Cybersecurity ยท China
Cybersecurity law & regulation in China (2026)
China shaded by its cybersecurity status
Cybersecurity in China: comprehensive law.
FrameworkCybersecurity Law (CSL, 2017; amended effective 1 Jan 2026), Data Security Law (DSL, 2021) and Personal Information Protection Law (PIPL, 2021), administered principally by the Cyberspace Administration of China (CAC), with supporting rules on CII protection, MLPS 2.0, cross-border data flows and incident reporting.
China operates one of the world's most comprehensive and prescriptive cybersecurity regimes, built on the CSL, DSL and PIPL trilogy and enforced by the CAC together with the Ministry of Public Security and sector regulators. The CSL was substantively amended in October 2025 (in force 1 January 2026) to sharpen penalties, expand extra-territorial enforcement, and add an AI-governance track; a unified national cybersecurity incident-reporting regime took effect on 1 November 2025 with strict short-window reporting timelines. Operators of Critical Information Infrastructure (CIIOs), network operators graded under the Multi-Level Protection Scheme (MLPS 2.0), and personal-information processors face layered obligations including localization, security assessments, and cross-border transfer controls.
Key points
The Standing Committee of the NPC adopted amendments to the CSL in October 2025 that took effect 1 January 2026, recalibrating penalties, aligning liability with the DSL/PIPL, expanding extra-territorial enforcement, and adding a new Article 20 supporting AI R&D and governance.
The CAC's Administrative Measures for National Cybersecurity Incident Reporting entered into force on 1 November 2025, requiring general network operators to report qualifying incidents within 4 hours and CIIOs within 1 hour; sector regulators must escalate 'major' or 'particularly major' incidents to national CAC and MPS within 30 minutes, with a full handling report due within 30 days.
CIIOs designated by sector regulators under the CII Protection Regulations must localize personal information and important data in China, establish dedicated security bodies, and pass CAC security review for cross-border transfers. In parallel, MLPS 2.0 (in force since December 2019) grades systems 1-5, requiring filing at Level 2+ and third-party certification at Level 3+ (annual re-assessment).
The PIPL is enforced by the CAC and provides for administrative fines of up to RMB 50 million or 5% of prior-year turnover. The CAC's Administrative Measures for Personal Information Protection Compliance Audits took effect 1 May 2025, and 2025 saw high-profile cross-border-transfer enforcement, including the September 2025 action against the Shanghai subsidiary of a European luxury brand for unlawfully exporting customer data to France.
The March 2024 Provisions on Promoting and Regulating Cross-border Data Flows relaxed thresholds but retained three pathways: CAC security assessment (mandatory for 'important data', CIIOs, or high-volume PI transfers), CAC-filed Standard Contract, and PI Protection Certification. The joint CAC/SAMR Measures for Certification of Cross-Border Personal Information Transfer took effect 1 January 2026, completing the framework.
The DSL (in force September 2021) establishes a hierarchical data-classification system (general/important/core/national-core data), imposes special protection duties on 'important data' handlers including risk assessments and CAC security assessment before export, and prohibits providing data stored in China to foreign judicial or law-enforcement bodies without Chinese government approval.
Timeline - major decisions & events
Amendments adopted by the NPC Standing Committee on Oct. 28, 2025 raise maximum fines to RMB 10 million, allow immediate penalties without prior warning, and broaden extraterritorial enforcement to any overseas activity endangering China's cybersecurity. It significantly hardens the original 2017 framework.
Reed Smith โThe State Council issued national-level regulations (effective Jan. 1, 2025) implementing the CSL, DSL and PIPL together, setting unified rules on important data, network data handlers, and cross-border transfers. It consolidates China's three core data laws into one operational framework.
China Briefing โThe CAC released rules taking immediate effect that ease outbound data transfer requirements, exempting six scenarios from security assessment/certification and raising volume thresholds. It marked a notable relaxation of the strict 2022 cross-border regime.
Library of Congress โCAC measures finalized July 7, 2022 require a government security assessment before exporting important data, or personal information above set thresholds, out of China. It established the first mandatory state review gate for outbound data.
Library of Congress โAfter a year-long cybersecurity review, the CAC found 16 violations of the CSL, DSL and PIPL and fined Didi RMB 8.026 billion plus RMB 1 million each on its chairman and CEO. It was the landmark first major enforcement case under the new data laws.
DigiChina (CAC statement translation) โChina's first comprehensive data privacy law, often compared to the GDPR, established consent rules, data subject rights, cross-border transfer conditions, and penalties up to 5% of annual turnover. It completed the trio of pillars governing personal data security obligations.
DLA Piper โAdopted June 10, 2021, the DSL created a national data classification and grading system, introduced 'important data' and 'national core data' regimes, and imposed data-handling security obligations across all sectors. It anchors data security alongside the CSL.
Skadden โThe State Council's first administrative regulations on CII (released Aug. 17, 2021) defined critical sectors, designated protection authorities, and set operator obligations. They operationalized the CII concept introduced in the 2016 Cybersecurity Law.
The State Council (gov.cn) โMinistry of Public Security national standards (GB/T 22239-2019 and others) updated the classified protection regime, requiring operators to grade systems across five levels and obtain assessments for Level 2+ systems. It became the core technical compliance baseline under the CSL.
Inside Privacy (Covington) โChina's foundational cybersecurity statute imposed network operator security duties, data localization for critical information infrastructure, real-name registration, and the multi-level protection scheme. It established the structural framework all later data laws build upon.
DigiChina (Stanford) โThe National People's Congress Standing Committee passed China's first unified cybersecurity law, designating the Cyberspace Administration of China as lead regulator. Its passage marked the formal birth of China's modern cybersecurity legal regime.
NPC Observer โChina - other topics
Cybersecurity in other countries
Last verified 8/28/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