China: Consultation opened on updated Measures for the Administration of Data Security in the Field of Industry and Information Technology including cybersecurity measures

Compare with different regulatory event:

Description

Consultation opened on updated Measures for the Administration of Data Security in the Field of Industry and Information Technology including cybersecurity measures

On 10 February 2022, the Ministry of Industry and Information Technology of China (MIIT) opened a public consultation on the updated version of the "Measures for the Administration of Data Security in the Field of Industry and Information Technology" until 21 February 2022. The document updates the requirements regarding data management and provides a review process for cross-border data transfers. The measures outline different requirements depending on the type of data, classifying it in “general data” and “important data”. Data on Chinese politics, military, economy, nuclear security, and artificial intelligence among others, is considered to be related to national security and is classified as “important data”. With regards to “important data”, companies must conduct a risk assessment and request approval from the MIIT before such data is shared with foreign national regulatory agencies. Furthermore, the measures require data administrators to notify the agency within three months if there are 30% or more changes with regards to the category of “important data”. Finally, the measures require companies to appoint a representative responsible for data security.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
infrastructure provider: internet and telecom services
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2021-09-30
in consultation

On 30 September 2021, the Chinese Ministry of Industry and Information Technology (MIIT) opened a p…

2021-10-30
processing consultation

On 30 October 2021, the Chinese Ministry of Industry and Information Technology (MIIT) closed its p…

2022-02-10
in consultation

On 10 February 2022, the Ministry of Industry and Information Technology of China (MIIT) opened a p…

2022-02-21
processing consultation

On 21 February 2022, the public consultation on the updated version of the Measures for the Adminis…

2022-12-08
adopted

On 8 December 2022, the Chinese Ministry of Industry and Information Technology (MIIT) issued the f…

2023-01-01
adopted

On 1 January 2023, the Regulation "Administrative Measures on Data Security in the Industry and Inf…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
corporate data (all forms): storage (any form)
Regulatory tool
Preventive security requirement
Responsive security requirement
Risk or other impact assessment requirement
Sanctions
Regulated subjects
1
corporate data (all forms): data collection
Regulatory tool
Preventive security requirement
Responsive security requirement
Risk or other impact assessment requirement
Sanctions
Regulated subjects
1
corporate data (all forms): data processing
Regulatory tool
Preventive security requirement
Responsive security requirement
Purpose/processing limitation
Risk or other impact assessment requirement
Sanctions
Regulated subjects
1
corporate data (all forms): transfer: cross-border

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

corporate data (all forms): storage (any form)

corporate data (all forms): data collection

corporate data (all forms): data processing

corporate data (all forms): transfer: cross-border