{"id":2918,"date":"2019-04-24T13:55:00","date_gmt":"2019-04-24T19:55:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2918"},"modified":"2024-12-17T10:00:29","modified_gmt":"2024-12-17T16:00:29","slug":"china-cybersecurity-law","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/china-cybersecurity-law\/","title":{"rendered":"The Giant Awakens: China Cybersecurity Law (CSL) and Data Protection Obligations"},"content":{"rendered":"\t\t<section id=\"block_81ae47af84edb1de92d5374362f0c4dd\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>The Giant Awakens: China Cybersecurity Law (CSL) and Data Protection Obligations<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_c293b70c5d2107f698eb98b7689b2da2\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>The new China Cybersecurity Law and data protection obligations<\/h2>\n<p>While many of us were focused on the European Union\u2019s GDPR and California\u2019s Consumer Privacy Act (CCPA), the giant on the other side of the world<a href=\"https:\/\/www.tradecommissioner.gc.ca\/china-chine\/cyber-security_cyber-securite_china-chine.aspx?lang=eng\" target=\"_blank\" rel=\"noopener\">\u00a0implemented China\u2019s Cybersecurity Law (CSL) in June 2017<\/a>.<\/p>\n<p>While CSL laid out broad data protection principles, there were noticeable implementation and scope gaps.<\/p>\n<p><strong>To operationalize and further clarify China Cybersecurity Law scope the Chinese government instituted six systems:<\/strong><\/p>\n<ul>\n<li>the Internet Information Content Management System;<\/li>\n<li>the Cybersecurity Multi-Level Protection System (MLPS);<\/li>\n<li>the Critical Information Infrastructure Security Protection System;<\/li>\n<li>the Network Products and Services Management System;<\/li>\n<li>the Cybersecurity Incident Management System;<\/li>\n<li>and the Personal Information and Important Data Protection System.<\/li>\n<\/ul>\n<p>While it is important for foreign businesses to review all aspects of CSL and the six systems, TrustArc has helped clients focus on the implications of the Personal Information and Important Data Protection System.<\/p>\n<p><strong>Specifically addressing the following regulations:<\/strong><\/p>\n<ul>\n<li>What are the requirements to store certain information (including a negative list) inside China, and at what level of required security measures (e.g., Ministry of Public Security [MPS] Regulation)?<\/li>\n<li>What procedures and reviews are needed before transferring certain information out of China (e.g., Cross-Border Data Transfer)?<\/li>\n<li>What are the required notice and consent requirements when collecting personal data?<\/li>\n<li>What are the MPS requirements in reporting a cyber incident within 24 hours?<\/li>\n<li>What does the Cyberspace Administration of China (CAC) require in the security assessment report annually?<\/li>\n<li>Data subjects have what individual rights under the PI Security Specification?<\/li>\n<\/ul>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/cyber-security\/\" class=\"badge\">Cyber Security<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>The giant on the other side of the world implemented China\u2019s Cybersecurity Law (CSL). To operationalize and further clarify China&#8217;s Cybersecurity Law scope, the Chinese government instituted six systems.<\/p>\n","protected":false},"featured_media":1697,"template":"","topic-resource":[62],"type-resource":[6],"class_list":["post-2918","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-cyber-security","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The Giant Awakens: China Cybersecurity Law (CSL) and Data Protection Obligations | TrustArc<\/title>\n<meta name=\"description\" content=\"The giant on the other side of the world implemented China\u2019s Cybersecurity Law (CSL). To operationalize and further clarify China&#039;s Cybersecurity Law scope, the Chinese government instituted six systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/china-cybersecurity-law\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/china-cybersecurity-law\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/china-cybersecurity-law\\\/\",\"name\":\"The Giant Awakens: China Cybersecurity Law (CSL) and Data Protection Obligations | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/china-cybersecurity-law\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/china-cybersecurity-law\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-woven-gray.png\",\"datePublished\":\"2019-04-24T19:55:00+00:00\",\"dateModified\":\"2024-12-17T16:00:29+00:00\",\"description\":\"The giant on the other side of the world implemented China\u2019s Cybersecurity Law (CSL). To operationalize and further clarify China's Cybersecurity Law scope, the Chinese government instituted six systems.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/china-cybersecurity-law\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/china-cybersecurity-law\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-woven-gray.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-woven-gray.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The Giant Awakens: China Cybersecurity Law (CSL) and Data Protection Obligations | TrustArc","description":"The giant on the other side of the world implemented China\u2019s Cybersecurity Law (CSL). To operationalize and further clarify China's Cybersecurity Law scope, the Chinese government instituted six systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/china-cybersecurity-law\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/china-cybersecurity-law\/","url":"https:\/\/trustarc.com\/resource\/china-cybersecurity-law\/","name":"The Giant Awakens: China Cybersecurity Law (CSL) and Data Protection Obligations | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/china-cybersecurity-law\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/china-cybersecurity-law\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-woven-gray.png","datePublished":"2019-04-24T19:55:00+00:00","dateModified":"2024-12-17T16:00:29+00:00","description":"The giant on the other side of the world implemented China\u2019s Cybersecurity Law (CSL). To operationalize and further clarify China's Cybersecurity Law scope, the Chinese government instituted six systems.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/china-cybersecurity-law\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/china-cybersecurity-law\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-woven-gray.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-woven-gray.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1697"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2918"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2918"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}