China (PIPL)

China's Network Data Regulations Put a Price on Scraping, Recommendation Switches and Important Data

Key Takeaways

  • Decree No. 790 was adopted by the State Council on 30 August 2024, signed by Premier Li Qiang on 24 September 2024 and has applied since 1 January 2025; it has 64 articles in nine chapters
  • A processor handling the personal information of 10 million or more people takes on two duties written for holders of important data: a named security officer and management body, and reporting on mergers and dissolutions
  • Holders of important data must run a risk assessment every year and send the report to a provincial or higher authority
  • A large network platform is defined as one with 50 million registered users or 10 million monthly active users, plus complex business and significant public impact
  • Article 35 adds a ground for export, performing a statutory duty or obligation, that the CAC's 2024 cross-border provisions did not list

Reading the Chinese Text

The Regulations were promulgated in Chinese only. The article-by-article descriptions below are this publication's translation of the text published on the central government portal, gov.cn. They are not drawn from, and should not be read as, an official English version.

A State Council Regulation Sitting Under Three Statutes

The Regulations on Network Data Security Management (网络数据安全管理条例) were adopted at the State Council's 40th executive meeting on 30 August 2024, promulgated as State Council Decree No. 790 over Premier Li Qiang's signature on 24 September 2024, published on 30 September 2024, and took effect on 1 January 2025 under Article 64.

They are an administrative regulation (行政法规) made by the State Council itself, not a departmental rule (部门规章) of the Cyberspace Administration of China. A joint Q&A from the Ministry of Justice and the CAC uses that second label for the CAC's export instruments, including the 2024 cross-border data provisions, and says the Regulations were built on experience implementing them. Article 1 names three parent statutes: the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law. The same Q&A records that the CAC drafted the text and consulted publicly, that the Ministry of Justice then reviewed it, and that the Regulations are meant to refine, supplement and complete the three laws rather than restate them.

One of those parents has since changed. On 28 October 2025 the NPC Standing Committee adopted a decision amending the Cybersecurity Law, in force from 1 January 2026. It renumbers the statute and, among other things, adds a paragraph to what is now Article 42 stating that network operators processing personal information must comply with that law, the Civil Code and the PIPL. The Regulations cite the Cybersecurity Law by name rather than by article, so the renumbering does not break their cross-references.

Who Counts as a Network Data Processor

Article 62 supplies the definitions. Network data is all electronic data processed and generated through networks. A network data processor (网络数据处理者) is an individual or organisation that independently decides the purposes and means of processing, the same controller-style test the PIPL uses for a personal information processor, but applied to all network data rather than personal information alone. Processing on another's behalf is 委托处理, entrusted processing, and two or more processors deciding purposes and means together is 共同处理, joint processing.

Article 2 sets the reach. The Regulations apply to network data processing and its supervision within China; to processing outside China of the personal information of individuals within China in the circumstances in PIPL Article 3(2); and, for liability purposes, to processing abroad that harms China's national security, public interest or the lawful rights of its citizens and organisations. Article 63 carves out individuals handling personal information for personal or household affairs, and routes core data and state secrets to other rules.

Several general duties in Chapter II apply to every processor regardless of data type:

  • Article 10. On finding a security defect or vulnerability in a network product or service, remedial measures at once and notice to users; where national security or the public interest is endangered, a report to the competent department within 24 hours
  • Article 11. Where a network data security incident harms individuals or organisations, prompt notice to the interested parties of the incident, the risk, the consequences and the remedial steps, by telephone, SMS, instant messaging, email or public announcement
  • Article 12. Contracts fixing purpose, method, scope and security obligations whenever personal information or important data is provided or entrusted to another processor, with records of that provision kept for at least three years
  • Article 18. Anyone using automated tools to access or collect network data must assess the impact on the network service, and may not unlawfully intrude on others' networks or disrupt their normal operation
  • Article 19. Providers of generative AI services must strengthen security management of training data and its processing

Personal Information Rules Added Beyond the PIPL

Chapter III is where the Regulations do most to the PIPL, and the Q&A describes it as a refinement of notice, consent and individual rights. The additions are specific:

