Loading…
Loading…
The CSL is the apex statute of China's digital-governance architecture — a 7-chapter, 79-article framework enacted under the authority of the NPC Standing Committee. It operates across three mutually reinforcing pillars:
1. Critical Information Infrastructure (CII) Regime (Arts. 31–39) CAC, in coordination with the Ministry of Public Security (MPS) and sector regulators, may designate operators in energy, transport, water, finance, public services, e-government, and defence-industrial domains as Critical Information Infrastructure Operators (CIIOs). CIIOs are subject to heightened obligations: mandatory annual cybersecurity inspection, dedicated security personnel and management systems, data-backup requirements, and — crucially — Art. 37 localisation: personal information and important data collected or generated in China's territory must be stored domestically. Cross-border transfers require a security assessment by the State Internet Information Office (now CAC). The CIIO designation regime was operationalised by the 2021 Regulations on the Security Protection of Critical Information Infrastructure (国务院令第745号, effective 1 September 2021).
2. Multi-Level Protection Scheme (MLPS 2.0 / 等级保护制度, Art. 21) All network operators (not only CIIOs) must comply with the tiered MLPS obligations set by the Public Security Ministry. MLPS 2.0, published as GB/T 22239-2019, expanded the original 2008 scheme to cover cloud platforms, mobile internet, IoT, and industrial-control systems — effectively mandating security-architecture assessments for any enterprise running infrastructure in China.
3. Network-Product and Service Security Reviews (Arts. 22–23) Network products and services that could affect national security must undergo a security review administered by CAC. This provision underpins the CAC Cybersecurity Review Measures (网络安全审查办法) of 2021/2022, under which:
NYSE IPO — and directed to halt new user registrations; the review concluded in July 2022 with a ¥8.026 billion fine and App Store delisting.
ruling that Micron's products posed "relatively serious cybersecurity risks," barring their use in Chinese critical-infrastructure projects — the first use of Art. 22/23 review to exclude a foreign semiconductor supplier from a defined market segment.
Art. 37 of the CSL is the original anchor for China's data-localisation regime. The provision was subsequently layered:
| Statute | Effective | Extension |
|---|---|---|
| CSL Art. 37 | 2017-06-01 | CIIO-scoped; important data + personal info |
| Data Security Law (DSL) Art. 31 | 2021-09-01 | Extends important-data localisation to all data processors |
| PIPL Art. 38–43 | 2021-11-01 | Adds SCC + certification pathways for personal info |
| CAC Cross-Border Data Flow Provisions | 2024-03-22 | Raises thresholds; FTZ pilot negative lists; see 2024-03-22-cn-cac-cross-border-data-flow-provisions |
The CSL thus functions as the parent statute for all four of the above instruments: DSL and PIPL should be read as sector-neutral extensions of the CIIO-scoped Art. 37 regime, and the 2024 CAC Provisions as Art. 37 implementation rules calibrated for the post-PIPL environment.
licensed cloud partners (Alibaba Cloud / 21Vianet, Azure East China / 21Vianet, GCP China). This structural separation increases opex and limits cross-border management-plane integration — headwind for MSFT/AMZN/GOOGL China revenue.
compliance costs and potential CIIO-designation exposure — relevant for CRM, ERP, HR-SaaS, and financial-software vendors.
data-localisation requirement — a structural barrier to post-acquisition IT integration.
leave sector-regulator discretion broad; new designations can retroactively impose Art. 37 obligations on foreign-invested enterprises.
2024-03-22-cn-cac-cross-border-data-flow-provisions will gain full parent chain once those are filed)