← New search

Law & Policy

Cybersecurity Law of the People's Republic of China

The Cybersecurity Law of the People's Republic of China (CSL) is a comprehensive legal framework governing network security, data protection, and critical information infrastructure within China. Enacted on November 7, 2016, and effective from June 1, 2017, it establishes obligations for network operators, users, and government agencies, reflecting China's approach to balancing technological development with state security and social stability.1

2016
Enacted
Year of enactment
2017
Effective
Year effective
7
Chapters
Number of chapters
79
Articles
Number of articles
1

Core Provisions and Scope

The CSL applies to the construction, operation, and use of networks within China, as well as the supervision and management of network security.1 It defines 'network operators' as owners and administrators of networks and service providers, imposing duties such as implementing security protection measures, maintaining user data confidentiality, and reporting security incidents to authorities. The law also establishes a multi-tiered protection scheme for critical information infrastructure (CII), requiring operators to undergo security reviews for procurement of network products and services that may affect national security. Additionally, it mandates that personal information be collected with user consent, used only for the intended purpose, and stored within China for CII operators.2

2

Implementation and Enforcement

Enforcement of the CSL is primarily carried out by the Cyberspace Administration of China (CAC) and other relevant departments, which have the authority to conduct inspections, issue fines, and suspend services for non-compliance.3 Penalties range from warnings and fines up to 1 million yuan for serious violations, with individuals facing personal liability.4 The law has been used to justify actions against foreign companies, such as the 2021 Didi Chuxing investigation, which led to the company's app removal for alleged data security violations. The CAC has also issued implementing regulations, including the Data Security Law and Personal Information Protection Law, which complement the CSL and provide more detailed rules on data governance.3

3

International and Business Implications

The CSL has significant extraterritorial reach, affecting multinational companies that operate in China or handle data of Chinese citizens. It requires CII operators to store personal information and important data locally, and any cross-border transfer must undergo a security assessment.2 This has led to compliance challenges for global firms, prompting them to establish local data centers and revise data governance policies. The law also encourages international cooperation in cybersecurity, but critics argue that its vague terms and broad state security exceptions create uncertainty and potential for protectionist enforcement.1 Despite these concerns, the CSL has been praised for raising awareness of cybersecurity and pushing companies to adopt stronger security measures.4

4

Lesser-known aspects

Beyond the headline provisions, the CSL includes lesser-known elements such as the prohibition of network operators from providing services to users who refuse to provide real identity information, a measure aimed at curbing anonymity online. It also mandates that network operators must not collect user information unrelated to the service provided, and must delete it upon user request.2 The law's 'security review' mechanism for CII procurement has been compared to similar review processes in other countries, but its implementation remains opaque. Additionally, the CSL has been used to justify the shutdown of VPN services that bypass government-approved internet access, although the law itself does not explicitly ban VPNs.3 These nuances highlight the law's role in shaping China's internet governance beyond simple data protection.

Glossary

CII
Critical Information Infrastructure – systems that, if disrupted, could endanger national security, public welfare, or public interests.
CAC
Cyberspace Administration of China – the primary regulator for internet and cybersecurity matters in China.
Network operator
Any owner or administrator of a network, or provider of network services, as defined by the CSL.

This article reflects the law as of 2023; subsequent amendments and implementing regulations may apply.