Regulations on the Administration of Network Data Security
Version and sources (verifiable)
Item Content Adopted 30 August 2024, at the 40th executive meeting of the State Council Promulgated 24 September 2024 (State Council Order No. 790, signed by Premier Li Qiang) Effective 1 January 2025 Structure 9 chapters, 64 articles Currently effective Yes (as of 2026-09-22) Chinese original State Council Order No. 790 — full text (the original gov.cn link is no longer reachable; this is the full text of the Order as republished on a government website) English version No official English translation published. This English text is a translation by our editorial team cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 64 articles, no gaps; chapter structure verified against the official text
Chapter I General provisions
Article 1 These Regulations are formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China and other laws, for the purposes of regulating network data processing activities, safeguarding network data security, promoting the lawful, reasonable and effective use of network data, protecting the lawful rights and interests of individuals and organisations, and maintaining national security and the public interest.
Article 2 These Regulations apply to network data processing activities carried out within the territory of the People’s Republic of China and to the supervision and administration of their security.
These Regulations also apply to activities processing, outside the territory of the People’s Republic of China, the personal information of natural persons within the territory of the People’s Republic of China, where the circumstances provided for in the second paragraph of Article 3 of the Personal Information Protection Law of the People’s Republic of China are met.
Where network data processing activities carried out outside the territory of the People’s Republic of China harm the national security or public interests of the People’s Republic of China or the lawful rights and interests of its citizens and organisations, legal liability shall be pursued in accordance with law.
Article 3 Network data security management work upholds the leadership of the Communist Party of China, implements the holistic approach to national security, and coordinates the promotion of the development and utilisation of network data with the safeguarding of network data security.
Article 4 The State encourages innovative applications of network data in all industries and fields, strengthens capacity-building for network data security protection, supports innovation in technologies, products and services relating to network data, carries out publicity, education and personnel training on network data security, and promotes the development and utilisation of network data and the growth of the industry.
Article 5 The State applies classified and graded protection to network data according to its importance in economic and social development and the degree of harm that tampering, destruction, leakage, unlawful acquisition or unlawful use would cause to national security, the public interest or the lawful rights and interests of individuals and organisations.
Article 6 The State actively participates in the formulation of international rules and standards relating to network data security and promotes international exchange and cooperation.
Article 7 The State supports relevant industry organisations in formulating, in accordance with their articles of association, norms of conduct for network data security, strengthening industry self-regulation, guiding their members in strengthening network data security protection, raising the level of network data security protection and promoting the sound development of the industry.
Chapter II General provisions
Article 8 No individual or organisation may use network data to engage in illegal activities, or engage in illegal network data processing activities such as stealing or otherwise unlawfully obtaining network data, or unlawfully selling or unlawfully providing network data to others.
No individual or organisation may provide programs or tools specifically used for the illegal activities in the preceding paragraph; where a person knows that another is engaged in the illegal activities in the preceding paragraph, the person must not provide that other person with technical support such as internet access, server hosting, network storage or communication transmission, or assistance such as advertising promotion or payment and settlement.
Article 9 Network data processors shall, in accordance with laws and administrative regulations and the mandatory requirements of national standards, and on the basis of the classified protection of cybersecurity, strengthen network data security protection, establish and improve network data security management systems, adopt technical measures such as encryption, backup, access control and security authentication and other necessary measures, protect network data against tampering, destruction, leakage, unlawful acquisition or unlawful use, handle network data security incidents, prevent and combat illegal and criminal activities directed at and using network data, and bear primary responsibility for the security of the network data they process.
Article 10 Network products and services provided by network data processors shall comply with the mandatory requirements of relevant national standards; where risks such as security defects or vulnerabilities in network products or services are discovered, remedial measures shall be taken immediately, users shall be promptly informed as required and a report shall be made to the competent departments; where national security or the public interest is endangered, the network data processor shall also report to the competent departments within 24 hours.
