TLDR; Below is the English-translated version of China’s Network Data Security Management Regulations (网络数据安全管理条例, State Council Order No. 790), promulgated September 24, 2024 and in effect since January 1, 2025.
If your company handles data from users in mainland China — whether you run apps, platforms, APIs, or cloud services there — these Regulations are the cross-cutting rulebook that ties the country’s three core data statutes into a single operating standard. Issued by the State Council, they build on the Cybersecurity Law, the Data Security Law, and the PIPL, spelling out concrete duties for network data processors: security obligations, personal-information handling, important-data controls, cross-border transfer, and heightened requirements for large network platforms.
Network Data Security Management Regulations (Promulgated September 24, 2024 by Order No. 790 of the State Council; effective January 1, 2025)
Chapter I — General Provisions
Article 1. These Regulations are formulated in accordance with the “Cybersecurity Law of the People’s Republic of China,” the “Data Security Law of the People’s Republic of China,” the “Personal Information Protection Law of the People’s Republic of China,” and other laws, in order to regulate network data processing activities, safeguard network data security, promote the lawful, reasonable, and effective use of network data, protect the lawful rights and interests of individuals and organizations, and safeguard national security and the public interest.
Article 2. These Regulations apply to network data processing activities carried out within the territory of the People’s Republic of China and to the security supervision and administration thereof.
These Regulations also apply to activities, carried out outside the territory of the People’s Republic of China, of processing the personal information of natural persons within the territory of the People’s Republic of China, where the circumstances fall under the second paragraph of Article 3 of the “Personal Information Protection Law of the People’s Republic of China.”
Where network data processing activities carried out outside the territory of the People’s Republic of China harm the national security or public interest of the People’s Republic of China or the lawful rights and interests of its citizens or organizations, legal liability shall be pursued in accordance with law.
Article 3. Work on network data security management shall uphold the leadership of the Communist Party of China, implement the holistic view of national security, and coordinate the promotion of the development and use of network data with the safeguarding of network data security.
Article 4. The State encourages the innovative application of network data in all industries and fields, strengthens the building of network data security protection capabilities, supports innovation in network-data-related technologies, products, and services, carries out publicity and education on network data security and the cultivation of talent, and promotes the development and use of network data and the development of the industry.
Article 5. The State implements classified and graded protection of network data according to the degree of importance of the network data in economic and social development and the degree of harm to national security, the public interest, or the lawful rights and interests of individuals or organizations that would be caused if the data were tampered with, damaged, or leaked, or illegally obtained or illegally used.
Article 6. The State actively participates in the formulation of international rules and standards relating to network data security, and promotes international exchange and cooperation.
Article 7. The State supports relevant industry organizations in formulating codes of conduct for network data security in accordance with their charters, strengthening industry self-discipline, guiding their members to strengthen network data security protection, raising the level of network data security protection, and promoting the healthy development of the industry.
Chapter II — General Rules
Article 8. No individual or organization may use network data to engage in unlawful activities, and no individual or organization may engage in unlawful network data processing activities such as stealing or otherwise illegally obtaining network data, or illegally selling or illegally providing network data to others.
No individual or organization may provide programs or tools dedicated to engaging in the unlawful activities described in the preceding paragraph; and anyone who knows that another person is engaging in the unlawful activities described in the preceding paragraph may not provide that person with technical support such as internet access, server hosting, network storage, or communications transmission, or provide assistance such as advertising promotion or payment settlement.
Article 9. Network data processors shall, in accordance with the provisions of laws and administrative regulations and the mandatory requirements of national standards, and on the basis of the cybersecurity multi-level protection scheme, strengthen network data security protection, establish and improve network data security management systems, adopt technical measures such as encryption, backup, access control, and security authentication and other necessary measures to protect network data against tampering, damage, or leakage or illegal acquisition or illegal use, dispose of network data security incidents, guard against unlawful and criminal activities directed at or making use of network data, and bear principal responsibility for the security of the network data they process.
