China’s data regime is a triad, and reading any one law alone misleads. The Cybersecurity Law (2017) secures the pipes and defines who counts as critical infrastructure. The Data Security Law (1 September 2021) protects all data, classified by national-interest sensitivity. PIPL (1 November 2021) protects natural persons’ information. A single customer database can engage all three: personal information on a network, some of it possibly important data. Compliance programs that only track PIPL miss the classification and catalog duties the DSL attaches to everything else.
| Law | CSL (2017) | DSL (2021) | PIPL (2021) |
|---|---|---|---|
| Object | Networks, CIIOs | All data, by class | Personal information |
| Key duty | MLPS, localization for CIIOs | Classification, important-data controls | Consent, rights, transfer mechanisms |
| Max penalty | RMB 1M+ (varies) | RMB 10M (core data) | RMB 50M or 5% of turnover |
| Regulator | CAC and sector bodies | same | same |
The DSL’s own duty set
Classification first: general, important, and core data (core being state-security-grade, with the harshest penalties). Then lifecycle duties scaled to class: security management systems, training, technical measures, risk monitoring with remediation, incident reporting to authorities and affected parties, and periodic risk assessments for important-data processors, filed with regulators. National security review applies to data activities affecting national security, and DSL Article 36 blocks providing China-stored data to foreign judicial or enforcement bodies without approval, the mirror of PIPL Article 41.
The persistent operational question is what qualifies as important data. Sector catalogs answer it incrementally: vehicle data rules came first (2021), the 2024 Network Data Security Management Regulation (effective 1 January 2025) consolidated obligations and adopted a notify-or-catalog presumption, so companies are not expected to self-declare importance absent guidance, but must cooperate when regulators or catalogs designate their data.
Where the laws intersect for a multinational
Exports. Important data: CAC security assessment, always. Personal information: PIPL’s three mechanisms and 2024 exemptions. Both: the stricter route wins.
Incidents. One breach can trigger DSL incident reporting, PIPL Article 57 notification, and CSL network-incident duties simultaneously; build a single playbook with all three notification maps.
Governance. The DSL’s classification program and PIPL’s handler duties share infrastructure: inventories, risk assessments, access controls. Run them as one data governance function, not two.
Enforcement. The Didi penalty (RMB 8.026 billion, 2022) charged violations of all three laws at once, the template for how Chinese enforcement treats the triad as a single fabric. Start the personal-information half with the PIPL roadmap, and baseline your public-facing collection with a free scan.