Article 11 Network data processors shall establish and improve emergency response plans for network data security incidents; when a network data security incident occurs, they shall immediately activate the plan, take measures to prevent the expansion of harm and eliminate hidden security dangers, and report to the competent departments as required.
Where a network data security incident harms the lawful rights and interests of individuals or organisations, the network data processor shall promptly notify the interested parties, by telephone, short message, instant messaging tool, email or public announcement, of the incident and the risk situation, the consequences of the harm and the remedial measures already taken; where laws and administrative regulations provide that notification may be dispensed with, those provisions shall prevail. Where a network data processor discovers in the course of handling a network data security incident any leads suggesting illegality or crime, it shall report the case to the public security organ and the State security organ as required and cooperate in investigation, inquiry and handling.
Article 12 Where a network data processor provides or entrusts the processing of personal information and important data to another network data processor, it shall, by contract or otherwise, agree with the network data recipient on the processing purpose, method, scope and security protection obligations, and supervise the recipient’s performance of those obligations. Records of the provision or entrusted processing of personal information and important data to another network data processor shall be kept for at least three years.
The network data recipient shall perform network data security protection obligations and process the personal information and important data in accordance with the agreed purpose, method and scope.
Where two or more network data processors jointly determine the processing purpose and method of personal information and important data, they shall agree on their respective rights and obligations.
Article 13 Where network data processing activities carried out by a network data processor affect or may affect national security, a national security review shall be conducted in accordance with the relevant provisions of the State.
Article 14 Where network data needs to be transferred due to merger, division, dissolution, bankruptcy or other reasons, the network data recipient shall continue to perform the network data security protection obligations.
Article 15 Where a State organ entrusts another person with the construction, operation or maintenance of an e-government system or with the storage or processing of government data, it shall, in accordance with the relevant provisions of the State, go through strict approval procedures, clarify the entrusted party’s network data processing authority and protection responsibilities, and supervise the entrusted party’s performance of network data security protection obligations.
Article 16 Where a network data processor provides services to a State organ or an operator of critical information infrastructure, or participates in the construction, operation or maintenance of other public infrastructure or public service systems, it shall perform network data security protection obligations in accordance with laws, regulations and the contract, and provide secure, stable and continuous services.
A network data processor referred to in the preceding paragraph must not, without the consent of the commissioning party, access, obtain, retain, use or divulge network data or provide it to others, or conduct correlation analysis of network data.
Article 17 Information systems providing services for State organs shall strengthen network data security management by reference to the management requirements for e-government systems, so as to safeguard network data security.
Article 18 Where a network data processor uses automated tools to access or collect network data, it shall assess the impact on network services, and must not unlawfully intrude into another’s network or interfere with the normal operation of network services.
Article 19 A network data processor providing generative artificial intelligence services shall strengthen the security management of training data and training data processing activities and take effective measures to prevent and handle network data security risks.
Article 20 Network data processors providing products or services to the public shall accept public supervision, establish convenient channels for complaints and reports about network data security, publish information such as the methods for making complaints and reports, and promptly accept and handle complaints and reports about network data security.
Chapter III Personal information protection
Article 21 Where a network data processor informs individuals in accordance with law by formulating personal information processing rules before processing their personal information, the personal information processing rules shall be publicly displayed in a centralised manner, easy to access and placed in a prominent position, and shall be clear, specific and easy to understand, including but not limited to the following:
(1) the name of the network data processor and its contact information;
(2) the purpose, method and categories of the processing of personal information, the necessity of processing sensitive personal information and the impact on individual rights and interests;
(3) the retention period of personal information and the method of handling it upon expiry; where the retention period is difficult to determine, the method for determining the retention period shall be specified;
(4) the methods and channels for individuals to access, copy, transfer, correct, supplement or delete personal information, restrict its processing, cancel accounts and withdraw consent.
