CHINA Trends and Developments Contributed by: Zhang Yunyan, Yang Dong, Shang Zicheng and Ye Xin, Beijing Jincheng Tongda & Neal (Shanghai) Law Firm
ance requirements. Together, these regulations and technical standards translate high-level legal princi - ples into practical compliance obligations for AI ser - vice providers. Cybersecurity legal regime China’s cybersecurity regime is built upon the Cyber - security Law of the People’s Republic of China, which serves as the cornerstone of the country’s cyberse - curity regulatory framework. Following its first major amendment in October 2025 (effective from 1 January 2026), the Cybersecurity Law introduced dedicated provisions addressing AI security, supporting the development of AI technologies while strengthening ethical governance and risk management. In addition, the Regulations on the Security Protection of Critical Information Infrastructure further specify the cyber - security obligations applicable to operators of critical information infrastructure. Personal information protection regime The Personal Information Protection Law remains the core legislation governing personal information pro - tection in China. In 2025, a series of supporting regu - lations came into force, including the Measures for the Administration of Personal Information Protection Compliance Audits and the Measures for the Security Management of Facial Recognition Technology Appli - cations, further strengthening the regulatory frame - work for personal information protection and cross- border data transfers. The issuance of the Measures for Personal Information Export Certification, together with the implementation of negative lists in pilot free trade zones, has further refined the regulatory regime governing cross-border data transfers. Data security and cross - border data transfer China’s data security regime places particular empha - sis on data classification and graded protection. Oper - ators of critical information infrastructure are generally required to store within China any personal informa - tion and important data collected or generated dur - ing their operations, while cross-border transfers of such data are subject to security assessment where required by law. Supporting regulations, including the Measures for Security Assessment of Cross-border Data Transfer, further specify the applicable assess - ment procedures with the dual objective of safeguard -
ing data security and facilitating the lawful and orderly flow of data across borders. Overall, China has gradually developed a multi-lay - ered regulatory framework for the IT sector, with the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law forming its leg - islative foundation, complemented by sector-specific rules governing areas such as AI and cross-border data transfers. In recent years, China’s regulatory approach has evolved from establishing high-level legal principles towards more refined and opera - tional compliance requirements, seeking to strike an appropriate balance between technological innova - tion, national security and the public interest while providing greater regulatory certainty for businesses operating in the IT sector. Key regulatory trends in the IT sector With the rapid development of emerging technologies such as AI, big data and cloud computing, China’s IT regulatory regime has evolved beyond the estab - lishment of a basic legal framework towards more detailed and refined regulatory rules. While continu - ing to support technological innovation, regulators are placing increasing emphasis on data security, cybersecurity and platform governance, encouraging businesses to establish more sophisticated compli - ance programmes in response to evolving regulatory expectations. Deepening AI governance China’s approach to AI governance continues to evolve towards a more comprehensive regulatory model. Regulatory attention has gradually expanded beyond technical standards to encompass broader issues such as AI ethics and the societal implica - tions of AI deployment. From a technical perspective, regulators continue to develop standards relating to algorithm transparency and explainability in order to enhance the safety, reliability and accountability of AI systems. Continued development of the data factor market The development of China’s data factor market is gradually shifting from institutional exploration towards a more mature and standardised market framework. Current policy initiatives focus on estab -
37 CHAMBERS.COM
Powered by FlippingBook