Loading…
Loading…
The DSL creates a three-tier data classification system:
1. General data — ordinary data subject to baseline security obligations. 2. Important data (重要数据) — data whose alteration, destruction, leakage, or illegal acquisition or use may endanger national security, economic operations, social stability, or public welfare. Each industry sector's regulator (CAC for internet data, MIIT for industrial data, PBOC for financial data, etc.) must publish its own catalogue defining what constitutes "important data" in that domain. Data handlers in possession of important data face mandatory risk-assessment, risk-monitoring, breach-reporting, and designated-management-personnel obligations. 3. National core data (国家核心数据) — data directly related to national security, the lifelines of the national economy, or key aspects of public interests. Processing national core data requires stricter controls and government oversight; unauthorised disclosure or export carries criminal liability.
Data-export security review (Article 31): Operators of critical information infrastructure (CIIO) and other data handlers dealing with "important data" collected or generated within China must pass a government security assessment before transmitting such data overseas. This provision is the statutory parent of the 2022 CAC Outbound Data Transfer Security Assessment Measures and the 2024 CAC Cross-Border Data Flow Provisions (2024-03-22-cn-cac-cross-border-data-flow-provisions), which operationalise the review thresholds and exemptions.
Blocking statute (Article 36): Chinese organisations and individuals must not provide data stored within China to foreign judicial or law-enforcement authorities without the approval of the competent Chinese authority. This provision forms the legal backbone of China's counter-discovery regime — the mechanism cited in the SEC audit-access standoff with Chinese-listed companies (PCAOB/CSRC 2021-2022 framework) and the extraterritorial friction generated by US court subpoenas directed at data held by Chinese subsidiaries of multinationals.
Data trading and intermediary licensing (Chapter V): Data-trading intermediaries must verify the legality of data sources before facilitating transactions and must not trade data acquired illegally. This lays the statutory groundwork for the Shanghai and Beijing Data Exchanges established in late 2021.
National Data Security Coordination Mechanism (Article 5-8): The CAC leads coordinated data-security work across MIIT, MPS (Ministry of Public Security), MSS (Ministry of State Security), and sector regulators. The coordination mechanism is the institutional architecture that enables multi-regulator enforcement (as seen in the Didi Global cybersecurity review that began within weeks of the DSL's announcement in July 2021).
The DSL is the second of three parent statutes constituting the modern Chinese data-governance legal framework:
All three are operationalised by downstream subsidiary instruments: the 2022 CAC Outbound Data Transfer Security Assessment Measures, the 2022 CAC Standard Contractual Clauses, the 2024 CAC Cross-Border Data Flow Provisions (filed), and sector-specific "important data" catalogues issued by MIIT, PBOC, NHSA, etc.