China’s Cybersecurity Law: A Practical Guide for Foreign Businesses

If your company stores data in China, operates a digital platform accessed by Chinese users, or runs any kind of online service touching the mainland market, China’s cybersecurity framework is not optional reading — it is operational reality. Over the past five years, Beijing has constructed one of the world’s most comprehensive data governance regimes, and enforcement has accelerated since 2022. This guide cuts through the complexity and tells you exactly what foreign businesses need to understand and act on in 2026.

The Three-Law Framework You Must Know

China’s cybersecurity regime rests on three interlocking laws, each administered by the Cyberspace Administration of China (CAC) in coordination with relevant sectoral regulators.

1. The Cybersecurity Law (CSL) — 2017

The Cybersecurity Law, effective June 1, 2017, is the foundational statute. It introduced the concept of Critical Information Infrastructure (CII) — systems covering energy, finance, transport, utilities, public services, and e-government that, if disrupted, could cause serious harm to national security or the public interest. Foreign firms operating in these sectors are explicitly subject to CII rules, including mandatory security reviews and restrictions on cross-border data transfers.

Key CSL obligations for foreign businesses include: implementing graded cybersecurity protection (等级保护, Dengji Baohu), retaining network logs for at least six months, using certified network products in certain categories, and notifying the public security bureau of security incidents within 24 hours of discovery.

2. The Data Security Law (DSL) — 2021

The Data Security Law, effective September 1, 2021, extends the framework beyond networks to all data activities — including processing, storage, use, provision, and deletion. It introduces a national data classification and grading system, with “core data” (核心数据) receiving the highest protections and restrictions. Businesses handling core data must obtain approval before any cross-border transfer.

The DSL also contains extraterritorial provisions: organizations outside China that harm China’s national security, public interest, or citizens’ lawful rights are subject to legal liability. This clause has direct implications for foreign companies processing China-sourced data offshore.

3. The Personal Information Protection Law (PIPL) — 2021

Effective November 1, 2021, the PIPL is China’s answer to the EU’s GDPR. It governs how personal information about Chinese individuals is collected, processed, and transferred — regardless of where the processing occurs. Foreign companies collecting data from Chinese customers must obtain separate, informed consent for each processing purpose, appoint a China-based compliance representative, and conduct Personal Information Protection Impact Assessments (PIPIAs) before undertaking high-risk activities.

The CAC has published detailed implementation rules, available on the CAC official site, that clarify consent standards and cross-border transfer mechanisms.

Cross-Border Data Transfer: The Rules in 2026

Cross-border data transfer is the most operationally critical compliance area for foreign businesses. China has established three legal pathways for transferring personal or important data outside the country:

1. Security Assessment (安全评估)

Mandatory for CII operators, companies transferring “important data,” and organizations that have processed personal information for more than 1 million individuals — or have transferred personal data of over 100,000 individuals or sensitive data of over 10,000 individuals in the preceding 12 months. The security assessment is administered by the CAC and typically takes 45 working days from acceptance, though complex cases take longer.

2. Standard Contractual Clauses (SCCs)

For companies below the security assessment thresholds, China’s SCCs (issued by the CAC in February 2023) allow data transfers via a standardized contractual template. The SCC must be signed between the Chinese data exporter and the overseas recipient, and a PIPIA must accompany it. Notably, the SCCs must be filed with provincial-level CAC offices within 10 working days of coming into effect.

3. Personal Information Protection Certification

An option for entities within a corporate group that process personal information across borders internally. Certification is granted by accredited bodies recognized by the State Administration for Market Regulation (SAMR) and is particularly suited to multinationals managing employee data or internal analytics across subsidiaries.

In 2025, the CAC updated its guidance to create a “negative list” exemption for routine business data (payroll, order confirmations, logistics tracking) that does not meet the volume thresholds — a pragmatic relief valve that many foreign firms have used to simplify compliance for day-to-day operations.

The Cybersecurity Review System

For companies seeking to list on overseas stock exchanges or those operating critical information infrastructure, the Cybersecurity Review Measures (effective February 15, 2022) require a mandatory review before proceeding. Any network platform operator with personal information from more than 1 million users that seeks an overseas listing must declare this to the CAC-led Cybersecurity Review Office.

Reviews examine whether the overseas listing could result in core data, important data, or large-scale personal information being affected by foreign government influence. Several major Chinese tech companies learned this lesson acutely in 2021; since then, due diligence on data governance has become a prerequisite, not an afterthought, for any IPO involving Chinese data assets. Foreign companies acquiring or investing in Chinese digital businesses face similar scrutiny.

Graded Cybersecurity Protection: What It Means Operationally

The Multi-Level Protection Scheme (MLPS 2.0), codified under national standard GB/T 22239-2019, requires all network operators in China — foreign-invested enterprises included — to classify their information systems into one of five tiers based on the potential harm if the system is compromised. Most commercial enterprise systems fall at Level 2 or Level 3.