Article 10. The network products and services provided by network data processors shall comply with the mandatory requirements of the relevant national standards; upon discovering risks such as security defects or vulnerabilities in network products or services, they shall immediately take remedial measures, promptly inform users in accordance with the relevant provisions, and report to the competent authorities concerned; where national security or the public interest is endangered, the network data processor shall also report to the competent authorities concerned within 24 hours.
Article 11. Network data processors shall establish and improve emergency response plans for network data security incidents; when a network data security incident occurs, they shall immediately activate the emergency response plan, take measures to prevent the harm from expanding and to eliminate security hazards, and report to the competent authorities concerned in accordance with the relevant provisions.
Where a network data security incident causes harm to the lawful rights and interests of individuals or organizations, the network data processor shall promptly notify the interested parties of the security incident and the risk situation, the harmful consequences, the remedial measures already taken, and the like, by means such as telephone, text message, instant messaging tool, email, or public announcement; where laws or administrative regulations provide that notification may be dispensed with, those provisions shall apply. Where, in the course of handling a network data security incident, a network data processor discovers clues of suspected unlawful or criminal activity, it shall report the case to the public security organ and the state security organ in accordance with the relevant provisions, and cooperate in carrying out detection, investigation, and disposal work.
Article 12. Where a network data processor provides personal information and important data to another network data processor, or entrusts another network data processor with the processing of personal information and important data, it shall, by means of a contract or the like, agree with the network data recipient on the purpose, manner, and scope of the processing and the security protection obligations, and the like, and shall supervise the network data recipient’s performance of its obligations. Records of the processing of personal information and important data provided to, or entrusted for processing to, another network data processor shall be retained for at least 3 years.
The network data recipient shall perform network data security protection obligations and process the personal information and important data in accordance with the agreed purpose, manner, scope, and the like.
Where two or more network data processors jointly determine the purpose and manner of processing personal information and important data, they shall agree on their respective rights and obligations.
Article 13. Where a network data processor carries out network data processing activities that affect or may affect national security, it shall undergo a national security review in accordance with the relevant provisions of the State.
Article 14. Where a network data processor needs to transfer network data due to a merger, division, dissolution, bankruptcy, or other such reason, the network data recipient shall continue to perform network data security protection obligations.
Article 15. Where a state organ entrusts another party to build, operate, or maintain an e-government system, or to store or process government affairs data, it shall, in accordance with the relevant provisions of the State, go through strict approval procedures, clearly specify the entrusted party’s network data processing authority, protection responsibilities, and the like, and supervise the entrusted party’s performance of network data security protection obligations.
Article 16. Where a network data processor provides services to a state organ or a critical information infrastructure operator, or participates in the construction, operation, or maintenance of other public infrastructure or public service systems, it shall perform network data security protection obligations in accordance with the provisions of laws and regulations and the terms of the contract, and shall provide secure, stable, and continuous services.
A network data processor referred to in the preceding paragraph may not, without the consent of the entrusting party, access, obtain, retain, use, leak, or provide to others the network data, and may not conduct correlation analysis of the network data.
Article 17. Information systems that provide services to state organs shall strengthen network data security management by reference to the management requirements for e-government systems, so as to safeguard network data security.
Article 18. Where a network data processor uses automated tools to access or collect network data, it shall assess the impact on network services, and may not illegally intrude into the networks of others or interfere with the normal operation of network services.
Article 19. Network data processors that provide generative artificial intelligence services shall strengthen the security management of training data and training-data processing activities, and take effective measures to prevent and address network data security risks.
Article 20. Network data processors that provide products or services to the public shall accept public oversight, establish convenient channels for complaints and reports concerning network data security, publish information such as the methods for making complaints and reports, and promptly accept and handle complaints and reports concerning network data security.
Chapter III — Personal Information Protection
Article 21. Where a network data processor, before processing personal information, informs individuals in accordance with law by means of formulating personal information processing rules, the personal information processing rules shall be displayed publicly in a centralized manner, be easy to access, and be placed in a conspicuous position, and their content shall be clear, specific, and easy to understand, including but not limited to the following:
(1) the name of the network data processor and its contact information;
(2) the purpose, manner, and types of the processing of personal information, the necessity of processing sensitive personal information, and the impact on the rights and interests of individuals;
(3) the retention period of the personal information and the manner of processing it after that period expires; where the retention period is difficult to determine, the method for determining the retention period shall be clearly specified;
(4) the methods and channels by which individuals may consult, copy, transfer, correct, supplement, or delete their personal information, restrict its processing, cancel their accounts, and withdraw their consent, and the like.
Where a network data processor, in accordance with the preceding paragraph, informs individuals of the purpose, manner, and types of collecting personal information and of providing it to other network data processors, as well as of the information of the network data recipients, it shall set these out in a list or similar form. Where a network data processor processes the personal information of minors under the age of 14, it shall also formulate dedicated personal information processing rules.
Article 22. Where a network data processor processes personal information on the basis of individual consent, it shall comply with the following provisions:
(1) the collection of personal information shall be that necessary for providing the product or service; personal information may not be collected beyond that scope, and individual consent may not be obtained by means of misleading, fraud, coercion, or the like;
(2) where sensitive personal information such as biometric data, religious belief, specific identity, medical health, financial account, or whereabouts is processed, the separate consent of the individual shall be obtained;
(3) where the personal information of a minor under the age of 14 is processed, the consent of the minor’s parents or other guardians shall be obtained;
(4) personal information may not be processed beyond the purpose, manner, types, and retention period of the processing to which the individual has consented;
(5) consent may not be sought frequently after the individual has expressly indicated that they do not consent to the processing of their personal information;
(6) where the purpose, manner, or types of the processing of personal information change, the individual’s consent shall be obtained anew.
Where laws or administrative regulations provide that written consent shall be obtained for the processing of sensitive personal information, those provisions shall apply.
Article 23. Where an individual requests to consult, copy, correct, supplement, or delete their personal information or to restrict its processing, or an individual cancels their account or withdraws consent, the network data processor shall promptly accept the request, and shall provide convenient methods and channels to support the individual in exercising their rights; it may not set unreasonable conditions to restrict the reasonable requests of individuals.
Article 24. Where, due to the use of automated collection technology or the like, it is unavoidable that non-essential personal information or personal information for which individual consent has not been obtained in accordance with law is collected, as well as where an individual cancels their account, the network data processor shall delete the personal information or anonymize it. Where the retention period prescribed by laws or administrative regulations has not yet expired, or where the deletion or anonymization of personal information is technically difficult to achieve, the network data processor shall cease all processing other than storing the data and taking necessary security protection measures.
Article 25. For a request to transfer personal information that meets the following conditions, the network data processor shall provide a channel for another network data processor designated by the individual to access and obtain the relevant personal information:
(1) the true identity of the requester can be verified;
(2) the personal information requested to be transferred is personal information that the individual has consented to provide or that was collected on the basis of a contract;
(3) the transfer of the personal information is technically feasible;
(4) the transfer of the personal information does not harm the lawful rights and interests of others.
Where the frequency of requests to transfer personal information, and the like, clearly exceeds a reasonable range, the network data processor may charge necessary fees based on the cost of transferring the personal information.
Article 26. Where a network data processor outside the territory of the People’s Republic of China processes the personal information of natural persons within the territory, and, in accordance with Article 53 of the “Personal Information Protection Law of the People’s Republic of China,” establishes a dedicated institution or designates a representative within the territory, it shall submit the name of the relevant institution or the name and contact information of the representative, and the like, to the cyberspace administration department at the level of the districted city where it is located; the cyberspace administration department shall promptly notify the competent authorities concerned at the same level.
Article 27. Network data processors shall, on a regular basis and either on their own or by entrusting a professional institution, conduct a compliance audit of their compliance with laws and administrative regulations in the processing of personal information.
Article 28. Where a network data processor processes the personal information of more than 10 million people, it shall also comply with the provisions of Articles 30 and 32 of these Regulations applicable to network data processors that process important data (hereinafter referred to as “important data processors”).
Chapter IV — Important Data Security
Article 29. The national data security work coordination mechanism coordinates the relevant departments in formulating catalogs of important data and strengthening the protection of important data. Each region and each department shall, in accordance with the system of classified and graded data protection, determine the specific catalog of important data for their respective region and department and for the relevant industries and fields, and shall give priority protection to the network data included in the catalog.
Network data processors shall identify and declare important data in accordance with the relevant provisions of the State. For data confirmed as important data, the relevant region or department shall promptly inform the network data processor or make a public announcement. The network data processor shall perform its network data security protection responsibilities.
The State encourages network data processors to use technologies and products such as data labels and identifiers to improve the level of important data security management.
Article 30. Important data processors shall designate a person responsible for network data security and a network data security management body. The network data security management body shall perform the following network data security protection responsibilities:
(1) formulating and implementing network data security management systems, operating procedures, and emergency response plans for network data security incidents;
(2) periodically organizing and carrying out activities such as the monitoring of network data security risks, risk assessment, emergency drills, and publicity, education, and training, and promptly addressing network data security risks and incidents;
(3) accepting and handling complaints and reports concerning network data security.
The person responsible for network data security shall possess professional knowledge of network data security and relevant management work experience, shall be a member of the management of the network data processor, and shall have the right to report the network data security situation directly to the competent authorities concerned.
Network data processors that hold important data of the specific types and scale prescribed by the competent authorities concerned shall conduct security background checks on the person responsible for network data security and the personnel in key positions, and shall strengthen the training of the personnel concerned. When conducting such checks, they may apply to the public security organ and the state security organ for assistance.
Article 31. Before providing, entrusting the processing of, or jointly processing important data, an important data processor shall conduct a risk assessment, except where this is done in the performance of a statutory duty or statutory obligation.
The risk assessment shall focus on assessing the following:
(1) whether the provision, entrusted processing, or joint processing of the network data, and the purpose, manner, and scope, and the like, of the network data recipient’s processing of the network data, are lawful, proper, and necessary;
(2) the risk that the network data provided, entrusted for processing, or jointly processed is tampered with, damaged, or leaked, or illegally obtained or illegally used, as well as the risk posed to national security, the public interest, or the lawful rights and interests of individuals or organizations;
(3) the integrity, law-abidingness, and the like of the network data recipient;
(4) whether the requirements concerning network data security in the relevant contract concluded or to be concluded with the network data recipient can effectively bind the network data recipient to perform network data security protection obligations;
(5) whether the technical and management measures taken or to be taken, and the like, can effectively guard against risks such as the network data being tampered with, damaged, or leaked, or illegally obtained or illegally used;
(6) other matters for assessment prescribed by the competent authorities concerned.
Article 32. Where an important data processor, due to a merger, division, dissolution, bankruptcy, or the like, may affect the security of important data, it shall take measures to safeguard network data security and report to the competent authorities concerned at or above the provincial level the disposal plan for the important data and the name and contact information of the recipient, and the like; where the competent authority is not clear, it shall report to the data security work coordination mechanism at or above the provincial level.
Article 33. Important data processors shall conduct a risk assessment of their network data processing activities on an annual basis and submit a risk assessment report to the competent authorities concerned at or above the provincial level; the competent authorities concerned shall promptly notify the cyberspace administration department and the public security organ at the same level.
The risk assessment report shall include the following:
(1) basic information about the network data processor, information about the network data security management body, and the name and contact information of the person responsible for network data security, and the like;
(2) the purpose, types, quantity, manner, scope, storage period, storage location, and the like of the processing of important data, and the situation of the network data processing activities carried out, not including the content of the network data itself;
(3) the network data security management system and its implementation, and the technical measures such as encryption, backup, labeling and identification, access control, and security authentication and other necessary measures, and their effectiveness;
(4) the network data security risks discovered, and the network data security incidents that have occurred and their handling;
(5) the risk assessment situation for the provision, entrusted processing, or joint processing of important data;
(6) the situation of the cross-border provision of network data;
(7) other reporting matters prescribed by the competent authorities concerned.
A risk assessment report submitted by a large network platform service provider that processes important data shall, in addition to the matters prescribed in the preceding paragraph, fully explain the security of network data in its key businesses and supply chain, and the like.
Where an important data processor engages in important data processing activities that may endanger national security, the competent authorities concerned at or above the provincial level shall order it to take measures such as rectification or ceasing the processing of important data. The important data processor shall immediately take measures in accordance with the relevant requirements.
Chapter V — Cross-Border Security Management of Network Data
Article 34. The national cyberspace administration department coordinates the relevant departments in establishing a special working mechanism for the security management of national outbound data transfers, in researching and formulating relevant policies for the security management of national outbound network data transfers, and in coordinating the handling of major matters concerning the security of outbound network data transfers.
Article 35. A network data processor may provide personal information to recipients outside the territory where one of the following conditions is met:
(1) it has passed a security assessment for outbound data transfers organized by the national cyberspace administration department;
(2) it has undergone personal information protection certification by a professional institution in accordance with the provisions of the national cyberspace administration department;
(3) it complies with the provisions on the standard contract for the outbound transfer of personal information formulated by the national cyberspace administration department;
(4) it is genuinely necessary to provide personal information to recipients outside the territory in order to conclude or perform a contract to which the individual is a party;
(5) it is genuinely necessary to provide employees’ personal information to recipients outside the territory in order to carry out cross-border human resources management in accordance with labor rules and regulations formulated in accordance with law and a collective contract concluded in accordance with law;
(6) it is genuinely necessary to provide personal information to recipients outside the territory in order to perform a statutory duty or statutory obligation;
(7) it is genuinely necessary, in an emergency, to provide personal information to recipients outside the territory in order to protect the life, health, or property safety of a natural person;
(8) other conditions prescribed by laws, administrative regulations, or the national cyberspace administration department.
Article 36. Where an international treaty or agreement that the People’s Republic of China has concluded or acceded to contains provisions on the conditions, and the like, for providing personal information to recipients outside the territory of the People’s Republic of China, those provisions may be followed.
Article 37. Where important data collected and generated by a network data processor in the course of operations within the territory of the People’s Republic of China genuinely needs to be provided to recipients outside the territory, it shall pass a security assessment for outbound data transfers organized by the national cyberspace administration department. Where a network data processor identifies and declares important data in accordance with the relevant provisions of the State but has not been informed by, or had it publicly announced by, the relevant region or department as important data, it is not required to declare it as important data for the security assessment for outbound data transfers.
Article 38. After passing a security assessment for outbound data transfers, a network data processor that provides personal information and important data to recipients outside the territory may not exceed the purpose, manner, scope, types, scale, and the like of the outbound data transfer that were specified at the time of the assessment.
Article 39. The State takes measures to prevent and address cross-border security risks and threats to network data. No individual or organization may provide programs, tools, or the like dedicated to damaging or circumventing technical measures; and anyone who knows that another person is engaging in activities such as damaging or circumventing technical measures may not provide that person with technical support or assistance.
Chapter VI — Obligations of Network Platform Service Providers
Article 40. Network platform service providers shall, through platform rules, contracts, or the like, clearly specify the network data security protection obligations of the third-party product and service providers that access their platforms, and shall urge third-party product and service providers to strengthen network data security management.
Manufacturers of devices such as smart terminals with pre-installed applications are subject to the provisions of the preceding paragraph.
Where a third-party product or service provider carries out network data processing activities in violation of the provisions of laws or administrative regulations or of the platform rules or contractual terms, thereby causing harm to users, the network platform service provider, the third-party product or service provider, and the manufacturer of devices such as smart terminals with pre-installed applications shall bear corresponding liability in accordance with law.
The State encourages insurance companies to develop network data damage compensation liability insurance products, and encourages network platform service providers and manufacturers of devices such as smart terminals with pre-installed applications to take out such insurance.
Article 41. Network platform service providers that provide application distribution services shall establish application verification rules and carry out network-data-security-related verification. Upon discovering that an application awaiting distribution or already distributed does not comply with the provisions of laws or administrative regulations or with the mandatory requirements of national standards, they shall take measures such as warning, refusing distribution, suspending distribution, or terminating distribution.
Article 42. Where a network platform service provider pushes information to individuals by means of automated decision-making, it shall set up an option to turn off personalized recommendations that is easy to understand, access, and operate, and shall provide users with functions such as refusing to receive pushed information and deleting user tags targeting their personal characteristics.
Article 43. The State advances the building of a public service for network identity authentication, and promotes its application in accordance with the principle of government guidance and user voluntariness.
Network platform service providers are encouraged to support users in using the national public service for network identity authentication to register and verify their real identity information.
Article 44. Large network platform service providers shall publish an annual social responsibility report on personal information protection; the content of the report shall include, but not be limited to, the measures for and results of personal information protection, the acceptance of applications by individuals to exercise their rights, and the performance of duties by the personal information protection supervisory body composed mainly of external members, and the like.
Article 45. Where a large network platform service provider provides network data across borders, it shall comply with the State’s requirements for the cross-border security management of data, improve the relevant technical and management measures, and guard against cross-border security risks to network data.
Article 46. Large network platform service providers may not use network data, algorithms, platform rules, or the like to engage in the following activities:
(1) processing the network data generated by users on the platform by means of misleading, fraud, coercion, or the like;
(2) restricting, without legitimate reason, users’ access to and use of the network data they generate on the platform;
(3) imposing unreasonable differential treatment on users, thereby harming users’ lawful rights and interests;
(4) other activities prohibited by laws or administrative regulations.
Chapter VII — Supervision and Administration
Article 47. The national cyberspace administration department is responsible for the overall coordination of network data security and related supervision and administration work.
Public security organs and state security organs, in accordance with the provisions of the relevant laws, administrative regulations, and these Regulations, assume network data security supervision and administration responsibilities within the scope of their respective duties, and prevent and combat, in accordance with law, unlawful and criminal activities that endanger network data security.
The national data administration department performs corresponding network data security duties in its specific undertaking of data administration work.
Each region and each department is responsible for the network data collected and generated in the work of that region or department and for the security of such network data.
Article 48. Each competent authority concerned that assumes network data security supervision and administration responsibilities for its own industry or field shall designate a network data security protection work body for that industry or field, formulate in a coordinated manner and organize the implementation of emergency response plans for network data security incidents in that industry or field, periodically organize and carry out network data security risk assessments for that industry or field, conduct supervision and inspection of network data processors’ performance of network data security protection obligations, and guide and urge network data processors to promptly rectify existing risks and hidden dangers.
Article 49. The national cyberspace administration department coordinates the competent authorities concerned in promptly collecting, analyzing and assessing, sharing, and releasing information relating to network data security risks, and strengthens work on network data security information sharing, the monitoring and early warning of network data security risks and threats, and the emergency response to network data security incidents.
Article 50. The competent authorities concerned may take the following measures to conduct supervision and inspection of network data security:
(1) requiring the network data processor and its relevant personnel to provide explanations regarding the matters under supervision and inspection;
(2) consulting and copying documents and records relating to network data security;
(3) inspecting the operation of network data security measures;
(4) inspecting equipment and items relating to network data processing activities;
(5) other necessary measures prescribed by laws and administrative regulations.
Network data processors shall cooperate with the network data security supervision and inspection lawfully carried out by the competent authorities concerned.
Article 51. When the competent authorities concerned conduct network data security supervision and inspection, they shall be objective and fair, and may not charge fees to the units being inspected.
In the course of network data security supervision and inspection, the competent authorities concerned may not access or collect business information unrelated to network data security, and the information obtained may only be used for the needs of safeguarding network data security and may not be used for any other purpose.
Where the competent authorities concerned discover that a network data processor’s network data processing activities pose a relatively large security risk, they may, in accordance with the prescribed authority and procedures, require the network data processor to suspend the relevant services, modify platform rules, improve technical measures, and the like, so as to eliminate hidden dangers to network data security.
Article 52. When conducting network data security supervision and inspection, the competent authorities concerned shall strengthen coordination, cooperation, and information communication, reasonably determine the frequency and manner of inspections, and avoid unnecessary inspections and overlapping, repetitive inspections.
Personal information protection compliance audits, important data risk assessments, security assessments for the outbound transfer of important data, and the like shall be better connected so as to avoid repetitive assessments and audits. Where the content of an important data risk assessment overlaps with that of a cybersecurity multi-level protection evaluation, the respective results may be mutually recognized.
Article 53. The competent authorities concerned and their staff shall, in accordance with law, keep confidential network data such as personal privacy, personal information, commercial secrets, and confidential business information that they become aware of in the performance of their duties, and may not leak it or illegally provide it to others.
Article 54. Where an organization or individual outside the territory engages in network data processing activities that endanger the national security or public interest of the People’s Republic of China, or infringe upon the personal information rights and interests of citizens of the People’s Republic of China, the national cyberspace administration department, together with the competent authorities concerned, may take corresponding necessary measures in accordance with law.
Chapter VIII — Legal Liability
Article 55. For violations of the provisions of Article 12, Articles 16 through 20, Article 22, the first and second paragraphs of Article 40, Article 41, or Article 42 of these Regulations, the competent authorities for cyberspace affairs, telecommunications, public security, and the like shall, in accordance with their respective duties, order corrections, give a warning, and confiscate the unlawful gains; where correction is refused or the circumstances are serious, a fine of not more than 1,000,000 yuan shall be imposed, and the relevant business may be ordered suspended, operations may be ordered suspended for rectification, the relevant business permit may be revoked, or the business license may be revoked, and a fine of not less than 10,000 yuan and not more than 100,000 yuan may be imposed on the directly responsible person in charge and other directly responsible persons.
Article 56. For violations of the provisions of Article 13 of these Regulations, the competent authorities for cyberspace affairs, telecommunications, public security, state security, and the like shall, in accordance with their respective duties, order corrections, give a warning, and may concurrently impose a fine of not less than 100,000 yuan and not more than 1,000,000 yuan, and may impose a fine of not less than 10,000 yuan and not more than 100,000 yuan on the directly responsible person in charge and other directly responsible persons; where correction is refused or the circumstances are serious, a fine of not less than 1,000,000 yuan and not more than 10,000,000 yuan shall be imposed, and the relevant business may be ordered suspended, operations may be ordered suspended for rectification, the relevant business permit may be revoked, or the business license may be revoked, and a fine of not less than 100,000 yuan and not more than 1,000,000 yuan shall be imposed on the directly responsible person in charge and other directly responsible persons.