  • Notice format (Article 21). A privacy policy used to give notice must be displayed centrally, be easy to access and sit in a prominent position, and must cover four listed matters, including a method for fixing retention where the period is hard to determine. Collection, and provision to other processors, must be itemised in list form, and processing of under-14s' data needs its own dedicated rules
  • Consent conduct (Article 22). No consent obtained by misleading, fraud or coercion; no processing beyond the purpose, method, type and retention consented to; and no frequent re-requests for consent after an individual has clearly refused
  • Rights (Article 23). Requests to access, copy, correct, supplement, delete, restrict, close an account or withdraw consent must be accepted promptly, without unreasonable conditions
  • Incidental collection (Article 24). Unnecessary personal information collected unavoidably by automated collection, data collected without the required consent, and data of closed accounts must be deleted or anonymised
  • Portability (Article 25). A transfer to another processor the individual designates must be enabled where identity can be verified, the data was provided with consent or collected under contract, the transfer is technically feasible and it harms no one else. A fee covering cost may be charged where the number of requests clearly exceeds a reasonable range
  • Offshore representatives (Article 26). A foreign processor that has set up a body or appointed a representative in China under PIPL Article 53 must file its details with the cyberspace department at the level of a districted city

Article 27 restates the PIPL audit duty; the CAC's implementing rules are the subject of this publication's post on the compliance audit measures. Article 28 is the provision with most reach: a processor handling the personal information of 10 million or more people must also comply with Articles 30 and 32, duties otherwise written for processors of important data, even if it holds none.

Important Data and the Risk Assessment Duty

Article 62(4) defines important data as data in particular fields, of particular groups or regions, or reaching a certain precision and scale, whose tampering, destruction, leakage or unlawful acquisition or use may directly endanger national security, economic operation, social stability or public health and safety. Article 29 puts the catalogues in the hands of the national data security coordination mechanism and of each region and department, and requires processors to identify and declare important data. Where data is confirmed as important, the region or department concerned must promptly notify the processor or publish it.

Four obligations follow for a processor of important data:

  • People (Article 30). A network data security officer, drawn from management, with expertise and the right to report directly to the competent department, plus a security management body that runs the rules, monitoring, drills and complaints. Processors holding types or volumes specified by the authorities must run security background checks on the officer and key staff
  • Before sharing (Article 31). A risk assessment before providing, entrusting or jointly processing important data, covering six listed matters including the recipient's integrity and compliance record and whether the contract can actually bind it
  • Restructuring (Article 32). On merger, division, dissolution or bankruptcy, a report of the disposal plan and the recipient to a provincial-level or higher authority
  • Every year (Article 33). An annual risk assessment of the processing, reported to a provincial-level or higher competent department. The report covers seven matters, among them purposes, volumes and storage locations, security measures, incidents, sharing assessments and data exports. Large platforms processing important data must also address critical business and supply-chain data security

Article 52 tries to contain the paperwork. Personal information compliance audits, important-data risk assessments and export security assessments are to be coordinated to avoid duplication, and where an important-data risk assessment overlaps with a multi-level protection scheme evaluation the results may be mutually recognised.

Cross-Border Provisions and How They Defer to the CAC Provisions

Chapter V does not redraw the export thresholds; those remain in CAC Order No. 16, charted in this publication's PIPL export guide. What Article 35 does is list, at the level of an administrative regulation, eight conditions under which personal information may go abroad: the three CAC mechanisms (security assessment, certification, standard contract); necessity for a contract with the individual; cross-border human resources management under lawful labour rules and collective contracts; performing a statutory duty or obligation; emergency protection of life, health and property; and other conditions set by law, administrative regulation or the CAC.

Set beside Order No. 16, two differences show. Article 5 of the Order exempts contract necessity, human resources and emergencies, but it lists no ground for statutory duties; Article 35(6) of the Regulations does. And the Order's volume exemption for fewer than 100,000 people does not appear in Article 35 by name; it survives through the eighth condition, which defers to conditions the CAC sets. Article 36 adds that treaties China has concluded or joined may be applied where they set conditions for export.

Article 37 lifts the Order's rule on unannounced important data into the regulation: data a processor identified and declared but which no region or department has notified or published as important need not be declared as important data for an export assessment. Article 38 holds an assessed exporter to the purpose, method, scope, type and scale fixed at assessment. Article 39 prohibits providing programs or tools specially designed to break or evade technical measures, or knowingly helping others do so.

