CHINA
Since May 2024, entry into force in October 2024
Pillar Cross-border data policies |
Indicator Infrastructure requirement
Interim Measures for Data Security Management of Accounting Firms (财政部 国家网信办关于印发《会计师事务所数据安全管理暂行办法》的通知)
Art. 13 of the "Interim Measures for Data Security Management of Accounting Firms" mandates that audit working papers produced by accounting firms must be stored within the territory of the People's Republic of China, in accordance with relevant regulations. Encryption devices are required to be installed domestically, managed and maintained by local teams, with encryption keys likewise retained within national borders. Pursuant to Art. 19, any transfer of audit working papers abroad must receive prior approval, and accounting firms are obliged to establish a tiered review mechanism governing such exports, alongside implementing comprehensive responsibilities for data security management and control. In addition, in accordance with Art. 14, accounting firms must establish a data backup system to ensure the continued access, retrieval, and use of relevant audit working papers in the event of disruption or restriction to audit-related application systems due to external technical factors.
Coverage Accounting firms
Sources
- https://web.archive.org/web/20250426014906/https://www.cac.gov.cn/2024-05/10/c_1717011564369521.htm
- https://web.archive.org/web/20250426015020/https://digitalpolicyalert.org/event/19863-implemented-interim-measures-for-data-security-management-of-accounting-firms-including-data-localisation-measures
- https://web.archive.org/web/20250426015507/https://www.dandreapartners.com/china-introduces-new-data-compliance-rules-for-accounting-firms/
- Show more...
CHINA
Since October 2020
Pillar Cross-border data policies |
Indicator Conditional flow regime
Amendment to the Information Security Technology – Personal Information Security Specification (GB/T 35273-2020) (信息安全技术-个人信息安全规范》(GB/T 35273-2020)修正案)
Section 9.2.i of the "Amendment to the Information Security Technology – Personal Information Security Specification" provides that where personal biometric information must not be shared or transferred unless actually essential for business needs, in which case the personal information subject must be separately informed of the purpose, types of biometrics involved, identification of the recipient and its data security capacity and the personal information subject consent must be explicitly obtained.
Coverage Horizontal
Sources
- https://web.archive.org/web/20231227001129/https://digichina.stanford.edu/work/information-security-technology-guidelines-for-personal-information-protection-on-public-and-commercial-service-informati...
- https://web.archive.org/web/20240712200613/https://www.dlapiperdataprotection.com/system/modules/za.co.heliosdesign.dla.lotw.data_protection/functions/handbook.pdf?country-1=CN
- https://web.archive.org/web/20231128172929/http://papers.ssrn.com/sol3/papers.cfm?abstract_id=2280037
- https://web.archive.org/web/20200727022639/http://law.emory.edu/elj/content/volume-64/issue-3/articles/data-nationalism.html
- https://web.archive.org/web/20211025231401/http://www.insideprivacy.com/international/china/china-releases-national-standard-for-personal-information-collected-over-information-systems-industr/
- Show more...
CHINA
Since March 2007, entry into force in June 2007
Pillar Intellectual Property Rights (IPRs) |
Indicator Adoption of the WIPO Performances and Phonograms Treaty
WIPO Performances and Phonograms Treaty
China has adopted the World Intellectual Property Organization (WIPO) Performances and Phonograms Treaty.
Coverage Horizontal
CHINA
Since July 2016, entry into force November 2016, last amended in November 2022
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Interim Measures for the Administration of Online Taxi Booking Business Operations and Services (网络预约出租汽车经营服务管理暂行办法)
China instituted a licensing system for online taxi companies, which requires that personal information and business data should be stored and used in mainland China and must not be transferred outside of China (Art. 27 of the Interim Measures for the Administration of Online Taxi Booking Business Operations and Services). Such information should be retained for two years, except when otherwise required by other laws and regulations. The Measurement also states that taxi companies' servers should be set up in Mainland China, with a network security management system and technical measures for security protection in compliance with regulations (Art. 5.2).
