Cybersecurity 2026

CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners

• store personal information and important data within the territory of China, and where it is strictly necessary to provide such data overseas due to business needs, complete a security assessment, as required; and • conduct an inspection and assessment of the security of their networks and potential risks at least once a year and report the assessment outcome and any rectification measures to the relevant departments responsible for the security protection of CII. 2.3 Incident Response and Notification Obligations CAC issued the Administrative Measures for the Reporting of National Cybersecurity Incidents (“Cyber - security Incident Reporting Measures”, in Chinese 国 家网络安全事件报告管理办法 ) that provide the harmonised rules and guidance for cybersecurity incident report - ing. The Cybersecurity Incident Reporting Measures came into force on 1 November 2025. Under the Measures, network operators operating in China shall report cybersecurity incidents that are classified as “Relatively Severe or above”. According to the appendix of the Cybersecurity Inci - dent Reporting Measures, the Cybersecurity Incident Classification Guidelines (“Classification Guidelines”, in Chinese 网络安全事件分级指南 ), cybersecurity incidents are categorised from low to high as: “General”, “Rel - atively Severe”, “Severe” and “Significantly Severe”. The Classification Guidelines specify different thresh - olds for key entities, including CIIOs, government agencies and other network operators, to assess the level of severity of their cybersecurity incidents. Typi - cally, if a CII experiences either a total outage lasting not less than ten minutes or a disruption of its primary functions lasting not less than 30 minutes, it will be constituted as “Relatively Severe”. From a practical perspective, most companies including CIIOs should focus on the core assessment criteria – ie, the vol - ume of impacted individuals. The bulk thresholds for the three levels of incident categories are relatively straightforward – ie, one million for Relatively Severe, 10 million for Severe and 100 million for Significantly Severe. China takes a broad-based approach (similar to GDPR) instead of a narrow-based one (for exam - ple, CCPA) when it comes to data breach notice-and-

report. The covered data compromised under a data breach that triggers notice-and-report is not limited to personally identifiable information but any personal information. Also, if a cybersecurity incident concerns the breach of national core data or important data under Chinese laws, regardless of volume, such inci - dent will reach “Relatively Severe or Above”. (Note: “national core data” refers to the most critical cat - egory of data under the data classification and grad - ing regime, characterised by relatively high coverage of specific fields, groups or regions, or meeting the thresholds of high accuracy, large scale and a cer - tain depth of information, the illegal use or sharing of which may directly jeopardise political security). Upon the detection of an incident, CIIOs must imme - diately report it to the CII protection department (ie, the sectoral regulator with oversight responsibilities on the CII. For example, in case of a telecom carrier, it will be MIIT) and PSB within one hour, and other network operators shall immediately report it to local CAC within four hours. The following information shall be included in a cyber - security incident report to be submitted to the CAC: • basic information – organisation name, responsible personnel, contact details; • incident description – basic information about the affected systems or facilities, time, location, type and level of the cybersecurity incident, as well as the impacts and harms already caused, the meas - ures taken, and their effectiveness; in the case of a ransomware attack, the report shall also include the ransom amount demanded, the payment method and the deadline; and • further assessment of cybersecurity incidents – how the incident has developed and the potential further impacts and harms, leads for tracing and investigation, root cause analysis, planned further response measures and requests for support, status of preservation of the incident scene, and so on. For further assessment, network operators may submit additional information in the form of supple - mentary reports within 72 hours following the initial report. In addition, network operators are required to submit a summary report on the cybersecurity incident handling within 30 days after the comple -

79 CHAMBERS.COM

Powered by