Platform Obligations

Chapter VI is new ground. Article 62(8) defines a large network platform as one with 50 million or more registered users or 10 million or more monthly active users, with complex business types, whose data processing has an important impact on national security, economic operation or people's livelihoods. The size figures alone do not make a platform large; the qualitative limbs are also part of the definition.

  • Article 40. Platform providers, and makers of devices with pre-installed apps, must set third-party data security obligations by platform rules or contract, and where a third party's unlawful processing harms users, the platform, the third party and the device maker bear corresponding liability in accordance with law. The state encourages insurers to write data damage liability cover
  • Article 41. App distribution platforms must run verification rules and warn, refuse, suspend or stop distribution of non-compliant apps
  • Article 42. Any platform pushing information by automated decision-making must provide an easy-to-understand option to turn off personalised recommendation, and functions to refuse pushed information and delete user tags based on personal characteristics
  • Article 43. Platforms are encouraged to support the state's public network identity authentication service, which is to be promoted on a voluntary basis
  • Articles 44 to 46. Large platforms publish an annual personal information protection social responsibility report, manage cross-border risk, and may not use data, algorithms or platform rules to mislead or coerce users, restrict without good reason users' access to the data they generate on the platform, or apply unreasonable differential treatment

Supervision and Penalties

Article 47 makes the CAC the coordinator, with public security and state security organs and the national data administration acting within their own remits and sector regulators supervising their own fields. Article 50 lists the inspection powers, from requiring explanations to examining equipment. Article 51 limits them: inspections are free of charge, may not collect business information unrelated to data security, and the information obtained may be used only for that purpose.

Chapter VIII sets fines by reference to the article breached:

BreachEntity fineResponsible individuals
Articles 12, 16 to 20, 22, 40(1) and (2), 41 and 42 (Article 55)Up to RMB 1 million where correction is refused or the case is serious, with possible suspension or licence revocationRMB 10,000 to 100,000
Article 13, national security review (Article 56)RMB 100,000 to 1 million; RMB 1 million to 10 million where correction is refused or the case is seriousRMB 10,000 to 100,000; RMB 100,000 to 1 million in serious cases
Articles 29(2), 30(2) and (3), 31 and 32, important data (Article 57)RMB 50,000 to 500,000; RMB 500,000 to 2 million where correction is refused or large-scale leakage resultsRMB 10,000 to 100,000; RMB 50,000 to 200,000 in serious cases

Everything else, including most of the personal information chapter outside Article 22, is punished under the parent statutes by Article 58. Article 59 applies the Administrative Penalty Law's leniency: lighter, mitigated or no penalty where a processor actively eliminates or reduces the harm, or where a first or minor violation is corrected promptly with little or no harmful consequence.

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

When did China's Regulations on Network Data Security Management take effect?
On 1 January 2025, under Article 64. They were adopted by the State Council on 30 August 2024 and promulgated as State Council Decree No. 790, signed on 24 September 2024 and published on 30 September 2024.
What is a network data processor?
Article 62(3) defines it as an individual or organisation that independently decides the purposes and means of processing in network data processing activities. Network data means all electronic data processed and generated through networks, so the term reaches beyond personal information.
Do the Regulations change the thresholds for exporting personal information?
No. Article 35 lists eight conditions for export, including the CAC's three mechanisms and a new ground for performing statutory duties or obligations, but the volume thresholds remain in CAC Order No. 16. Article 35(8) defers to other conditions the CAC sets.
What does the regulation require of recommendation algorithms?
Article 42 requires a platform pushing information to individuals by automated decision-making to provide an option to turn off personalised recommendation that is easy to understand, access and operate, and functions letting users refuse pushed information and delete user tags aimed at their personal characteristics. A breach falls within the Article 55 fine tier.
Which companies count as a large network platform?
Under Article 62(8), a platform with 50 million or more registered users or 10 million or more monthly active users, with complex business types, whose data processing has an important impact on national security, economic operation or people's livelihoods. Articles 44 to 46 then apply, including an annual social responsibility report on personal information protection.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.