Data Security Law of the People's Republic of China
Data Security Law of the People's Republic of China (Data Security Law, adopted 10 June 2021) is in force in China. This page holds what the official text states: dates, the named requirements, who supervises it and where the text is published.
- Data Security Law of the People's Republic of China names classified and graded protection of data, duties for important data and requests from foreign authorities.
- Data Security Law of the People's Republic of China does not settle whether a single shipment, transfer or service meets the requirement; that follows from the facts of the case and from the supervising body.
- Supervised by Standing Committee of the National People's Congress and Cyberspace Administration of China. Published by National People's Congress.
- EU: GDPR — Regulation (EU) 2016/679. Article 48 of the GDPR also governs disclosure to an authority in another country.
- US: GLBA Safeguards Rule. Both texts require a named person responsible for the security programme.
Identity
| Name in Chinese | 数据安全法 |
|---|---|
| Identifier | Data Security Law, adopted 10 June 2021 |
| Adopted | 2021-06-10 |
| Applies from | 2021-09-01 |
| Status as published | The law applies since 1 September 2021 and covers data of every kind, not only personal data. |
| Supervision | Standing Committee of the National People's Congress, Cyberspace Administration of China |
| Areas named | Personal data, Cross-border data transfer |
| Read against the source | 2026-08-17 |
Requirements in the text
- Classified and graded protection of data — Reference: DSL Article 21. Data classified by importance, with a catalogue of important data.
- Duties for important data — Reference: DSL Article 27. A named person responsible, risk assessment and reporting for important data.
- Requests from foreign authorities — Reference: DSL Article 36. Approval required before data stored in China is given to a foreign authority.
Compared with the EU register
- GDPR — Regulation (EU) 2016/679: Article 48 of the GDPR also governs disclosure to an authority in another country.
Compared with the US register
- GLBA Safeguards Rule: Both texts require a named person responsible for the security programme.
Official sources
- 中华人民共和国数据安全法 — National People's Congress
The register states what the official texts say. It is not advice and it is not a verdict on any company.
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.