China has become one of the world’s most complex regulatory environments for cybersecurity and data governance. For multinational companies (MNCs), succeeding in China now requires more than enterprise-grade controls—it demands a China-specific compliance posture that spans laws, product certifications, procurement rules, and vendor risk management. This guide explains what changed, how the rules fit together, and the practical steps global CISOs, privacy leads, and procurement teams should take in the next 6–12 months.
Executive Summary
- China’s core data and cybersecurity laws—CSL, DSL, PIPL—set obligations for system security, data classification, and personal information handling.
- Cross-border transfers have been eased for certain low-risk scenarios under 2024 rules, but high-volume or “important data” exports still trigger strict reviews.
- Product and solution compliance is non-negotiable: MLPS 2.0 grading, cryptography filings/certifications, and testing for critical network equipment can be mandatory.
- Procurement involving critical information infrastructure (CII) or sensitive sectors may require cybersecurity reviews and the use of certified products.
- Vendor risk management must be localized: assess Chinese and non-Chinese vendors’ China-specific controls, hosting, certifications, and transfer mechanisms.
China’s legal stack: what MNCs need to know
Cybersecurity Law (CSL) and MLPS 2.0
- The Cybersecurity Law (effective 2017) is the foundation for network security and includes the Multi-Level Protection Scheme 2.0 (MLPS 2.0).
- MLPS 2.0 requires organizations to classify each information system from Level 1 to Level 5 based on its impact on national security, social order, and public interest.
- Typical obligations by level:
- Level 1–2: baseline technical/organizational controls, vulnerability management, logging, and routine assessments.
- Level 3 and above: filing with the Public Security Bureau (PSB), use of compliant products, annual third-party testing, and more rigorous monitoring and incident handling.
Why it matters: Many enterprise ERP, CRM, manufacturing control, ecommerce, and cloud-hosted workloads in China land at Level 2–3. Level 3 introduces formal filings and annual audits—which can influence product choices and architecture.
Data Security Law (DSL)
- The DSL (effective 2021) requires data classification and grading, risk assessments, security controls, and special handling for “important data.”
- Sectoral catalogs and local government lists may define what counts as important data (e.g., industrial, mapping, automotive, health). If in scope, expect stricter localization and export controls.
Personal Information Protection Law (PIPL)
- PIPL (effective 2021) is China’s comprehensive privacy law, similar in spirit to the GDPR but with China-specific mechanics.
- Key duties:
- Lawful basis for processing, transparency, and purpose limitation.
- Stringent rules for sensitive personal information (biometrics, health, precise location, minors).
- Data subject rights and incident notification.
- Requirements to appoint responsible personnel, perform DPIAs, and execute processor contracts where relevant.
Cross-border data transfers: tighter design, targeted relief
The three main outbound transfer routes
- CAC Security Assessment: Mandatory for higher-risk transfers, including large-volume personal data or “important data.” Requires submission and approval by the Cyberspace Administration of China (CAC).
- Standard Contract (SCC) pathway: China-specific SCCs can be used for lower-risk transfers below certain thresholds, typically with filing to provincial CAC.
- Certification: A personal information protection certification by approved bodies can serve as a transfer mechanism for certain scenarios (e.g., intra-group transfers).
Note: Organizations handling large amounts of personal information or any “important data” should plan for security assessment. Smaller volumes or lower risk can use SCCs or certification, subject to filing and documentation.
2024 Provisions: easing some transfers
- In March 2024, the CAC issued rules that relaxed requirements for certain low-risk, routine transfers (e.g., necessary for performing contracts like cross-border payments or travel bookings, routine HR, emergencies, and small-volume personal data exports).
- Free trade zones may implement “negative lists” that further clarify exempt data flows.
- However, transfers involving important data, CIIOs, or high volumes of personal information generally still require the security assessment.
Practical guidance:
- Map your transfers by scenario, volume, and data category. Use the least burdensome legal route available, but document the rationale and conduct DPIAs.
- If you rely on exemptions, record them in your transfer registry and monitor volumes to avoid crossing thresholds.
Product and solution compliance: certifications and filings
MLPS 2.0 grading and audits
- Expect MLPS 2.0 classification for major China-hosted systems. Level 3+ drives:
- Registration with PSB.
