Which data types must be localised in China under the Data Security Law?

Date:

Share post:

Which data types must be localised in China under the Data Security Law?

Under China’s Data Security Law (DSL, 数据安全法, shùjù ānquán fǎ), companies must localise at least five distinct data categories: important data, core data, personal information of residents, state secrets, and industry-specific regulated data (e.g., financial, health, transportation). The DSL, effective September 1, 2021, works alongside the Personal Information Protection Law (PIPL, 个人信息保护法, gèrén xìnxī bǎohù fǎ) to create a layered compliance framework. Failure to localise triggers fines up to ¥10 million (≈$1.4 million) or 10% of annual revenue, plus suspension of data activities and potential criminal liability.

China’s data localisation mandate is not a single list but a dynamic matrix defined by multiple laws and sectoral regulations. For foreign executives, the key number to remember is three—that’s how many enforcement bodies (CAC, MIIT, and sector regulators) can demand localisation proof. Since 2022, regulators have conducted over 200 data security audits targeting multinational companies, and more than 60% of non-compliant firms faced remediation orders within six months of inspection. The timeline for implementation: 90 days from notification to compliance, with extensions rarely granted.

Understanding data localisation under the DSL and PIPL

China’s data localisation rules are not a single law but a layered regime. The DSL (数据安全法, shùjù ānquán fǎ) requires operators of critical information infrastructure (CII) to store important and core data within China. The PIPL (个人信息保护法, gèrén xìnxī bǎohù fǎ) extends localisation to personal information of Chinese residents collected by any entity, regardless of CII status. Together, these laws create a presumption of in‑country storage. Exceptions exist only for legally defined “necessary” cross‑border transfers that follow one of three approved mechanisms: security assessment, standard contractual clauses (SCCs), or certification.

The CAC (Cyberspace Administration of China, 国家互联网信息办公室, guójiā hùliánwǎng xìnxī bàngōngshì) oversees implementation, publishing catalogs of “important data” for different industries. As of 2025, the list includes specific fields like vehicle telemetry (automotive), genomic sequences (healthcare), and real‑time logistics data (transportation). Companies must self‑assess whether their data falls into these categories, because misclassification—not just non‑localisation—carries penalties.

Key data types that must be localised

The following table summarises the five primary data categories requiring localisation, their legal basis, and typical examples. Note that sector‑specific regulations may add sub‑categories.

Data categoryDefined inExamples
Important dataDSL Art. 21 & sector catalogsIndustrial control logs, energy grid metrics, population health records
Core dataDSL Art. 21National security‑related data, military technology
Personal information (PI) of residentsPIPL Art. 38–40Names, ID numbers, location history, biometrics
State secretsState Secrets Law & DSL Art. 24Classified government documents, encrypted intelligence
Industry‑specific regulated dataSector regulations (e.g., PBOC, MIIT, NHC)Financial transaction logs, vehicle VIN‑associated data, clinical trial results

Each category triggers different localisation obligations. For personal information, if a company processes >100,000 individuals’ data or handles “sensitive PI” (e.g., health, finance, location), the PIPL mandates localisation regardless of CII status. Important data requires a security assessment before any cross‑border transfer. Core data may be completely prohibited from leaving China unless authorised at the State Council level.

Exceptions: when cross‑border transfer is allowed

Localisation is not an absolute ban on cross‑border data flows. The DSL and PIPL outline three legal pathways for transfer:

  1. Security assessment by the CAC – mandatory for CII operators and for non‑CII entities handling important data or large volumes of PI (≥1 million individuals). Application includes a data impact assessment and an agreement with the foreign recipient. Processing time averages 60–120 days.
  2. Standard contractual clauses (SCCs) – available for smaller‑scale PI transfers (<100,000 individuals) if no important data is involved. The clauses must be filed with the provincial CAC within 10 working days of execution.
  3. Certification by an accredited body – an alternative for multinationals that have adhered to China’s cross‑border data security standards (e.g., GB/T 35273). Less common but used by some financial and healthcare firms.

Even with a legal pathway, the data must still be stored in China as the primary copy. Only copies necessary for the immediate business purpose may be transferred abroad, and all transfers must be logged for regulator inspection.

