Skip to content

China Data Security Risk Assessment Measures

In force China · In force Aug 20, 2026 · no upcoming deadlines

Deadlines

DateWhat happens
Aug 20, 20265 weeks agoRisk assessment measures take effect

Summaries for reference, not legal advice. Check the official text.

What it does

Implements the annual risk assessment duty for important data handlers under the DSL and Network Data Security Regulations. Important data handlers must assess risk every year and submit the report to their regulator within 20 working days of finishing; general data handlers are encouraged to assess at least every 3 years. Regulators can order an assessment by a certified third party after serious risks or large leaks.

Who it applies to
Network data handlers in China, with mandatory annual assessments for handlers of important data.
Penalties
Handled under the DSL and Network Data Security Regulations. Regulators may order handlers to stop processing important data if they fail to remediate.
Enforced by
CAC with MIIT, MPS and sector regulators
Official name
Measures for Network Data Security Risk Assessment
Citation
CAC Order No. 24 (joint with MIIT, MPS)
Topics
cybersecurity, privacy
Verified 2026-09-25 gov.cn
Research notes

Adopted 2026-06-01, signed and published 2026-06-18. The same assessor may not run more than 3 consecutive annual assessments for one handler. Reports must be kept at least 3 years.

Related

Questions about China Data Security Risk Assessment Measures
What are the China Data Security Risk Assessment Measures compliance deadlines?
Aug 20, 2026: Risk assessment measures take effect.
When does China Data Security Risk Assessment Measures take effect?
China Data Security Risk Assessment Measures took effect on Aug 20, 2026.
Who does China Data Security Risk Assessment Measures apply to?
Network data handlers in China, with mandatory annual assessments for handlers of important data.
What are the penalties under China Data Security Risk Assessment Measures?
Handled under the DSL and Network Data Security Regulations. Regulators may order handlers to stop processing important data if they fail to remediate.

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.