Chinese flag with a hologram of a lock symbolizing data protection.

“Important Data” Under Chinese Law: Definition, Identification, and Compliance Obligations

Few concepts in Chinese data law cause as much uncertainty for European companies as “important data”重要数据). The term triggers some of the strictest obligations in China’s data regime, including mandatory localization and government security assessments. This blog explains what important data is, how to identify it, and what obligations follow under the Cybersecurity Law (CSL) and the Data Security Law (DSL).

What Is Important Data?

The CSL introduced the term in 2017 under Article 37 but never defined it. The DSL built the surrounding framework in 2021. It established a national system that classifies data by its importance to economic and social development and by the harm that would result from its compromise. It created three tiers: general data, important data, and core national data, with core data subject to the strictest controls.

A workable definition arrived only in 2024. The national standard GB/T 43697-2024 defines important data as data specific to certain fields, groups, or regions, or reaching a certain precision and scale, that, once leaked, tampered with, or destroyed, may directly endanger national security, economic operation, social stability, or public health and safety. The Network Data Security Management Regulations (“NDSMR”), effective 1 January 2025, carry a materially aligned statutory definition into binding law. Data that affects only a single organization or individual generally falls outside the concept.

How to Identify Important Data: A Practical Sequence

Identification is catalog-driven, not self-judged in the first instance. The DSL directs regions and sector regulators to formulate important data catalogs for their respective areas under Article 21. In practice, companies should proceed in four steps.

First, check for notifications and catalogs. Under Article 2 of the 2024 Regulations on Promoting and Regulating Cross-Border Data Flow, data does not need to be treated as important data unless a regulator or region has notified the controller, or the data appears in a publicly released catalog. This presumption is the single most useful safe harbor in the regime.

Second, screen your data against the factors in GB/T 43697-2024. Its Annex G lists considerations such as effects on territorial security, undisclosed natural resource information, military relevance, strategic reserves, critical infrastructure, and key economic sectors. Sector regulators use these factors when building catalogs, so the standard is the best available proxy.

Third, document the assessment. The identification exercise should be repeatable and defensible, especially for industrial, mapping, health, and automotive data.

Fourth, report where required. The Article 29 of NDSMR require controllers to identify and declare important data in line with national catalog mechanisms.

Relationship to the CSL and the DSL

The two laws play different roles. The CSL is network-focused. It created the multi-level protection scheme for network operators and attached the first hard consequence to important data: localization for critical information infrastructure operators (CIIOs). The DSL is data-focused. It governs all data processing, established the classification system, and assigned catalog-making to regions and sectors. The NDSMR and GB/T 43697-2024 now supply the definitional and operational detail both laws lacked.

Obligations Once Data Is Classified as Important

Under the DSL, controllers of important data must designate a person responsible for data security and set up a data security management body. They must conduct periodic risk assessments of their processing activities and submit the reports to the competent regulator; reports must cover data types, volumes, processing activities, risks, and countermeasures. Cross-border transfers of important data are restricted: CIIOs follow the CSL regime, and all other controllers follow rules set by the Cyberspace Administration of China. In practice, exporting important data requires a government security assessment.

Under the CSL, the consequences fall mainly on CIIOs. Personal information and important data collected or generated in China must be stored in mainland China. Any transfer abroad that is truly necessary requires a security assessment, which aligns with the obligations under DSL. 

The NDSMR add further duties: annual risk assessment reports to provincial or higher regulators, risk assessments before sharing or entrusting important data, and disposal plans when mergers or insolvencies affect important data.

Takeaway

European groups with Chinese subsidiaries should take a measured approach. Data does not need to be treated as important data unless a regulator has issued a notification or the data appears in a published catalog. Until then, three measures are sufficient: maintain a documented screening process, monitor the catalogs issued for your sector, and prepare internal procedures so that the DSL and CSL obligations can be implemented promptly if a designation is made.



No comments


« Previous post