Data Security Law of China · Yalla China
中华人民共和国数据安全法 / Data Security Law of China
Enacted: 2021-06-10 ✅ Effective: 2021-09-01
📝 Overview
Regulates data processing in China and classifies it by security importance, imposing strict security obligations on companies for important and core data.
This is general information only, not legal advice. For your specific case, consult a licensed lawyer.
📜 The law text / key provisions
The Data Security Law (2021) classifies data into three tiers: general, important, and core (state). Processors of important data must: conduct regular security assessments; provide immediate notification of security incidents; restrict transfer of important data outside China. It legally prohibits complying with foreign data disclosure requests without Chinese government approval. Foreign companies operating in China are subject to the same obligations.
💬 Practical reading
💬 This is a general reading/opinion for orientation — not the official legal text nor legal advice.
Foreign companies handling large-scale data in China need to assess whether their data falls within the important data category.
📎 Official source
National People's Congress Standing Committee
🕒 Updated: 16 March 2026
