Cybersecurity 2026

CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners

resolution settlement institutions for dispute resolu - tion. Furthermore, for the purpose of safeguarding service continuity in the event of termination of out - sourcing arrangements, Article 14 of the IT Outsourc - ing Risk Management Measures requires banking and insurance institutions to put in place exit strategies and contingency arrangements. Under Article 28 and Article 46 of PBOC DSL, where data processing is entrusted to third parties, the trus - tee’s data security obligations must be clearly defined, enhanced due diligence is required before entrusting third parties to process important or core data, and the trustee should refrain from transferring any data restricted by PBOC from outsourcing to a third party. Overall, legal restrictions for ICT and other third-party providers are “spotty” and scattered around different regulations. It is worth noting that ICT service providers that ser - vice the government or state-owned enterprises (such as state-owned banks), will be subject to a Xinchuang (ie, trust and innovation) programme, which is essen - tially a localisation programme where only govern - ment-approved local ICT vendors can participate. The programme also calls for gradual phase-out and sometimes rip-and-replace of critical components in the IT system if they are sourced from outside of China or if the service provider is otherwise not on the Xin- chuang list. 3.3 Key Operational Resilience Obligations Under the CSL, financial institutions must comply with the MLPS and establish a sound operational resilience management system. Core obligations focus on establishing internal security management systems, designating cybersecurity-responsible per - sons, deploying technical measures to guard against cyber threats, implementing network monitoring and log retention for no less than six months, and car - rying out data classification, backup and encryption. For CIIOs, additional obligations involve establishing specific security management institutions, provid - ing cybersecurity training for employees, conducting security background checks on key personnel, set - ting up disaster recovery backups for critical systems and databases, developing cybersecurity incident

response plans with regular drills and performing annual risk assessments. The Measures for the Administration of the Report - ing of Cybersecurity Incidents in the Business Fields of the PBOC further refine these requirements, such as clarifying emergency disposal responsibilities and requiring professional data security personnel and annual training. For incident reporting, financial insti - tutions must submit: brief reports within one hour and detailed reports within 24 hours for Relatively Severe or above-level incidents; and progress reports every two hours for Severe or above-level incidents until disposal, with a post-incident summary within ten working days. Under the Measures for the Reporting, Investigation and Handling of Cybersecurity Incidents in the Securi - ties and Futures Industry, securities and futures insti - tutions are required to promptly report any network or information system failures that may constitute cyber - security incidents, irrespective of the incident classifi - cation level. Where an incident is assessed as poten - tially “Significantly Severe” or “Severe”, institutions must provide ongoing progress updates at intervals of no less than every 30 minutes until normal system operations are fully restored, whereas for Relatively Severe or general incidents, continuous reporting is not required after the initial report unless material developments arise. 3.4 Operational Resilience Enforcement In China, cybersecurity obligations applicable to criti - cal ICT services providers are enforced under the CSL, under which providers may be subject to regulatory rectification orders, warnings and monetary penalties when they fail to timely address security defects or vulnerabilities, discontinue required security mainte - nance, or inadequately respond to cybersecurity inci - dents. Where a provider refuses to rectify or causes consequences endangering cybersecurity, adminis - trative fines ranging from CNY50,000 to CNY500,000 may be imposed, together with personal fines of CNY10,000 to CNY100,000 on directly responsible personnel. Regarding enforcement targeting critical ICT ser - vice providers, in 2024, the WIND system, a leading

82 CHAMBERS.COM

Powered by