Database

Browse Database

CHINA

Since September 2002, last amended in 2024

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Regulations on Administration of Business Premises for Internet Access Services (互联网上网服务营业场所管理条例)
Art. 23 of the "Regulations on Administration of Business Premises for Internet Access Services" stipulates that the operators of internet access service premises must verify and register the identity documents, such as identity cards, of individuals using internet services and must record relevant information concerning their internet usage. The particulars of these registrations and the associated backup records shall be retained for a minimum of 60 days and must be produced upon the lawful request of the cultural administrative authorities or public security organs, and such registration details and backup records shall not be altered or deleted during the prescribed retention period. Art. 2 provides that, for the purposes of these Regulations, "Internet access service premises" refers to commercial establishments such as internet cafés and computer leisure centres that provide internet access services to the public via computers or comparable devices.
Coverage Operators of internet access service premises

CHINA

Since October 2000

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Provisions for the Administration of Internet Electronic Bulletin (互联网电子公告服务管理规定)
Art. 14 of the "Provisions for the Administration of Internet Electronic Bulletin" requires electronic bulletin service providers to record all information posted on their systems, including the content, the time of publication, and the relevant Internet Protocol address or domain name, and to retain backups of these records for 60 days for provision to the competent state authorities upon lawful request. Art. 2 clarifies that, for the purposes of these Provisions, "electronic bulletin services" denotes facilities enabling Internet users to publish information online through interactive formats such as electronic noticeboards, electronic whiteboards, electronic forums, online chat rooms, and message boards.
Coverage Electronic bulletin services

CHINA

Since August 2021, entry into force in November 2021

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法)
Art. 52 of the Personal Information Protection Law requires the appointment of a data protection officer when the personal information handler meets specified conditions. In addition, under Arts. 55 and 56, a personal information protection impact assessment is required in certain circumstances.
Coverage Horizontal

CHINA

Since June 2021, entry into force in September 2021

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Data Security Law of the People's Republic of China (中华人民共和国数据安全法)
Art. 27 of the Data Security Law mandates the designation of personnel responsible for overseeing data security. This obligation applies solely to processors of important data; however, the statute itself does not provide a definition of that category.
Coverage Processors of important data

CHINA

Since October 2020

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Amendment to the Information Security Technology – Personal Information Security Specification (GB/T 35273-2020) (信息安全技术-个人信息安全规范) (GB/T 35273-2020) 修正案)
The 2020 Personal Information Security Specification provides that personal information controllers shall appoint a person and a department responsible for personal information (PI) protection. The person responsible for PI protection must have relevant management experience and personal information protection expertise, participate in important decisions on personal information processing activities, and report directly to the principal of the organization.
Coverage Horizontal

CHINA

Since November 2016, entry into force in June 2017

Pillar Domestic data policies  |  Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法)
Art. 21 of the Cybersecurity Law requires network operators to appoint persons in charge of cybersecurity. Critical information infrastructure operators (CIIO) are also required to set up specialised security management bodies and persons responsible for security management. Further, CIIO's must conduct security background checks on those responsible persons and personnel in critical positions (Art. 34).
Coverage Horizontal

CHINA

Since June 2021, entry into force in September 2021

Pillar Domestic data policies  |  Indicator Requirement to allow the government to access personal data collected
Data Security Law of the People’s Republic of China (中华人民共和国数据安全法)
Art. 35 of the Data Security Law stipulates that where public security or national security authorities need to consult any data in order to safeguard national security or investigate a crime, the relevant organizations and individuals must provide such data. The same article stipulates that before getting access to the data held by private organizations, public security or national security authorities must go through strict approval formalities in advance.
Coverage Horizontal

CHINA

Since December 2015, entry into force in January 2016, last amended in April 2018

Pillar Domestic data policies  |  Indicator Requirement to allow the government to access personal data collected
Counterterrorism Law of the People's Republic of China (中华人民共和国反恐怖主义法)
Art. 18 of the Counterterrorism Law requires Internet service providers and the telecommunication sector to “provide technical support and assistance, such as technical interface and decryption, to support the activities of the public security and state security authorities in preventing and investigating terrorist activities.”
Coverage Internet service providers and telecommunication sector

