CHINA
Since October 2000
Pillar Domestic data policies |
Indicator Minimum period for data retention
Provisions for the Administration of Internet Electronic Bulletin (互联网电子公告服务管理规定)
Art. 14 of the "Provisions for the Administration of Internet Electronic Bulletin" requires electronic bulletin service providers to record all information posted on their systems, including the content, the time of publication, and the relevant Internet Protocol address or domain name, and to retain backups of these records for 60 days for provision to the competent state authorities upon lawful request. Art. 2 clarifies that, for the purposes of these Provisions, "electronic bulletin services" denotes facilities enabling Internet users to publish information online through interactive formats such as electronic noticeboards, electronic whiteboards, electronic forums, online chat rooms, and message boards.
Coverage Electronic bulletin services
Sources
- https://web.archive.org/web/20260323214640/http://www.moe.gov.cn/s78/A13/s8353/moe_774/tnull_1058.html
- https://web.archive.org/web/20230110061559/https://www.coe.int/t/dg1/legalcooperation/economiccrime/cybercrime/Documents/CountryProfiles/567%20china-d-Comparative%20Research_ed1a.PDF
- https://web.archive.org/web/20241009080813/http://www.china.org.cn/business/2010-01/20/content_19274960_2.htm
- Show more...
CHINA
Since August 2021, entry into force in November 2021
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法)
Art. 52 of the Personal Information Protection Law requires the appointment of a data protection officer when the personal information handler meets specified conditions. In addition, under Arts. 55 and 56, a personal information protection impact assessment is required in certain circumstances.
Coverage Horizontal
CHINA
Since June 2021, entry into force in September 2021
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Data Security Law of the People's Republic of China (中华人民共和国数据安全法)
Art. 27 of the Data Security Law mandates the designation of personnel responsible for overseeing data security. This obligation applies solely to processors of important data; however, the statute itself does not provide a definition of that category.
Coverage Processors of important data
CHINA
Since October 2020
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Amendment to the Information Security Technology – Personal Information Security Specification (GB/T 35273-2020) (信息安全技术-个人信息安全规范) (GB/T 35273-2020) 修正案)
The 2020 Personal Information Security Specification provides that personal information controllers shall appoint a person and a department responsible for personal information (PI) protection. The person responsible for PI protection must have relevant management experience and personal information protection expertise, participate in important decisions on personal information processing activities, and report directly to the principal of the organization.
Coverage Horizontal
Sources
- https://web.archive.org/web/20230221153710/https://www.tc260.org.cn/upload/2020-09-18/1600432872689070371.pdf
- https://web.archive.org/web/20211124183425/https://www.manafoundation.org/uploads/soft/200601/%E4%BF%A1%E6%81%AF%E5%AE%89%E5%85%A8%E6%8A%80%E6%9C%AF%E4%B8%AA%E4%BA%BA%E4%BF%A1%E6%81%AF%E5%AE%89%E5%85%...
CHINA
Since November 2016, entry into force in June 2017
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法)
Art. 21 of the Cybersecurity Law requires network operators to appoint persons in charge of cybersecurity. Critical information infrastructure operators (CIIO) are also required to set up specialised security management bodies and persons responsible for security management. Further, CIIO's must conduct security background checks on those responsible persons and personnel in critical positions (Art. 34).
Coverage Horizontal
CHINA
Since June 2021, entry into force in September 2021
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Data Security Law of the People’s Republic of China (中华人民共和国数据安全法)
Art. 35 of the Data Security Law stipulates that where public security or national security authorities need to consult any data in order to safeguard national security or investigate a crime, the relevant organizations and individuals must provide such data. The same article stipulates that before getting access to the data held by private organizations, public security or national security authorities must go through strict approval formalities in advance.
Coverage Horizontal
CHINA
Since December 2015, entry into force in January 2016, last amended in April 2018
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Counterterrorism Law of the People's Republic of China (中华人民共和国反恐怖主义法)
Art. 18 of the Counterterrorism Law requires Internet service providers and the telecommunication sector to “provide technical support and assistance, such as technical interface and decryption, to support the activities of the public security and state security authorities in preventing and investigating terrorist activities.”
Coverage Internet service providers and telecommunication sector
Sources
- https://web.archive.org/web/20230324194915/http://www.hoover.org/sites/default/files/research/docs/segal_webreadypdf_updatedfinal.pdf
- https://web.archive.org/web/20231129113030/http://www.xinhuanet.com//politics/2015-12/27/c_128571798.htm
- https://web.archive.org/web/20221210010510/http://www.npc.gov.cn/zgrdw/npc/xinwen/2018-06/12/content_2055871.htm
- Show more...
CHINA
Since September 2000, last amended in 2024
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Measures for the Administration of Internet Information Services (互联网信息服务管理办法)
According to Art. 14 of the Measures for the Administration of Internet Information Services, ISPs must provide user information to the authorities upon request, without judicial oversight.
