Database

Browse Database

CHINA

Since April 2010, entry into force in October 2010
Since September 1988, entry into force in May 1989, until 2010

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Law of the People's Republic of China on Guarding State Secrets - Order of the President of the People's Republic of China No. 28 (中华人民共和国保守国家秘密法 - 中华人民共和国主席令. 第二十八 号)

Law of the People's Republic of China on Guarding State Secrets - Order of the President of the People's Republic of China No. 6 (中华人民共和国保守国家秘密法 - 中华人民共和国主席令 第六号)
Art. 25 of the Law on Guarding State Secrets prohibits the export of carriers containing state secrets. According to Art. 17, such carriers include paper, optical, and electromagnetic media that bear state secrets. This law revises legislation of the same name from 1988, in which Art. 26 prohibited the cross-border transfer of any data containing state secrets.
Coverage Horizontal

CHINA

Since August 2021, entry into force in October 2021

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Provisions on Management of Automotive Data Security (Trial) (汽车数据安全管理若干规定(试行))
According to Arts. 11 and 12 of the Provisions on Management of Automotive Data Security (Trial), important data must be stored domestically in compliance with legal requirements. If cross-border data transfer is necessary, security assessments must be conducted in coordination with the Cyberspace Administration of China and other relevant governmental authorities. Furthermore, the Management Provisions stipulate that vehicle data processors who provide important data to foreign entities must adhere strictly to the purpose, scope, method, type, and scale of data as specified in the security assessment. Data categorized as important includes video and image data captured outside of vehicles that contain facial information and personal information pertaining to 100,000 or more identified or identifiable vehicle owners, drivers, passengers, and individuals outside the vehicles.
Coverage Automotive sector

CHINA

Since July 2016, entry into force in November 2016, last amended in November 2022

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
Interim Measures for the Administration of Online Taxi Booking Business Operations and Services (网络预约出租汽车经营服务管理暂行办法)
Art. 5 of the Interim Measures mandates that online taxi reservation platforms must maintain their servers within the territorial boundaries of China.
Coverage Online taxi reservation platforms

CHINA

Since August 2017

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
Guiding Opinions on Encouraging and Regulating the Development of Internet Rental Bicycles (交通运输部等10部门关于鼓励和规范互联网 租赁自行车发展的指导意见)
According to Section 13 of the Guiding Opinions on Encouraging and Regulating the Development of Internet Rental Bicycles, companies offering internet-based bicycle rental services are required to establish domestic servers and store operational data collected within China.
Coverage Internet rental bicycle services

CHINA

Since February 2002

Pillar Telecom infrastructure & competition  |  Indicator Signature of the WTO Telecom Reference Paper
WTO Telecom Reference Paper
China has appended the World Trade Organization (WTO) Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector

CHINA

Since February 2016

Pillar Cross-border data policies  |  Indicator Infrastructure requirement
Online Publishing Service Management Rules (网络出版服务管理规定)
Arts. 8 and 9 of the Online Publishing Service Management Rules mandate that the servers and storage equipment of online publishers must be situated within the borders of China.
Coverage Online publishers

CHINA

N/A

Pillar Telecom infrastructure & competition  |  Indicator Presence of an independent telecom authority
Lack of independent telecom authority
The Ministry of Industry and Information Technology (MIIT) acts as the telecommunications authority in the country, and therefore, there is no independence from the government in its decision-making process.
Coverage Telecommunications sector

CHINA

Since August 2021, entry into force in November 2021

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Personal Information Protection Law (个人信息保护法)
Art. 40 of the Personal Information Protection Law provides that critical information infrastructure operators and personal information processors handling personal information must store personal information collected and produced within the borders of China. Where such information needs to be provided abroad, they shall pass a security assessment organised by the National Cyberspace Department. Also, according to Art. 38, the processors of personal information must apply one of the conditions to provide information outside of the PRC: passing the security assessment organised by the National Cyberspace Department; obtaining personal information protection certification from the relevant specialised institution according to the provisions issued by the national cyberspace department; concluding a contract stipulating both parties' rights and obligations with the overseas recipient following the standard contract formulated by the national cyberspace department; and meeting other conditions set forth by laws and administrative regulations and by the national cyberspace department.
Where a processor of personal information provides personal information outside the People's Republic of China, it is required to inform the individual of the name or names of the overseas recipient, the contact information, the purpose of processing, the manner of processing, the type of personal information, as well as the manner and procedure for the individual to exercise his or her rights under this Law with the overseas recipient, and obtain the individual's consent (Art. 39). Personal information processors shall not provide personal information stored in the People's Republic of China to foreign judicial or law enforcement agencies without the approval of the competent authorities of the People's Republic of China (Art. 41).
Coverage Horizontal

CHINA

Since January 2011, entry into force in May 2011
Since February 2020

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Yinfa No. 17/2011, Notice of the People's Bank of China on Protecting Personal Financial Information by Banking Financial Institutions (人民银行关于银行业金融机构做好个人金融信息保护工作的通知)

