Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · CAC DATA EXPORT Q&A (MAY 2025)

Policy Q&A on Data Export Security Management (May 2025).

数据出境安全管理政策问答(2025年5月)

Promulgated by: Cyberspace Administration of China (CAC).
Document No.: None (published as an official policy Q&A).
Published May 30, 2025.

Translation note — DCC. Translated in full from the official Chinese text published by the CAC on cac.gov.cn and on the 网信中国 (Cyberspace China) WeChat channel. Terminology follows DCC’s bilingual glossary. Read with the Measures for the Security Assessment of Data Export and the Regulation on Network Data Security Management.


The Cyberspace Administration of China continues to strengthen the dissemination of data export security management policy, guiding and helping data handlers carry out data export activities efficiently and in compliance. Having studied the inquiries received recently, it hereby publishes a number of representative questions and answers as follows.

Q1. What is the specific procedure for identifying and declaring important data?

A: Article 21 of the Data Security Law provides that the national data security work coordination mechanism shall coordinate the relevant departments in formulating catalogues of important data and strengthening the protection of important data. Each region and department shall, in accordance with the data classification and grading protection system, determine the specific catalogue of important data for its own region and department and for the relevant industries and fields, and give priority protection to the data listed in the catalogue.

Article 29 of the Regulation on Network Data Security Management provides that network data handlers shall identify and declare important data in accordance with relevant State provisions. For data confirmed as important data, the relevant regions and departments shall promptly notify the network data handler or publicly release the determination.

To implement the relevant laws and regulations, the departments are formulating data classification and grading standards and specifications and rules for the identification and declaration of important data for the relevant industries and fields, providing data handlers in those industries and fields with a concrete basis and operational guidance for identifying and declaring important data. Data classification and grading standards and specifications and rules for the identification and declaration of important data for some industries and fields have already been published, such as the Guide to the Identification of Important Data in the Industrial Field for the industrial sector, the Guide to the Identification of Important Data in the Telecommunications Field for the telecommunications sector, the Work Guide for the Classification and Grading of Geographic Information Data (Trial) for the natural resources sector, and the Measures for the Administration of Statistical Data Security for the statistics sector; others have been communicated to data handlers by convening meetings, issuing documents, one-to-one notification and the like. Data handlers shall, in accordance with the relevant standards and specifications, declaration rules and the requirements of the relevant competent departments, promptly carry out the identification and declaration of important data. The relevant industry competent departments determine whether the important data declared by data handlers qualifies as such, and for data confirmed as important data, will promptly notify the data handler or publicly release the determination. If a data handler has been notified that it holds important data, or the data it holds has been publicly released as important data, it shall fulfill its responsibility for the security protection of important data in accordance with the requirements of the relevant laws and regulations. Where no data classification and grading standards and specifications or rules for the identification and declaration of important data have been published for an industry or field, and the data handler has not been notified by the relevant departments that it should carry out the identification and declaration of important data, a data handler that has not identified or declared important data and has not given priority protection to the relevant data will not be found to have violated the provisions on the protection of important data, and will not be subject to administrative penalties on that account.

Q2. How can important data export activities be carried out in compliance?

A: Under Article 37 of the Cybersecurity Law, Article 31 of the Data Security Law, Article 37 of the Regulation on Network Data Security Management and the relevant provisions of the Measures for the Security Assessment of Data Export and the Provisions on Promoting and Regulating Cross-border Data Flows, where important data collected and generated by a data handler in the course of its operations within the territory of the People’s Republic of China genuinely needs to be provided abroad, it shall pass the data export security assessment organized by the national cyberspace administration. For the procedure for declaring a data export security assessment, refer to the Guidelines for the Declaration of Data Export Security Assessment published by the Cyberspace Administration of China. For important data that genuinely needs to be exported, where the data export security assessment finds that the export will not endanger national security or the public interest, the data may be exported.

Data handlers shall identify and declare important data in accordance with relevant provisions; where data has not been notified or publicly released as important data by the relevant departments or regions, the data handler need not declare it for data export security assessment as important data, the relevant data export activity will not be found to be an unlawful or non-compliant export of important data, and no administrative penalty will be imposed on that account. After a data handler has been notified that it holds important data, or the data it holds has been publicly released as important data, if it needs to continue the relevant data export activities, it shall, within 2 months of being notified or of the public release, declare a data export security assessment to the national cyberspace administration through the provincial-level cyberspace administration of its locality. Data handlers shall carry out data export activities in compliance with the security assessment result issued by the national cyberspace administration, and effectively safeguard the security of important data exports.

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

No briefs filed yet under this law.

§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →