The Cyberspace Administration of China (the “CAC”), the Ministry of Industry and Information Technology and the Ministry of Public Security have jointly issued the Measures for Cyberspace Data Security Risk Assessment (Order No. 24, the “Measures”), which became effective on 20 August 2026.

1. Regulatory Purpose of the Measures
The Measures aim at refining practical requirements for data security risk assessments (the “DSA”) and resolve five years of regulatory ambiguity.
The mandatory DSA regime first debuted back in 2021 under the PRC Data Security Law. Entities processing important data are obliged to conduct regular DSA’s and submit official reports to the competent authorities, to identify, analyse and evaluate risks, detailing categories and volumes of important data processed, details of data processing activities, existing data security risks and corresponding mitigation measures. Afterwards, the 2024 Regulations on Cyberspace Data Security Management further reiterated this assessment obligation and supplemented detailed assessment dimensions to guide the compliance practices.
Even with these updates, the entire regulatory framework remained overly principle-based and lacked actionable implementation rules over the past five years. While the law clarified general obligations, it answered almost none of the critical operational questions: there were no standardized assessment workflows, no mandatory assessment frequency requirements, and no official guidelines on report submission procedures.
The Measures effectively resolve these long-standing pain points by clarifying several operational questions.
2. Obligations to conduct Data Security Risk Assessments
The Measures clearly define important data processors as the sole obliged parties to conduct the DSA. As a rule of thumb, any company that handles important data in routine business is legally required to conduct the DSA.
The identification of “important data” standard adopts a dual judgment mechanism: general principles + sector-specific guidelines, making it both unified and industry-tailored.
In principle, important data refers to data that, once tampered with, destroyed, leaked or illegally exploited, will pose direct threats to national security, economic operation, social stability, or public health and safety. It covers data involving specific fields, user groups, geographic regions, or data that reaches certain precision and scale thresholds. Per existing national standard, typical examples include national grain and energy reserve data, core industrial process data, non-public census data, special surveying and mapping data, and undisclosed environmental monitoring data.
Industry-specific rules further expand the scope, bringing more business scenarios into compliance supervision, which include for example:
- Automotive Industry: Vehicle manufacturers, autonomous driving firms and telematics service providers shall pay close attention to data categories in vehicle trajectory records, autonomous driving algorithms, road traffic flow statistics, and remote vehicle control.
- Healthcare Industry: Clinical trial data for Class II and Class III medical devices, as well as data related to public health monitoring, large-scale patient cases and infectious disease prevention, are all likely to be classified as important data.
- General Manufacturing Industry with Export Activities: Data involving technical control points under the Catalogue of Technologies Prohibited or Restricted from Export in China and items on the China Export Control List of Dual-Use Items will also be deemed as important data. A typical example is core formula parameters of power battery materials, including positive/negative electrode active substances, electrolytes and adhesive ratios. This is a key cross-border compliance highlight, especially for manufacturing enterprises with frequent export businesses, as China further aligns data security supervision with customs and export control regimes.
- Personal Information Threshold: Entities processing the personal information of more than 10 million individuals per year also fall under the scope of “processing important data”.
Enterprises, which are not processing important data, are encouraged (but not obliged) by the regulator to conduct the DSA every three years.
3. Rundown of the DSA
The new Measures standardise the entire assessment workflow with clear and executable rules, which are summarised as follows:
- Mandatory Annual Assessment: Important data processors are obliged to appoint dedicated in-house personnel to take charge of the assessment work and complete a full risk assessment every calendar year. For enterprises formally notified or self-identified as important data processors previously, the DSA shall be completed within one year after the Measures become effective, i.e., by 20 August 2027. For enterprises newly identified as important data processors due to business restructuring or new policy releases, the first DSA shall generally be completed within three months.
- Fixed Reporting Timeline: The assessment report shall be submitted to the competent industry authority within 20 working days upon completion. If no specific industry regulator applies, reports shall be filed with provincial or national CAC authorities.
- Dual Assessment Options: Enterprises may conduct assessments via in-house team or engage CAC-certified third-party professional institutions. If external support is engaged, the same firm and its affiliates shall not be selected for three consecutive assessment rounds.