Where a network data processor informs individuals, in accordance with the preceding paragraph, of the purpose, method and categories of collecting personal information and providing it to other network data processors, and of the information of the network data recipient, it shall set them out in a list or other form. Where a network data processor processes the personal information of minors under the age of fourteen, it shall also formulate dedicated personal information processing rules.
Article 22 Where a network data processor processes personal information on the basis of individual consent, it shall comply with the following provisions:
(1) the collection of personal information shall be necessary for providing products or services; it must not collect personal information beyond the necessary scope, and must not obtain consent by misleading, deceiving or coercing individuals;
(2) where sensitive personal information such as biometric data, religious belief, specific identity, medical and health information, financial accounts or whereabouts is processed, the individual’s separate consent shall be obtained;
(3) where the personal information of minors under the age of fourteen is processed, the consent of the minors’ parents or other guardians shall be obtained;
(4) personal information must not be processed beyond the purpose, method, categories and retention period consented to by the individual;
(5) where an individual has clearly expressed that he or she does not consent to the processing of his or her personal information, consent must not be sought frequently;
(6) where the purpose, method or categories of processing of personal information change, the individual’s consent shall be obtained anew.
Where laws and administrative regulations provide that written consent shall be obtained for the processing of sensitive personal information, those provisions shall prevail.
Article 23 Where an individual requests access to, a copy of, correction, supplementation or deletion of, or restriction on the processing of his or her personal information, or cancels an account or withdraws consent, the network data processor shall promptly accept the request and provide convenient methods and channels to support the individual’s exercise of rights, and must not impose unreasonable conditions to restrict the individual’s reasonable requests.
Article 24 Where non-essential personal information or personal information for which individual consent has not been lawfully obtained is inevitably collected through the use of automated collection technology, or where an individual cancels an account, the network data processor shall delete the personal information or anonymise it. Where the retention period provided for by laws and administrative regulations has not expired, or where deletion or anonymisation of personal information is technically difficult to achieve, the network data processor shall stop processing other than storage and the taking of necessary security protection measures.
Article 25 For a request to transfer personal information that meets the following conditions, the network data processor shall provide a channel for other network data processors designated by the individual to access and obtain the relevant personal information:
(1) the true identity of the requesting person can be verified;
(2) what is requested to be transferred is personal information provided with the individual’s consent or collected on the basis of a contract;
(3) the transfer of the personal information is technically feasible;
(4) the transfer of the personal information does not harm the lawful rights and interests of others.
Where the number of requests to transfer personal information clearly exceeds a reasonable range, the network data processor may charge a necessary fee based on the cost of transferring the personal information.
Article 26 Where a network data processor outside the territory of the People’s Republic of China processes the personal information of natural persons within the territory and, in accordance with Article 53 of the Personal Information Protection Law of the People’s Republic of China, establishes a dedicated institution or designates a representative within the territory, it shall report the name of the institution or the name and contact information of the representative to the cyberspace administration department of the city with districts where it is located; the cyberspace administration department shall promptly notify the relevant competent departments at the same level.
Article 27 Network data processors shall, periodically and by themselves or by engaging a professional institution, conduct compliance audits of their processing of personal information for compliance with laws and administrative regulations.
Article 28 A network data processor that processes the personal information of 10 million or more individuals shall also comply with the provisions of Articles 30 and 32 of these Regulations applicable to network data processors processing important data (hereinafter “processors of important data”).
Chapter IV Important data security
Article 29 The national data security work coordinating mechanism shall coordinate the relevant departments in formulating a catalogue of important data and shall strengthen the protection of important data. All regions and departments shall, in accordance with the classified and graded protection system for data, determine the specific catalogues of important data for their region, department and relevant industries and fields, and apply key protection to the network data included in the catalogues.
Network data processors shall identify and report important data in accordance with the relevant provisions of the State. Where data is confirmed to be important data, the relevant region or department shall promptly inform the network data processor or make it public. The network data processor shall perform its network data security protection responsibilities.
The State encourages network data processors to use technologies and products such as data labelling to improve the level of important data security management.
