Law / China

Data Security Law, Risk Monitoring and Incident Reporting Duty

Data Security Law of the People's Republic of China, Art. 29

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 September 2021.

A vulnerability and incident reporting rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds the same data processor as this jurisdiction's Data Security Law data-security-program duty; it adds a risk-monitoring and incident-response duty rather than reaching a different party.
  • Strengthen risk monitoring of your data-processing activity, and on discovering a data-security defect, vulnerability, or other risk, immediately take remedial measures.
  • On an actual data-security incident, immediately take disposal measures, promptly notify affected users as provided, and report the incident to the competent authority; the statute states no numeric deadline, only immediacy and promptness.
  • A processor of important data carries an additional, periodic risk-assessment-and-reporting duty under Article 30 tied to the important-data classification rather than to any activity in this vocabulary, so it is not flagged as its own instrument.

If you get it wrong

Criminal exposureNo

Criminal exposure note

Article 45's penalties for a violation of Articles 27, 29, or 30 are administrative fines and business restrictions only; the separate, heavier national-core-data tier of Article 45 that can draw criminal liability is not this duty.

Penalty structure

Article 45 punishes a failure to perform the duties of Articles 27, 29, and 30 together, without a separate penalty clause for Article 29 alone: a base tier of a corrective order and a warning, escalating to a fine of 50,000 to 500,000 yuan (10,000 to 100,000 yuan against the directly responsible manager), and a further escalation to 500,000 to 2,000,000 yuan (50,000 to 200,000 yuan against the manager) for refusing to correct the violation or causing a large-scale data leak or other serious consequence. The separate national-core-data tier, up to 2,000,000 to 10,000,000 yuan with possible criminal liability, is not part of this duty.

Rule
Fixed only
As of
12 September 2026
Currency
CNY
Fixed cap
2,000,000

Who enforces it

Enforcement body

The competent department exercising data-security supervisory duties over the processor's industry or field.

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Any organization or individual engaging in a data-processing activity must strengthen risk monitoring and, on discovering a data-security defect, vulnerability, or other risk, immediately take remedial measures. On an actual data-security incident, the organization or individual must immediately take disposal measures, promptly notify affected users as provided, and report the incident to the competent authority.

The statute sets no numeric deadline for that notice or report, only immediacy and promptness; the National Cybersecurity Incident Reporting Measures set an operative reporting clock for such an incident, but bind by a network-operator classification recorded in the jurisdiction summary rather than raised as an instrument here.

The penalties for a violation are the same tiered fines as this jurisdiction's Data Security Law data-security-program row, since Article 45 punishes a failure under Articles 27, 29, and 30 together.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, cac.gov.cn (sourced to Xinhua News Agency), Data Security Law of the People's Republic of China

Back to the example  ·  Lint your app