty list, a two-tier filing chain under which county plans and agreements flow to the city and then to the province within one month, a mandatory pre-release evaluation report on every data product covering legality, accuracy, de-identification and consent, full retention of network logs for at least five years, free use of products for public governance with government-guided pricing for industry, and a 'three distinctions' fault-tolerance clause that relieves officials of liability for good-faith deviations. For overseas counsel, the Measures show how a northeastern province operationalizes the 'raw data does not leave its domain' rule and where a data-source unit's consent sits in the chain.
- § 34 · Mobile App Information Services Provisions
Provisions on the Administration of Mobile Internet Application Information Services (2022 Revision)
移动互联网应用程序信息服务管理规定(2022 修订)
The 2022 revision of the CAC's flagship app-governance rule, effective 1 August 2022, imposes dual-track obligations on app providers and app distribution platforms (including app stores, mini-program platforms, and browser plug-in platforms). App providers must verify users' real identity information via mobile-phone number, identity-document number, or unified social credit code before enabling publication or messaging features, and must comply with personal information minimization requirements — including a prohibition on denying core service functionality solely because a user declines to supply non-essential personal information. App distribution platforms must register with provincial-level CAC offices within 30 days of going live, implement multi-factor real identity verification of every app provider seeking to list on the platform, and conduct substantive pre-listing and ongoing review of apps for legal compliance, data security risks, and illegal or excessive collection and use of personal information. Overseas counsel advise on these provisions because they set the compliance baseline that any foreign app operator — whether publishing directly or distributing through Chinese app stores — must satisfy before reaching Chinese users.
- § 35 · Ningxia Public Data Authorized Operation Measures
Ningxia Hui Autonomous Region Measures for the Administration of Authorized Operation of Public Data Resources (Trial)
宁夏回族自治区公共数据资源授权运营管理办法(试行)
Issued by the Development and Reform Commission of Ningxia Hui Autonomous Region (which also houses the regional Data Bureau) on September 26, 2025 as a local normative document (宁发改规发〔2025〕11号), effective November 1, 2025 and valid through October 31, 2027, these 33-article Measures localize the NDRC/NDA Implementation Specifications for the autonomous region. The Ningxia model departs from the national template in several respects: during a trial period capped at three years the whole region uses a single overall-authorization model, the implementing institution must be a public institution (事业单位) designated by the regional government, and the operating institution is chosen not by bidding but through a published solicitation, application and review with a public announcement of at least five working days. The Measures then build a full third tier — 'data developers' — who access public data on a 'one scenario, one application' basis through a five-working-day acceptance, joint review by the data administration department, implementing institution and data-source unit, and a development-and-utilization agreement filed with the regulator. All authorized operation runs through a single regional Data Element Comprehensive Service Platform; products for public governance are free, while industrial uses may bear an operating service fee under government-guided pricing set by the DRC. A dedicated data security and supervision chapter assigns primary security responsibility to all three tiers.
- § 36 · Shandong Public Data Authorized Operation Measures
Shandong Province Measures for the Administration of Authorized Operation of Public Data Resources (Trial)
山东省公共数据资源授权运营管理办法(试行)
Issued by the Shandong Provincial Big Data Bureau on April 2, 2025 with the approval of the provincial government (鲁数发〔2025〕3号), effective May 1, 2025 and valid until May 1, 2028, these 41-article Measures are among the earliest and most complete provincial implementations of the NDRC/NDA Implementation Specifications. Shandong's distinctive choice is institutional: the data administration department at each level at or above the county is itself the implementing institution, overall authorization is the default model, and every application, review and service-monitoring step runs through a unified authorization-management module on the provincial integrated big data platform, to which provider units must aggregate all public data resources. The Measures require operators to hold data resources by application against a minimum-necessary test, to register their products, to trade them only through data trading institutions, and to submit annual reports; revenue-distribution terms must be cleared with the finance department, plans and agreements are filed with the province within 20 working days, and income of administrative and public institutions is treated as government non-tax revenue. A dedicated security chapter mandates privacy computing, pre-employment training, confidentiality agreements and regulator-run drills, and the supplementary provisions extend the procedure by reference to data held by water, gas, heat, power and public-transport utilities.
- § 37 · Shanghai Public Data Authorized Operation Measures
Shanghai Municipality Measures for the Administration of Authorized Operation of Public Data Resources
上海市公共数据资源授权运营管理办法
Issued by the General Office of the Shanghai Municipal People's Government as 沪府办发〔2025〕15号 on July 12, 2025 and effective the same day, these 34-article Measures are Shanghai's implementation of the national public-data authorized-operation regime under the 2024 CPC Central Committee and State Council Opinions and the NDRC/NDA Implementing Specifications. Shanghai's model is distinctive on four points. It adopts a single citywide 'whole-authorization' model: one implementing institution determined by the municipal government, with districts allowed to run their own programs only with the approval of the municipal data leading group. It builds a unified authorized-operation infrastructure — an 'authorized operation domain' on the citywide data infrastructure using blockchain, privacy computing and trusted data spaces — inside which operators develop basic public data products and development entities re-develop them. It separates roles sharply: operators are chosen by fair competition, must keep separate accounts, may not re-develop delivered products, and are bound by anti-monopoly and unfair-competition prohibitions; development entities must run scenario compliance assessments. And pricing follows the national split — free or conditionally free for public governance and public-interest uses, government-guided pricing for commercial uses — with a 'who invests, who contributes, who benefits' revenue rule. Personal information in public data must be anonymized or authorized via channels such as Suishenma. For overseas counsel, it is the reference text for how China's largest data market will license public data to commercial developers.
- § 38 · Shanxi Public Data Authorized Operation Measures
Shanxi Province Measures for the Administration of the Authorized Operation of Public Data Resources (Trial)
山西省公共数据资源授权运营管理办法(试行)
Issued by the General Office of the Shanxi Provincial People's Government on August 2, 2025 as 晋政办发〔2025〕23号 and effective September 1, 2025 for a two-year trial period, these 40-article Measures localize the NDRC/NDA Implementation Specifications for Shanxi. The distinctive feature is a two-tier authorization architecture: the Provincial Data Bureau, acting as implementing institution, selects a single tier-one operating entity that builds and runs the province-wide authorized-operation platform and performs primary data processing, and then, sector by sector, selects tier-two operating entities jointly with the provincial sectoral departments; a third layer of development entities applies for data through the platform under a 'one scenario, one application, one review' rule. Sectoral departments and their affiliates are expressly barred from granting authorization or operating on their own. Terms are capped at five years, plans and agreements pass through 'three majors and one large' deliberation and are filed level by level, fees for industry use are government-guided on a cost-compensation basis, and exiting operators must keep at least three years of work logs. For overseas counsel, the entry shows how a province can insert an intermediary platform operator between government data holders and the market while keeping raw data from leaving the domain.
