Law / China

Data Security Law, Data Security Protection Obligations

Data Security Law of the People's Republic of China, Art. 27

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 September 2021.

A security baseline statutes rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds any organization or individual engaging in a data-processing activity, regardless of sector, and reaches data generally rather than only personal information.
  • Establish and maintain a full-process data-security management system covering the collection, storage, use, processing, transmission, provision, and disclosure of the data you process, and provide data-security education and training to your staff.
  • Take the technical measures and other necessary measures appropriate to your processing to keep your data secure.
  • Where you process data over the internet or another information network, meet this duty in addition to, not instead of, your classified-protection obligations under the Cybersecurity Law, already this jurisdiction's own deferred network-operator duty.
  • If you process important data, an official classification this corpus cannot flag against on its own, designate a person responsible for data security and a managing body, and implement that responsibility.

If you get it wrong

Criminal exposureNo

Criminal exposure note

Article 45's penalties for a violation of Articles 27, 29, or 30 are administrative fines and business restrictions only; a separate, heavier tier in Article 45's third paragraph, for violating the national core data management system specifically, can draw criminal liability, but that tier is not this duty.

Penalty structure

Article 45's first paragraph sets a base tier of a corrective order and a warning, escalating to a fine of 50,000 to 500,000 yuan (10,000 to 100,000 yuan against the directly responsible manager) for a violation of Articles 27, 29, or 30, and a further escalation to 500,000 to 2,000,000 yuan (50,000 to 200,000 yuan against the manager) for refusing to correct the violation or causing a large-scale data leak or other serious consequence. A separate, narrower tier in the same article's second paragraph, for violating the national core data management system specifically, reaches 2,000,000 to 10,000,000 yuan and can draw criminal liability; that tier is not part of this duty and is not the figure this field records.

Rule
Fixed only
As of
12 September 2026
Currency
CNY
Fixed cap
2,000,000

Who enforces it

Enforcement body

The competent department exercising data-security supervisory duties over the processor's industry or field.

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Any organization or individual engaging in a data-processing activity must, under the law and administrative regulations, establish and improve a full-process data-security management system, organize data-security education and training, and take the technical measures and other necessary measures appropriate to keep the data secure.

Where a data-processing activity is conducted using the internet or another information network, this data-security duty applies on top of, not instead of, the network operator's classified-protection duty under the Cybersecurity Law. A processor of important data must designate a person responsible for data security and a managing body, and implement that responsibility.

An ordinary violation draws a corrective order and a warning, escalating to a fine of 50,000 to 500,000 yuan, with a further escalation to 500,000 to 2,000,000 yuan for refusing to correct or causing a large-scale data leak or another serious consequence; a violation of the separate national core data management system carries its own, heavier fine of 2,000,000 to 10,000,000 yuan and can draw criminal liability, but that heavier tier is not this duty.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, cac.gov.cn (sourced to Xinhua News Agency), Data Security Law of the People's Republic of China

Back to the example  ·  Lint your app