China Data Localisation Requirements Audit Checklist Tool for Foreign Companies

Date:

Share post:






China Data Localisation Requirements Audit Checklist Tool for Foreign Companies


China Data Localisation Requirements Audit Checklist Tool for Foreign Companies

China’s data localisation framework requires certain categories of data to be stored within the People’s Republic of China, and restricts — or in some cases prohibits — the cross-border transfer of that data. The legal basis for these requirements is distributed across three primary laws — the Cybersecurity Law (CSL, 2017), the Data Security Law (DSL, 2021), and the Personal Information Protection Law (PIPL, 2021) — supplemented by sectoral regulations issued by industry-specific regulators. For foreign businesses operating in China, navigating this patchwork of localisation requirements is a significant compliance challenge. This comprehensive audit checklist tool provides foreign companies with a systematic framework for assessing their data localisation compliance status, identifying gaps, and implementing corrective measures.

The Legal Framework for Data Localisation in China

Understanding the scope of data localisation obligations requires reference to multiple legal instruments. The following table provides an overview of the primary localisation requirements.

Legal Instrument Effective Date Scope of Localisation Requirement Entities Covered Penalties for Non-Compliance
Cybersecurity Law (CSL) Article 37 June 1, 2017 Personal information and important data collected and generated by CII operators in China must be stored within China CII operators in all sectors Up to RMB 1 million fine; possible business suspension; liability for responsible individuals up to RMB 100,000
Data Security Law (DSL) Article 31 September 1, 2021 Important data collected by CII operators and other entities processing important data must be stored within China; cross-border transfer requires security assessment CII operators + entities processing important data Up to RMB 10 million fine; business licence revocation; criminal liability in severe cases
Personal Information Protection Law (PIPL) Article 40 November 1, 2021 CII operators and processors of large volumes of personal information must store personal information collected in China within China; cross-border transfer must pass security assessment CII operators + entities processing > 1M individuals’ data Up to RMB 50 million or 5% of annual revenue; business suspension; blacklisting; individual fines up to RMB 100,000
Measures for Security Assessment of Cross-Border Data Transfer (2022, amended 2024) September 1, 2022 Specifics localisation obligations for important data, CII operators, and high-volume personal information processors As per CSL, DSL, and PIPL thresholds Mandatory security assessment required before any transfer; transfers without approval are unlawful
PBOC Financial Data Security Regulations Various Financial data (customer identity, transaction records, credit information, account data) must be stored within China All financial institutions operating in China PBOC administrative penalties; business restrictions up to RMB 50 million
NHC Health Data Regulations Various (updated 2024) Health records, genomic data, clinical trial data, and epidemiological data must be stored within China All healthcare providers, research institutions, and health data processors NHC administrative sanctions; suspension of clinical trial approvals; fines up to RMB 10 million
MIIT Industrial Data Security Guidelines 2023 Industrial data classified as important data or core data must be stored within China All industrial enterprises in sectors under MIIT regulation MIIT corrective orders; suspension of telecom/internet business licences
State Council Regulations on Automobile Data Security (2022) October 1, 2022 Automotive data including vehicle location data, driving behaviour data, and in-vehicle personal information must be stored within China All automotive manufacturers and service providers operating in China MIIT/CAC joint enforcement; vehicle type approval impacts; fines up to RMB 10 million

The Data Localisation Audit Checklist — 8 Audit Modules

This audit checklist is organised into eight modules that collectively cover all data localisation compliance areas. Each module contains specific audit checklist items with guidance on how to assess compliance, required evidence, and common non-compliance findings. The checklist is designed to be used by internal audit teams or external compliance consultants to conduct a comprehensive data localisation compliance audit.

Module 1: Organisational Scope and Applicability Assessment

☐ 1.1 Determine whether the organisation is a CII operator

Audit Procedure: Review any written notifications from sectoral regulators regarding CII operator designation. If no notification has been received, assess whether the organisation’s operations fall within CII designation criteria under Article 19 of the Regulations on Security Protection of Critical Information Infrastructure. Document the basis for the conclusion.

Required Evidence: Copy of CII operator designation notice (if applicable), or documented analysis of CII designation criteria assessment with legal counsel sign-off.