CHINA

Since September 2000, last amended in 2024

Pillar Domestic data policies  |  Indicator Requirement to allow the government to access personal data collected
Measures for the Administration of Internet Information Services (互联网信息服务管理办法)
According to Art. 14 of the Measures for the Administration of Internet Information Services, ISPs must provide user information to the authorities upon request, without judicial oversight.
Coverage Internet service providers

CHINA

Since August 2021, entry into force in November 2021
Since March 2024

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法)

Provisions on Promoting and Regulating the Cross-Border Flow of Data (促进和规范数据跨境流动规定)
Under Art. 40 of the Personal Information Protection Law (PIPL), personal information handlers who process personal data exceeding the thresholds stipulated by regulatory authorities, as well as operators of critical information infrastructure, are required to store the personal information they collect and generate within the territory of China. If it is genuinely necessary for a personal information handler to transfer personal information abroad, specific regulatory requirements must be satisfied. In accordance with Art. 38 of the PIPL and Arts. 7 and 8 of the Provisions on Promoting and Regulating the Cross-Border Flow of Data, personal information handlers seeking to provide or transfer personal data outside of China must meet one of the following conditions:
1. Obtain approval through a security assessment conducted by the Cyberspace Administration of China (CAC), applicable if any of the following criteria are met: the handler is a critical information infrastructure operator; the handler (not classified as a critical information infrastructure operator) has, since 1 January of the current year, cumulatively provided the personal information of 1,000,000 individuals or sensitive personal information of 10,000 individuals to overseas recipients; the handler seeks to transfer personal information classified as important data or otherwise containing important data outside China.
2. Satisfy requirements through either of the following mechanisms: enter into the standard contract formulated by the CAC with the overseas data recipient; or obtain personal information protection certification from professional institutions in accordance with CAC rules. This applies when the handler is not a critical information infrastructure operator; or intends to transfer non-sensitive personal information of more than 100,000 but less than 1,000,000 individuals, or sensitive personal information of fewer than 10,000 individuals, on a cumulative basis, since 1 January of the current year.
Notwithstanding the above requirements, the outbound transfer of personal information, excluding important data, is exempt from these provisions under Arts. 3, 4, and 5 of the Provisions if the transfer arises from the following circumstances:
- International trade, cross-border transportation, academic collaboration, transnational manufacturing, marketing, or similar activities that do not involve personal or important data.
- Exporting personal information collected or generated outside China and then processed in China, provided no domestic personal information collected within China is included.
- Transfers necessary for the performance of contracts involving the data subject, such as cross-border shopping, payments, travel bookings, visa applications, or similar services.
- Employee-related data transfers for implementing human resources management under employment policies or collective labour agreements.
- Transfers required to protect the life, health, or property security of individuals in emergencies.
- Transfers involving non-sensitive personal information of fewer than 100,000 individuals on a cumulative basis by handlers who are not critical information infrastructure operators since 1 January of the current year.
Additionally, Arts. 38, 39, 41, 53, and 55 of the PIPL impose further obligations on personal information handlers seeking to transfer personal data outside China, including:
- Demonstrating a legitimate business or operational need for the cross-border transfer.
- Implementing measures to ensure that overseas recipients process the data in compliance with the protection standards set out in the PIPL.
- Providing adequate prior notification to individuals and obtaining their explicit consent.
- Securing approval from the relevant Chinese authorities for transfers to foreign judicial or law enforcement agencies.
- Establishing local representatives or agencies within China for overseas recipients who do not have a local entity and are classified as personal information handlers outside Mainland China.
- Conducting a personal information protection impact assessment before initiating a cross-border transfer.
Coverage Horizontal

