The Data Security Law, effective September 1, 2021, is China's foundational law in the data security field. Enterprises must fully fulfill data security protection obligations.
The state establishes a data classification and grading protection system, implementing classified and graded protection based on the importance of data in economic and social development, and the degree of harm to national security, public interests, or lawful rights of individuals and organizations if data is tampered with, destroyed, leaked, illegally obtained, or illegally used. Data related to national security, lifelines of the national economy, important people's livelihood, and major public interests constitutes national core data, subject to stricter management.
Enterprises must fulfill: establish and improve a full-process data security management system; organize data security education and training; adopt corresponding technical measures and other necessary measures to ensure data security; strengthen risk monitoring in data processing activities, immediately take remedial measures upon discovering data security defects, vulnerabilities, or other risks; immediately take response measures upon data security incidents and notify users and report to competent authorities per regulations; important data processors must designate data security officers and management bodies.
Specific catalogs of important data are determined by each region and department per the data classification and grading protection system. Enterprises processing important data must regularly conduct risk assessments and submit risk assessment reports to competent authorities. Cross-border security management of important data collected and generated during domestic operations by critical information infrastructure operators is governed by the Cybersecurity Law; other data processors providing important data abroad must conduct data export security assessments per regulations.
Legal liability for violating the Data Security Law includes: ordering correction, warnings, fines (up to RMB 5 million for units, up to RMB 500,000 for individuals), ordering suspension of related business, business suspension and rectification, revocation of relevant business licenses or business licenses. Criminal liability applies for crimes (e.g., illegal acquisition of computer information system data crime, infringement of citizens' personal information crime). Conducting data security compliance audits and establishing data security management systems is recommended.