- Mandatory Third-Party Engagement: Enterprises are obliged to engage external professional bodies in high-risk scenarios such as where their data processing activities may harm national security or public interests, or where a cybersecurity incident has occurred causing leakage or theft of important data or massive personal information.
4. Liability Risks in case of Non-Compliance
Non-compliance with the Measures triggers liability risks on the affected company and its management. The following shows a selection of these corporate and personal liability risks.
4.1 Corporate Liability Risks
Regulators, including competent industry authorities and CAC have robust intervention powers. Where data processing activities pose potential risks to national security or public interests, authorities may order rectification. Failure to make rectifications may trigger an order directly requiring enterprises to suspend relevant data processing operations, which means the enterprise will temporarily be unable to process the data and may face access blocks imposed by regulators.
Non-compliance will trigger explicit administrative penalties, with tiered sanctions based on severity:
- General violations: Failure to complete annual assessments or submit reports on time will result in fines ranging from RMB 50,000 to RMB 500,000.
- Severe violations: For failure to rectify as required, or incidents of large-scale data leakage and other serious consequences, regulators may order business suspension, rectification shutdowns or revocation of business licenses. Fines for severe breaches range from RMB 500,000 to RMB 2,000,000.
4.2 Personal Liability Risks
Personal liability risks may apply to “persons in charge directly responsible” and “other directly responsible personnel”. The regulator will determine in the individual scenario, which employees of the affected company shall be regarded as “persons in charge directly responsible” and “other directly responsible personnel” bearing in mind the corporate governance of the company. The “person in charge directly responsible” may include, for example, the data security officer, which is a mandatory role for important data processors. The “other directly responsible personnel” may include, for example, the head of the IT department of the affected company.
Liability for responsible individuals is tiered as follows:
- General violations: Fines of RMB 10,000 to RMB 100,000 for responsible individuals.
- Severe violations: Where enterprises fail to rectify breaches or suffer serious outcomes such as large-scale data leakage, responsible individuals face fines between RMB 50,000 and RMB 200,000.
5. Recommendations for Mitigation of Liability Risks
With the implementation of the new Measures, compliance expectations have become clearer and stricter. We recommend all data processing enterprises taking proactive actions to close compliance gaps, with three core priorities:
(1) Accurately map important data and monitor sector-specific rules: Conduct a comprehensive internal data review and stay up to date on industry-specific regulatory requirements to avoid overlooking high-risk data scenarios.
- Optimise internal compliance mechanisms: Establish internal data security management systems and appoint dedicated personnel to handle routine risk assessment preparation and emergency compliance responses.
- Build re-usable compliance asset libraries: Sort out and standardise daily compliance materials, including:
- internal data management systems
- data flow charts
- data asset inventories
- classification and grading ledgers
- historical rectification records and
- operation & maintenance audit logs
These ready-made materials can be directly re-used for official risk assessments, greatly improving compliance efficiency and reducing operational costs
6. Strategies for Managing Investigation Risks by Regulators
Beyond daily compliance rectification and documentation sorting, enterprises should build targeted investigation response preparations to cope with sudden regulatory inspections by the CAC and industry competent authorities. Adequate advance preparation can streamline the inspection process, fully demonstrate compliance validity, and reduce regulatory risks.
Enterprises shall pre-prepare and dynamically update a complete set of compliant supporting documents for inspection verification, covering all core compliance links required by the Measures. The key inspection-ready materials are listed as follows:
- Updated important data identification results, data asset inventory and hierarchical classification ledgers;
- Complete records of regular and ad-hoc DSA, together with official reporting/filing vouchers (if any);
- Internal data security management systems, operational specifications and personnel appointment documents;
- Full-process data flow records, daily operation logs and security audit archives;
- Closed-loop risk management documents, including problem identification, rectification plans and completion verification records; and
- Compliance training records and emergency response plans for data security incidents.
In addition, enterprises shall designate dedicated response personnel to unify communication with regulators during investigations, ensure consistent and accurate information disclosure, and avoid compliance liabilities caused by missing materials, inconsistent replies or irregular response procedures.
How can we help you?
Sharon Hu
Senior Associate