China - Network Data Security Management (Decree No. 790)
Regulations on Network Data Security Management
网络数据安全管理条例
China
RAI-CN-NA-RNDSMXX-2024The Regulations on Network Data Security Management set detailed administrative rules for the classification, protection, cross-border transfer, and lawful use of network data in China. Promulgated by the State Council (Decree No.790) on 24 September 2024 and effective 1 January 2025, the Regulation introduces obligations for network data processors, heightened duties for "large network platforms" and important-data processors, and procedures for incident reporting and supervision. (gov.cn)
Summary
The Regulations on Network Data Security Management (网络数据安全管理条例), promulgated by the State Council by Decree No. 790 on 24 September 2024 and entering into force on 1 January 2025, are an administrative regulation implementing and harmonizing provisions of the Cybersecurity Law, Data Security Law and the Personal Information Protection Law. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Structure and purpose: The Regulation (9 chapters, 64 articles) establishes a comprehensive framework to regulate "network data processing activities" (covering both personal information and non-personal network data) carried out within the People’s Republic of China and, in specified cases, certain extraterritorial processing of personal information concerning PRC residents. It aims to (i) classify and grade data according to importance and risk, (ii) mandate organizational, technical and contractual safeguards, (iii) require risk assessments, audits and reporting for important-data processors and large network platforms, and (iv) clarify cross-border transfer requirements and national security-related reviews. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Key definitions and coverage: The Regulation defines core terms (network data, personal information, important data, joint processing, large network platform, etc.) and makes explicit that it applies to network data processing activities carried out inside China as well as, in certain circumstances defined by PIPL, processing of PRC residents’ personal information outside China. Important-data categories are to be coordinated by national and local authorities; the Regulation requires processors to identify, declare and, where designated by authorities, treat certain datasets as important. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Heightened obligations: Entities that process important data or large volumes of personal information (for example, processors of information concerning 10 million or more individuals) must implement an internal data security governance structure (appoint a data security head and a data-security management body), conduct pre-transfer risk assessments, perform annual risk assessments, retain processing records for specified periods, and submit certain risk assessment reports to competent authorities. "Large network platforms" are defined by user-scale and impact criteria (registered users above 50 million or monthly active users above 10 million, complex business types, and activities with significant societal or national impact) and are subject to additional oversight, such as annual social-responsibility reporting on personal information protection and prohibitions on abusing platform power for discriminatory or coercive data processing. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Cross-border transfers and national security: The Regulation reinforces the requirement that cross-border transfers of important data or large-scale personal information follow national rules and security assessment mechanisms. Where network data processing activities affect or may affect national security, the Regulation requires national security review in accordance with existing rules. The Regulation clarifies that data need not be treated as important unless declared or listed by competent authorities, preserving the principle that designation is an administrative act. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Operational duties and consumer rights: The text requires all network data processors to establish management systems, adopt technical measures (encryption, backups, access control, identity authentication), prepare and activate incident response plans, notify affected parties of incidents causing harm, and provide easy mechanisms for individuals to exercise rights (access, correction, deletion, portability and consent withdrawal). It also limits collection of personal data to necessity for services and requires separate consent for sensitive categories and for processing minors below statutory ages. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Enforcement and penalties: Administrative penalties align with the Cybersecurity Law, Data Security Law and PIPL, while adding tailored enforcement measures and possible leniency for promptly corrected or minor violations. Enforcement authorities include the Cyberspace Administration of China (CAC), public security organs, market and industry regulators, and other competent departments, each acting within its statutory jurisdiction. Serious violations may trigger criminal liability under PRC criminal law. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Implications: The Regulation consolidates central government oversight of network data, increases compliance obligations for platforms and large processors, and clarifies administrative procedures for the identification and governance of important data. It also strengthens data-localization, cross-border controls and national-security review mechanisms while promoting innovation, industry standards and international cooperation in data governance. Practitioners should monitor implementing rules and local catalogues (important-data lists) and take immediate steps to update governance, contracts, technical controls, audit and incident-response processes. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Full article
Read full text ↗Overview
The Regulations on Network Data Security Management (网络数据安全管理条例) were promulgated by the State Council (Decree No.790) on 24 September 2024 and entered into force on 1 January 2025. The Regulation establishes detailed administrative rules to implement and harmonize key provisions of the Cybersecurity Law, Data Security Law and Personal Information Protection Law, focusing on classification and graded protection of network data, obligations of network data processors (including platform operators), rules for cross-border transfers and processes for incident response and national security review. For the official promulgation text see State Council Gazette (Chinese) and the English summary on the central government portal gov.cn (English). ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Definitions
Key defined terms include "network data" (encompassing both personal and non-personal data generated by networks), "personal information" (as in PIPL), "important data" (data designated by competent authorities for heightened protection), "core data" (subject to additional rules), "joint handling" and "entrusted processing". "Large network platform" is defined by three cumulative attributes: scale (registered users over 50 million or monthly active users over 10 million), complexity of business types, and the societal/national impact of its data processing activities. The Regulation also adopts familiar PIPL concepts such as sensitive information and separate (specific) consent. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Governance and Institutional Framework
