Posted in

Cybersecurity & MLPS (等保) for FIEs

China operates a mandatory, tiered cybersecurity regime (MLPS + CII) that FIEs cannot opt out of; MLPS is the baseline obligation for virtually every network operator. 中国实行强制、分层的网络安全制度(等保+关键信息基础设施),外商投资企业无法退出;等保几乎适用于所有网络运营者,是合规底线。 MLPS 2.0 (GB/T 22239-2019, effective 1 December 2019) has five steps: grading, filing, … Cybersecurity & MLPS (等保) for FIEsRead more

Posted in

China’s Draft Rule for Large Personal-Information Processors: What Foreign-Invested Platforms and Apps Need to Know

China’s cyberspace regulator has released a draft rule for “large personal-information processors,” consolidating two earlier platform-focused drafts into one accountability regime for the biggest data holders.国家网信部门发布《大型个人信息处理者个人信息保护规定(征求意见稿)》,将早前两份聚焦平台的规定整合为面向最大规模数据处理者的统一责任制度。 A processor handling over 10 million individuals’ personal information, or meeting other significance tests, … China’s Draft Rule for Large Personal-Information Processors: What Foreign-Invested Platforms and Apps Need to KnowRead more

Posted in

Cybersecurity Review and Critical Information Infrastructure Procurement Compliance for Foreign-Invested Enterprises

The Cybersecurity Review regime applies whenever a Critical Information Infrastructure (CII) operator procures network products or services that may affect national security — and foreign-invested enterprises supplying those products are squarely within scope. 当关键信息基础设施(CII)运营者采购可能影响国家安全的网络产品与服务时,网络安全审查制度即被触发;向这些运营者供应产品的外商投资企业同样被直接纳入监管视野。 The legal backbone is the Cybersecurity … Cybersecurity Review and Critical Information Infrastructure Procurement Compliance for Foreign-Invested EnterprisesRead more

Posted in

Data Classification, Grading and Critical Information Infrastructure Obligations for Foreign-Invested Enterprises

China mandates a data classification and grading (数据分类分级) baseline; the national standard GB/T 43697-2024 took effect on 1 October 2024. 中国确立了数据分类分级基线制度,国家标准GB/T 43697-2024于2024年10月1日施行。 The Network Data Security Management Regulations (State Council Order No. 790, effective 1 January 2025) require handlers to … Data Classification, Grading and Critical Information Infrastructure Obligations for Foreign-Invested EnterprisesRead more

Posted in

China’s amended Cybersecurity Law in force from 1 January 2026: AI clauses, tenfold penalties and wider extraterritorial reach

The Decision amending the Cybersecurity Law was adopted on 28 October 2025 and takes effect on 1 January 2026, with 14 amendments and a reissued text. 修改《网络安全法》的决定于2025年10月28日通过、2026年1月1日起施行,共14项修改并重新公布。 A new Article 20 builds the first basic-law “development plus oversight” framework for … China’s amended Cybersecurity Law in force from 1 January 2026: AI clauses, tenfold penalties and wider extraterritorial reachRead more

Posted in

China’s Network Data Security Regulation: what foreign-invested firms must do

China’s Network Data Security Regulation (State Council Order 790) took effect on 1 January 2025, turning the Cybersecurity Law, Data Security Law and PIPL into operational, enforceable obligations for every network data processor — including foreign-invested firms. 《网络数据安全管理条例》(国务院令790号)自 2025 年 … China’s Network Data Security Regulation: what foreign-invested firms must doRead more