China’s Cybersecurity Law comes into force today, establishing the country’s first comprehensive legal framework for cyber security and data protection.
Key points
- Network operators must implement graded security protections, including the Multi-Level Protection Scheme.
- Critical information infrastructure operators must store personal information and important data in China.
- Security assessments are required for cross-border transfers by critical operators.
- Network products and services must meet national security standards.
UK organisations operating in China, or supplying networks and services there, need to assess obligations under the law, particularly for data localisation and cross-border transfers.
Source: Cybersecurity Law of the PRC (Cyberspace Administration of China)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.