- § 39 · Tianjin FTZ Negative List (2024)
China (Tianjin) Pilot Free Trade Zone Data Export Management List (Negative List) (2024 Edition)
中国(天津)自由贸易试验区数据出境管理清单(负面清单)(2024年版)
Published on May 9, 2024 after approval by the Tianjin Municipal Cyberspace Affairs Commission and filing with the Cyberspace Administration of China and the National Data Administration, the Tianjin negative list was the first in China issued under Article 6 of the 2024 Provisions on Promoting and Regulating Cross-border Data Flows. Its logic is inverted from the general regime: an enterprise registered in the Tianjin FTZ that exports data not on the list is exempt from security assessment, standard contract and certification; only listed data must go through the national routes. Part I lists 45 items across 13 categories that require a CAC security assessment — strategic materials and commodities (oil, petrochemicals, gas, agricultural products), natural resources and environment (geographic information, remote sensing, meteorology, environmental protection, water, oceans), industry (defense, chemicals, steel and non-ferrous metals, rare earths, other minerals, electricity, electronics, civil nuclear facilities, industrial equipment, industrial internet and control systems, intelligent vehicles), finance (banks, insurance, financial leasing), statistics, telecommunications and broadcasting, housing provident funds, postal and transport, public health (medical, food, drugs, biosecurity, disease control), public security (physical, cyber, emergency management), internet services and e-commerce (service outsourcing, platforms), science and technology (export-controlled items, restricted technologies, key IP), and personal information above the 1 million / 10,000-sensitive thresholds or from CIIOs. Part II lists one item — the 100,000-to-1-million and under-10,000-sensitive band — that requires a standard contract or certification. State secrets, core data and government data are outside the list and follow general law.
- § 40 · Xianyang Public Data Authorized Operation Measures
Xianyang Municipal Measures for the Administration of Authorized Operation of Public Data Resources (Interim)
咸阳市公共数据资源授权运营管理办法(暂行)
Issued by the General Office of the Xianyang Municipal People's Government (Shaanxi) on June 18, 2025 as a local normative document (咸政办函〔2025〕48号) after approval at the 59th executive meeting of the municipal government, and effective July 20, 2025 for two years, these 27-article interim Measures are a compact, prefecture-level adaptation of the NDRC/NDA Implementation Specifications. What distinguishes the Xianyang model is that the Municipal Data Bureau itself acts as the implementing institution under a single overall-authorization model (with scenario-based authorization to be explored later), and that the Measures add a third commercial tier — 'public data development entities' selected by the operating institution on market principles without regard to geography, sector or ownership — beneath the operator. Agreement content is incorporated by cross-reference to Article 14 of the national Specifications rather than restated, pricing follows national policy with 'conditional paid use' for industrial applications, and the data-quality chain includes a level-by-level traceback mechanism. The Measures cite the Shaanxi Provincial Big Data Regulations as a local legal basis. For overseas counsel, the text is a useful example of how a mid-sized city layers a development-entity market on top of a single authorized operator.
- § 41 · Yanbian Public Data Authorized Operation Measures
Yanbian Prefecture Measures for the Administration of Authorized Operation of Public Data Resources
延边州公共数据资源授权运营管理办法
Issued by the People's Government of Yanbian Korean Autonomous Prefecture in Jilin Province as 延州政规〔2026〕1号 on January 22, 2026 and effective the same day, these 43-article Measures are a prefecture-level implementation of the national public-data authorized-operation regime under the Jilin provincial measures and the NDRC/NDA Implementing Specifications. What sets them apart is their framing around Yanbian's position as a border, ethnic-minority prefecture: the Measures direct authorized operation toward Korean-ethnic culture and tourism, Northeast-Asia cross-border e-commerce and port logistics, geographical-indication agricultural products (Yanbian yellow cattle, Changbai Mountain ginseng, Wangqing black fungus) with 'one product, one code' traceability, and multilingual smart-border governance. Institutionally, the Prefecture Government Affairs and Data Bureau leads, the Prefecture Big Data Center is the implementing institution, and a whole-authorization model is the default. Before any authorization, resources must appear on the prefecture's 'two lists' (total inventory and authorizable inventory) drawn from a state-owned data census, be registered on the Jilin provincial registration platform, and pass a compliance review; counties may not build their own platforms; and government systems must migrate into a prefecture data resource pool. Operators may not export raw data, reverse-engineer it, sublicense it or re-develop delivered products. Border counties trigger a special security risk assessment and joint supervision by public security, state security and foreign affairs. Effectiveness evaluation weighs social benefits — cultural transmission, border-resident income, agricultural premiums, trade facilitation — as core indicators.
- § 42 · Zhaoqing Public Data Authorized Operation Measures
Zhaoqing Municipality Administrative Measures for the Authorized Operation of Public Data Resources (Trial)
肇庆市公共数据资源授权运营管理办法(试行)
Issued by the Zhaoqing Municipal People's Government (Guangdong) on April 29, 2025 after adoption at the 92nd executive meeting of the 14th Municipal Government, and effective May 1, 2025 for a three-year trial period, these 33-article Measures are one of the earliest prefecture-level implementations of the NDRC/NDA Implementation Specifications. Zhaoqing's model is distinctive for its four-tier chain of actors: the Municipal Government Affairs and Data Bureau acts as the 'data management institution', a municipal-government-designated implementing institution selects the operating institution through public bidding, invited bidding or negotiation, and the operating institution in turn licenses 'development institutions' scenario by scenario under a 'one scenario, one authorization, one scenario, one approval' rule. The data flow runs through two infrastructures — the municipal government big-data platform and a municipal public-data-resource operation service platform — with each tier bearing primary security responsibility for its own segment. Public-governance and public-welfare products are conditionally free; commercial products follow national pricing policy. Counsel structuring data-product ventures in the Greater Bay Area hinterland will find the platform-segmented liability allocation in Article 29 the most practically important provision.
- § 43 · Zhejiang Public Data Authorized Operation Measures
Zhejiang Province Administrative Measures for the Authorized Operation of Public Data Resources
浙江省公共数据资源授权运营管理办法
Issued by the General Office of the Zhejiang Provincial People's Government on September 1, 2025 as 浙政办发〔2025〕30号 and effective October 1, 2025, these Measures replace Zhejiang's 2023 trial rules and serve as the province's overall implementation plan under the NDRC/NDA Implementation Specifications. Zhejiang's model is distinctive in three respects: it adopts scenario-based authorization (依场景授权) as the default rather than whole-package authorization, it makes the data administration authority at each level the implementing institution, and it builds the whole regime around an 'authorized-operation domain' (授权运营域) — a secure enclave on the province's integrated intelligent public data platform or a trusted data space, from which raw data may not leave and through which every product must pass an exit review. Operating institutions are chosen through an open scenario-application and review process rather than bidding, agreements generally run no more than three years (shorter than the national five-year cap), data-source units must review data requests within five working days, and operators price their products under a legality, universality and reasonable-return standard while implementing institutions may charge for cloud, computing and technical services. Overseas counsel advising data-product ventures in Zhejiang should read this alongside the national Specifications and the Zhejiang Public Data Regulations.
- § 44 · Zhengzhou Public Data Authorized Operation Measures
Zhengzhou Municipality Measures for the Administration of Authorized Operation of Public Data Resources (Trial)
郑州市公共数据资源授权运营管理办法(试行)
Issued by the General Office of the Zhengzhou Municipal People's Government as 郑政办〔2026〕15号 on April 23, 2026 and effective the same day for a two-year trial, these 28-article Measures implement the NDRC/NDA Implementing Specifications and the Henan provincial implementing measures (豫政办〔2025〕5号) at the municipal level. Zhengzhou opts for a single whole-authorization model in which the municipal data authority — not a separate implementing institution — selects the operator by fair competition, signs the agreement after consulting the finance department on revenue sharing, and runs the 'three majors and one large' approval. The operator's mandate is unusually broad: it builds the authorized-operation platform (to MLPS and commercial-cryptography assessment standards), does primary processing, cultivates the market ecosystem and drafts the rules for admitting 'development entities.' Those entities must meet capability, premises, personnel and credit-record conditions (relaxed for firms holding national or provincial science awards) and sign development agreements capped at three years; they receive only primary-processed data through the platform on a 'raw data stays in-domain, usable but not visible' basis, and exported products may not be reversible. Operators may not sublicense or re-develop delivered products; trading through data exchanges is encouraged; and a 'three distinctions' due-diligence exemption protects officials and operators who err in good faith while exploring.
