CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners
Fangda Partners 24/F, HKRI Centre Two HKRI Taikoo Hui 288 Shi Men Yi Road Shanghai 200041 China Tel: +8621 2208 1166 Fax: +8621 5298 5599 Email: email@fangdalaw.com Web: www.fangdalaw.com
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy China’s cybersecurity regulation strategy is anchored in a state-led model that treats cybersecurity as a foundational element of national security and eco - nomic governance. A key recent development is that the amendment to the Cybersecurity Law (CSL, in Chinese 网络安全法 ), was adopted on 28 October 2025 and the new law came into force on 1 January 2026. The revision reinforces legal liability and enhances co- ordination with the broader data and cybersecurity law framework. For details, see 1.2 Cybersecurity Laws . Building on this strategy, China’s legislative frame - work pursues three core, hierarchical purposes: • safeguarding cybersecurity to uphold cyberspace sovereignty, national security and public interest; • protecting the legitimate rights and interests of citizens, legal persons and other organisations; and • advancing informatisation and the digital economy. To achieve these objectives, China’s cybersecurity framework sets out multiple regulatory priorities. In practice, enhanced obligations are imposed on criti - cal information infrastructure (CII) (Note: although the name is CII, the substance is similar to critical infra - structure in other jurisdictions) and important data (which refers to data involving specific fields, groups, regions or meeting certain accuracy and scale require - ments that could directly jeopardise national security, economic operation, social stability, and public health
and safety if compromised, with specific scopes cata - logued by respective industry regulators), supported by China’s Multi-Level Protection Scheme (MLPS). The framework also emphasises prevention and resil - ience, which are guaranteed through requirements for monitoring, early warning and incident response. Within this regulatory approach, the Data Security Law (DSL, in Chinese 数据安全法 ), promulgated on 10 June 2021 and effective from 1 September 2021, treats data as a strategic and economic resource subject to risk-based regulation, while the Personal Informa - tion Protection Law (PIPL, in Chinese 个人信息保护法 ), promulgated on 20 August 2021 and effective from 1 November 2021, focuses on safeguarding individual rights in personal information processing. 1.2 Cybersecurity Laws China’s cybersecurity regime is structured around a combination of general legislation, sector-specialised laws and regulations, and national and industry stand - ards. The overarching structure at the top is known as “Three laws plus two regulations”, as summarised below: The “Three Laws” At the general level, the CSL applies to the construc - tion, operation, maintenance and use of a network, as well as the supervision and administration of cyberse - curity within the territory of China (note: Hong Kong Special Administrative Region, Macau Special Admin - istrative Region and Taiwan China are separate juris -
75 CHAMBERS.COM
Powered by FlippingBook