☐ 1.2 Identify all data categories processed by the organisation

Audit Procedure: Conduct a comprehensive data inventory covering all business operations, support functions, and IT systems. Classify each data category as: personal information (general or sensitive), important data (referencing applicable sectoral catalogues), core data, or other data. Map data to specific data processing systems and storage locations.

Required Evidence: Complete data inventory register with classification labels, data flow diagrams for all major processing activities, and cross-reference to applicable important data catalogues.

☐ 1.3 Measure total personal information processing volume

Audit Procedure: Calculate the total number of unique individuals whose personal information is processed by the organisation, including employees, customers, suppliers, website visitors, app users, and any other data subjects. Calculate cumulative cross-border transfer volumes for the period since January 1 of the previous year.

Required Evidence: Data volume calculation methodology document, population counts by data category, and certification from data custodian of calculation accuracy.

☐ 1.4 Determine applicable sectoral localisation regulations

Audit Procedure: Identify all sectoral regulators applicable to the organisation’s operations based on industry classification, business scope, and licences held. Review each applicable sectoral regulation for data localisation provisions that may be more stringent than baseline requirements. Create a regulatory compliance matrix showing each regulation and its localisation requirements.

Required Evidence: Regulatory applicability matrix with relevant regulation texts excerpted and cross-referenced to internal data processing activities.

Module 2: Data Storage Location Audit

☐ 2.1 Verify physical storage location of all personal information and important data

Audit Procedure: For each data processing system identified in Module 1, verify the physical location of primary production databases, backup databases, disaster recovery systems, and archived data. Document server locations, cloud service provider data centre locations, and any data replication arrangements with overseas systems.

Required Evidence: System-level storage location inventory, cloud service provider data centre confirmation letters, and network architecture diagrams showing data flows and storage nodes.

☐ 2.2 Assess cloud service provider compliance with Chinese requirements

Audit Procedure: Review cloud service agreements to confirm that all cloud services hosting Chinese personal information or important data are provisioned from data centres physically located within mainland China. Verify that cloud providers hold Multi-Level Protection Scheme (MLPS / 等级保护) certification at the appropriate level for the data sensitivity. Document any contractual provisions that allow the cloud provider to replicate data to overseas locations.

Required Evidence: Cloud service agreements with data location clauses, MLPS certificates, cloud provider security compliance certifications, and data replication audit trail.

☐ 2.3 Identify any data stored in overseas systems

Audit Procedure: Scan network traffic and system configurations to identify any personal information or important data that is being transmitted to or stored on overseas servers. This includes data stored in global HR systems, CRM platforms, ERP systems, email systems, collaboration tools, and cloud storage services. Document each instance of overseas data storage with data categories, volumes, system owner, and business purpose.

Required Evidence: Network traffic analysis report, system configuration audit results, and list of all overseas systems with data storage findings.

☐ 2.4 Verify that backup and disaster recovery data is stored within China

Audit Procedure: Review backup and disaster recovery (DR) configurations for all systems identified as containing personal information or important data. Verify that backup data is stored in Chinese data centres and that DR sites are located within mainland China. Document any exceptions where backup or DR data is stored overseas and assess the compliance risk.

Required Evidence: Backup configuration documentation, DR plan with site locations, backup storage location inventory, and DR testing records showing Chinese-only data footprint.

Module 3: Data Classification and Labelling Audit

☐ 3.1 Verify data classification framework aligns with legal requirements

Audit Procedure: Review the organisation’s data classification policy and verify that it aligns with the three-tier classification system under the DSL (general data, important data, core data) and the PIPL personal information classification (general personal information, sensitive personal information). Verify that classification criteria reference the applicable sectoral important data catalogues.

Required Evidence: Data classification policy document, mapping to legal classification requirements, and evidence of policy approval by senior management.

☐ 3.2 Confirm automated classification tools are correctly configured

Audit Procedure: If automated data classification tools are deployed, verify that classification rules are configured to correctly identify important data based on applicable sectoral catalogues, sensitive personal information under PIPL Article 28, and data types subject to sectoral localisation requirements. Test classification accuracy on a sample of data across different business units.

