China: National Information Security Standardisation Technical Committee adopted guidelines on data security requirements for academic and scientific service platforms including cross-border data transfer requirements

Description

National Information Security Standardisation Technical Committee adopted guidelines on data security requirements for academic and scientific service platforms including cross-border data transfer requirements

On 16 September 2025, the National Information Security Standardisation Technical Committee (TC260) released the cybersecurity standard practice guidelines – data security requirements for academic and scientific service platforms. The guidelines require non-public data collected or generated domestically to undergo data export security assessments before being provided abroad. Operators must complete approval procedures, apply desensitisation to sensitive datasets, comply with outbound personal information management requirements, and prohibit disclosure of sensitive unit information. Annual risk assessment reports must specify recipient identity, type, volume, purpose, location, duration, and access conditions of outbound data.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cross-border data transfer regulation
Regulated Economic Activity
search service provider, platform intermediary: other
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2024-09-30
in consultation

On 30 September 2024, the Secretariat of the National Cybersecurity Standardization Technical Commi…

2024-10-14
processing consultation

On 14 October 2024, the Secretariat of the National Cybersecurity Standardization Technical Committ…

2025-09-16
adopted

On 16 September 2025, the National Information Security Standardisation Technical Committee (TC260)…