Personal Financial Information Protection Technical Specification (个人金融信息保护技术规范)
The "Notice of the People's Bank of China on Protecting Personal Financial Information by Banking Financial Institutions" states that the processing of personal information collected by commercial banks must be stored, handled and analysed within the territory of China, and such personal information is not allowed to be transferred overseas (paragraph 6).
The Personal Financial Information Protection Technical Specification (PFI Specification) regulates “any personal information collected, processed and stored by Financial Institutions during the provision of financial products and services" (PFI). The PFI specification requires that PFI collected or generated in mainland China is stored, processed and analysed within the territory. Further, under the PFI Specification, where there is a business need for cross-border transfer of personal financial information (PFI) and the financial institution obtains explicit consent to the transfer from the personal financial information subjects (i.e. the persons under the PFI Specification providing the data), conducts a security assessment and then supervises the offshore recipient to ensure responsible processing, storage and deletion of PFI (Section 7.1.3).
Coverage Financial sector

CHINA

Since November 2012, entry into force in February 2013

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Guidelines for Personal Information Protection Within Public and Commercial Services Information Systems (公共及商用服务信息系统个人信息保护指南)
Art. 5.4.5. of the Guidelines for Personal Information Protection Within Public and Commercial Services Information Systems prohibit the transfer of personal data abroad without the express consent of the data subject, government permission or explicit regulatory approval "absent express consent of the subject of the personal information, or explicit legal or regulatory permission, or absent the consent of the competent authorities". If these conditions are not fulfilled, "the administrator of personal information shall not transfer the personal information to any overseas receiver of personal information, including any individuals located overseas or any organisations and institutions registered overseas." Although the Guidelines are a voluntary technical document, they might serve as a regulatory basis for judicial authorities and lawmakers.
Coverage Public and Commercial Services Information Systems
Sources

CHINA

Since May 2014

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Administrative Measures for Population Health Information (For Trial Implementation) (人口健康信息的管理措施(试行))
Population health information needs to be stored and processed within China. In addition, storage is not allowed overseas (Art. 10).
Coverage Health sector

CHINA

Since July 2016, entry into force November 2016, last amended in November 2022

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Interim Measures for the Administration of Online Taxi Booking Business Operations and Services (网络预约出租汽车经营服务管理暂行办法)
China instituted a licensing system for online taxi companies, which requires that personal information and business data should be stored and used in mainland China and must not be transferred outside of China (Art. 27 of the Interim Measures for the Administration of Online Taxi Booking Business Operations and Services). Such information should be retained for two years, except when otherwise required by other laws and regulations. The Measurement also states that taxi companies' servers should be set up in Mainland China, with a network security management system and technical measures for security protection in compliance with regulations (Art. 5.2).
Coverage Online taxi sector

CHINA

Since September 2000, last amended in February 2016

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Telecommunications Regulations of the People’s Republic of China (中华人民共和国电信条例)
It is reported that China's Telecommunications Regulations require all data collected within the country to be stored on Chinese servers. However, the relevant article has not been found in the regulations. Moreover, it is reported that, as a result of this regulation, Hewlett-Packard, Qualcomm, and Uber had to divest more than 50% of their businesses in China to Chinese companies to avoid fines.
Coverage Telecommunication services and cloud services

CHINA

Since November 2016, entry into force in June 2017
Since July 2022, entry into force in September 2022

Pillar Cross-border data policies  |  Indicator Ban to transfer and local processing requirement
Cybersecurity Law (网络安全法)

Outbound Data Transfer Security Assessment Measures (数据出境安全评估办法)
Art. 37 of the Cybersecurity Law requires "key information infrastructure" operators to store personal information and critical data within China. Personal information and critical data can be stored outside of China where there is a genuine need for business; in such cases a "security assessment" needs to be conducted in accordance with procedures formulated by the Cyberspace Administration of China (CAC) in collabouration with other authorities.
Art. 4 of the Outbound Data Transfer Security Assessment Measures, promulgated by the CAC, outlines four situations where a security assessment is necessary before an outbound transfer can take place, which include:
1) Cases where the transfer concerns “important data”, which is broadly defined as data that could endanger national security, economic operation, social stability, public health and safety;
2) Cases the transfer concerns personal data by a critical information infrastructure operator or processor of personal information that processed data for 1 million or more individuals;
3) Cases of transfers concerning personal data by a personal information processor that has made outbound transfers of personal information of 100,000 individuals or sensitive personal information of 10,000 persons in the preceding year;
4) Any other situation where the CAC deems a security assessment necessary.
Art. 8 of the Measures covers the factors the CAC considers when undertaking a security assessment, including:
- The risks that the transfer may entail for national security or public interests, among other policy objectives;
- Legitimacy, necessity and method of transfer;
- Whether the level of data protection in the recipient country meets the requirements of laws in China;
- Sensitivity of the data and risks of being tampered with abroad;
- Agreed safeguard measures between the data processor and data recipient;
- Any other matter that the CAC deems necessary.
In case of unfavourable outcomes, the data handler can ask the CAC for a re-assessment and a final decision. In case of a positive decision, the permission to transfer data abroad is valid for two years, but if substantial changes in the risk factors arise, a new assessment might be needed.
Coverage Key information infrastructure operators

Report issue     Report new measure