Asia-Pacific China

China's DSL and PIPL: How the Two Data Laws Fit Together

How the Data Security Law and PIPL divide the field: data classification vs personal information, important data, state secrets, and overlapping export controls.

Regulation

Data Security Law (DSL, effective 1 September 2021); PIPL; Cybersecurity Law (CSL)

Max Penalty

DSL: RMB 10 million (core data violations); PIPL: RMB 50 million or 5% of turnover

Enforcing Authority

CAC, with sector regulators and public security organs

Official Source

www.cac.gov.cn

Executive Summary

  • China regulates data through a triad: the Cybersecurity Law (2017) secures networks, the Data Security Law (September 2021) protects all data by classification, and PIPL (November 2021) protects personal information.
  • The DSL applies to any data processing, personal or not, and requires classification into general, important, and core data, with escalating protection duties.
  • 'Important data' is the pivot: its export always requires a CAC security assessment, and identifying it depends on sector catalogs still being issued.
  • Both laws block providing China-stored data to foreign courts or law enforcement without approval (DSL Article 36, PIPL Article 41).
  • One dataset frequently sits under all three laws: a customer database is personal information (PIPL), potentially important data (DSL), on network infrastructure (CSL).

China’s data regime is a triad, and reading any one law alone misleads. The Cybersecurity Law (2017) secures the pipes and defines who counts as critical infrastructure. The Data Security Law (1 September 2021) protects all data, classified by national-interest sensitivity. PIPL (1 November 2021) protects natural persons’ information. A single customer database can engage all three: personal information on a network, some of it possibly important data. Compliance programs that only track PIPL miss the classification and catalog duties the DSL attaches to everything else.

LawCSL (2017)DSL (2021)PIPL (2021)
ObjectNetworks, CIIOsAll data, by classPersonal information
Key dutyMLPS, localization for CIIOsClassification, important-data controlsConsent, rights, transfer mechanisms
Max penaltyRMB 1M+ (varies)RMB 10M (core data)RMB 50M or 5% of turnover
RegulatorCAC and sector bodiessamesame

The DSL’s own duty set

Classification first: general, important, and core data (core being state-security-grade, with the harshest penalties). Then lifecycle duties scaled to class: security management systems, training, technical measures, risk monitoring with remediation, incident reporting to authorities and affected parties, and periodic risk assessments for important-data processors, filed with regulators. National security review applies to data activities affecting national security, and DSL Article 36 blocks providing China-stored data to foreign judicial or enforcement bodies without approval, the mirror of PIPL Article 41.

The persistent operational question is what qualifies as important data. Sector catalogs answer it incrementally: vehicle data rules came first (2021), the 2024 Network Data Security Management Regulation (effective 1 January 2025) consolidated obligations and adopted a notify-or-catalog presumption, so companies are not expected to self-declare importance absent guidance, but must cooperate when regulators or catalogs designate their data.

Where the laws intersect for a multinational

Exports. Important data: CAC security assessment, always. Personal information: PIPL’s three mechanisms and 2024 exemptions. Both: the stricter route wins.

Incidents. One breach can trigger DSL incident reporting, PIPL Article 57 notification, and CSL network-incident duties simultaneously; build a single playbook with all three notification maps.

Governance. The DSL’s classification program and PIPL’s handler duties share infrastructure: inventories, risk assessments, access controls. Run them as one data governance function, not two.

Enforcement. The Didi penalty (RMB 8.026 billion, 2022) charged violations of all three laws at once, the template for how Chinese enforcement treats the triad as a single fabric. Start the personal-information half with the PIPL roadmap, and baseline your public-facing collection with a free scan.

Frequently Asked Questions

Do we need to comply with both DSL and PIPL?

If you process any data in China, yes to the DSL; if any of it is personal information, yes to both. The DSL's classification, risk monitoring, and incident duties apply to corporate, technical, and commercial data that PIPL never touches, so DSL scope is strictly broader on data type.

What counts as 'important data'?

Data that, if tampered with, destroyed, leaked, or illegally used, could endanger national security, economic operation, social stability, or public health and safety. Concrete scoping arrives via regional and sector catalogs (automotive was first: the 2021 vehicle data rules). The 2024 network data regulation presumes data is not important unless notified or cataloged, easing over-classification fears.

How do the export rules stack?

Important data exports always require the CAC security assessment regardless of volume. Personal information exports follow PIPL's three mechanisms and the 2024 facilitation exemptions. A dataset that is both follows the stricter path: assessment. The blocking provisions (DSL Art. 36, PIPL Art. 41) apply to foreign judicial requests either way.

What are DSL penalties?

Up to RMB 10 million for violations of core data management rules (with business shutdown possible), up to RMB 5 million for important-data and export violations, plus personal fines for responsible individuals. Smaller ceilings than PIPL's turnover-based fines, but DSL violations frequently accompany PIPL charges, as in the Didi case.

Where does the Cybersecurity Law still matter?

The CSL governs network operators and designates critical information infrastructure operators (CIIOs), whose status cascades: CIIOs must localize personal information and important data in China and pass security assessments for any export. Multi-level protection scheme (MLPS) grading also flows from the CSL.

Regulatory Crosswalk

PIPLChina CSLGDPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.