Required Evidence: Classification tool configuration documentation, classification accuracy test results on a sample of at least 500 data records, and evidence of quarterly classification rule updates.

☐ 3.3 Verify that data labelling is consistently applied

Audit Procedure: Conduct a sample audit of data repositories (databases, file shares, email archives, document management systems) to verify that classified data carries appropriate labels indicating its classification level. Check at least 200 data items across different business units and systems. Document labelling gaps and assess their severity.

Required Evidence: Data labelling audit report with sample size and gap analysis, corrective action plan for unlabelled or mislabelled data.

Module 4: Cross-Border Transfer Audit

☐ 4.1 Inventory all existing cross-border data transfers

Audit Procedure: Identify and document every current cross-border data transfer. For each transfer, document: sending entity, receiving entity, data categories and volumes, transfer mechanism, legal basis, frequency, purpose, and whether localisation requirements apply. Include transfers to parent companies, affiliates, subsidiaries, third-party service providers, cloud platforms, and any other overseas recipient.

Required Evidence: Complete cross-border data transfer register with all fields completed, signed off by business unit data owners.

☐ 4.2 Verify that each transfer has a valid legal mechanism

Audit Procedure: For each transfer identified, verify that an appropriate cross-border data transfer mechanism (CAC Security Assessment, China SCC, or Certification) has been implemented. Check that required filings have been made with the provincial CAC (for SCCs) or that certification has been obtained (for Certification). For transfers subject to mandatory Security Assessment, verify that approval has been received and is still valid.

Required Evidence: Copy of CAC Security Assessment approval certificate or SCC filing receipt or certification certificate for each transfer, with validity dates checked.

☐ 4.3 Identify transfers subject to localisation requirements

Audit Procedure: Cross-reference the cross-border transfer register against the localisation requirements identified in Module 1. Identify any transfers that involve data subject to mandatory localisation (e.g., financial data, health data, automotive data) and verify that the transfer complies with both the general cross-border transfer regulations and any sectoral-specific localisation restrictions.

Required Evidence: Cross-reference matrix showing transfer vs. localisation requirement compliance status, with findings documented for any non-compliant transfers.

☐ 4.4 Verify that data subject consent has been obtained

Audit Procedure: Review consent records for data subjects whose personal information is transferred cross-border. Verify that separate consent specific to cross-border transfer was obtained (not bundled with general consent). Check that consent notices include all required information under PIPL Article 39. Document any gaps in consent coverage.

Required Evidence: Consent records sample (at least 50 records), consent notice template, consent management system audit log, and gap analysis report.

Module 5: Sectoral-Specific Localisation Compliance Audit

☐ 5.1 Financial data localisation compliance

Audit Procedure: If the organisation operates in or provides services to the financial sector, verify that all customer financial data (account information, transaction records, credit data, investment records, insurance records) is stored within China. Review PBOC regulations on financial data localisation (《金融数据安全 数据安全分级指南》) for applicable data categories and security requirements. Verify that any cross-border financial data transfers (e.g., for global treasury management) have received PBOC approval.

Required Evidence: Financial data storage location inventory, PBOC compliance confirmation, and any cross-border transfer approvals from PBOC.

☐ 5.2 Health and medical data localisation compliance

Audit Procedure: If the organisation processes health data (including clinical trial data, patient records, genomic data, epidemiological data, hospital administration data), verify compliance with NHC health data regulations and the Measures for Management of Health and Medical Big Data Standards. Confirm that all health data is stored in China-licensed data centres with appropriate MLPS certification. For clinical trial data, verify compliance with NMPA clinical trial data management requirements including the requirement for Chinese investigator site data to remain in China.

Required Evidence: Health data inventory and classification, data centre MLPS certification, NHP (National Health Commission) or NMPA compliance confirmation.

☐ 5.3 Automotive data localisation compliance

Audit Procedure: If the organisation manufactures, sells, or services vehicles in China, verify compliance with the Provisions on Management of Automobile Data Security (Trial) (《汽车数据安全管理若干规定(试行)》). Confirm that vehicle location data, driving behaviour data, in-vehicle camera data, and any personal information collected by connected vehicle systems is stored within China. Verify that any cross-border transfer of automotive data for vehicle development, navigation, or fleet management purposes has received the required CAC security assessment.