The Regulation emphasizes a multi-agency governance model: the national data security coordination mechanism and relevant departments will coordinate important-data catalogues, risk review mechanisms and enforcement. At enterprise level, entities processing important data must appoint a network data security director and set up a dedicated data security management body; these bodies are tasked with drafting and implementing internal data security management rules, emergency response plans, risk monitoring and audits. Regulators named in implementing materials and Q&A documents include the Cyberspace Administration of China (网信办), public security authorities, market regulators, industry ministries and local-level competent departments; the Ministry of Justice and CAC have issued explanatory materials to clarify obligations and the administrative relationships. See the official promulgation and related Q&A for further institutional guidance: State Council Gazette (Chinese) and Ministry of Justice Q&A. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Key Focus Areas
The Regulation addresses multiple focus areas: (1) Data classification and graded protection: competent authorities will publish important-data catalogues at national, sectoral and local levels and processors must identify and declare important data. (2) Organizational and technical controls: encryption, access management, backups, authentication and logging are mandated; processors must implement security-by-design and security-by-default measures. (3) Governance obligations: recordkeeping, contracts for cross-entity processing, pre-transfer risk assessments for important data, background checks for staff in critical roles, and routine compliance audits are required. (4) Platform governance: platform service providers have duties to monitor third-party processors on their platforms, and large platforms (by scale and impact) are subject to gatekeeping obligations including annual social-responsibility reporting on personal-data protection and prohibitions against abusing algorithmbased restrictions or discriminatory treatments. (5) Incident response and reporting: entities must have incident plans, report to regulators within prescribed timeframes for incidents affecting national security/public interest, and notify affected individuals when their rights are harmed. (6) Cross-border data flows: outbound transfers of important data or large-volume personal data remain subject to national security assessments, contractual safeguards and other procedural controls; the Regulation reiterates that data are not important by default unless designated by authorities. These focus areas align the Regulation with existing PRC data and cybersecurity laws while offering more detailed administrative obligations. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Implementation Framework
Implementation rests on (a) administrative designation of important data lists at national and local levels; (b) enterprise-level compliance: systems, appointed responsible person, internal rules, contracts, technical measures, audits and employee vetting; and (c) supervisory measures by CAC and other competent departments. Important-data processors and large platforms must perform pre-transfer and annual risk assessments, retain processing records (at least three years for certain outsourced processing), and, in some cases, submit assessment reports to provincial-or-above authorities. The Regulation also contemplates implementing regulations and guidance by specialized agencies (e.g., CAC and MIIT) to clarify operational thresholds and reporting formats. Practitioners should prepare by mapping data holdings, inventorying processing activities, updating contracts and technical controls, and planning for required reporting and audits. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Monitoring and Evaluation
Supervision will be performed by a combination of national and local authorities coordinated by the national data security mechanism. Monitoring tools include mandatory reporting, submission of risk-assessment reports, on-site inspections, compliance audits and public reporting obligations for large platforms. The Regulation requires annual risk assessments for important-data processors and provides for periodic audits (self-audits or thirdparty audits). Regulators retain discretion to publish guidance on sampling, thresholds and technical standards; industry organizations are encouraged to adopt codes of conduct to supplement official supervision. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Penalties, Liability, and Appeals
The Regulation reiterates administrative enforcement measures consistent with PRC administrative law and related data laws: orders to correct, warnings, fines, confiscation of illegal gains, suspension of business, license revocation and public censure. For severe breaches implicating national security or criminal offenses, agencies may transfer cases to public security organs and state security authorities for criminal investigation. Article provisions allow mitigation or exemption of administrative penalties where violations are minor, promptly corrected, and do not cause harm. Entities should maintain records to support mitigation claims and prepare internal appeal channels aligned with administrative procedures. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Relationship to Other Instruments
The Regulation is explicitly drafted to implement and be consistent with the Cybersecurity Law, Data Security Law and PIPL. It provides administrative-level operational rules and further detail (for example, thresholds, recordkeeping periods and reporting obligations) that supplement those laws. It also references national standards (including mandatory requirements under China’s graded protection system) and anticipates supplementary measures and implementing rules from sector regulators and CAC; in some domains (state secrets, work secrets) other laws (e.g., State Secrets Law) continue to apply. Relevant implementing measures already published or expected include CAC guidance on cross-border transfers and audits. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
International Alignment
The Regulation signals China’s intent to strengthen domestic data governance while participating in international rule-making and technical standard-setting. It reaffirms the state’s interest in cross-border data-security mechanisms but also tightens administrative controls on the outbound transfer of important data and large-volume personal data. The Regulation’s design—designation-by-authority (rather than automatic classification), required contractual and technical safeguards, and sectoral catalogues—creates both points of alignment with international good practices (risk assessment, DPIA-equivalent audits, transparency obligations) and points of divergence (administrative designation, national-security review, stricter gatekeeper duties for platforms). Multinational entities should map regulatory overlaps and watch for implementing rules and negative/positive lists from CAC and commerce authorities. ([gov.cn](https://www.gov.cn/gongbao/2024/issue_11646/202410/content_6980863.html))
Implementation Timeline
| Event | Date |
|---|---|
| State Council adoption at 40th executive meeting | 2024-08-30 |
| State Council promulgation (Decree No.790; Premier signature) | 2024-09-24 |
| Official publication in State Council Gazette | 2024-09-30 |
| Regulation effective date | 2025-01-01 |
| Expected phased implementing rules and sectoral catalogues (ongoing) | 2025 (and ongoing) |
Sources and References
| Source | Type |
|---|---|
| 中华人民共和国国务院令(第790号) 网络数据安全管理条例 (State Council Gazette) | Primary Source |
| China issues regulations on network data security management (gov.cn English) | Primary Source (official English summary) |
| Ministry of Justice — Q&A on Regulations (司法部) | Primary Source (official commentary) |
Requirements for a company
What an organisation has to do under China - Network Data Security Management (Decree No. 790), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
14- Appoint a network data security director and establish a dedicated management body.Entities processing important data.