Coverage Online taxi sector
Sources
- https://web.archive.org/web/20221206231444/https://www.ft.com/content/d08338b6-6fde-11e5-ad6d-f4ed76f0900a
- https://web.archive.org/web/20200103063359/https://www.cnbc.com/2016/07/28/uber-didi-hail-chinas-new-taxi-app-rules.html
- https://web.archive.org/web/20220120180804/https://thelawreviews.co.uk/title/the-privacy-data-protection-and-cybersecurity-law-review/china
- https://web.archive.org/web/20220211121149/http://www.gov.cn/xinwen/2016-07/28/content_5095584.htm
- Show more...
CHINA
Since July 2015
Pillar Intellectual Property Rights (IPRs) |
Indicator Mandatory disclosure of business trade secrets such as algorithms or source code
National Security Law of the People's Republic of China (中华人民国国家安全法)
According to Art. 25 of the Chinese government’s 2015 National Security Law, all information systems in China must be "secure and controllable". As a result of this policy, it is reported that every company operating in China – whether domestic or foreign – is required to provide the Chinese government with access to its source code, encryption keys, and backdoor access to their computer networks in China.
Coverage Horizontal
Sources
- https://web.archive.org/web/20240225175901/https://intpolicydigest.org/the-global-implications-of-china-s-national-and-cyber-security-laws/
- https://web.archive.org/web/20230202090346/http://www.xinhuanet.com//politics/2015-07/01/c_1115787097.htm
- https://web.archive.org/web/20220330120525/http://www.gov.cn/zhengce/2015-07/01/content_2893902.htm
- Show more...
CHINA
Since November 2016, entry into force in June 2017, last amended in October 2025
Since March 2024
Since March 2024
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法)
Provisions on Promoting and Regulating the Cross-Border Flow of Data (促进和规范数据跨境流动规定)
Provisions on Promoting and Regulating the Cross-Border Flow of Data (促进和规范数据跨境流动规定)
Art. 39 of the Cybersecurity Law requires that personal information and important data collected or generated by operators of critical information infrastructure within mainland China be stored domestically, and allows their transfer abroad only when genuinely necessary for business purposes and subject to a security assessment conducted in accordance with measures issued jointly by the national cybersecurity and informatization authority and relevant State Council departments, unless other laws provide otherwise. Art. 33 defines critical information infrastructure to include sectors such as public communications and information services, energy, transport, water, finance, public services, and e‑government, as well as any infrastructure whose damage, loss of function, or data leakage could seriously endanger national security, public welfare, or the public interest. Art. 7 of the Provisions on Promoting and Regulating the Cross-Border Flow of Data requires data handlers to apply for a data export security assessment when critical information infrastructure operators export personal information or important data, but Art. 5 exempts certain transfers of personal information, though not important data, where the transfer is genuinely necessary for the performance of a contract, for lawful cross-border human resources management, or for emergency protection of life, health, or property. Art. 10 obliges data handlers exporting personal information to provide notice, obtain separate consent, and conduct a personal information protection impact assessment, and Art. 11 further requires them to fulfil data security obligations and adopt technical and other necessary measures to ensure the security of exported data.
Coverage Critical information infrastructure operators
CHINA
Since September 1993, entry into force in December 1993, last amended in 2025
Since November 1995, last amended in December 1998
Since November 1995, last amended in December 1998
Pillar Intellectual Property Rights (IPRs) |
Indicator Effective protection covering trade secrets
Law Against Unfair Competition of the People's Republic of China (中华人民共和国反不正当竞争法)
Provisions on Prohibiting Infringement of Trade Secrets (關於禁止侵犯商業秘密行為的若干規定)
Provisions on Prohibiting Infringement of Trade Secrets (關於禁止侵犯商業秘密行為的若干規定)
The Law Against Unfair Competition of the People’s Republic of China and the Provisions on Prohibiting Infringement of Trade Secrets constitute an effective legal framework for the protection of trade secrets. In addition to these two primary instruments, the broader system governing undisclosed information and trade secrets is further supported by the Administrative Licensing Law, the Criminal Law, the Labour Law and other relevant legislation.
Despite the existence of this framework, reports indicate that significant enforcement challenges persist. These challenges include stringent evidentiary requirements, limited opportunities for discovery and difficulties in meeting the demanding conditions necessary to enforce agreements intended to safeguard trade secrets and confidential business information from misappropriation. Stakeholders also observe that securing damages awards at levels sufficient to deter infringement remains difficult. Furthermore, there are continuing concerns about the risk of unauthorised disclosure of trade secrets and confidential information by government officials and third‑party experts. This issue is considered particularly acute in sectors such as software.