- § 45 · School Protection Provisions
Provisions on the Protection of Minors by Schools
未成年人学校保护规定
MOE Order No. 50, the school-facing implementing rule under the Law on the Protection of Minors. For the online-protection regime its load-bearing provision is Article 21: teachers and staff who discover students fabricating facts to defame others, spreading rumors or false information, or maliciously disseminating others' private information through networks or other means must stop it promptly — the hook that turns online defamation and privacy-spreading incidents among students into a school management duty, with civil supplementary liability under Civil Code Article 1201 if the school fails to act.
- § 46 · Data Export Declaration Guide (v3)
Guidelines for the Declaration of Data Export Security Assessment (Third Edition)
数据出境安全评估申报指南(第三版)
The CAC's third-edition procedural guide — issued and effective 27 June 2025 — sets out in detail who must file a Data Export Security Assessment declaration, the step-by-step filing process through the online declaration system (sjcj.cac.gov.cn), the eight categories of required materials (including the self-assessment report and the legally binding contract with the overseas recipient), and the newly introduced procedure for applying to extend an approved assessment's validity period. It supersedes the first and second editions, streamlines the documentary requirements, and clarifies the conditions (capped volume increases of no more than 20 % over the prior three-year approval period) and timeline (60 working days before expiry) for extension applications. Overseas counsel advising on cross-border data transactions need this guide to prepare compliant declaration packages and to structure the legal agreement with the overseas recipient so that it satisfies the mandatory contractual checklist in the self-assessment report template.
- § 47 · Data Security Certification Announcement
Announcement of the State Administration for Market Regulation and the Cyberspace Administration of China on Carrying Out Data Security Management Certification
国家市场监督管理总局、国家互联网信息办公室关于开展数据安全管理认证工作的公告
Announcement (SAMR/CAC Announcement No. 18 of 2022) launching a voluntary data security management certification scheme that encourages network operators to certify their network-data processing activities (collection, storage, use, processing, transmission, provision, disclosure, etc.) and strengthen network data security protection. The attached Data Security Management Certification Implementation Rules, based on the Regulations on Certification and Accreditation and the standard GB/T 41479 (Information security technology—Security requirements for network data processing), set out a certification mode of 'technical verification + on-site audit + post-certification supervision', the certification procedure, a three-year certificate validity period, and rules on certificates, certification marks and the responsibilities of certification bodies. Effective June 5, 2022.
- § 48 · GBA (Mainland-Macao) SCC Guidelines
Implementation Guidelines for the Standard Contract for the Cross-Border Flow of Personal Information within the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland, Macao)
粤港澳大湾区(内地、澳门)个人信息跨境流动标准合同实施指引
Jointly issued on 10 September 2024 by the CAC, the Economic and Technological Development Bureau of the Macao SAR, and the Personal Data Protection Bureau of the Macao SAR, these Implementation Guidelines establish a bilateral facilitation arrangement that allows eligible personal information handlers registered or located in the nine Guangdong cities of the Greater Bay Area or the Macao SAR to transfer personal information between those two jurisdictions by executing a prescribed Standard Contract and filing it with the applicable local authority within 10 working days, without needing to pass a CAC security assessment — even where data volumes exceed the national thresholds that would otherwise trigger that assessment. The arrangement operates under the Cooperation Memorandum on Promoting Cross-Border Data Flows in the Guangdong-Hong Kong-Macao Greater Bay Area signed between the CAC and the Economic and Finance Bureau of the Macao SAR. The Guidelines exclude personal information classified as important data and require handlers to complete a Personal Information Protection Impact Assessment (PIPIA) before each cross-border provision. For overseas counsel, the arrangement is significant because it creates a distinct GBA intra-Bay-Area pathway that sits alongside — and in some respects relaxes — the three national cross-border transfer routes under PIPL and the Provisions on Promoting and Regulating Cross-border Data Flows.
- § 49 · GBA (Mainland-Hong Kong) SCC Guidelines
Implementation Guidelines for the Standard Contract for the Cross-Border Flow of Personal Information within the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland, Hong Kong)
粤港澳大湾区(内地、香港)个人信息跨境流动标准合同实施指引
The 2023 GBA Mainland-Hong Kong facilitation arrangement jointly issued by the CAC and Hong Kong's Innovation, Technology and Industry Bureau on 10 December 2023, implementing the bilateral Memorandum of Cooperation on Promoting Cross-Border Data Flows in the Greater Bay Area. It establishes a simplified standard-contract pathway enabling personal information handlers and recipients registered or located in the nine mainland GBA cities (Guangzhou, Shenzhen, Zhuhai, Foshan, Huizhou, Dongguan, Zhongshan, Jiangmen, Zhaoqing) or in Hong Kong SAR to transfer personal information cross-border without triggering the full national-level security assessment regime, subject to a mandatory Personal Information Protection Impact Assessment and filing with the Guangdong CAC or the Hong Kong Office of the Government Chief Information Officer within ten working days of contract entry into force. Personal information that has been notified or publicly released as important data is excluded. This arrangement was the model for the subsequent September 2024 GBA Mainland-Macao version and matters to overseas counsel because it creates a distinct, lighter-touch bilateral track for intra-GBA flows that operates alongside — and does not replace — PIPL's three national-level pathways.
- § 50 · PIPO Reporting Announcement
Announcement on Carrying Out the Reporting of Personal Information Protection Officer Information
关于开展个人信息保护负责人信息报送工作的公告
The July 2025 CAC announcement operationalises the person-in-charge-of-personal-information-protection (PIPO) designation and filing requirement under PIPL Article 52 and Article 12 of the Administrative Measures for Personal Information Protection Compliance Audits: any personal information handler that processes the personal information of one million or more individuals must report the identity and contact details of its designated person in charge of personal information protection to the municipal-level CAC office where it is registered. Personal information handlers that had already crossed the one-million threshold before 18 July 2025 were given until 29 August 2025 to complete the initial filing; those crossing the threshold after that date must file within 30 business days. Reporting is done exclusively online through the Personal Information Protection Business System (grxxbh.cacdtsc.cn), also reachable from the CAC website's 'National Cyberspace Administration Affairs Hall.' For overseas counsel advising China-facing businesses, this announcement means that any client meeting the PIPL Art. 52 threshold must have a named, reported PIPO on file with the local regulator — failure to do so is an express regulatory violation.
- § 51 · Minors PI Audit Reporting Announcement
Announcement on Submitting Reports on the Compliance Audit of Minors' Personal Information Protection
关于报送未成年人个人信息保护合规审计情况的公告
Issued by the CAC on 29 December 2025, this short announcement operationalizes the annual compliance-audit-and-report obligation that Article 37 of the Regulations on the Protection of Minors in Cyberspace imposes on every personal information handler that processes personal information of minors. It fixes the annual reporting deadline (by 31 January of the following year), designates the local prefecture-level cyberspace administration authority as the recipient, mandates online submission through the CAC's Personal Information Protection Business System, and warns that failure to conduct or report the compliance audit will be dealt with under the applicable laws, regulations, and rules. The announcement bridges the PI Audit Measures (effective May 2025) and the minors-protection regime: any handler—regardless of scale—must audit its minors-PI practices each year. Overseas counsel advising multinationals with Chinese apps or platforms that reach minors should ensure clients have a standing annual audit-and-submission process in place before 31 January.
