China Data Security Law Compliance Guide
China’s Data Security Law took effect on September 1, 2021, and its reach is broader than most Western compliance teams expect. The Standing Committee of the Thirteenth National People’s Congress adopted the law on June 10, 2021, and it was issued as Order No. 84, according to the official English text published by the National People’s Congress. Article 2 extends the law beyond mainland territory: if data processing outside China harms national security, public interests, or the lawful rights of Chinese individuals and organizations, legal liability can be pursued. For a foreign company handling Chinese data on an overseas server, that clause is the starting point, not an afterthought.
Key Takeaways:
- The DSL divides data into core, important, and general tiers under Article 21, with important data catalogs set by industry regulators rather than by the company itself.
- Article 24 creates a national security review for any data processing that affects or may affect national security, and review decisions are final.
- Cross-border transfer of important data requires a CAC security assessment; smaller personal information flows can use a standard contract or certification.
- Article 33 makes data transaction intermediaries verify data sources and both parties’ identities, and retain the records.
- The CAC reported that of 44 security assessment submissions involving important data as of March 2025, seven failed.
What the DSL Classifies as Important Data
Article 21 sets up a categorized protection system. Data is sorted by its importance to economic and social development and by the harm that alteration, destruction, leakage, or illegal use would cause to national security, public interests, or individual rights. The law defines two higher tiers. Important data is coordinated through a national catalog, and data concerning national security, key parts of the national economy, important aspects of people’s lives, and major public interests is designated core data, which has a stricter management system.

The practical point is who decides. Under Article 21, localities and departments prepare specific catalogs of important data for their own regions, departments, and industries. A foreign company cannot self-certify that its data is merely general. The classification is issued by sector regulators, and the CAC has said companies do not need to treat their data as important data unless a relevant government authority specifically notifies them, per Arnold & Porter’s June 2025 advisory on the CAC FAQ. That said, the same guidance recommends companies consult the national standard GB/T 43697-2024 on data classification and categorization to assess their own exposure.
For critical information infrastructure operators, Article 31 adds a second layer. Outbound security management of important data collected or produced by CII operators during their operations in China is governed by the Cybersecurity Law, while the rules for other data processors are set by the national cyberspace authority together with State Council departments. The practical effect is that the same dataset can have different obligations depending on whether the processor is a designated CII operator.
Security Assessment and the Transfer Pathways
Article 30 requires processors of important data to conduct risk assessments regularly and submit the reports to the competent departments. Those reports must cover the types and amounts of important data processed, the processing activities, the security risks identified, and the response measures. This is an ongoing obligation, not a one-time filing at launch.
Cross-border transfer of important data requires a CAC security assessment. The other two routes, a standard contractual clause filing and personal information protection certification, apply mainly to personal information that does not qualify as important data. The CAC’s 2025 FAQ explains how the assessment is judged: whether the transfer is necessary, whether the number of individuals affected matches the business purpose, and whether the scope of data collected is appropriately limited.
The numbers from the regulator show the assessment is not a formality. As of March 2025, the CAC had completed review of 298 security assessment submissions, 44 of which involved important data. Of those 44, seven failed. The 44 submissions covered 509 data items, of which 325 were approved for cross-border transfer. The CAC also extended the validity of an approved security assessment from two years to three, with extension applications due through provincial CAC within 60 working days before expiry.
China has also narrowed the scope of what must be assessed. The CAC’s March 2024 Provisions on Regulating and Promoting Cross-border Data Flows created full exemptions for data that is neither personal information nor important data, for pass-through data collected outside China, and for transfers genuinely needed to perform a contract or manage employees, as detailed in Clifford Chance’s briefing on the new provisions. A de minimis exemption covers non-sensitive personal information of fewer than 100,000 individuals exported since January 1 of the current year by a processor that is not a CII operator.
Free trade zones operate a separate route. FTZs may publish negative lists, and data not captured by the list can be transferred without going through the general framework. The CAC confirmed that a negative list enacted by one FTZ is automatically effective in other FTZs. Tianjin, Beijing, Hainan, Shanghai, and Zhejiang have released lists covering 17 industry sectors, with Beijing’s list covering automobile and life sciences and Shanghai’s limited to reinsurance, international shipping, and certain retail, food, and hotel membership programs. Companies whose local FTZ list does not cover their industry can refer to Beijing’s list to determine their obligations.
National Security Review and Data Transactions
Article 24 sets up a review system for data security, under which the state conducts national security reviews of data processing that affects or may affect national security. The article states plainly that security review decisions made in accordance with law are final. The law does not describe an appeals process, which is why the review is treated as a gating risk rather than a procedural step.
Article 25 adds export control. Data that is a controlled item and concerns national security and interests, or the performance of international obligations, is subject to export control in accordance with law. Article 26 gives China a countermeasure mechanism: where another country or region adopts discriminatory prohibitions or restrictions against China related to data and data development technologies, China may respond based on the circumstances.
Data transactions have their own rules. Article 19 directs the state to establish sound systems for data trading management and to build a data trading market. Article 33 then places duties on the intermediaries that make that market work: data transaction intermediaries must require data providers to specify the sources of their data, verify the identities of both parties to a transaction, and retain the verification and transaction records. For a foreign company buying or selling datasets in China, the intermediary is now a compliance checkpoint, and records of provenance matter.