Penalties for non‑compliance

Fines are severe and scale with company revenue. The DSL sets maximum penalties of ¥10 million (≈$1.4 million) or 10% of the previous year’s turnover, whichever is higher. Additionally, responsible executives face personal fines up to ¥1 million (≈$140,000) and a ban on serving in data‑related roles for up to five years. Since 2023, regulators have publicly named over a dozen companies for localisation failures, including a multinational auto manufacturer fined ¥8 million (≈$1.1 million) in 2024 for transferring vehicle telematics data abroad without a security assessment.

Beyond monetary penalties, the CAC can order cessation of data collection, temporary suspension of data activities, or revocation of business licenses. For foreign‑invested enterprises, non‑compliance can trigger heightened scrutiny on subsequent data applications, effectively freezing new product launches or cross‑border operations.

Three common pitfalls for foreign companies

Pitfall 1: Misclassifying important data as ordinary business data.
Cost: ¥3 million RMB (≈$420,000) in fines + mandatory remediation audit.
Fix: Conduct a formal data classification mapping every 12 months, using the sector catalogs published by the MIIT and CAC. Engage a local consultant if your internal team lacks China‑specific expertise.
Pitfall 2: Assuming that cloud storage in Hong Kong meets localisation requirements.
Cost: ¥5 million RMB (≈$700,000) penalty + 60‑day suspension of data operations.
Fix: Use Chinese‑based cloud providers (e.g., Alibaba Cloud, Tencent Cloud) with data centres inside mainland China. Ensure that contractual SLAs include “data not leaving mainland China” clauses.
Pitfall 3: Delaying the CAC security assessment until after a cross‑border transfer has started.
Cost: ¥2 million RMB (≈$280,000) fine + months of remediation delay.
Fix: Begin the security assessment application at least 90 days before the intended first transfer. Prepare a data impact assessment (DIA) and a transfer agreement in parallel to shorten the timeline.

Practical compliance steps

To operationalise data localisation, multinationals should adopt a structured approach. First, establish a data inventory that maps every category of data stored or processed in China against the DSL/PIPL classifications. Second, appoint a legal representative in China who can sign compliance documents and interact with regulators. Third, implement technical controls such as data classification labels, access logs, and cross‑border transfer audit trails. Many companies also choose to set up a wholly foreign‑owned enterprise (WFOE, 外商独资企业, wàishāng dúzī qǐyè) to host their China data architecture under a separate legal entity, reducing cross‑entity risk.

For foreign executives, the most cost‑effective decision often depends on data volume and sensitivity. If your company processes fewer than 100,000 individuals’ personal information and no important data, the SCC pathway may suffice. If you handle telematics, financial records, or health data, full localisation with a security assessment is unavoidable. In both cases, starting the classification and assessment process early—at least six months before any intended transfer—saves significant penalties and operational delays.

NEXT STEPS

  1. Read our full guide on the Data Security Law compliance framework. It includes a step‑by‑step checklist for data classification and cross‑border transfer pathways. Learn more
  2. Review the latest cross‑border data transfer mechanisms. Understand how standard contractual clauses and security assessments apply to your specific data profile. Explore options
  3. Evaluate your company’s personal information processing threshold. If you handle ≥100,000 individuals’ PI, you likely need full localisation. Get the PIPL guide

— China Gateway 360 —
Remote China market entry support, built around execution.

Official Sources

Related articles

China’s Overseas Auto-Competition Guideline: Test Pricing, Dealers and Data Country by Country

Information date: 4 September 2026 — China’s commerce, industry and market-regulation authorities issued a 20-article guideline dated 24 August 2026 for Chinese automotive companies conducting international operations. K

China Ends the Foreign-Investor Dividend Exemption: Build Withholding Into Every September 2026 Payment

Information date: 4 September 2026 — A Ministry of Finance and State Taxation Administration announcement effective 1 September 2026 states that dividends and bonuses paid by foreign-invested enterprises to foreign indiv

China Import-Duty Calculator Workflow: Classification and Customs Value Come Before the Percentage

Information date: 4 September 2026 — China Customs provides tariff-query services, but a payable import amount still depends on the declared commodity code, origin, customs value, applicable rate and import-stage taxes f

China Business-Licence Record: Registration Is the Start of the Operating-Control Chain

Information date: 4 September 2026 — A foreign-invested enterprise in China is registered under the national market-entity framework and receives a business licence recording core identity information, but other tax, cus