- § 52 · FISR Measures
Measures for the Security Review of Foreign Investments
外商投资安全审查办法
The Foreign Investment Security Review (FISR) Measures govern review of foreign investment in China that affects or may affect national security. Article 2 covers new projects, M&A of equity or assets, and other forms of domestic investment by foreign investors. Article 4 brings important information technology, internet products and services, and key technologies into the mandatory pre-notification scope. The test for the security review's bite is actual control — defined broadly to include >50% equity, voting-share thresholds, and other circumstances that materially influence operational decisions, personnel, finance, or technology. These Measures were the legal basis for the April 2026 ban on the Meta–Manus acquisition.
- § 53
Interim Measures for the Registration and Administration of Public Data Resources
公共数据资源登记管理暂行办法
The Interim Measures establish a nationally unified registration system for public data resources — data collections produced by Party and government organs and public institutions in the course of performing statutory duties or providing public services. Registration is mandatory for public data resources that fall within authorized-operation scope; voluntary registration is encouraged for other public data resources and for data products and services derived from them. The Measures set the registration procedure (application, acceptance, formal review, public announcement, code issuance), define four registration types (initial, change, correction, deregistration), establish a three-year validity period with renewal, and provide for graded supervision under NDA's overall administration. Effective March 1, 2025, with a five-year validity period. DCC translation; no official English version exists.
- § 54
Implementation Specifications for Authorized Operation of Public Data Resources (Trial)
公共数据资源授权运营实施规范(试行)
Companion rule to the Public Data Registration Interim Measures (also NDRC + NDA, January 2025). The Specifications establish the framework for 'authorized operation' (授权运营) of public data resources — the mechanism by which governments at and above the county level, and national sectoral authorities, can authorize qualified operating institutions to develop and operationalize public data resources, deliver data products and services to the market, and share in the revenue. Covers implementing institutions, operating institutions, the implementation plan, the agreement, supervision, anti-monopoly and security duties. The Operating-institution authorization period is capped at five years. Effective March 1, 2025, with a five-year validity period. DCC translation; no official English version exists.
- § 55 · Cybersecurity Label Measures
Measures for the Administration of Cybersecurity Labels
网络安全标识管理办法
A joint CAC–MIIT–MPS rule establishing a voluntary product-certification scheme — the 'China Cybersecurity Label' — for internet-connected products, layered into one/two/three-star tiers (basic, enhanced, and leading cybersecurity capability). Coverage is catalogue-managed: products are added in batches, each with its own implementing rules and technical basis, and critical network equipment and dedicated cybersecurity products already regulated under the 2023 security-management framework are carved out. Three-star products must clear penetration testing by a qualified third-party lab, and every label carries a scannable filing code linking to the test report and the manufacturer's compliance declaration. Misuse — forged or misappropriated labels, false advertising, or fabricated test results — triggers filing revocation, public naming, a one-year bar on re-filing, and entry into the national credit-information system. For overseas counsel, this is a market-facing trust mark rather than a mandatory compliance gate, but it interacts with existing MLPS and product-security obligations and is likely to become a de facto procurement or channel-access signal even though participation is nominally voluntary.
- § 56 · Trade Secret Protection Provisions
Provisions on the Protection of Trade Secrets
商业秘密保护规定
SAMR's rewrite of China's 1995 trade-secret enforcement rules — issued as Order No. 126 under the Anti-Unfair Competition Law — folds algorithms, data, and source code squarely into the definition of a protectable technical-information trade secret, and for the first time recognizes tiered access, data masking, and audit-log retention as adequate confidentiality measures for remote-work and cross-border collaboration setups. It also names electronic intrusion and unauthorized transfer of files to personal cloud drives or external storage as 'improper means' of misappropriation, giving SAMR an administrative-enforcement path for conduct that would otherwise only surface as a data-security incident or a cybercrime case. For overseas counsel, it matters less as a data-protection instrument than as the rule that now lets an aggrieved company route an insider data-exfiltration episode through market-regulation enforcement rather than the police or the courts alone.
- § 57 · Minors Harmful-Info Classification Measures
Measures for the Classification of Online Information That May Affect the Physical and Mental Health of Minors
可能影响未成年人身心健康的网络信息分类办法
A short but operationally important CAC-led rule that, for the first time, defines and catalogues a middle tier of online content: material that falls short of outright illegal content but may still harm minors' physical or mental health. It sorts this content into four classes — inducements to imitate unsafe or antisocial behavior, content harmful to values, improper use of a minor's image, and improper disclosure or use of a minor's personal information — and requires platforms to label it prominently and keep it out of high-traffic slots like homepages, push notifications, and trending lists when the audience includes minors. For overseas counsel, Article 6's personal-information category is the one to watch: it reaches conduct such as showing an under-14's schooling or daily life in enough detail to expose identifying information without guardian consent, or content that induces minors to disclose their own or others' personal information, layering content-moderation duties on top of existing PIPL and minors-protection consent obligations.
National Standards .
国家标准 · GB/T, TC260
- § 01 · GB/T 44297—2024
GB/T 44297—2024 Data Items of Video and Image Information for Public Security
GB/T 44297—2024 公共安全视频图像信息数据项
GB/T 44297—2024 is the national recommended standard that specifies the data items used in public-security video image information systems — the underlying field-level schema that camera systems, video platforms, and analysis tools use to describe and exchange video and image data. It applies to data exchange in networked public-security video applications. The standard catalogs more than twenty top-level data-item groups — covering camera information, system/platform information, equipment status, video clips, images, file objects, persons of interest, vehicles of interest, non-motor vehicles, items, scenes, events, regions, motion targets, subscriptions, feature vectors, organized data libraries, and real-time matching against reference lists — plus a set of normative code tables (Appendix D) used to encode the field values. The standard is technical reference material for system integrators and data engineers operating public-security video systems. Cross-reference to the *Administrative Regulation for Public Security Video Image Information Systems* (State Council Decree No. 799) and the *Facial Recognition Technology Application Measures* (CAC + MPS Decree No. 19), which set the legal duties; this standard tells operators what field-level data to capture and exchange in order to meet those duties.
- § 02 · TC260 Sensitive PI Guide
Cybersecurity Standards Practice Guide — Sensitive Personal Information Identification Guide (v1.0, September 2024)
网络安全标准实践指南 — 敏感个人信息识别指南 (v1.0-202409)
TC260's September 2024 practice guide for identifying sensitive personal information under PIPL Article 28. Sets out a four-rule identification framework — damage to personal dignity, to personal safety, to property safety, and aggregation effects — and lists eight common categories of sensitive personal information with illustrative examples in Appendix A. The guide is not a mandatory standard; it is advisory practice guidance issued by the TC260 Secretariat to help organizations operationalize PIPL's sensitive-PI regime. Practical reference for handlers performing the PIPIA required by PIPL Article 55(I) before processing sensitive personal information.
- § 03 · GB/T 43697
Data Security Technology — Rules for Data Classification and Grading (GB/T 43697-2024)
数据安全技术 数据分类分级规则 (GB/T 43697-2024)
GB/T 43697-2024 is the foundational national standard operationalizing the data classification and grading protection system mandated by DSL Article 21. Issued 15 March 2024 and effective 1 October 2024, it sets out the principles, framework, methods and workflow for classifying data by sector/business attribute and grading it into three tiers — core data (核心数据), important data (重要数据) and general data (一般数据) — and provides an important-data identification guide. It is the reference document that sector regulators use to build sector-specific catalogues and that data processors use to classify and grade their own holdings.