Article 36 blocks a route that Western legal teams often assume is available. Requests for data from foreign judicial or law enforcement authorities are handled by Chinese competent authorities under relevant laws, treaties, or principles of equality and reciprocity. Without approval from those authorities, organizations and individuals in China may not provide data stored within Chinese territory to any overseas judicial or law enforcement body. A US subpoena served on a Chinese subsidiary does not create a lawful path to export the data.
Penalties and Enforcement
The penalty structure is where the DSL’s influence becomes concrete. The compliance guide published by China Policy Guide puts the maximum fine for a serious DSL violation at RMB 10 million, alongside business suspension and criminal prosecution, with personal liability for responsible individuals. Illegal cross-border transfer carries the same RMB 10 million ceiling, a correction order, and possible suspension of operations. Those figures sit below the PIPL ceiling of RMB 50 million or 5% of annual revenue, but the DSL’s national security framing means a violation can also trigger the review and export control mechanisms described above.
| Violation type | Maximum penalty | Additional consequence |
|---|---|---|
| Serious DSL violation | Up to RMB 10 million | Business suspension; criminal prosecution |
| Illegal cross-border transfer | Up to RMB 10 million | Correction order; business suspension |
| PIPL violation (serious) | Up to RMB 50 million or 5% of annual revenue | Business suspension; personal fines of RMB 100,000 to 1 million |
| Failure to report a data breach | Up to RMB 1 million | Personal fines for responsible individuals |
Enforcement has teeth. China’s internet watchdog fined ride-hailing firm Didi Global more than 8 billion yuan, about $1.2 billion, following an investigation into its cybersecurity and data practices, reported by the Associated Press. The Didi case is the clearest signal that the review and penalty machinery is used at scale, not reserved for hypothetical scenarios.
The surrounding framework is tightening too. Amendments to the Cybersecurity Law were introduced by the Standing Committee of the National People’s Congress on October 28, 2025, and took effect on January 1, 2026. As Latham & Watkins summarized on JD Supra, the amendments increase penalties and broaden extraterritorial enforcement. Because Article 31 of the DSL routes CII outbound data management through the CSL, those higher penalties reach directly into cross-border data decisions.
Self-Assessment Checklist for Foreign Companies
This checklist follows the sequence the law itself implies: know your data, know your regulator, then choose a transfer route.
- Inventory and classify. Map every dataset the China operation collects, stores, or processes, and sort it into general, important, and core tiers using the GB/T 43697-2024 standard as a reference. Do not assume your data is general until you have checked the relevant industry catalog.
- Identify whether you are a CII operator. If you are designated critical information infrastructure, Article 31 applies the CSL’s outbound rules to your important data. Finance, energy, transport, healthcare, and telecom are the common designations.
- Confirm your regulator. Important data catalogs are set by industry and regional authorities. Identify which department governs your sector before deciding your classification.
- Decide the transfer route. Transferring important data means a CAC security assessment. Personal information below the important-data line may qualify for a standard contract filing, certification, or a full exemption if it fits the 2024 provisions.
- Check the de minimis threshold. If you are not a CII operator and are exporting non-sensitive personal information of fewer than 100,000 individuals since January 1, the de minimis exemption may apply.
- File the risk assessment. Article 30 requires regular risk assessments for important data processors, submitted to the competent department with data types, volumes, risks, and response measures.
- Audit data transactions. If you buy or sell datasets, confirm the intermediary verifies data sources and both parties’ identities and retains records, per Article 33.
- Screen overseas requests. Establish a process that blocks any response to a foreign judicial or law enforcement data request without Chinese competent authority approval under Article 36.
- Plan for review timing. A security assessment is not instant. Budget for the review period and for the possibility of a failed assessment, given that seven of 44 important-data submissions failed as of March 2025.
- Track FTZ eligibility. If you operate in a free trade zone, check whether your data falls on the applicable negative list, which can remove the general transfer framework entirely.
Where the DSL Sits in China’s Three-Law Framework
The DSL is one of three laws that together govern data in China, and confusing their scopes causes compliance gaps. The Cybersecurity Law, effective since 2017, covers network security and places data localization obligations on critical information infrastructure operators. The Personal Information Protection Law, effective November 2021, regulates personal data and sets the cross-border transfer mechanisms most foreign companies recognize. The DSL, effective September 2021, governs data by importance and adds the national security dimension.
The distinction matters because the three laws use different thresholds and different penalties. A transfer that is small enough to fall under the PIPL de minimis exemption can still be blocked if the data qualifies as important under a sector catalog. A company that has filed standard contractual clauses under the PIPL has not satisfied the DSL’s security assessment requirement for important data. This is the layered reality that catches foreign firms, and it is why we treat connectivity and compliance as separate problems in our cross-border data rules guide.
For teams that also need to understand the network layer these laws operate over, our explainer on how the Great Firewall works covers the connectivity side, and our guide to cloud storage in China covers where regulated data can physically sit.
The DSL’s core logic is that classification drives everything. Once data is designated important, the security assessment, the recurring risk report, and the national security review follow. The work for a foreign company is to establish its classification before a regulator does it, because the review decision under Article 24 is final.
Related Reading
More in-depth coverage from this blog on closely related topics:
- How to Host a Website in China
- How to Protect Data in China
- What Is the Great Firewall and How It Works
Sources and References
Sources cited while researching and writing this article:
Victor Zhao
Cross-border business consultant with deep expertise in China's technology landscape and regulatory environment.