Article 30 A processor of important data shall designate a person responsible for network data security and a network data security management body. The network data security management body shall perform the following network data security protection responsibilities:
(1) formulate and implement network data security management systems, operating procedures and emergency response plans for network data security incidents;
(2) periodically organise network data security risk monitoring, risk assessment, emergency drills and publicity, education and training activities, and promptly handle network data security risks and incidents;
(3) accept and handle complaints and reports about network data security.
The person responsible for network data security shall have professional knowledge of network data security and relevant management experience, shall be a member of the management of the network data processor, and shall have the authority to report network data security situations directly to the competent departments.
A network data processor that controls important data of the specific categories and scale prescribed by the competent departments shall conduct security background checks on the person responsible for network data security and personnel in key positions and strengthen the training of the relevant personnel. In conducting the checks, it may apply to the public security organ and the State security organ for assistance.
Article 31 A processor of important data shall, before providing, entrusting the processing of, or jointly processing important data, conduct a risk assessment, except where this is for the performance of statutory duties or legal obligations.
The risk assessment shall focus on the following:
(1) whether providing, entrusting the processing of or jointly processing network data, and the purpose, method and scope of the network data recipient’s processing of network data, are lawful, legitimate and necessary;
(2) the risk of the network data provided, entrusted for processing or jointly processed being tampered with, destroyed, leaked or unlawfully acquired or used, and the risks to national security, the public interest or the lawful rights and interests of individuals and organisations;
(3) the integrity and law-abiding conduct of the network data recipient;
(4) whether the network data security requirements in the relevant contracts concluded or to be concluded with the network data recipient can effectively bind the recipient to perform its network data security protection obligations;
(5) whether the technical and management measures taken or to be taken can effectively prevent risks such as the network data being tampered with, destroyed, leaked or unlawfully acquired or used;
(6) other assessment contents prescribed by the competent departments.
Article 32 Where a processor of important data may affect the security of important data due to merger, division, dissolution, bankruptcy or other reasons, it shall take measures to safeguard network data security and report to the relevant competent departments at or above the provincial level the disposal plan for the important data and the name and contact information of the recipient; where the competent department is unclear, it shall report to the data security work coordinating mechanism at or above the provincial level.
Article 33 A processor of important data shall conduct a risk assessment of its network data processing activities each year and submit a risk assessment report to the relevant competent departments at or above the provincial level, and the relevant competent departments shall promptly notify the cyberspace administration departments and public security organs at the same level.
The risk assessment report shall include the following:
(1) basic information on the network data processor, information on the network data security management body, and the name and contact information of the person responsible for network data security;
(2) the purpose, categories, quantity, method, scope, storage period and storage location of the processing of important data, and the situation of network data processing activities, excluding the content of the network data itself;
(3) the network data security management system and its implementation, and technical measures such as encryption, backup, labelling, access control and security authentication, other necessary measures and their effectiveness;
(4) network data security risks discovered, and network data security incidents that occurred and their handling;
(5) the risk assessment of providing, entrusting the processing of, or jointly processing important data;
(6) the situation of network data cross-border transfer;
(7) other report contents prescribed by the competent departments.
A large online platform service provider processing important data shall, in addition to the contents in the preceding paragraph, fully explain the network data security situation of its key business and supply chain in its risk assessment report.
Where the processing activities of important data by a processor of important data may endanger national security, the relevant competent departments at or above the provincial level shall order it to take measures such as rectification or to stop processing important data. The processor of important data shall immediately take measures in accordance with the relevant requirements.
Chapter V Security administration of cross-border network data transfer
Article 34 The national cyberspace administration department shall coordinate the relevant departments in establishing a special working mechanism for national data export security administration, studying and formulating national policies for the security administration of network data export, and coordinating the handling of major matters concerning network data export security.
