China - Data Security Law (2021)
Data Security Law of the People's Republic of China
中华人民共和国数据安全法
China
RAI-CN-NA-DSPRCXX-2021The Data Security Law (DSL) establishes a national legal framework to regulate data processing, protect data security, and promote lawful data development and utilization in the People's Republic of China. The Law requires classification and graded protection of data, imposes obligations on processors (especially processors of "important data"), establishes national coordination and security review mechanisms, and sets administrative, civil and criminal liabilities for non-compliance.
Summary
Read full text ↗Plain English
Overview
The Data Security Law (DSL) of the People's Republic of China, adopted on June 10, 2021 and in force from September 1, 2021, establishes a national legal framework to regulate data processing, ensure data security and promote data development and utilization. The text defines data broadly and creates a classification and graded protection system that distinguishes "important data" and "core state data," imposes obligations on data processors (including designation of responsible persons and regular risk assessments), and requires a national data security review for activities affecting national security. The law also clarifies responsibilities for government data and cross-border matters. The full official English reference text is available from the National People’s Congress website: Data Security Law (NPC English translation), and the promulgation notice is published on the central government portal: Promulgation Notice (Gov.cn).
Definitions
The DSL adopts expansive definitions central to scope and obligations: "data" means any record of information in electronic or other forms; "data processing" includes collection, storage, use, processing, transmission, provision and disclosure; "data security" means ensuring data is effectively protected and lawfully used through necessary measures and having the capacity to guarantee continuous security; "important data" and "core state data" are categories determined by importance to national security, economic lifelines, major public interest and people’s livelihoods, with more stringent protection applied to the latter. The law's definitions set the baseline for classification, risk assessment and obligations imposed on processors.
Governance and Institutional Framework
The DSL assigns roles across national institutions. The central national security authority leads decision-making and coordination of national data security policy; the "national data security work coordination mechanism" conducts overall planning and coordinates departments. Sectoral supervisory responsibilities are allocated to ministries (e.g., industrial, telecoms, transport, finance, natural resources, health, education, technology) while public security and national security organs exercise oversight in their legally defined domains. The national cyberspace affairs department is charged with overall planning and coordination of network data security and related supervision. The law also contemplates participation by industry associations, standards bodies and professional testing and certification institutions. Authoritative sources include the law text and government promulgation: NPC - DSL text and Gov.cn promulgation.
Key Focus Areas
The DSL’s principal regulatory pillars include: (1) Classification and graded protection: data are classified by importance and potential harm if tampered with or leaked; (2) Protection obligations for processors of "important data": designated responsible persons, data security bodies, routine risk assessments and reporting obligations; (3) National-level risk monitoring, early-warning and emergency response mechanisms requiring coordinated information sharing and incident reporting; (4) A national security review system to assess data processing activities that may affect national security; (5) Controls on cross-border transfer of important data and coordination with the Cybersecurity Law and CAC measures to require security assessment or other compliance paths for outbound transfers; (6) Regulation of data trade and intermediaries, requiring source verification and retention of transaction records; (7) Government data governance balancing openness and confidentiality obligations for government-collected data; (8) Encouragement of standards, testing, evaluation and accreditation for products and services related to data security. The law is intentionally broad to be implemented through follow-on measures and departmental rules; see the DSL text and implementing measures by relevant agencies for operational details (NPC; CAC measures are issued separately by the national cyberspace authority).
Implementation Framework
Implementation rests on a combination of national-level coordination and sectoral supervision. The DSL instructs the national coordination mechanism to compile catalogs of important data and requires localities, departments and industries to prepare their important data lists for prioritized protection. Processors of important data must establish institutional arrangements for data security, carry out regular risk assessments, and submit reports to competent departments. For outbound transfers, the law defers detailed procedures to the national cyberspace authority in conjunction with other ministries; in practice, the Cybersecurity Law and subsequent CAC measures and standards provide mechanisms for security assessment, standard contracts and certification pathways for cross-border transfers. The DSL also tasks the State Council standardization department and other ministries with developing technical and product standards. Practical compliance therefore involves legal analysis, technical controls, recordkeeping, risk testing/assessment, coordination with regulators and regular internal governance measures.
Monitoring and Evaluation
The DSL establishes centralized monitoring: a unified mechanism for data security risk assessment, reporting, information sharing, monitoring and early warning. The national coordination mechanism is expected to collect, analyze and issue alerts on data security risks; the DSL requires emergency response plans and mandates that competent departments activate emergency measures and publish public warnings when incidents arise. Processors are required to conduct risk monitoring and to report incidents and remedial measures, and the law authorizes regulators to require periodic reports (notably for important data processors). The statute also encourages independent third-party testing, evaluation and accreditation services for data security that can contribute to monitoring and evaluation functions.
Penalties, Liability, and Appeals
The DSL provides for layered accountability: civil liability for damages caused by breaches of the law; administrative penalties for breaches including fines, orders to rectify, suspension and other administrative sanctions; and criminal liability where conduct constitutes a crime under PRC criminal law. The Law further provides for disciplinary measures against state functionaries who neglect or abuse their data security regulatory duties. Appeals and remedies follow PRC administrative and judicial procedures; organizations and individuals may file complaints with competent departments and protected whistleblower/complainant confidentiality is required by the law.