  • Level 2: Requires filing with the local public security bureau, annual self-assessment, and basic security controls (access management, log retention, encryption of sensitive fields)
  • Level 3: Requires third-party assessments by a MLPS-certified testing agency every year, and implementation of more rigorous controls including intrusion detection systems, security operations center monitoring, and quarterly vulnerability scans
  • Levels 4 and 5: Reserved for national security-critical systems; foreign companies rarely reach these tiers except in specific regulated industries

Compliance with MLPS 2.0 is assessed by the Ministry of Public Security (MPS), which maintains a national database of registered systems. Local public security bureaus handle day-to-day enforcement.

Sectoral Overlays: Finance, Health, and E-Commerce

Beyond the three core laws, sector-specific regulators have issued their own cybersecurity and data rules that foreign firms must layer on top of the baseline framework:

  • Financial services: The China Securities Regulatory Commission (CSRC) and People’s Bank of China have issued rules on financial data classification; firms holding securities licenses must comply with data residency requirements that go beyond the general CSL framework
  • Healthcare: The National Health Commission’s 2018 Health Data Standards and 2022 health data security guidance require medical data to be stored within China with near-absolute restrictions on outbound transfer
  • E-commerce platforms: The Provisions on the Management of Network Data Security (draft finalized in late 2024) impose specific obligations on platform operators regarding user data portability, algorithm transparency, and profiling disclosures

If you operate in Shenzhen’s tech corridor or another innovation hub, local authorities may also apply pilot regulations that exceed national standards — Shenzhen has issued its own data regulations since 2021 that are frequently cited as a preview of national rules to come.

Enforcement: The Practical Risk Landscape

The CAC has conducted multiple rounds of enforcement since 2022, typically focusing on large consumer-facing platforms. However, the agency has also investigated foreign-invested enterprises, particularly in financial services and technology. Penalties under the CSL can reach RMB 1 million per violation; the PIPL allows fines of up to 5% of the previous year’s annual revenue for serious violations, with the possibility of suspending operations.

In 2025, the CAC concluded two high-profile investigations involving overseas companies’ Chinese subsidiaries, each resulting in corrective orders, fines, and mandatory audits. The reputational risk of being named in a CAC enforcement action is considerable, even for companies with limited China exposure.

For a broader view of how Chinese legal frameworks intersect with foreign investment structures, see our guide to setting up a VIE structure in China, which also covers the regulatory approval dimensions relevant to tech companies.

Practical Compliance Checklist for Foreign Businesses

For most foreign companies operating in China, a structured compliance program should address the following areas:

  1. Data inventory: Map all personal and important data collected, processed, or stored in China — including HR data, customer databases, and operational telemetry
  2. Legal basis documentation: Confirm that a valid legal basis (consent, contractual necessity, legitimate interest as defined under PIPL) exists for each processing activity
  3. Cross-border transfer pathway: Determine which of the three transfer mechanisms applies based on your data volume and type; file SCCs if required
  4. MLPS classification: Register all information systems with the local public security bureau; engage a certified testing agency for Level 3 assessments
  5. Incident response plan: Establish a documented breach response protocol with CAC and MPS notification timelines; test annually
  6. Vendor due diligence: Audit third-party processors (cloud providers, SaaS vendors, marketing platforms) for PIPL compliance; ensure data processing agreements are in place
  7. China-based representative: Appoint a designated PIPL compliance officer or representative in China, as required for companies headquartered outside the mainland

The US-China Business Council’s research and advocacy resources provide ongoing policy updates on data governance developments, which is valuable for compliance teams tracking regulatory changes in real time.

Working With Chinese Legal Counsel

Given the pace of regulatory change and the complexity of enforcement at the provincial level, retaining qualified Chinese legal counsel is not optional for any company with material China data operations. Look for firms with dedicated cybersecurity and data protection practices and experience advising foreign-invested enterprises — not simply IP or corporate transactional lawyers who have recently expanded into data compliance.

US firms operating in China should also be aware that the US Commercial Service in China maintains resources and referral networks for identifying reputable local legal advisors, and the American Chamber of Commerce in China tracks enforcement trends that directly affect US-invested companies.

Understanding China’s anti-monopoly and competition law framework is equally important for digital businesses — our guide to China’s Anti-Monopoly Law covers how platform regulation intersects with data governance requirements, since the CAC administers both sets of rules for large digital platforms.

The Bottom Line

China’s cybersecurity framework is mature, actively enforced, and expanding in scope. For foreign businesses, the core challenge is not understanding the rules in isolation — each law is individually comprehensible — but managing the interaction between the CSL, DSL, and PIPL simultaneously, while layering sectoral regulations and staying current with CAC guidance that updates regularly.

Companies that treat China data compliance as a one-time project will find themselves behind the curve. The most operationally resilient foreign firms in China have built compliance into their data architecture from the ground up: data minimization by design, localized storage where required, a clear cross-border transfer pathway documented and filed, and a legal team with direct CAC channels. That combination is what separates companies that operate in China with confidence from those that operate with anxiety.