Coverage Internet service providers
Sources
CHINA
N/A
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Lack of intermediary liability framework in place for copyright infringements
A basic legal framework on intermediary liability for copyright infringement is absent in China's law and jurisprudence. A safe harbour defence for internet intermediaries providing hosting services is spelt out in the Guiding Framework on Protection of Copyright for Network Dissemination (Art. 14-17, 22). The hosting defence established in Art. 22, only applies to service providers who host third-party materials. However, Art. 36 of the Tort Law of the People's Republic of China states that a "network service provider" shall assume the tort liability if it infringes "upon the civil right or interest of another person."
Furthermore, the Tort Law allows victims of the tort to notify the network service provider to demand the deletion, blocking or disconnection of the cause of infringement. Failing to do so can lead to further liability for the network provider in the event of further harm to the user. Finally, liability can be further increased in the event that the network service provider knew of the infringement but did not take action.
Furthermore, the Tort Law allows victims of the tort to notify the network service provider to demand the deletion, blocking or disconnection of the cause of infringement. Failing to do so can lead to further liability for the network provider in the event of further harm to the user. Finally, liability can be further increased in the event that the network service provider knew of the infringement but did not take action.
Coverage Internet intermediaries
Sources
- https://web.archive.org/web/20240129171425/http://www.article19.org/data/files/Intermediaries_ENGLISH.pdf
- https://web.archive.org/web/20200222120116/http://www.jetlaw.org/2016/01/18/executives-of-a-chinese-online-video-sharing-service-provider-stood-trial-for-internet-pornography/
- https://web.archive.org/web/20220120082414/http://www.wipo.int/export/sites/www/copyright/en/doc/liability_of_internet_intermediaries.pdf
- https://web.archive.org/web/20180425225959/http://www.wipo.int/wipolex/en/text.jsp?file_id=182630
- https://web.archive.org/web/20170402022917/http://www.wipo.int/wipolex/en/details.jsp?id=13403
- https://web.archive.org/web/20231210140045/http://www.hrw.org/news/2013/01/04/china-renewed-restrictions-send-online-chill
- https://web.archive.org/web/20240226143908/http://www.gov.cn/zwgk/2006-05/29/content_294000.htm
- https://web.archive.org/web/20220112052017/http://www.gov.cn/flfg/2009-12/26/content_1497435.htm
- https://web.archive.org/web/20200714182556/http://www.npc.gov.cn/wxzl/wxzl/2000-12/17/content_4680.htm
- Show more...
CHINA
N/A
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place for copyright infringements
A basic legal framework on intermediary liability beyond copyright infringement is absent in China's law and jurisprudence. A safe harbour defence for internet intermediaries providing hosting services is spelt out in the Guiding Framework on Protection of Copyright for Network Dissemination (Art. 14-17, 22). The hosting defence established in Art. 22, only applies to service providers who host third-party materials. However, Art. 36 of the Tort Law of the People's Republic of China states that a "network service provider" shall assume the tort liability if it infringes "upon the civil right or interest of another person."
Furthermore, the Tort Law allows victims of the tort to notify the network service provider to demand the deletion, blocking or disconnection of the cause of infringement. Failing to do so can lead to further liability for the network provider in the event of further harm to the user. Finally, liability can be further increased in the event that the network service provider knew of the infringement but did not take action.
Furthermore, the Tort Law allows victims of the tort to notify the network service provider to demand the deletion, blocking or disconnection of the cause of infringement. Failing to do so can lead to further liability for the network provider in the event of further harm to the user. Finally, liability can be further increased in the event that the network service provider knew of the infringement but did not take action.
Coverage Internet intermediaries
Sources
- https://web.archive.org/web/20240129171425/http://www.article19.org/data/files/Intermediaries_ENGLISH.pdf
- https://web.archive.org/web/20200222120116/http://www.jetlaw.org/2016/01/18/executives-of-a-chinese-online-video-sharing-service-provider-stood-trial-for-internet-pornography/
- https://web.archive.org/web/20220120082414/http://www.wipo.int/export/sites/www/copyright/en/doc/liability_of_internet_intermediaries.pdf
- https://web.archive.org/web/20180425225959/http://www.wipo.int/wipolex/en/text.jsp?file_id=182630
- https://web.archive.org/web/20170402022917/http://www.wipo.int/wipolex/en/details.jsp?id=13403
- https://web.archive.org/web/20231210140045/http://www.hrw.org/news/2013/01/04/china-renewed-restrictions-send-online-chill
- https://web.archive.org/web/20240226143908/http://www.gov.cn/zwgk/2006-05/29/content_294000.htm
- https://web.archive.org/web/20220112052017/http://www.gov.cn/flfg/2009-12/26/content_1497435.htm
- https://web.archive.org/web/20200714182556/http://www.npc.gov.cn/wxzl/wxzl/2000-12/17/content_4680.htm
- Show more...
