China Network Data Security Regulations
In force China · In force Jan 1, 2025 · no upcoming deadlines
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Implementing regulations under the CSL, DSL and PIPL covering personal information, important data, cross-border data and platform duties. Processors of PI of 10 million+ people must also meet important-data processor duties, such as naming a security lead and filing annual risk assessments. Platforms must offer an easy opt-out from personalized recommendations.
- Who it applies to
- Network data processing activities in China, plus offshore processing of data of people in China that harms national security or public interest. Processors of PI of 10 million or more individuals take on the important-data duties in Arts. 30 and 32 (Art. 28). Important-data processors must file annual risk assessment reports with provincial-level regulators (Art. 33).
- Penalties
- Violating specified articles (e.g. Arts. 12, 16-20, 22, 40-42): warning and confiscation, and for refusal or serious cases fines up to RMB 1 million plus possible suspension or license revocation; responsible individuals RMB 10,000-100,000 (Art. 55). Other violations are punished under the CSL, DSL and PIPL.
- Enforced by
- CAC, telecom, public security and other competent departments
- Official name
- Regulations on Network Data Security Management (State Council Order No. 790)
- Citation
- State Council Order No. 790
- Topics
- privacy, cybersecurity, data-residency
Research notes
Adopted at the State Council executive meeting of 2024-08-30, signed as Order No. 790 on 2024-09-24, published 2024-09-30. Annual risk assessment timing is 'each year' with no fixed calendar date.
Related
Questions about China Network Data Security Regulations
- What are the China Network Data Security Regulations compliance deadlines?
- Jan 1, 2025: Network Data Regulations take effect.
- When does China Network Data Security Regulations take effect?
- China Network Data Security Regulations took effect on Jan 1, 2025.
- Who does China Network Data Security Regulations apply to?
- Network data processing activities in China, plus offshore processing of data of people in China that harms national security or public interest. Processors of PI of 10 million or more individuals take on the important-data duties in Arts. 30 and 32 (Art. 28). Important-data processors must file annual risk assessment reports with provincial-level regulators (Art. 33).
- What are the penalties under China Network Data Security Regulations?
- Violating specified articles (e.g. Arts. 12, 16-20, 22, 40-42): warning and confiscation, and for refusal or serious cases fines up to RMB 1 million plus possible suspension or license revocation; responsible individuals RMB 10,000-100,000 (Art. 55). Other violations are punished under the CSL, DSL and PIPL.