Required Evidence: Automotive data storage location inventory, CAC security assessment approval for automotive data transfers (if applicable), and MIIT compliance confirmation.

☐ 5.4 Industrial and critical infrastructure data localisation compliance

Audit Procedure: If the organisation operates in sectors regulated by MIIT (telecommunications, internet platforms, industrial manufacturing, industrial internet), verify compliance with MIIT data security management measures and any sector-specific important data catalogues. Confirm that industrial data classified as important data or core data under applicable sectoral catalogues is stored within China.

Required Evidence: Industrial data classification inventory, MIIT sectoral catalogue cross-reference, and data centre location verification.

Module 6: Organisational Governance Audit

☐ 6.1 Verify appointment of data security officer

Audit Procedure: Confirm that the organisation has appointed a data security officer (DSO) and a dedicated data security management body as required by the DSL for entities processing important data. Verify that the DSO’s role, responsibilities, reporting line, and authority are documented. Confirm that the DSO has adequate resources and organisational authority to implement data localisation compliance measures.

Required Evidence: DSO appointment letter, job description, organisational chart showing reporting line, and evidence of DSO involvement in data localisation compliance decisions.

☐ 6.2 Review data localisation policies and procedures

Audit Procedure: Review the organisation’s data governance policies and procedures for explicit references to data localisation requirements. Verify that policies address: data classification and localisation applicability, data storage location requirements, cross-border transfer procedures and approvals, consent management, vendor management including cloud service provider localisation requirements, and incident response for data localisation breaches.

Required Evidence: Data governance policy suite with localisation sections highlighted, policy approval records, and evidence of distribution to all relevant employees.

☐ 6.3 Verify local representative appointment (if applicable)

Audit Procedure: If the organisation is a foreign business without a legal establishment in China, verify that a local representative has been appointed as required by PIPL Article 53. Confirm that the representative’s name, contact information, and scope of authority are documented and that the representative has been registered with the relevant provincial CAC office.

Required Evidence: Local representative appointment agreement, registration documentation with provincial CAC, and evidence of representative’s ability to fulfil compliance responsibilities.

Module 7: Technical Controls Audit

☐ 7.1 Verify network segmentation controls

Audit Procedure: Review network architecture to confirm that systems storing personal information and important data subject to localisation requirements are logically or physically segmented from systems that have connectivity to overseas networks. Verify that data leaving the China network segment is logged and requires explicit authorisation. Test network segmentation controls through penetration testing or architecture review.

Required Evidence: Network architecture diagram with segmentation highlighted, firewall rule sets, network access control lists, and penetration test results.

☐ 7.2 Verify data loss prevention (DLP) controls

Audit Procedure: Review DLP system configuration to confirm that it detects and blocks unauthorised cross-border transfers of data subject to localisation requirements. Verify that DLP rules are configured to identify important data, sensitive personal information, and sectoral-specific localised data categories. Test DLP effectiveness through controlled data transfer exercises.

Required Evidence: DLP configuration documentation, DLP rule sets for localised data categories, DLP detection and blocking logs, and DLP effectiveness test results.

☐ 7.3 Verify data-at-rest encryption within China

Audit Procedure: Confirm that all personal information and important data stored in China-based systems is encrypted at rest using approved encryption algorithms under China’s commercial encryption regulations. Verify that encryption keys are managed in accordance with Chinese requirements and are stored within China. Document key management procedures and key storage locations.

Required Evidence: Encryption implementation documentation, commercial encryption compliance confirmation, key management policy, and key storage location verification.

Module 8: Audit Reporting and Remediation Tracking

☐ 8.1 Compile audit findings and risk ratings

Audit Procedure: Aggregate findings from all audit modules into a consolidated audit report. Classify each finding by severity (critical, high, medium, low) based on regulatory risk, potential penalty exposure, and business impact. Include specific regulatory references for each finding.

Required Evidence: Consolidated audit report with findings register, severity classification, and regulatory references.