Article 35 A network data processor may provide personal information abroad where one of the following conditions is met:
(1) it has passed a data export security assessment organised by the national cyberspace administration department;
(2) it has obtained personal information protection certification from a professional institution in accordance with the provisions of the national cyberspace administration department;
(3) it complies with the provisions on standard contracts for the export of personal information formulated by the national cyberspace administration department;
(4) it is truly necessary to provide personal information abroad for the conclusion or performance of a contract to which the individual is a party;
(5) it is truly necessary to provide employees’ personal information abroad for cross-border human resources management implemented in accordance with lawfully formulated labour rules and lawfully concluded collective contracts;
(6) it is truly necessary to provide personal information abroad for the performance of statutory duties or legal obligations;
(7) it is truly necessary to provide personal information abroad in an emergency to protect the life, health and property safety of natural persons;
(8) other conditions provided for by laws, administrative regulations or the national cyberspace administration department.
Article 36 Where international treaties or agreements concluded or acceded to by the People’s Republic of China provide for the conditions for providing personal information outside the territory of the People’s Republic of China, those provisions may be followed.
Article 37 Where important data collected and generated by a network data processor in the course of its operations within the territory of the People’s Republic of China is truly necessary to be provided abroad, it shall pass a data export security assessment organised by the national cyberspace administration department. Where a network data processor has identified and reported important data in accordance with the relevant provisions of the State but has not been informed or publicly notified by the relevant region or department that the data is important data, it need not report it as important data for the data export security assessment.
Article 38 After passing a data export security assessment, a network data processor providing personal information and important data abroad must not exceed the purpose, method, scope, categories and scale of data export specified in the assessment.
Article 39 The State takes measures to prevent and handle network data cross-border security risks and threats. No individual or organisation may provide programs or tools specifically used to destroy or circumvent technical measures; where a person knows that another is engaged in activities such as destroying or circumventing technical measures, the person must not provide technical support or assistance to that other person.
Chapter VI Obligations of online platform service providers
Article 40 Online platform service providers shall, through platform rules or contracts, clarify the network data security protection obligations of third-party product and service providers accessing their platforms, and urge third-party product and service providers to strengthen network data security management.
The preceding paragraph applies to producers of devices such as smart terminals with pre-installed applications.
Where a third-party product or service provider carries out network data processing activities in violation of laws and administrative regulations, platform rules or contractual agreements and causes harm to users, the online platform service provider, the third-party product or service provider and the producer of devices such as smart terminals with pre-installed applications shall bear corresponding liability in accordance with law.
The State encourages insurance companies to develop insurance products covering liability for damage caused by network data and encourages online platform service providers and producers of devices such as smart terminals with pre-installed applications to take out such insurance.
Article 41 An online platform service provider providing application distribution services shall establish verification rules for applications and carry out verification relating to network data security. Where it discovers that an application to be distributed or already distributed does not comply with laws and administrative regulations or the mandatory requirements of national standards, it shall take measures such as issuing a warning, refusing distribution, suspending distribution or terminating distribution.
Article 42 Where an online platform service provider pushes information to individuals through automated decision-making, it shall provide an easy-to-understand, easy-to-access and easy-to-operate option to turn off personalised recommendations, and provide users with functions such as refusing to receive pushed information and deleting user tags targeting their personal characteristics.
Article 43 The State promotes the building of a national public service for online identity authentication, which is promoted and applied on the principle of government guidance and user voluntariness.
Online platform service providers are encouraged to support users in using the national public service for online identity authentication to register and verify their true identity information.
Article 44 Large online platform service providers shall publish an annual social responsibility report on personal information protection, covering, among other things, personal information protection measures and their results, the handling of applications for individuals to exercise their rights, and the performance of duties by the personal information protection supervision body composed mainly of external members.
Article 45 Where a large online platform service provider provides network data across borders, it shall comply with the State’s requirements for the security administration of cross-border data, improve the relevant technical and management measures, and prevent network data cross-border security risks.