- Draft and implement internal data security management rules and emergency response plans.Entities processing important data.
- Identify and declare important data according to national or local catalogues.Network data processors.
- Implement mandated technical controls like encryption, access management, backups, authentication, and logging.Network data processors.
- Conduct pre-transfer risk assessments for important data.Processors of important data.
- Avoid abusing algorithm-based restrictions or discriminatory treatments.Large network platforms.
- +8 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under China - Network Data Security Management (Decree No. 790), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Entities processing important data. | Appoint a network data security director and establish a dedicated management body. “entities processing important data must appoint a network data security director and set up a dedicated data security management body” | Jan 1, 2025 | — | Critical |
| 2 | Entities processing important data. | Draft and implement internal data security management rules and emergency response plans. “these bodies are tasked with drafting and implementing internal data security management rules, emergency response plans” | Jan 1, 2025 | — | Critical |
| 3 | Network data processors. | Identify and declare important data according to national or local catalogues. “processors must identify and declare important data.” | When required | — | Critical |
| 4 | Network data processors. | Implement mandated technical controls like encryption, access management, backups, authentication, and logging. “encryption, access management, backups, authentication and logging are mandated” | Jan 1, 2025 | — | Critical |
| 5 | Processors of important data. | Conduct pre-transfer risk assessments for important data. “pre-transfer risk assessments for important data... are required.” | Before outbound transfer | — | Critical |
| 6 | Large network platforms. | Avoid abusing algorithm-based restrictions or discriminatory treatments. “prohibitions against abusing algorithm-based restrictions or discriminatory treatments.” | Jan 1, 2025 | — | Critical |
| 7 | Network data processors. | Develop incident response plans and report incidents to regulators within prescribed timeframes. “entities must have incident plans, report to regulators within prescribed timeframes” | Jan 1, 2025 | — | Critical |
| 8 | Network data processors. | Notify affected individuals when their rights are harmed by an incident. “notify affected individuals when their rights are harmed.” | As soon as possible after incident | — | Critical |
| 9 | Network data processors transferring data cross-border. | Ensure outbound transfers of important or large-volume personal data meet national security assessments and safeguards. “outbound transfers of important data or large-volume personal data remain subject to national security assessments” | Before outbound transfer | — | Critical |
| 10 | Important-data processors and large platforms. | Perform annual risk assessments. “Important-data processors and large platforms must perform... annual risk assessments” | Annually | — | Critical |
| 11 | Large network platforms. | Submit annual social-responsibility reports on personal data protection. “large platforms... are subject to gatekeeping obligations including annual social-responsibility reporting on personal-data protection” | Annually | — | Critical |
| 12 | Network data processors. | Implement security-by-design and security-by-default measures. “processors must implement security-by-design and security-by-default measures.” | Jan 1, 2025 | — | Important |
| 13 | Platform service providers. | Monitor third-party processors operating on their platforms. “platform service providers have duties to monitor third-party processors on their platforms” | Jan 1, 2025 | — | Important |
| 14 | Network data processors. | Retain processing records for at least three years for certain outsourced processing. “retain processing records (at least three years for certain outsourced processing)” | Ongoing | — | Important |
Related Regulations
Data Security Law of the People's Republic of China
China91% similar
Cybersecurity Law of the People's Republic of China
China90% similar
Security Assessment Measures for Outbound Data Transfers (Measures for the Security Assessment of Outbound Data Transfers)
China89% similar
Personal Information Protection Law of the People's Republic of China (PIPL)
China89% similar
Interim Measures for the Administration of Generative AI Services (Generative AI Services Management Interim Measures)
China87% similar
© Regulations.AI · updated on 13-Jun-2026