☐ 8.2 Develop remediation plan with timelines

Audit Procedure: For each audit finding, develop a specific remediation action with assigned owner, target completion date, and success criteria. Prioritise critical and high-severity findings for immediate remediation. Ensure remediation actions address root causes rather than symptoms.

Required Evidence: Remediation plan with actions, owners, timelines, and success criteria. Status tracking mechanism (spreadsheet, compliance management tool, or project management platform).

☐ 8.3 Establish ongoing compliance monitoring

Audit Procedure: Implement ongoing monitoring mechanisms to detect new data localisation compliance issues as they arise. This should include: automated data discovery scans on a quarterly schedule, network traffic monitoring for unauthorised cross-border data flows, regulatory change monitoring for new localisation requirements, and periodic data localisation compliance reviews (at least annually).

Required Evidence: Monitoring schedule, automated monitoring tool deployment confirmation, regulatory change monitoring process documentation, and evidence of periodic review completion.

Audit Scoring and Reporting Template

The following scoring methodology can be used to calculate an overall data localisation compliance score based on the audit findings:

Compliance Level Score Range Description Recommended Action
Fully Compliant 90–100% All applicable localisation requirements are met. No critical or high-severity findings. Medium/low findings with remediation plans in place. Continue monitoring; schedule next full audit in 12 months.
Substantially Compliant 70–89% Most requirements met. Some medium-severity findings exist. No critical findings. Limited high-severity findings with remediation in progress. Prioritise remediation of high-severity findings within 90 days. Schedule next full audit in 6 months.
Partially Compliant 50–69% Significant compliance gaps exist. Critical or multiple high-severity findings present. Remediation plans not yet fully developed. Engage external counsel. Develop and implement remediation plan within 60 days. Schedule monthly compliance review until score exceeds 70%.
Non-Compliant Below 50% Major localisation compliance failures. Unauthorised cross-border transfers likely occurring. Significant regulatory exposure. Immediate suspension of non-compliant data processing activities. Engage external legal counsel and compliance consultants. Report to Board of Directors. Implement emergency remediation within 30 days.

Critical Warning: Data localisation non-compliance carries some of the most severe penalties in China’s regulatory framework. Unlike general data protection violations, localisation violations can trigger multi-regulator enforcement involving the CAC, the applicable sectoral regulator, and potentially the Ministry of Public Security. In the most serious cases — particularly where important data or core data has been transferred in violation of localisation requirements — responsible individuals may face criminal liability under Articles 286 and 287 of China’s Criminal Law for illegal acquisition, provision, or dissemination of data. Foreign companies must treat data localisation compliance as a board-level priority with appropriate governance, resources, and accountability structures.

Conclusion

China’s data localisation requirements represent a fundamental shift in data governance that foreign businesses cannot afford to ignore. The regulatory framework is complex, multi-layered, and continues to evolve as sectoral regulators issue new important data catalogues and localisation rules. This comprehensive audit checklist tool provides foreign companies with a systematic methodology for assessing their compliance status across all applicable legal instruments, data categories, and business operations. By working through the eight audit modules, identifying gaps, implementing remediation measures, and establishing ongoing monitoring, foreign businesses can achieve and maintain data localisation compliance that protects them from enforcement risk while enabling compliant cross-border operations where permitted. The key to successful localisation compliance is not a one-time audit project, but a sustained commitment to data governance that keeps pace with China’s rapidly evolving regulatory environment.

Last updated: July 2026. Regulatory references may change. Always verify with official sources before acting on this information.


Related articles

What Documents Are Required for Contract Litigation in China? An Essential FAQ for Foreign Executives

What Documents Are Required for Contract Litigation in China? An Essential FAQ for Foreign Executives Contract litigation in China requires 7 essentia

Are non-compete clauses enforceable against Chinese employees?

Are non-compete clauses enforceable against Chinese employees? Are non-compete clauses enforceable against Chinese employees? Quick Answer Yes, non-co

How to get a contract notarized and legalized for use in China?

How to get a contract notarized and legalized for use in China? How to get a contract notarized and legalized for use in China? Quick Answer To get a

What damages can foreign companies recover in China contract cases?

What damages can foreign companies recover in China contract cases? What damages can foreign companies recover in China contract cases? Quick Answer U