Article 46 A large online platform service provider must not use network data, algorithms or platform rules to engage in the following activities:
(1) processing the network data generated by users on the platform by misleading, deceiving or coercing users;
(2) restricting users’ access to or use of the network data generated by them on the platform without justified reasons;
(3) applying unreasonable differential treatment to users, harming users’ lawful rights and interests;
(4) other activities prohibited by laws and administrative regulations.
Chapter VII Supervision and administration
Article 47 The national cyberspace administration department is responsible for coordinating network data security and the related supervision and administration.
Public security organs and State security organs shall, in accordance with the provisions of relevant laws and administrative regulations and these Regulations, assume network data security supervision and administration duties within the scope of their respective duties, and prevent and combat illegal and criminal activities endangering network data security in accordance with law.
The national data management department shall perform the corresponding network data security duties in the specific work of data management.
All regions and departments are responsible for the network data collected and generated in the work of their region or department and for the security of that network data.
Article 48 The relevant competent departments shall assume network data security supervision and administration duties for their respective industries and fields, designate the bodies responsible for network data security protection in their respective industries and fields, coordinate the formulation and organisation of the implementation of emergency response plans for network data security incidents in their respective industries and fields, periodically organise network data security risk assessments in their respective industries and fields, supervise and inspect the performance by network data processors of their network data security protection obligations, and guide and urge network data processors to promptly rectify existing risks and hidden dangers.
Article 49 The national cyberspace administration department shall coordinate the relevant competent departments in promptly compiling, assessing, sharing and publishing information related to network data security risks, and in strengthening the sharing of network data security information, the monitoring and early warning of network data security risks and threats, and the emergency handling of network data security incidents.
Article 50 The relevant competent departments may take the following measures to supervise and inspect network data security:
(1) require network data processors and the relevant personnel to explain matters relating to the supervision and inspection;
(2) consult and copy documents and records relating to network data security;
(3) inspect the operation of network data security measures;
(4) inspect equipment and articles relating to network data processing activities;
(5) other necessary measures provided for by laws and administrative regulations.
Network data processors shall cooperate with the network data security supervision and inspection carried out by the relevant competent departments in accordance with law.
Article 51 In carrying out network data security supervision and inspection, the relevant competent departments shall be objective and impartial and must not charge fees to the entities inspected.
In network data security supervision and inspection, the relevant competent departments must not access or collect business information unrelated to network data security, and the information obtained may only be used for the needs of maintaining network data security and must not be used for other purposes.
Where the relevant competent departments discover that a network data processor’s network data processing activities involve relatively serious security risks, they may, in accordance with the prescribed powers and procedures, require the network data processor to suspend the relevant services, revise platform rules, improve technical measures, etc. so as to eliminate hidden dangers to network data security.
Article 52 In carrying out network data security supervision and inspection, the relevant competent departments shall strengthen coordination and information communication, reasonably determine the frequency and methods of inspection, and avoid unnecessary inspections and duplicative overlapping inspections.
Personal information protection compliance audits, important data risk assessments, important data export security assessments and the like shall be better connected so as to avoid duplicative assessment and auditing. Where the contents of an important data risk assessment and a cybersecurity classified protection evaluation overlap, the relevant results may be mutually accepted.
Article 53 The relevant competent departments and their staff shall, in accordance with law, keep confidential the personal privacy, personal information, trade secrets and confidential business information and other network data learned in the performance of their duties, and must not divulge them or unlawfully provide them to others.
Article 54 Where an organisation or individual outside the territory engages in network data processing activities that endanger the national security or public interest of the People’s Republic of China, or infringe the personal information rights and interests of citizens of the People’s Republic of China, the national cyberspace administration department, together with the relevant competent departments, may take corresponding necessary measures in accordance with law.
Chapter VIII Legal liability
Article 55 Where the provisions of Articles 12, 16 to 20, 22, the first and second paragraphs of Article 40, Article 41 and Article 42 of these Regulations are violated, the competent departments for cyberspace administration, telecommunications and public security shall, in accordance with their respective duties, order correction, give a warning and confiscate the unlawful gains; where the offender refuses to correct or the circumstances are serious, a fine of not more than RMB 1,000,000 shall be imposed, and the competent departments may order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence, and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.