- § 04 · GB 46864
Data Security Technology — Technical Requirements for Information Sanitization of Electronic Products (GB 46864-2025)
数据安全技术 电子产品信息清除技术要求 (GB 46864-2025)
GB 46864-2025 is a mandatory national standard published December 2, 2025 and taking effect January 1, 2027, drafted to close the gap between 'delete' — which merely marks data invalid — and genuine erasure when phones, computers and other devices with non-volatile storage are resold, sent for repair or scrapped; it is expressly tied to the State Council's 2024 trade-in program for consumer goods. It applies to electronic products made or sold in China, to manufacturers and third parties that build erasure functions, and to recycling operators. Chapter 5 defines the erasure baseline: all user data — files, contacts and call logs, installed apps and their data, credentials and biometrics, bound smart-card details, settings, backups and caches — must go; encryption keys and all copies must be destroyed on encrypted devices; accounts must be logged out with auto-login, cloud sync and old-passcode activation disabled; magnetic media must be overwritten at least three times including one random pass, semiconductor media must have the logical-physical mapping deleted and be overwritten at least once or block-erased. Chapter 6 requires manufacturers to ship a built-in erasure function (or supply a tool or free service), disclose scope, method and effects and obtain consent before running it, verify pre-conditions, and offer alternatives on failure. Chapter 7 binds recyclers: prompt users to erase, never access or retain data without consent, physically destroy media that cannot be erased, verify before resale, keep erasure records for three years, and never resell or export un-erased devices. For device makers and refurbishers selling into China, it is the erasure specification to build to before 2027.
- § 05 · GB/T 35273
Information Security Technology — Personal Information Security Specification (GB/T 35273-2020)
信息安全技术 个人信息安全规范 (GB/T 35273-2020)
GB/T 35273-2020 is China's foundational recommended national standard on personal information protection. First issued in 2017 and revised in 2020, it predates PIPL and shaped much of its drafting; it sets out detailed good-practice requirements across the full personal-information lifecycle — collection, storage, use, sharing/transfer/disclosure, deletion — plus security incident handling and organizational governance. Although a recommended (non-mandatory) standard, it has long been the operational benchmark Chinese regulators reference, and it remains the most detailed practical gloss on PIPL's principles.
- § 06 · GB/T 41807
Information Security Technology — Security Requirements of Voiceprint Recognition Data (GB/T 41807-2022)
信息安全技术 声纹识别数据安全要求 (GB/T 41807-2022)
GB/T 41807-2022 is a recommended national standard published October 12, 2022 and implemented May 1, 2023 that sets security requirements for voiceprint recognition data — the voice samples, extracted voiceprint features and templates, and comparison results used to identify or verify individuals by voice. It is one of a family of TC260 biometric standards (with face, gait, fingerprint and iris counterparts) that translate the PIPL's treatment of biometric identifiers as sensitive personal information into engineering controls. Its core structure follows the data lifecycle: a general chapter on lawful basis, separate consent, purpose limitation and the preference for verification over identification; collection (necessity, notice, no covert capture, immediate feature extraction); storage (encryption, separation of voiceprint features from identity data, template protection, no retention of raw voice beyond necessity, local storage preference); use (matching thresholds, anti-spoofing, prohibition on repurposing and on inferring other attributes such as health or emotion); transfer and provision (encrypted channels, consent for onward provision, restrictions on cross-border transfer); deletion (on withdrawal of consent, purpose achieved or account closure, and on request); and management (security assessment, incident response, personnel and audit). Annexes cover typical voiceprint scenarios such as payment, account login, customer-service verification and smart devices, and a security-analysis framework. DCC's copy of the standard is font-encoded and could not be verified clause by clause; the structure above follows the published table of contents and the standard's known content.
- § 07 · GB/T 46903
Data Security Technology — Requirements for Personal Information Protection Compliance Audits (GB/T 46903-2025)
数据安全技术 个人信息保护合规审计要求 (GB/T 46903-2025)
GB/T 46903-2025, published December 31, 2025 and implemented July 1, 2026, is the national standard that gives operational content to the CAC's 2025 Personal Information Protection Compliance Audit Measures, replacing the 2024 TC260 practice guide as the reference text for auditors and audited handlers. It applies to personal information handlers and professional audit institutions. Its general requirements track the Measures — handlers of more than 1 million individuals' data must designate a PIPO to lead audits, large platforms must set up an outside-member supervisory body, professional institutions may not subcontract or audit the same client more than three consecutive times, and audit frequency is at least every two years above 10 million individuals, every three to four years between 1 and 10 million, preferably every five years below, and annually for minors' data — and add staffing floors: at least ten auditors (one senior, three intermediate) above 10 million and five (two intermediate or above) between 1 and 10 million, with junior, intermediate and senior competence profiles defined by years of experience and project counts. Chapter 5 sets a five-stage process — preparation, fieldwork, reporting, rectification and archiving — with required contents for the audit plan, working papers and report, signature rules, and a dispute-resolution mechanism. Chapter 6 is the substance: 26 audit areas, each with audit content, reference evidence and method, covering lawful basis and consent, processing rules and notice, joint and entrusted processing, transfers on merger, provision to third parties, automated decision-making, public disclosure, public-place image capture, publicly available data, sensitive data, children under 14, cross-border transfers, deletion and individual rights, internal rules, technical measures, training, the PIPO, impact assessments, incident plans and response, large-platform rules and social-responsibility reports. Annexes give an evidence typology and templates for working papers and the report.
- § 08 · GB/T 47469
Data Security Technology — Management Guidance for Smart Mobile Terminals on Personal Information Processing Activities of Mobile Internet Applications (Apps) (GB/T 47469-2026)
数据安全技术 移动智能终端的移动互联网应用程序(App)个人信息处理活动管理指南 (GB/T 47469-2026)
GB/T 47469-2026, published April 30, 2026 and implemented November 1, 2026, is the first national standard addressed not to app developers but to the makers of the phones and tablets apps run on. Drafted by TC260 with Huawei, OPPO, vivo and the major app platforms, it tells smart-terminal providers how to build operating-system controls that make app data collection knowable and controllable by users. It defines terminal personal information (contacts, call logs, SMS, media, device identifiers, phone number, app list, location, network data), six principles (user knowledge, user control, security, fine-grained management, proportionality and clear rules), and three risk classes, then prescribes two tiers of measures — basic and enhanced. Transparency: a persistent on-screen indicator whenever an app uses the microphone, camera or location in foreground or background; a behavior log covering location, contacts, media, SMS, biometrics, device identifiers, call logs, microphone, camera, screen capture, self-start and associated start, app-list and clipboard reads, retained at least seven days with per-event detail; and a single management entry in the settings menu. Behavior management: one-time and while-in-use permission grants, editable permission-purpose text, automatic permission reset after about three months of non-use; app-list and clipboard access control; screenshot control; coarse-location option; no background microphone or camera; picker-based access to selected photos, contacts and files without blanket permissions; metadata stripping on shared images; restrictions on contacts, SMS and call-log permissions to apps with those functions; system dialers and SMS composers that need no permission; controls on immutable and resettable device identifiers with MAC randomization and per-app advertising-ID switches; private app storage and encryption. Lifecycle: no silent installs, no one-shot permission bundles, user-controlled self-start and associated start, and complete deletion of app data on uninstall. Annex A tabulates prompt, logging and grant granularity per data type.