Article 57. For violations of the provisions of the second paragraph of Article 29, the second and third paragraphs of Article 30, Article 31, or Article 32 of these Regulations, the competent authorities for cyberspace affairs, telecommunications, public security, and the like shall, in accordance with their respective duties, order corrections, give a warning, and may concurrently impose a fine of not less than 50,000 yuan and not more than 500,000 yuan, and may impose a fine of not less than 10,000 yuan and not more than 100,000 yuan on the directly responsible person in charge and other directly responsible persons; where correction is refused or serious consequences such as the leakage of a large amount of data are caused, a fine of not less than 500,000 yuan and not more than 2,000,000 yuan shall be imposed, and the relevant business may be ordered suspended, operations may be ordered suspended for rectification, the relevant business permit may be revoked, or the business license may be revoked, and a fine of not less than 50,000 yuan and not more than 200,000 yuan shall be imposed on the directly responsible person in charge and other directly responsible persons.
Article 58. For violations of other relevant provisions of these Regulations, the competent authorities concerned shall pursue legal liability in accordance with the relevant provisions of the “Cybersecurity Law of the People’s Republic of China,” the “Data Security Law of the People’s Republic of China,” the “Personal Information Protection Law of the People’s Republic of China,” and other laws.
Article 59. Where a network data processor voluntarily eliminates or mitigates the harmful consequences of an unlawful act, where the unlawful act is minor and is corrected in a timely manner and has caused no harmful consequences, or where it is a first-time violation with minor harmful consequences that is corrected in a timely manner, or there are other such circumstances, a lighter or mitigated administrative penalty shall be imposed, or no administrative penalty shall be imposed, in accordance with the provisions of the “Administrative Penalty Law of the People’s Republic of China.”
Article 60. Where a state organ fails to perform the network data security protection obligations provided for in these Regulations, its superior organ or the competent authority concerned shall order corrections; the directly responsible person in charge and other directly responsible persons shall be given sanctions in accordance with law.
Article 61. Where a violation of the provisions of these Regulations causes harm to others, civil liability shall be borne in accordance with law; where the violation constitutes an act in violation of public security administration, a public security administration penalty shall be imposed in accordance with law; where it constitutes a crime, criminal liability shall be pursued in accordance with law.
Chapter IX — Supplementary Provisions
Article 62. The following terms used in these Regulations have the meanings set out below:
(1) “Network data” means all kinds of electronic data processed and generated through networks.
(2) “Network data processing activities” means activities such as the collection, storage, use, processing, transmission, provision, disclosure, and deletion of network data.
(3) “Network data processor” means an individual or organization that independently determines the purpose and manner of processing in network data processing activities.
(4) “Important data” means data in a specific field, specific group, or specific region, or reaching a certain degree of precision and scale, that, if tampered with, damaged, or leaked, or illegally obtained or illegally used, may directly endanger national security, economic operation, social stability, or public health and safety.
(5) “Entrusted processing” means network data processing activities that a network data processor entrusts an individual or organization to carry out in accordance with an agreed purpose and manner.
(6) “Joint processing” means network data processing activities in which two or more network data processors jointly determine the purpose and manner of processing network data.
(7) “Separate consent” means specific and explicit consent given by an individual specifically for a particular processing of their personal information.
(8) “Large network platform” means a network platform with more than 50 million registered users or more than 10 million monthly active users, with complex business types, whose network data processing activities have an important bearing on national security, economic operation, the national economy and people’s livelihood, and the like.
Article 63. Network data processing activities involving core data shall be carried out in accordance with the relevant provisions of the State.
These Regulations do not apply to the processing of personal information by a natural person for personal or family affairs.
Network data processing activities involving state secrets or work secrets are subject to the provisions of the “Law of the People’s Republic of China on Guarding State Secrets” and other laws and administrative regulations.
Article 64. These Regulations shall take effect on January 1, 2025.
Closing
The original document was published in Chinese by the State Council of the People’s Republic of China; we translated it into English, which is what you read above. This translation is provided for quick comprehension only and should be used at your own discretion and risk — always confirm the current requirements with qualified legal counsel.
If you need further help from our team, contact us today, and our experts will help you keep your presence in China compliant from the ground up.