Article 56 Where Article 13 of these Regulations is violated, the competent departments for cyberspace administration, telecommunications, public security and State security shall, in accordance with their respective duties, order correction, give a warning and may concurrently impose a fine of not less than RMB 100,000 and not more than RMB 1,000,000, and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons; where the offender refuses to correct or the circumstances are serious, a fine of not less than RMB 1,000,000 and not more than RMB 10,000,000 shall be imposed, and the competent departments may order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 100,000 and not more than RMB 1,000,000 on the directly responsible persons in charge and other directly responsible persons.
Article 57 Where the second paragraph of Article 29, the second and third paragraphs of Article 30, Article 31 or Article 32 of these Regulations are violated, the competent departments for cyberspace administration, telecommunications and public security shall, in accordance with their respective duties, order correction, give a warning and may concurrently impose a fine of not less than RMB 50,000 and not more than RMB 500,000, and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons; where the offender refuses to correct or causes serious consequences such as the leakage of a large volume of data, a fine of not less than RMB 500,000 and not more than RMB 2,000,000 shall be imposed, and the competent departments may order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 50,000 and not more than RMB 200,000 on the directly responsible persons in charge and other directly responsible persons.
Article 58 Where other relevant provisions of these Regulations are violated, the relevant competent departments shall pursue legal liability in accordance with the relevant provisions of the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China and other laws.
Article 59 Where a network data processor voluntarily eliminates or mitigates the harmful consequences of an unlawful act, or the unlawful act is minor and promptly corrected without causing harmful consequences, or it is a first violation with minor harmful consequences that is promptly corrected, a mitigated or reduced administrative penalty shall be imposed or no administrative penalty shall be imposed in accordance with the provisions of the Administrative Penalty Law of the People’s Republic of China.
Article 60 Where a State organ fails to perform the network data security protection obligations provided for in these Regulations, its superior authority or the relevant competent department shall order it to correct; the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.
Article 61 Where a violation of these Regulations causes damage to another person, civil liability shall be borne in accordance with law; where the act constitutes a violation of public security administration, a public security administration penalty shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be pursued in accordance with law.
Chapter IX Supplementary provisions
Article 62 For the purposes of these Regulations, the following terms have the meanings set out below:
(1) “network data” means various electronic data processed and generated through networks;
(2) “network data processing activities” means activities such as the collection, storage, use, processing, transmission, provision, disclosure and deletion of network data;
(3) “network data processor” means an individual or organisation that independently determines the processing purpose and processing method in network data processing activities;
(4) “important data” means data in a specific field, for a specific group or in a specific region, or of a certain precision and scale, which, once tampered with, destroyed, leaked, or unlawfully acquired or used, may directly endanger national security, economic operation, social stability, or public health and safety;
(5) “entrusted processing” means network data processing activities carried out by an individual or organisation entrusted by a network data processor in accordance with the agreed purpose and method;
(6) “joint processing” means network data processing activities in which two or more network data processors jointly determine the processing purpose and processing method of network data;
(7) “separate consent” means a specific and explicit consent specially given by an individual for specific processing of his or her personal information;
(8) “large online platform” means an online platform with more than 50 million registered users or more than 10 million monthly active users, with complex business types, whose network data processing activities have an important impact on national security, economic operation, the national economy and people’s livelihood.
Article 63 Network data processing activities involving core data shall be carried out in accordance with the relevant provisions of the State.
These Regulations do not apply to natural persons processing personal information for personal or family affairs.
Network data processing activities involving State secrets or work secrets shall be governed by the provisions of laws and administrative regulations such as the Law of the People’s Republic of China on Guarding State Secrets.
Article 64 These Regulations shall come into force on 1 January 2025.