- Use of compliant security products (meeting Chinese standards).
- Periodic third-party testing and annual assessments.
- Align your asset inventory and system boundaries early—MLPS scope creep can raise costs and timelines.
Critical network equipment and specialized cybersecurity products
- China maintains a catalogue of “critical network equipment” and “specialized cybersecurity products” that require certification/testing before sale or use in China.
- Commonly covered items include enterprise routers, core switches, firewalls, IDS/IPS, secure gateways/VPNs, SIEM/security platforms, and certain industrial security devices.
- Government and CIIO procurement often mandate certified products—plan this into architecture and bill of materials.
Commercial Cryptography Law (encryption controls)
- Products and services using commercial encryption may require certification or filing with the State Cryptography Administration.
- Expect requirements for:
- Using approved algorithms/modules for certain use cases.
- Certification/filing of cryptographic products.
- Restrictions on importing/exporting some cryptographic items.
Tip: Engage vendors early to confirm their commercial cryptography status in China—especially for VPNs, HSMs, secure communication, and encrypted endpoints.
Telecom and wireless approvals for connected devices
- Network Access License (NAL) for telecom terminal equipment and SRRC certification for radio transmission equipment may apply to IoT/OT devices.
- These are separate from cybersecurity certifications but often required in parallel.
Management system certifications
- ISO/IEC 27001 is widely recognized, and Chinese standards (e.g., GB/T 22080) are aligned.
- For cloud, check if the provider holds China-specific attestations relevant to MLPS, PIPL, and sectoral rules.
Cybersecurity review and procurement risk
Critical Information Infrastructure (CII) and the Cybersecurity Review Measures
- Operators of CII (e.g., in finance, energy, telecom, transportation, healthcare, public services) face heightened obligations, including:
- Local storage of personal information and important data.
- Security assessments for cross-border transfers.
- Cybersecurity reviews when purchasing network products/services that may impact national security.
- Reviews evaluate supply chain security, data control, product vulnerabilities, and potential national security risks.
Implication for MNCs:
- If your Chinese entity is (or supplies) a CII operator, factor review timelines into procurements, use certified products, and prepare robust supply chain documentation.
Apps, SDKs, and algorithm filings
- App operators must meet personal information compliance requirements and pass periodic inspections. Some SDKs require filings and transparent data practices.
- Algorithm recommendation services in certain categories may be subject to filing or review.
Cloud and data center choices
- China-hosted workloads should be on licensed domestic cloud infrastructure (e.g., operated by local entities) with clear segregation from global environments.
- Verify the provider’s MLPS status, incident response capabilities, cryptographic compliance, and data residency options.
Vendor risk for MNCs: a China-specific approach
Risk categories to assess
- Legal exposure: Can the vendor comply with PIPL, DSL, and sector rules? Do they understand MLPS?
- Product compliance: Does the product require (and have) certification—MLPS-compatible, cryptography certification/filing, catalogue testing?
- Data flows: What personal data or important data will the vendor access? Where is it stored and processed?
- Cross-border mechanics: Which transfer route is used (assessment, SCC, certification, exemption)? Are filings current?
- Supply chain security: Sub-processors in China and abroad; vulnerability management; SBOMs; secure development standards.
- Operational resilience: Local support, patch SLAs, logging/monitoring, backup/DR in China.
Due diligence checklist (practical)
- Provide a China addendum to your global vendor questionnaire:
- PIPL lawful basis, notices, and consent models.
- PI classification and minimization; sensitive PI handling.
- MLPS experience and past filings; target system level.
- Cryptography certification/filing status; algorithm and cipher details.
- Catalogue certification status for any covered hardware/software.
- Data localization approach, hosting region, and CSP certifications.
- Cross-border transfer route and documentation (DPIA, SCC, assessment, or exemption basis).
- Incident notification timelines aligned to Chinese expectations; regulator engagement protocols.
- Request evidence:
- Current certificates, assessment reports, filing receipts, and third-party test reports.
- Architecture diagrams marking China data residency and cross-border paths.
- Data retention and deletion procedures, including on exit.
Contractual controls to include
- China-specific data protection annex mapping PIPL and DSL duties.