- § 09 · TC260 GBA (HK) Cross-boundary PI Requirements
Cybersecurity Standards Practice Guide — Protection Requirements for Cross-boundary Processing of Personal Information in the Guangdong–Hong Kong–Macao Greater Bay Area (Mainland, Hong Kong) (v1.0-202411)
网络安全标准实践指南——粤港澳大湾区(内地、香港)个人信息跨境处理保护要求(v1.0-202411)
Issued jointly in November 2024 by the TC260 Secretariat and Hong Kong's Office of the Privacy Commissioner for Personal Data as TC260-PG-20245A, this practice guide is the certification and recognition basis for the second Greater Bay Area transfer route — 'security mutual recognition' — created under the June 2023 CAC–ITIB memorandum alongside the GBA standard contract. A Mainland handler or recipient in the nine Guangdong cities may seek GBA cross-boundary security certification, and a Hong Kong handler or recipient may apply to join the PCPD's recognition list; either then moves personal information across the boundary without the national assessment, SCC or certification routes, except for data designated as important. The guide sets six principles and then requirements keyed to 'local law' on each side (PIPL and related laws for the Mainland; the Personal Data (Privacy) Ordinance and its Schedule 1 data protection principles for Hong Kong): lawful bases, collection notice and consent (guardian consent under 14 on the Mainland, prescribed consent under 18 in Hong Kong), retention limits and re-consent, marketing and automated-decision opt-outs, joint, entrusted and onward processing. The cross-boundary chapter is the core: pre-transfer agreement on purpose, method, categories, volume, transmission, storage location and period and same-jurisdiction onward provision; a security management system with encryption, de-identification and access controls; three-year transfer records; a binding document (binding corporate rules qualify) obliging the recipient to honor data-subject rights and never re-export outside the GBA; a PIPIA kept for three years; supervision of the recipient by contract, audit or self-assessment; and, for recipients, deletion at end of purpose or termination, least-privilege access, incident notification to the handler and the local regulator, no onward transfer outside the GBA, conditions for same-jurisdiction third parties, sub-processing consent, audit cooperation and rights fulfilment. Chapters 5 and 6 add rights-handling duties, a Mainland stop-transfer clause where national security or Chinese residents' rights are affected, and baseline security measures including a designated PIPO, encryption of sensitive data and incident plans.
- § 10 · GB/T 39335
Information Security Technology — Guide for Personal Information Security Impact Assessment (GB/T 39335-2020)
信息安全技术 个人信息安全影响评估指南 (GB/T 39335-2020)
GB/T 39335-2020 is the recommended national standard that operationalizes the personal-information security impact assessment (PIA / 个人信息安全影响评估). It sets out the principles, implementation method, working steps and reporting format for assessing the risks that personal-information processing poses to data subjects' rights and interests. Issued in 2020 and effective 1 June 2021, it is the practical reference China's handlers use to conduct the impact assessment that PIPL Article 55 makes mandatory before high-risk processing activities.
- § 11 · GB/T 41479
Information Security Technology — Security Requirements for Network Data Processing (GB/T 41479-2022)
信息安全技术 网络数据处理安全要求 (GB/T 41479-2022)
GB/T 41479-2022 is the recommended national standard specifying security requirements for the processing of network data — data collected, stored, transmitted, used, provided, disclosed and deleted through networks. It sets lifecycle security requirements for network data processing activities by network operators, organized by processing stage, and serves as a baseline reference for implementing the data-security duties of the Cybersecurity Law and Data Security Law. It applies across general network operations and informs the Network Data Security Management Regulations.
- § 12 · GB/T 42460
Information Security Technology — Guide for Evaluation of Personal Information De-identification Effect (GB/T 42460-2023)
信息安全技术 个人信息去标识化效果评估指南 (GB/T 42460-2023)
GB/T 42460-2023 is the recommended national standard for evaluating whether a personal-information de-identification process has actually worked. It sets out the goals, principles, evaluation framework and methods for judging re-identification risk in de-identified datasets — covering identifiers, the choice of de-identification models, and how to test residual risk. It complements GB/T 37964 (the de-identification guide) by providing the effectiveness-evaluation half, and supports PIPL's treatment of de-identification and anonymization.
- § 13 · GB/T 42574
Information Security Technology — Implementation Guide for Notification and Consent in Personal Information Processing (GB/T 42574-2023)
信息安全技术 个人信息处理中告知和同意的实施指南 (GB/T 42574-2023)
GB/T 42574-2023 is the recommended national standard that operationalizes PIPL's notification (告知) and consent (同意) obligations. It gives handlers practical guidance on what to tell data subjects and how, when and in what form to obtain consent — including separate consent, written consent, consent from minors' guardians, and withdrawal of consent — across web, app and other interfaces. It is the implementation manual for PIPL Articles 14–17 and 23/25/29/39, turning the statute's notice-and-consent rules into concrete design requirements.
- § 14 · GB/T 44588
Data Security Technology — Personal Information Processing Rules for Internet Platforms and Products/Services (GB/T 44588-2024)
数据安全技术 互联网平台及产品服务个人信息处理规则 (GB/T 44588-2024)
GB/T 44588-2024 is a recommended national standard setting personal-information processing rules tailored to internet platforms and their products and services. It addresses how platform operators — and the products, services and third-party providers within their ecosystems — should handle personal information consistently with PIPL, including the heightened 'gatekeeper' obligations PIPL imposes on large platforms. It is one of the 2024 'Data Security Technology' series standards that build sector- and scenario-specific guidance on top of PIPL's general framework.
- § 15 · GB/T 45574
Data Security Technology — Security Requirements for Processing Sensitive Personal Information (GB/T 45574-2025)
数据安全技术 敏感个人信息处理安全要求 (GB/T 45574-2025)
GB/T 45574-2025 is a recommended national standard setting security requirements for processing sensitive personal information (敏感个人信息) as defined by PIPL Article 28. It addresses the heightened safeguards that attach across the lifecycle when handling sensitive PI — separate (and where required written) consent, specific-purpose and strict-necessity limits, intensified impact assessment, and enhanced technical and organizational controls. It complements the TC260 sensitive-PI identification guide by specifying how, once identified, sensitive PI must be protected.
- § 16 · GB/T 45577
Data Security Technology — Data Security Risk Assessment Method (GB/T 45577-2025)
数据安全技术 数据安全风险评估方法 (GB/T 45577-2025)
GB/T 45577-2025 is a recommended national standard specifying a method for assessing data security risk. It provides the principles, framework, process and assessment content for identifying and evaluating risks to data across its lifecycle — covering data assets, threats, vulnerabilities, existing safeguards and potential impact — and for rating overall data-security risk. It is a 2025 'Data Security Technology' series standard supporting the risk-assessment duties of the Data Security Law and the network-data regime.
- § 17 · GB/T 46068
Data Security Technology — Security Certification Requirements for Cross-Border Processing of Personal Information (GB/T 46068-2025)
数据安全技术 个人信息跨境处理活动安全认证要求 (GB/T 46068-2025)
GB/T 46068-2025 is a recommended national standard setting the security requirements for certifying cross-border processing of personal information — the personal-information protection certification route that PIPL Article 38 offers as one lawful basis for transferring personal information abroad. It specifies the requirements that handlers and overseas recipients must meet to be certified, including legally binding agreements, organizational and technical safeguards, and protection of data subjects' rights. It elevates and complements the earlier TC260 certification specification.