Despite the existence of this framework, reports indicate that significant enforcement challenges persist. These challenges include stringent evidentiary requirements, limited opportunities for discovery and difficulties in meeting the demanding conditions necessary to enforce agreements intended to safeguard trade secrets and confidential business information from misappropriation. Stakeholders also observe that securing damages awards at levels sufficient to deter infringement remains difficult. Furthermore, there are continuing concerns about the risk of unauthorised disclosure of trade secrets and confidential information by government officials and third‑party experts. This issue is considered particularly acute in sectors such as software.
Coverage Horizontal
Sources
- https://web.archive.org/web/20260306152852/https://www.spp.gov.cn/spp/fl/202506/t20250627_699862.shtml
- https://web.archive.org/web/20260317194733/https://www.beijing.gov.cn/gate/big5/www.beijing.gov.cn/zhengce/zhengcefagui/qtwj/201904/t20190426_776416.html
- https://web.archive.org/web/20260317190016/https://docs.wto.org/dol2fe/Pages/SS/directdoc.aspx?filename=q:/WT/TPR/S458R1.pdf&Open=True
- https://web.archive.org/web/20260317192653/https://ustr.gov/sites/default/files/files/Issue_Areas/Enforcement/2025%20Special%20301%20Report%20(final).pdf
- Show more...
CHINA
Since April 2018
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Measures for the Management of Scientific Data (科学数据管理办法)
According to Art. 13 of the "Measures for the Management of Scientific Data," any scientific data generated within the framework of a project supported by Chinese public funds must be collected by the entity responsible for the research project and subsequently submitted to the relevant designated scientific data centre, as specified by the Ministry of Science and Technology, for archiving and processing. Art. 14 stipulates that when scientific data produced within the framework of a project funded by Chinese public funds is to be disseminated outside China for the purpose of producing an academic paper to be published in a foreign journal, the data must first be submitted to the Chinese research institute where the author is employed. The institute’s management must approve the data before the paper can be published. The Measures also impose general obligations applicable to all scientific data, irrespective of whether they are funded by the Chinese government. Specifically, Art. 26 states that if it is necessary to provide a foreign party with scientific data related to state secrets in the context of international collaboration, the transfer of such data is subject to approval by the relevant authorities and the signing of confidentiality agreements between the parties involved in the research.
Coverage Horizontal
Sources
- https://web.archive.org/web/20250508215353/https://cset.georgetown.edu/publication/china-scientific-data-management-measures/
- https://web.archive.org/web/20250508215458/https://www.gov.cn/zhengce/content/2018-04/02/content_5279272.htm
- https://web.archive.org/web/20250508221555/https://www.cyberpolicyobservatory.org/digital-sovereignty-the-chinese-regulations-on-scientific-data-management/
- Show more...
CHINA
Reported in 2017, last reported in 2025
Pillar Telecom infrastructure & competition |
Indicator Passive infrastructure sharing obligation
Requirement of passive infrastructure sharing
It is reported that there is an obligation for passive infrastructure sharing in China to deliver telecom services to end users. Moreover, passive infrastructure sharing is practised in both the mobile and fixed sectors based on commercial agreements.
Coverage Telecommunications sector
CHINA
Since December 1998, as amended in December 2019
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Securities Law of the People's Republic of China (中华人民共和国证券法
Under Art. 177 of the Securities Law, the export of information pertaining to securities operations to overseas entities is contingent upon obtaining approval from the China Securities Regulatory Commission and other relevant authorities of the State Council.