- Sub-processor disclosure and approval rights within China and cross-border.
- Localization commitments for PI/important data where required.
- Audit rights and access to certifications/filings; right to suspend transfers if thresholds are crossed.
- Breach notification aligned to Chinese timelines; cooperation on CAC/PSB inquiries.
Continuous monitoring
- Establish KPIs and attestations (quarterly/semi-annual) for:
- Volume of PI exported vs. thresholds.
- Changes to product certification status or sub-processors.
- Security incidents or regulator interactions.
- Schedule annual China-focused vendor reviews, synchronized with MLPS assessment cycles.
Implementation roadmap for MNCs
0–90 days: baseline and triage
- Build your China data map: systems, vendors, PI categories, important data candidates, cross-border routes.
- Classify in-scope systems under MLPS 2.0; identify Level 3+ candidates.
- Freeze risky transfers: where routes are unclear, pause expansion and design toward SCC or exemption paths.
- Prioritize CII exposure: confirm whether you operate or supply CII and the implications for procurement reviews.
90–180 days: compliance architecture
- Choose and document transfer routes: CAC assessment, SCC, certification, or exemption basis; complete filings where needed.
- Align products to certifications: swap or upgrade to certified network/security equipment; initiate cryptography filings if applicable.
- Contract updates: roll out China data processing terms and vendor addenda; renegotiate SLAs for incident response and regulator cooperation.
- Strengthen logging and DPIAs: ensure auditable evidence for PI handling, sensitive PI flows, and important data safeguards.
6–12 months: operationalize and optimize
- Complete MLPS filings and third-party testing for Level 3 systems; address remediation items.
- Automate monitoring: dashboards for PI export volumes, threshold alerts, and certification status tracking.
- Conduct a tabletop exercise: simulate a regulator inquiry on cross-border transfers or app data compliance.
- Begin continuous improvement: reduce sensitive PI collection, adopt privacy-enhancing tech, and shift to exempt/low-risk transfer scenarios where feasible.
Common pitfalls and how to avoid them
- Assuming global policies are sufficient: China-specific obligations (MLPS, cryptography filings, catalogue certifications) require bespoke controls and documentation.
- Underestimating timelines: Security assessments, certifications, and product swaps can take months—plan early, especially for CII-related procurements.
- Ignoring “important data”: Even if you think you don’t process it, confirm with sector regulators and track evolving local catalogs.
- Treating 2024 transfer easings as a blanket waiver: Exemptions are scenario- and volume-specific. Keep evidence and watch your thresholds.
- Overlooking app/SDK compliance: Mobile apps and embedded SDKs face strict personal information checks and periodic audits.
FAQs
Do we have to store all data in China?
- Not necessarily. CIIOs and entities processing important data face stricter localization. For others, cross-border transfers are allowed if you use the appropriate legal route (assessment, SCC, certification) or qualify for exemptions.
Which systems typically fall under MLPS Level 3?
- Systems supporting core operations that, if compromised, could significantly impact public order or economic activity—common examples include large ecommerce backends, manufacturing execution systems, or financial platforms.
Can we keep using our global VPN and encryption stack?
- You may need to adapt. Commercial encryption in China is regulated; certain products/services require certification or filing. Confirm legality and certification status, and consider China-specific alternatives where necessary.
What about using global clouds?
- China-hosted workloads should run on locally licensed cloud infrastructure operated by Chinese entities. Global cloud brands often operate separate China regions via local partners—check their certifications and data residency controls.
Conclusion
For MNCs, cybersecurity in China has matured into a defined—if complex—discipline. The path forward is manageable with a localized operating model: classify systems under MLPS, align products to Chinese certifications, design lawful cross-border transfer routes, and embed China-specific controls into vendor risk management. Done well, you’ll reduce legal exposure, speed procurement, and create a durable foundation for secure, compliant growth in the world’s second-largest economy.
Keywords to target:
- China Cybersecurity Law, MLPS 2.0, Data Security Law, Personal Information Protection Law
- Cross-border data transfer China, CAC security assessment, China SCC exemptions
- Critical network equipment certification, commercial cryptography certification China
- CII cybersecurity review, vendor risk China, data localization China, China cloud compliance





