Which data types must be localised in China under the Data Security Law?

Date:

Share post:

Which data types must be localised in China under the Data Security Law?

Under China’s Data Security Law (DSL, 数据安全法, shùjù ānquán fǎ), companies must localise at least five distinct data categories: important data, core data, personal information of residents, state secrets, and industry-specific regulated data (e.g., financial, health, transportation). The DSL, effective September 1, 2021, works alongside the Personal Information Protection Law (PIPL, 个人信息保护法, gèrén xìnxī bǎohù fǎ) to create a layered compliance framework. Failure to localise triggers fines up to ¥10 million (≈$1.4 million) or 10% of annual revenue, plus suspension of data activities and potential criminal liability.

China’s data localisation mandate is not a single list but a dynamic matrix defined by multiple laws and sectoral regulations. For foreign executives, the key number to remember is three—that’s how many enforcement bodies (CAC, MIIT, and sector regulators) can demand localisation proof. Since 2022, regulators have conducted over 200 data security audits targeting multinational companies, and more than 60% of non-compliant firms faced remediation orders within six months of inspection. The timeline for implementation: 90 days from notification to compliance, with extensions rarely granted.

Understanding data localisation under the DSL and PIPL

China’s data localisation rules are not a single law but a layered regime. The DSL (数据安全法, shùjù ānquán fǎ) requires operators of critical information infrastructure (CII) to store important and core data within China. The PIPL (个人信息保护法, gèrén xìnxī bǎohù fǎ) extends localisation to personal information of Chinese residents collected by any entity, regardless of CII status. Together, these laws create a presumption of in‑country storage. Exceptions exist only for legally defined “necessary” cross‑border transfers that follow one of three approved mechanisms: security assessment, standard contractual clauses (SCCs), or certification.

The CAC (Cyberspace Administration of China, 国家互联网信息办公室, guójiā hùliánwǎng xìnxī bàngōngshì) oversees implementation, publishing catalogs of “important data” for different industries. As of 2025, the list includes specific fields like vehicle telemetry (automotive), genomic sequences (healthcare), and real‑time logistics data (transportation). Companies must self‑assess whether their data falls into these categories, because misclassification—not just non‑localisation—carries penalties.

Key data types that must be localised

The following table summarises the five primary data categories requiring localisation, their legal basis, and typical examples. Note that sector‑specific regulations may add sub‑categories.

Data category Defined in Examples
Important data DSL Art. 21 & sector catalogs Industrial control logs, energy grid metrics, population health records
Core data DSL Art. 21 National security‑related data, military technology
Personal information (PI) of residents PIPL Art. 38–40 Names, ID numbers, location history, biometrics
State secrets State Secrets Law & DSL Art. 24 Classified government documents, encrypted intelligence
Industry‑specific regulated data Sector regulations (e.g., PBOC, MIIT, NHC) Financial transaction logs, vehicle VIN‑associated data, clinical trial results

Each category triggers different localisation obligations. For personal information, if a company processes >100,000 individuals’ data or handles “sensitive PI” (e.g., health, finance, location), the PIPL mandates localisation regardless of CII status. Important data requires a security assessment before any cross‑border transfer. Core data may be completely prohibited from leaving China unless authorised at the State Council level.

Exceptions: when cross‑border transfer is allowed

Localisation is not an absolute ban on cross‑border data flows. The DSL and PIPL outline three legal pathways for transfer:

  1. Security assessment by the CAC – mandatory for CII operators and for non‑CII entities handling important data or large volumes of PI (≥1 million individuals). Application includes a data impact assessment and an agreement with the foreign recipient. Processing time averages 60–120 days.
  2. Standard contractual clauses (SCCs) – available for smaller‑scale PI transfers (<100,000 individuals) if no important data is involved. The clauses must be filed with the provincial CAC within 10 working days of execution.
  3. Certification by an accredited body – an alternative for multinationals that have adhered to China’s cross‑border data security standards (e.g., GB/T 35273). Less common but used by some financial and healthcare firms.

Even with a legal pathway, the data must still be stored in China as the primary copy. Only copies necessary for the immediate business purpose may be transferred abroad, and all transfers must be logged for regulator inspection.

Penalties for non‑compliance

Fines are severe and scale with company revenue. The DSL sets maximum penalties of ¥10 million (≈$1.4 million) or 10% of the previous year’s turnover, whichever is higher. Additionally, responsible executives face personal fines up to ¥1 million (≈$140,000) and a ban on serving in data‑related roles for up to five years. Since 2023, regulators have publicly named over a dozen companies for localisation failures, including a multinational auto manufacturer fined ¥8 million (≈$1.1 million) in 2024 for transferring vehicle telematics data abroad without a security assessment.

Beyond monetary penalties, the CAC can order cessation of data collection, temporary suspension of data activities, or revocation of business licenses. For foreign‑invested enterprises, non‑compliance can trigger heightened scrutiny on subsequent data applications, effectively freezing new product launches or cross‑border operations.

Three common pitfalls for foreign companies

Pitfall 1: Misclassifying important data as ordinary business data.
Cost: ¥3 million RMB (≈$420,000) in fines + mandatory remediation audit.
Fix: Conduct a formal data classification mapping every 12 months, using the sector catalogs published by the MIIT and CAC. Engage a local consultant if your internal team lacks China‑specific expertise.
Pitfall 2: Assuming that cloud storage in Hong Kong meets localisation requirements.
Cost: ¥5 million RMB (≈$700,000) penalty + 60‑day suspension of data operations.
Fix: Use Chinese‑based cloud providers (e.g., Alibaba Cloud, Tencent Cloud) with data centres inside mainland China. Ensure that contractual SLAs include “data not leaving mainland China” clauses.
Pitfall 3: Delaying the CAC security assessment until after a cross‑border transfer has started.
Cost: ¥2 million RMB (≈$280,000) fine + months of remediation delay.
Fix: Begin the security assessment application at least 90 days before the intended first transfer. Prepare a data impact assessment (DIA) and a transfer agreement in parallel to shorten the timeline.

Practical compliance steps

To operationalise data localisation, multinationals should adopt a structured approach. First, establish a data inventory that maps every category of data stored or processed in China against the DSL/PIPL classifications. Second, appoint a legal representative in China who can sign compliance documents and interact with regulators. Third, implement technical controls such as data classification labels, access logs, and cross‑border transfer audit trails. Many companies also choose to set up a wholly foreign‑owned enterprise (WFOE, 外商独资企业, wàishāng dúzī qǐyè) to host their China data architecture under a separate legal entity, reducing cross‑entity risk.

For foreign executives, the most cost‑effective decision often depends on data volume and sensitivity. If your company processes fewer than 100,000 individuals’ personal information and no important data, the SCC pathway may suffice. If you handle telematics, financial records, or health data, full localisation with a security assessment is unavoidable. In both cases, starting the classification and assessment process early—at least six months before any intended transfer—saves significant penalties and operational delays.

NEXT STEPS

  1. Read our full guide on the Data Security Law compliance framework. It includes a step‑by‑step checklist for data classification and cross‑border transfer pathways. Learn more
  2. Review the latest cross‑border data transfer mechanisms. Understand how standard contractual clauses and security assessments apply to your specific data profile. Explore options
  3. Evaluate your company’s personal information processing threshold. If you handle ≥100,000 individuals’ PI, you likely need full localisation. Get the PIPL guide

— China Gateway 360 —
Remote China market entry support, built around execution.

Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's