CHINA

Since November 2012, entry into force in February 2013

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Guidelines for Personal Information Protection Within Public and Commercial Services Information Systems (公共及商用服务信息系统个人信息保护指南)
Art. 5.4.5. of the Guidelines for Personal Information Protection Within Public and Commercial Services Information Systems prohibit the transfer of personal data abroad without the express consent of the data subject, government permission or explicit regulatory approval "absent express consent of the subject of the personal information, or explicit legal or regulatory permission, or absent the consent of the competent authorities". If these conditions are not fulfilled, "the administrator of personal information shall not transfer the personal information to any overseas receiver of personal information, including any individuals located overseas or any organisations and institutions registered overseas." Although the Guidelines are a voluntary technical document, they might serve as a regulatory basis for judicial authorities and lawmakers.
Coverage Public and commercial services information systems

CHINA

N/A

Pillar Cross-border data policies  |  Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
China has not joined any agreement with binding commitments to open transfers of data across borders. Art. 12.15 of the Regional Comprehensive Economic Partnership (RCEP) recognises that each party may maintain its own regulatory requirements governing cross‑border transfers of information by electronic means and stipulates that such transfers shall not be restricted when undertaken for the conduct of business by a covered person; however, the article simultaneously allows parties to adopt or maintain any measures they themselves deem necessary to achieve a legitimate public policy objective, as well as any measures necessary to protect essential security interests, with the parties expressly affirming that the determination of such necessity lies solely with the implementing party and that such measures shall not be subject to dispute. It is reported that this formulation enables China to preserve its domestic data‑control regime under the rubric of national security without risking inter‑state disputes, and that the relative weakness of Chapter 12 renders its provisions largely ineffectual in facilitating the liberalisation of cross‑border data flows, particularly because the clause entrusting necessity assessments to the implementing party effectively permits any measure to be characterised as legitimate at that party’s discretion.
Coverage Horizontal

CHINA

Since August 2021, entry into force in November 2021

Pillar Domestic data policies  |  Indicator Framework for data protection
Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法)
The Personal Information Protection Law provides a comprehensive regime of data protection in China.
Coverage Horizontal

CHINA

Since January 2019

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Banking Financial Institutions Anti-Money Laundering and Counter Terrorist Financing Management Measures
Pursuant to Art. 28 of the ¨Banking Financial Institutions Anti-Money Laundering and Counter-Terrorist Financing Management Measures¨, banking and financial institutions are prohibited from transmitting customer identification information and transaction data obtained in the course of fulfilling anti-money laundering and counter-terrorist financing obligations to entities outside the country, except where such transmission is authorised by applicable laws and administrative regulations.
Coverage Financial sector

CHINA

Since May 2019, entry into force in July 2019
Since June 2023, entry into force in July 2023

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
P.R.C Regulation on the Management of Human Genetic Resources (中华人民共和国人类遗传资源管理条例)

Implementation Rules for the Regulations on the Management of Human Genetic Resources (人类遗传资源管理条例实施细则)
According to the Regulation on the Management of Human Genetic Resources, the export of human genetic resources information from China is prohibited unless explicitly approved. Under Arts. 7, 8, 9, and 10, the provision of human genetic resources to foreign entities must comply with ethical principles, undergo corresponding ethical reviews, and meet the technical standards established by the scientific administrative departments of the State Council. Such actions must not compromise public health, national security, or public interests. Foreign organisations and individuals, as well as entities directly controlled by them, are prohibited from transferring China’s human genetic resources abroad.
Art. 28 stipulates that, in addition to a record filing, any provision of data to foreign parties or the permission for its use by foreign parties requires submission of a copy of the relevant data to the Office of Human Genetic Resource Administration within the Ministry of Science and Technology. A “security assessment” may also be required if the provision or use of such data could potentially affect China's public health, national security, or public interest. Art. 37 of the Implementation Rules details the categories of human genetic resources information that must undergo a national security review before being transferred or made accessible to foreign parties. Particular attention must be given to the export of genetic resources information, including that related to significant genetic families or populations from specific geographic regions, or exome sequencing and genome sequencing data involving more than 500 human subjects.
Coverage Health sector
Sources

Report issue     Report new measure