Legal authority

Data Security Law (China, 2021)

China's Data Security Law is a national statute governing data-processing security, classification, risk management and official powers. Adopted on 10 June 2021, it entered into force on 1 September 2021 and remained in force on 30 July 2026. It frames data as a security and development concern within state policy and Economic statecraft.

Structure and scope

The law establishes a classified and graded protection approach, duties for data processors, risk monitoring, incident response and controls concerning important data. It also contains provisions concerning foreign legal or enforcement requests and permits measures responding to discriminatory foreign data-related restrictions.

Its reach is not identical to every later Chinese data rule. The Personal Information Protection Law addresses personal information. Rules on Data-localisation and cross-border-data restriction define security assessments, contracts, certification and exemptions for specified transfers. Network-data regulations effective in 2025 added operational requirements. Cross-border certification rules issued later belong to that evolving framework, not to the 2021 Act alone.

Strategic classification

The statute supports resilience, regulatory control and potential denial. It does not make every Chinese data-compliance action coercion. A requirement imposed on a domestic processor, a cross-border transfer assessment, an enforcement decision and retaliation against a foreign measure have different purposes and authorities.

The law sits beside the Foreign Relations Law (China, 2023) and Export Control Law (China, 2020), but those statutes regulate different conduct. Treating Data as strategic resource and cross-border data flows as important does not establish hostile intent or prove that a particular investigation served foreign-policy compellence.

Current analysis must specify the data category, processor, transfer route, authority and operative implementing rule. Later network-data and cross-border provisions should be cited directly. The Data Security Law supplies the framework, not every detailed threshold or filing procedure.

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'Data Security Law (China, 2021).' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 30 July 2026. https://jamesjtennant.com/entries/data-security-law-china-2021/.

Suggest an edit