Coverage Securities operations
CHINA
Since December 2001, entry into force in January 2002, last amended in March 2022
Since 2000, last amended in 2015
Since 2000, last amended in 2015
Pillar Telecom infrastructure & competition |
Indicator Maximum foreign equity share for investment in the telecommunication sector
Administrative Provisions on Foreign-funded Telecommunications Enterprises (外商投资电信企业管理规定)
Classification Catalogue of Telecommunications Services (电信业务分类目录)
Classification Catalogue of Telecommunications Services (电信业务分类目录)
Art. 6 of the "Administrative Provisions on Foreign‑funded Telecommunications Enterprises" stipulates that, unless otherwise prescribed by the State, the aggregate equity held by foreign investor(s) in a foreign‑funded telecommunications enterprise engaged in basic telecommunications services, excluding radio paging services, may not ultimately exceed 49%, and the "Classification Catalogue of Telecommunications Services" identifies all categories of basic telecommunications services that fall within the scope of this restriction.
Coverage Basic telecommunications services
Sources
CHINA
Last reported in 2024
Pillar Telecom infrastructure & competition |
Indicator Presence of shares owned by the government in telecom companies
Presence of shares owned by the government in the telecom sector
It is reported that the government holds equity stakes in several telecommunications enterprises. In particular, state ownership represents 75.15% of shares in China Telecom, 70.42% in China Mobile, 51.7% in China Unicom, and 100% in China Broadnet.
Coverage Telecommunications sector
CHINA
N/A
Pillar Telecom infrastructure & competition |
Indicator Functional/accounting separation for operators with significant market power
Lack of mandatory functional and accounting separation for dominant network operators
It is reported that China does not mandate functional or accounting separation for operators with significant market power (SMP) in the telecom market.
Coverage Telecommunications sector
CHINA
Since September 2000, last amended in February 2016
Since September 2017
Since September 2017
Pillar Telecom infrastructure & competition |
Indicator Licensing restrictions to operate in the telecom market
Telecommunications Regulations of the People’s Republic of China (中华人民共和国电信条例)
Administrative Measures on Telecommunications Business Permits (电信业务经营许可管理办法)
Administrative Measures on Telecommunications Business Permits (电信业务经营许可管理办法)
Pursuant to Art. 7 of the Telecommunications Regulations, the State is required to implement a licensing regime for telecommunications enterprises in accordance with the categorisation of telecommunications services, which, as set out in the Appendix to the Regulations, includes basic telecommunications services. Art. 5.6 of the Administrative Measures on Telecommunications Business Permits further provides that the minimum registered capital for an operator conducting business within a single province, autonomous region, or centrally administered municipality is RMB 100 million (approx. USD 14.5 million), whereas operators providing services nationwide or across multiple such jurisdictions must have a minimum registered capital of RMB 1 billion (approx. USD 145 million). Under Art. 8 of the Telecommunications Regulations, basic telecommunications services are defined as the provision of public network infrastructure, public data transmission services, and basic voice communication services. It is reported that China’s restrictions on basic telecommunications services, including for example the imposition of very high capital requirements, have hindered foreign suppliers from entering the country’s basic telecommunications market.
Coverage Basic telecommunications services
Sources
- https://web.archive.org/web/20260324220926/https://www.beijing.gov.cn/zhengce/zhengcefagui/qtwj/202306/t20230609_3128623.html
- https://web.archive.org/web/20260325184217/https://www.moj.gov.cn/pub/sfbgw/flfggz/flfggzbmgz/201708/t20170803_146030.html
- https://web.archive.org/web/20260312191557/https://ustr.gov/sites/default/files/files/Press/Reports/2025NTE.pdf
- https://web.archive.org/web/20260325184713/https://datahub.itu.int/data/?i=100051&s=19296&e=CHN
- Show more...
CHINA
Since February 1996, last amended in 2024
Pillar Telecom infrastructure & competition |
Indicator Licensing restrictions to operate in the telecom market
Provisional Regulation of the People’s Republic of China for the Administration of International Networking of Computer Information Networks (中华人民共和国计算机信息网络国际联网管理暂行规定)
Arts. 8 and 9 of the "Provisional Regulation of the People’s Republic of China for the Administration of International Networking of Computer Information Networks" require access entities to obtain a licence prior to engaging in either operational or non-operational activities involving international networking, which, under Art. 3, is defined as the connection of domestic computer information networks with foreign networks for the purpose of international information exchange. Art. 6 additionally mandates that any computer information network directly engaging in international networking must rely solely on the international inbound and outbound channels provided by the national public telecommunications network; no entity or individual is permitted to establish independent channels or to utilise any alternative channels for international connectivity.
Coverage International networking