- § 18 · GB/T 46071
Data Security Technology — Guide to Social Responsibility for Data Security and Personal Information Protection (GB/T 46071-2025)
数据安全技术 数据安全和个人信息保护社会责任指南 (GB/T 46071-2025)
GB/T 46071-2025 is a recommended national standard offering guidance on social responsibility in data security and personal information protection. It frames data security and PI protection as elements of organizational social responsibility, providing principles and guidance for organizations to take responsibility toward data subjects, society and the public — covering governance, transparency, stakeholder engagement and accountability. It is a 2025 'Data Security Technology' series standard that complements the binding duties of the DSL and PIPL with a responsibility-and-governance framing.
- § 19 · TC260 PI Audit Guide
Cybersecurity Standards Practice Guide — Personal Information Protection Compliance Audit Requirements
网络安全标准实践指南 — 个人信息保护合规审计要求
This TC260 practice guide sets out requirements for conducting the personal-information-protection compliance audit that PIPL Article 54 requires handlers to perform periodically. It provides an audit framework — the matters to examine across a handler's personal-information processing against PIPL obligations — to support both self-audits and audits commissioned to professional bodies under the Administrative Measures for Personal Information Protection Compliance Audits. It is advisory practice guidance, not a mandatory standard.
- § 20 · TC260 FRT Payment Guide
Cybersecurity Standards Practice Guide — Personal Information Security Protection Requirements for Facial-Recognition Payment Scenarios
网络安全标准实践指南 — 人脸识别支付场景个人信息安全保护要求
This TC260 practice guide sets personal-information security protection requirements specific to facial-recognition payment (人脸识别支付) scenarios. It addresses how face data should be collected, verified, transmitted, stored and protected when facial recognition is used to authorize payments, with an emphasis on consent, the availability of non-facial alternatives, anti-spoofing and minimization. It is advisory practice guidance complementing the facial-recognition application rules and PIPL's sensitive-PI regime.
- § 21 · TC260 QR Ordering Guide
Cybersecurity Standards Practice Guide — Personal Information Protection Requirements for QR-Code Ordering
网络安全标准实践指南 — 扫码点餐个人信息保护要求
This TC260 practice guide sets personal-information protection requirements for QR-code ordering (扫码点餐) in restaurants and similar settings — a response to the common practice of forcing customers to follow accounts, register, or hand over excessive personal information just to view a menu or order. It emphasizes minimum necessity, the availability of order-without-registration options, and no forced follows or over-collection. It is advisory practice guidance applying PIPL's minimum-necessity principle and the app necessary-PI rules to this everyday scenario.
- § 22 · TC260 Data Risk Assessment Guide
Cybersecurity Standards Practice Guide — Implementation Guidelines for Network Data Security Risk Assessment
网络安全标准实践指南 — 网络数据安全风险评估实施指引
This TC260 practice guide gives step-by-step implementation guidelines for conducting a network data security risk assessment. It walks organizations through preparing for, executing and reporting an assessment of data-security risks across the data lifecycle — identifying assets, threats, vulnerabilities and impacts and rating overall risk — in support of the assessment duties created by the Network Data Security Management Regulations. It is the practice-oriented companion to the GB/T 45577 risk-assessment method, and is advisory rather than mandatory.
- § 23 · GB/T 47949
Asset Management — Classification and Codes for Data Assets (GB/T 47949-2026)
资产管理 数据资产分类与代码 (GB/T 47949-2026)
GB/T 47949-2026 is the first national standard giving data assets a fixed place in China's asset-classification code system. Issued 2 July 2026 and effective 1 September 2026, it assigns data assets the code block A0806020000 — intangible assets (08) → information-and-data intangible assets (06) → data (02) — and breaks that block into three top-level classes (structured, semi-structured, unstructured data) and fourteen sub-classes, each with a prescribed unit of measure. The taxonomy is deliberately narrow: it classifies data assets by their basic technical attributes so they can be configured, registered, inventoried and reported in asset-management systems, and it expressly does not change how data assets are defined or classified under existing accounting standards. Notably, it carves out a dedicated sub-class for AI-training multimodal data (A0806020307), measured in megabytes and tokens. It is the classification companion to GB/T 47950-2026 on data-asset registration.
- § 24 · GB/T 47950
Asset Management — Guidance for Data Assets Registration (GB/T 47950-2026)
资产管理 数据资产登记指南 (GB/T 47950-2026)
GB/T 47950-2026 is the national standard for registering data as an asset on an organization's own books — the internal counterpart to the NDA's data property-rights registration regime. Issued 2 July 2026 and effective 1 September 2026, it sets three overall principles (security, compliance, traceability), allocates the registration work across four internal functions (data business owner, asset management, accounting, and data-technology compliance review), and specifies a dual registration content: the asset register (资产台账), maintained through a data asset card, and the accounting books. Its process model turns on data asset confirmation: a data resource that meets the confirmation conditions goes to initial registration; one that does not yet meet them goes into an asset subsidiary record (备查簿) instead of being lost. Change and deregistration follow the same four-role pattern, each gated by a compliance review. Asset numbering is unique-code, and classification and units of measure are taken from GB/T 47949. Annex A gives the full registration data model — basic, financial, use, authorization and disposal information — worked for administrative institutions.
- § 25 · GB/T 46901-2025 (PI Portability)
Data Security Technology — Requirements for Personal Information Transfer Based on Individual Requests (GB/T 46901—2025)
数据安全技术 基于个人请求的个人信息转移要求(GB/T 46901—2025)
The first national standard implementing the personal-information-portability right in PIPL Article 45, effective July 1, 2026. It sets out two transfer models (subject-as-intermediary and processor-as-intermediary), scopes the portable-data boundary to actively-provided information and service-usage records — expressly excluding derived data such as profiling tags and friend graphs, network logs, trade secrets, and anonymized data — and fixes three preconditions: a consent-or-contract-necessity legal basis, no harm to third-party rights, and requests kept within reasonable limits (indicatively no more than twice a year). It prescribes a five-step process (initiation, verification, processing, export, import) with 15-working-day response times, mandatory structured and machine-readable export formats (CSV/JSON/XML), and dedicated rules for minors under 14, third-party data caught up in a transfer, and overseas recipients. Any consumer-facing personal information handler now has a concrete technical and procedural playbook to build against.
Judicial Interpretations .
司法解释 · Supreme People's Court
- § 01 · FRT Judicial Interpretation
Provisions of the Supreme People's Court on Several Issues Concerning the Application of Law in the Trial of Civil Cases Involving the Use of Facial Recognition Technology to Process Personal Information
最高人民法院关于审理使用人脸识别技术处理个人信息相关民事案件适用法律若干问题的规定
The Supreme People's Court's interpretation of how civil courts should apply law in cases involving facial recognition. Defines what counts as 'processing facial information', enumerates conduct that infringes personality rights, addresses consent validity (mandatory consent through a service agreement is not valid), and sets out remedies and burden-of-proof allocation. Issued before PIPL took effect but designed to interoperate with PIPL's sensitive-personal-information regime.
