China: National Information Security Standardisation Technical Committee adopted guidelines on data security requirements for academic and scientific service platforms including cybersecurity regulation

Description

National Information Security Standardisation Technical Committee adopted guidelines on data security requirements for academic and scientific service platforms including cybersecurity regulation

On 16 September 2025, the National Information Security Standardisation Technical Committee (TC260) released the cybersecurity standard practice guidelines – data security requirements for academic and scientific service platforms. The guidelines require operators to implement organisational management, user management, content management, emergency response, security auditing, and security risk assessments. Obligations include appointment of data security officers and management institutions for platforms with more than 10 million users or handling important data, establishment of internal management systems, incident reporting and notification, and annual security risk assessments in accordance with GB/T 45577—2025.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
search service provider, platform intermediary: other
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2024-09-30
in consultation

On 30 September 2024, the Secretariat of the National Cybersecurity Standardization Technical Commi…

2024-10-14
processing consultation

On 14 October 2024, the Secretariat of the National Cybersecurity Standardization Technical Committ…

2025-09-16
adopted

On 16 September 2025, the National Information Security Standardisation Technical Committee (TC260)…