CHINA
Since June 2022, entry into force in August 2022
Pillar Intermediary liability |
Indicator User identity requirement
Provisions on the Management of Mobile Internet Applications' Information Services (移动互联网应用程序信息服务管理规定)
Art. 6 of the "Provisions on the Management of Mobile Internet Applications’ Information Services" stipulates that application providers offering services such as information dissemination or instant messaging must verify the real identity information of individuals seeking to register. Such verification shall be conducted using credentials including mobile telephone numbers, identification numbers, or a unified social credit code. Where users fail to provide authentic identity information, or unlawfully appropriate the identity details of organisations or other individuals to falsify registration, the relevant services must not be made available to them.
Coverage Application providers
Sources
- https://web.archive.org/web/20260324190250/https://www.chinalawtranslate.com/en/mobile-app-information-services/
- https://web.archive.org/web/20260108110224/https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm
- https://web.archive.org/web/20260324191714/https://www.sohu.com/a/562231688_120942243
- Show more...
CHINA
Since December 2015, entry into force in January 2016, last amended in April 2018
Pillar Intermediary liability |
Indicator User identity requirement
Counterterrorism Law of the People's Republic of China (中华人民共和国反恐怖主义法)
Pursuant to Art. 21 of the Counter-Terrorism Law, providers of telecommunications, internet, and financial services are obligated to verify the identities of their customers or clients and to withhold services from those who refuse to supply such information.
Coverage Telecommunications, internet, and financial services providers
Sources
- https://web.archive.org/web/20220330120526/http://www.npc.gov.cn/zgrdw/npc/xinwen/2018-06/12/content_2055871.htm
- https://web.archive.org/web/20231004000427/https://www.chinalawtranslate.com/en/counter-terrorism-law-2015/
- https://web.archive.org/web/20240114092836/https://www.cov.com/-/media/files/corporate/publications/2016/01/china_enacts_broad_counter_terrorism_law.pdf
- Show more...
CHINA
Since November 2016, entry into force in June 2017, last amended in 2025
Pillar Domestic data policies |
Indicator Minimum period for data retention
Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法)
Art. 23.3 of the Cybersecurity Law stipulates that network operators must retain network logs for a minimum period of six months in accordance with the relevant regulatory provisions. Pursuant to Art. 78, the term network operators encompasses network owners, managers, and providers of network services.
Coverage Network operators
CHINA
Since November 2022
Pillar Intermediary liability |
Indicator User identity requirement
Provisions on the Management of Internet Post Comments Services (互联网跟帖评论服务管理规定)
Art. 4 of the Provisions on the Management of Internet Post Comments Services outlines the requirements for "post comment service providers" to verify the real identity information of registered users, adhering to the principle of "using a real name in the back end, while allowing either an alias or a real name at the front end." For individual users, identity verification may be conducted using mobile phone numbers and identification numbers. For corporate users, identity verification may be conducted through the use of uniform social credit codes. "Post comment services" refers to services provided by Internet websites, applications, and other website platforms of a public opinion nature or with the capacity to mobilize the public, for users to express text, code, emojis, pictures, audio, video, or other information through methods such as commenting, responding, leaving messages, realtime streaming comments, "liking", and so forth. Therefore, they include blogs, microblogs, instant messaging services, online discussion forums, news comment sections, among others.
The Provisions repealed a 2017 legislation of the same name, which already included a similar restriction in Art. 5.
The Provisions repealed a 2017 legislation of the same name, which already included a similar restriction in Art. 5.
Coverage "Post comment service providers"
Sources
- https://web.archive.org/web/20231205115456/https://www.cac.gov.cn/2022-11/16/c_1670253725725039.htm
- https://web.archive.org/web/20240423084210/https://www.chinalawtranslate.com/en/comments-section-2022/
- https://web.archive.org/web/20241202200439/https://www.lexology.com/library/detail.aspx?g=3432eb17-958b-4580-8098-be6a7b67cae6
- https://web.archive.org/web/20231024080345/https://www.chinalawtranslate.com/en/provisions-on-the-management-of-internet-post-comments-services/
- Show more...
CHINA
Since August 2018, entry into force in January 2019
Pillar Domestic data policies |
Indicator Minimum period for data retention
E-Commerce Law of the People's Republic of China (中华人民共和国电子商务法)
Art. 31 of the E‑Commerce Law stipulates that operators of e‑commerce platforms must record and retain information relating to the goods and services offered on the platform, as well as transaction data, and must ensure that such information remains complete, confidential, and accessible. The retention period for records concerning goods, services, and transactions must not be less than three years from the date on which the relevant transaction is finalised.
Coverage Operators of e‑commerce platforms
