Cybersecurity 2026

CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners

In addition to the “three laws plus two regulations”, there are other cross-sector regulations and rules with “dense” or “spotty” cybersecurity requirements. For example, the MLPS requirements were updated in 2025 through the Notice on Further Strengthening Cybersecurity Tiered-Protection Work (Gongwang’an [2025] No 1001) on 8 March 2025, and the Notice on Further Specifying Matters Related to Cybersecu - rity Tiered-Protection Work (Gongwang’an [2025] No 1846) on 27 April 2025. The updated basic require - ments specify data inventory survey, MLPS filing, identification and handling of potential risks and vul - nerabilities and formulation of a protection workplan and corresponding filing. There are also sectoral rules applicable to specific industries. For example, the Administrative Measures on Data Security for Banking and Insurance Insti - tutions (effective from 27 December 2024) and the Administrative Measures on Data Security in the Busi - ness Scope of the People’s Bank of China (effective from 30 June 2025) provide the relevant requirements on cybersecurity specifically applicable in the financial services sector. To complement these laws and regulations, a series of national and industry standards, including those applicable in the financial services sector, have been promulgated. For example, Data Security Technology- Guidelines on Social Responsibility for Data Security and Personal Information Protection (GB/T 46071- 2025), Data Security Technology-Security Certifica - tion Requirements for Cross-Border Processing of Personal Information (GB/T 46068-2025), Financial Data Security-Data Lifecycle Security Specifica - tion (JR/T 0223-2021), Financial Data Security-Data Security Classification and Grading Guidelines (JR/T 0197-2020) and Technical Specifications for Personal Financial Information Protection (JR/T 0171-2020). Even though such national and industry standards are in general not mandatory, they are a good reference point to companies when implementing the require - ments under the various laws and regulations. 1.3 Cybersecurity Regulators In China, the enforcement of cybersecurity-related laws is jointly undertaken by multiple competent authorities with overlapping powers.

The Cyberspace Administration of China (CAC) is primarily the regulatory authority responsible for for - mulating cybersecurity and data protection rules, co- ordinating network data security and building aware - ness with the general public. CAC is also in charge of law enforcement, but it usually takes a “soft” approach to this, for example, informal inquiries, invitation for a private talk, onsite inspections and orders for rectifica - tion of breaches of the regulations. Occasionally, CAC may also launch an investigation and hand out penal - ties. The cybersecurity division of the Public Security Bureau (PSB) or “cyber police” is the law enforcement agency responsible for enforcing cybersecurity laws and regulations, conducting inspections and ensur - ing that businesses comply with local data protec - tion requirements. It has broad enforcement powers to inspect and monitor internet service providers and other businesses processing personal information. It also has the power to detain bad actors if any criminal activities are suspected. The Ministry of Industry and Information Technology (MIIT) supervises data security in the IT, industrial and telecommunications sectors. It enforces filing require - ments and classification standards, conducts inspec - tions and imposes penalties. The State Administration for Market Regulation over - sees data security in market activities and investigates unfair competition and consumer rights violations. These authorities co-ordinate to form a comprehen - sive supervision and incident response system, ensur - ing effective law enforcement. Moreover, the National Data Bureau (NDB), which is under the administration of National Development and Reform Commission, was officially established on 25 October 2023. The NDB is tasked with advancing the development of basic data institutions, co-ordinating the integration, sharing, development and application of data resources, as well as promoting the planning and construction of a Digital China, the digital econ - omy and a digital society. In specific industries, sectoral regulators are also responsible for data security management. For exam - ple, in the financial services sector, such regulators mainly include the National Financial Regulatory

77 CHAMBERS.COM

Powered by