Relationship to Other Instruments
The DSL operates together with the Cybersecurity Law (2016), the Personal Information Protection Law (PIPL, 2021), the National Security Law, the State Secrets Law and various sectoral and departmental regulations. The Cybersecurity Law remains the core statute for CIIO obligations and technical network security grade protections; the PIPL regulates personal information processing rights and obligations and intersects with DSL protections where personal information also constitutes important data; the DSL focuses on national-level data security and the state’s governance over data development and risks. Implementing measures (e.g., CAC measures on cross-border transfers, security assessment rules and standard contractual frameworks) and national standards provide operational guidance for many DSL obligations.
International Alignment
The DSL declares the state will participate in international exchanges and cooperation on data governance and promote safe cross-border data flows, yet it also firmly prioritizes national sovereignty and security. The law includes provisions restricting direct access by foreign judicial or law enforcement bodies to data stored in China without Chinese authority approval. The DSL’s classification regime and national security review, together with CAC cross-border measures, have informed international compliance strategies for multinationals operating in China and interact with global norms on data protection and transfer (notably EU adequacy frameworks, cross-border adequacy discussions and sectoral international standards). Practitioners must reconcile DSL obligations with foreign legal requests and overseas compliance exposure while relying on Chinese administrative routes for lawful cross-border disclosures.
Implementation Timeline
| Event | Date |
|---|---|
| Law adopted by NPC Standing Committee | 2021-06-10 |
| Promulgation / Presidential Order | 2021-06-10 |
| Law entered into force (effective date) | 2021-09-01 |
| CAC Measures on Data Export (Measures of Security Assessment for Data Export) | 2022-07-07 (CAC measures issued; implementation thereafter) |
| Ongoing: sectoral implementing rules and standards | 2021–present (refer to CAC, State Council and sectoral ministries) |
Compliance Checklist
| Action | Notes |
|---|---|
| Identify and classify data | Create an inventory and designate "important data" where applicable |
| Designate data security officer and management body | Document roles and governance |
| Establish full-process data security management | Policies, procedures, technical and organizational measures |
| Conduct regular risk assessments | Maintain reports and submit to competent authorities if required |
| Prepare incident response and reporting procedures | Align with statutory emergency response and notification rules |
| Verify sources and retain records for data transactions | Data trading intermediaries must keep identity and transaction records |
| Assess cross-border transfer obligations | Follow CAC measures, standard contracts or security assessments as required |
| Ensure government data handling compliance | Limit collection to statutory scope and protect confidential categories |
Sources and References
China's Data Security Law (DSL) establishes a national framework to regulate how data is processed, protect its security, and promote its lawful use, applying to all organizations and individuals processing data within the country. This broad law, effective September 1, 2021, defines "data" expansively as any recorded information and "data processing" to include everything from collection to disclosure.
The law places significant obligations on anyone handling data, especially those dealing with "important data" or "core state data," which are categories determined by their significance to national security and public interest. Key requirements include: - All data must be classified and protected based on its importance and the potential harm if compromised. - Data processors, particularly those handling "important data," must designate responsible persons, establish data security bodies, conduct regular risk assessments, and report their findings to relevant authorities. - Any data processing activity that could affect national security must undergo a national security review. - Transferring "important data" outside China is tightly controlled, generally requiring a security assessment or other compliance mechanisms as detailed in related regulations.
Non-compliance carries serious consequences, including administrative penalties like fines, orders to rectify issues, and business suspension. Organizations can also face civil liability for damages and, in severe cases, criminal charges. A practical pitfall for businesses is the law's broad scope, which means most digital activities are covered. Moreover, the specific criteria for what constitutes "important data" are still being developed by various sectors and localities, making compliance a continuously evolving challenge that requires ongoing monitoring and adaptation.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 11 marked completePlain-English obligations under China - Data Security Law (2021). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Ongoing
Applies to: All data processors.
“data are classified by importance and potential harm if tampered with or leaked”
- #2Critical⏰ Ongoing
Applies to: Processors of important data.
“designated responsible persons, data security bodies”
- #3Critical⏰ Ongoing
Applies to: Processors of important data.
“routine risk assessments”
- #4Critical⏰ Ongoing
Applies to: Processors of important data.
“reporting obligations”
- #5Critical⏰ Ongoing
Applies to: All data processors.
“requiring coordinated information sharing and incident reporting”
- #6Critical⏰ Immediately upon discovery
Applies to: All data processors.
“report incidents and remedial measures”
- #7Critical⏰ Before activity commencement
Applies to: Data processors whose activities may affect national security.
“A national security review system to assess data processing activities that may affect national security”
- #8Critical⏰ Before transfer
Applies to: Data processors transferring important data or personal information cross-border.
“require security assessment or other compliance paths for outbound transfers”
- #9Important⏰ Ongoing
Applies to: Processors of important data.
“establish institutional arrangements for data security”
- #10Important⏰ Ongoing
Applies to: Data trading intermediaries.
“requiring source verification and retention of transaction records”
- #11Recommended
Applies to: Data processors.
“encourages independent third-party testing, evaluation and accreditation services for data security”
Related Regulations
Cybersecurity Law of the People's Republic of China
China93% similar
Personal Information Protection Law of the People's Republic of China (PIPL)
China92% similar
Regulations on Network Data Security Management (网络数据安全管理条例)
China91% similar
Security Assessment Measures for Outbound Data Transfers (Measures for the Security Assessment of Outbound Data Transfers)
China90% similar
Interim Measures for the Administration of Generative AI Services (Generative AI Services Management Interim Measures)
China86% similar
© Regulations.AI — created on 13-Jun-2026