- § 02 · PI Criminal Interpretation
Interpretation of the Supreme People's Court and the Supreme People's Procuratorate on Several Issues Concerning the Application of Law in Handling Criminal Cases of Infringing upon Citizens' Personal Information
最高人民法院、最高人民检察院关于办理侵犯公民个人信息刑事案件适用法律若干问题的解释
The principal judicial interpretation governing the crime of infringing upon citizens' personal information under Article 253a of the Criminal Law. It defines 'citizens' personal information', clarifies what constitutes 'providing' and 'illegally obtaining' such information, and sets quantitative thresholds for 'serious circumstances' and 'particularly serious circumstances' (e.g., 50 items of tracking, communication-content, credit-reporting or property information; 500 items of accommodation, communication-record, health or transaction information; 5,000 items of other personal information). It also addresses corporate liability, sentencing for related network crimes, and the determination of fines.
- § 03 · SPP PI Crime Reply
Reply of the Research Office of the Supreme People's Procuratorate on the Solicitation of Opinions Concerning the Application of Law in the Crime of Infringing upon Citizens' Personal Information
最高人民检察院法律政策研究室关于侵犯公民个人信息罪有关法律适用问题征求意见的复函
A short reply letter (Fa Yan [2018] No. 11) addressing whether 'citizens' personal information' under Article 253a of the Criminal Law is confined to the personal information of Chinese nationals. It concludes that the term covers not only the personal information of Chinese citizens but also that of foreign nationals and stateless persons, reasoning from the wording of the statute, legislative intent (equal protection), and judicial practice (excluding foreigners would let offenders escape punishment and be unworkable in mixed-data cases).
Drafts in Consultation .
征求意见稿
- § 01 · Large Handler Provisions (Draft) · DRAFT
Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment)
大型个人信息处理者个人信息保护规定(征求意见稿)
CAC's draft for comment, released 7 August 2026 with comments due 7 September 2026, is the counterweight to the small-handler regime: where Order No. 25 scales PIPL down for handlers under 100,000 people, these 50 articles scale it up for handlers at or above 10 million. It consolidates two earlier drafts — the Supervision Committee provisions of 12 September 2025 and the Large Network Platform provisions of 22 November 2025 — and in doing so renames the subject from 'large network platform' to 'large personal information handler,' replacing the old registered-user and monthly-active-user tests with a three-factor designation covering headcount of data subjects, systemic importance of the service, and impact on national security, economic operation, social stability and public health. Designation is not automatic: a qualifying handler must self-declare through its provincial CAC, and the national CAC publishes a public list. The obligations that follow are the heaviest in the PIPL system — full domestic storage of all personal information collected or generated in China (Article 13), data centers whose legal representative or actual controller must hold PRC nationality (Article 14), a personal information protection officer drawn from management with a direct reporting line to the provincial CAC (Articles 25–26), impact assessments filed with the national CAC (Article 31), compliance audits at least every two years (Article 33), an annual public social responsibility report (Article 30), and a Personal Information Protection Supervision Committee of at least seven members, two-thirds external, headed by an external member (Chapter 4). An annex supplies the committee's working-rules drafting guidelines.
- § 02 · GB/T 35273 (2026 draft) · DRAFT
Data Security Technology — Personal Information Security Specification (2026 Draft for Comment)
数据安全技术 个人信息安全规范(征求意见稿)
The 2026 draft revision of GB/T 35273 — released by TC260 for public comment on June 17, 2026 (project No. 20260700-T-469; drafting lead CESI) to replace GB/T 35273-2020. It retitles the standard 'Data Security Technology — Personal Information Security Specification', expands normative references from one standard to eight, and recasts China's most-cited personal information benchmark from a consent/notice manual into a full-lifecycle governance framework. Headline additions: a Chapter 5 lawful-basis chapter importing PIPL Art. 13's seven bases with hard per-basis boundaries; a sensitive-PI redefinition aligned to PIPL Art. 28 with an aggregation rule; a 'separate consent' definition; a new eighth 'quality assurance' principle; dedicated AI/generative-AI clauses (6.7, 6.1, 8.4, 8.5.4); unified-account (8.6) and terminal/IoT (6.8) collection clauses; a wholly new Chapter 11 on overseas-jurisdiction determination and conflict handling; and a systematized internal-control chapter (person in charge, records, PIPIA, GB/T 46903 compliance audit). Subject-rights response tightens from 30 days to 15 working days. Comment draft, non-binding and non-final; formal release expected after 2027.
- § 03 · App PI Collection and Use Provisions (Draft) · DRAFT
Provisions on the Collection and Use of Personal Information by Internet Applications (Draft for Public Consultation)
互联网应用程序个人信息收集使用规定(征求意见稿)
A 39-article CAC draft, opened for comment on January 10, 2026, that consolidates app-privacy regulation into a single instrument covering four classes of actors for the first time: app operators, SDK operators, distribution platforms (app stores, mini-program and quick-app platforms), and smart-terminal/OS makers. It operationalizes minimum-necessary and notice-and-consent principles into granular, engineering-level rules — permission requests tied to the moment of use, scenario-based consent toggles, mandatory system-level storage-access frameworks in place of blanket storage permissions, on-device-only default storage for biometric identifiers, a 15-business-day account-cancellation deadline, and behavioral-audit duties for embedded SDKs. It also builds out platform-level gatekeeping: distribution platforms and terminal makers must vet operator identity before listing or preinstalling an app, refuse apps lacking a privacy policy or deletion/cancellation function, and post risk warnings on apps that regulators have publicly named for violations. For overseas counsel, this draft would sit alongside (and in several respects supersede in practice) the 2019 App PI Identification Method and the 2021 Necessary PI Scope Provisions, raising the bar on SDK due diligence, permission-timing UX, and cross-entity contractual allocation of responsibility across the app supply chain.
- § 04 · Cybercrime Prevention Law (Draft) · DRAFT
Cybercrime Prevention Law (Draft for Public Consultation)
网络犯罪防治法(征求意见稿)
China's first standalone, comprehensive cybercrime statute, drafted by the Ministry of Public Security with a comment period that closed March 2, 2026. It goes well beyond the Criminal Law's cybercrime provisions to build a full prevention and governance framework: real-name controls over phone cards, bank accounts, and network accounts; a fifteen-item catalogue of prohibited "cybercrime ecosystem" conduct such as technical support, financial support, and personal-information or data misuse; tiered monitoring and reporting duties for ten categories of internet service, including a special obligation for AI service providers to detect and block abuse of their services; and cross-border tools including technical blocking of offshore actors, asset seizure, and entry/exit bans. Overseas counsel should read it closely for Article 2's extraterritorial reach, which extends to any offshore entity serving PRC users whose conduct harms China's national security, public interest, or the lawful rights of PRC citizens or organizations.
- § 05 · Small PI Processor Protection Guide (Draft) · DRAFT
Data Security Technology — Guide for Personal Information Protection by Small Personal Information Processors (Draft for Public Consultation)
数据安全技术 小型个人信息处理者个人信息保护指南(征求意见稿)
A TC260 draft national standard implementing PIPL Article 62's mandate to write simplified personal-information rules for small processors — those handling fewer than 100,000 people's personal information, such as small merchants, sole proprietors, and community-service providers. It systematically scales down compliance expectations: oral or posted-notice consent in place of layered privacy policies, a five-year (rather than annual) compliance-audit cycle, a one-page impact-assessment worksheet (Annex D) instead of a formal PIPIA report, and SMS or phone verification for identity checks on rights requests. It also sets out four cross-border exemption scenarios and an audit exemption for processors already holding personal information protection certification. For overseas counsel, this is the practitioner-level document defining what proportionate PIPL compliance looks like at the smallest end of the market — the small merchants, franchisees, and local service providers that portfolio companies and platform counterparties often deal with in China.