Continental Postal Services of Hebland

Navigating China’s New Network Data Security Risk Assessment Regime


On 20 August 2026, the Measures for Network Data Security Risk Assessment (the “Assessment Measures”) jointly promulgated by the Cyberspace Administration of China (the “CAC”)the Ministry of Industry and Information Technology, and the Ministry of Public Security, among other authorities, formally came into effect, marking a new phase in which network data security risk assessment has transitioned from principled requirements to an institutionalised, standardised, and routine regulatory framework.

In this article, we highlight the key provisions of the Assessment Measures and set out our observations.

BACKGROUND

The network data security risk assessment regime derives from the Data Security Law of the People’s Republic of China (the “DSL”), which expressly requires the establishment of a data security risk assessment mechanism and requires important data processors to conduct regular risk assessments. The Network Data Security Management Regulations (the “Network Data Regulations”), which took effect in 2024, further specify these requirements by requiring important data processors to conduct annual risk assessments of their network data processing activities and submit assessment reports. Together, the DSL and the Network Data Regulations establish the basic legal framework for the network data security risk assessment regime.

An important aspect of the network data security risk assessment regime is its close connection with the protection of important data. Under China’s data security framework, important data is subject to heightened protection due to the potential impact that its leakage, damage, or misuse may have on national security, public interests, or the legitimate interests of individuals and organizations. Accordingly, the risk assessment regime is designed in significant part to identify and mitigate security risks associated with the processing of important data.

However, the higher-level legislation mentioned above lacked detailed rules regarding the specific operational rules of when network data security risk assessments should be triggered, the manner in which assessments should be conducted, and the applicable submission requirements. This resulted in difficulties for enterprises in accurately understanding their compliance obligations in practice and left regulators without a uniform basis for inspection and enforcement. The Assessment Measures build upon the existing obligations established under the foregoing regulations and systematically elaborate on the requirements concerning assessment methodology, procedures, report submission, third-party assessment institutions, and regulatory inspection.

KEY PROVISIONS AND OBSERVATIONS

I. Who Needs to Pay Attention? 

The network data security risk assessment regime under the Network Data Regulations and the Assessment Measures does not impose uniform mandatory requirements on all network data processors. Rather, it establishes differentiated assessment requirements applicable to distinct categories of entities, based on the type, volume, and potential security risk of the data processed.

Applicable Entity

Specific Requirements

Assessment Methodology

Our Comments

Important Data Processor

Important data processors are required to conduct an annual risk assessment. In addition, where a material change occurs in the security status of important data that may have an adverse impact on data security, a risk assessment of the changes and their effects shall be conducted in a timely manner. (Article 5 of the Assessment Measures)

Assessments may be conducted internally or entrusted to a third-party assessment institution:

  • For internal assessments, a designated person-in-charge shall be appointed.
  • For assessments entrusted to a third-party institution, the rights and obligations of both parties shall be clearly set out by contract or other legally effective instrument. The same assessment institution and its affiliated entities shall not conduct the annual risk assessment for the same network data processor for three or more consecutive years.

Important data processors are required to conduct annual assessments on a scheduled basis. They should establish a mechanism to identify material changes and conduct ad hoc assessments in a timely manner upon material changes in the processing environment, security measures, or relevant risk status of important data, as well as prior to providing, entrusting the processing of, or jointly processing important data.

However, it is worth noting that the Assessment Measures do not introduce any new rules regarding the identification of important data. Enterprises therefore still need to rely on the important data catalogues issued by local authorities or competent industry regulators to identify and determine what constitutes important data.

Article 31 of the Network Data Regulations requires important data processors to conduct a risk assessment prior to providing, entrusting the processing of, or jointly processing important data, except where this is done in the performance of a statutory duty or legal obligation. (Article 31 of the Network Data Regulations)

Network Data Processors Processing the Personal Information of over 10 million Individuals 

Under the Network Data Regulations, network data processors that process the personal information of over 10 million individuals are required to comply with certain security management obligations of important data processors under articles 30 and 32 of the Regulations, which include the obligation to “conduct regular network data security risk assessments.” (Article 28 of the Network Data Regulations) 

Accordingly, even where an enterprise does not process important data, if the volume of personal information it processes reaches 10 million or more individuals, it is nonetheless required to conduct annual assessments in accordance with the standards applicable to important data processors.

Network data processors that process the personal information of over 10 million individuals are required to conduct annual assessments on a scheduled basis.

Network Data Processors Facing Relatively Large Network Data Security Risks or Serious Security Incidents 

Where  the competent authorities identify, through the review of risk assessment reports, supervisory inspections, or other activities, that a network data processor falls under any of the following circumstances, they may require it to commission a certified assessment institution to conduct a risk assessment (Article 17 of the Assessment Measures): 

  • Network data processing activities face relatively large security risks that may endanger national security or the public interest.
  • A network data security incident has occurred resulting in the leakage or theft of important data or large-scale personal information.
  • Other circumstances specified by the relevant authorities.

Risk assessment shall be conducted by an assessment institution that has obtained certification in accordance with regulatory requirements.

Where significant network data security risks or serious security incidents occur, enterprises may be required by the regulatory authorities to conduct a risk assessment led by an external institution. Accordingly, this should be planned and prepared for in advance within the relevant security incident emergency response plan.

It is worth noting that there are currently no clear criteria for determining what constitutes “relatively large security risks” or “large-scale personal information.” Further clarification by regulatory authorities in practice is therefore still required.

Network Data Processors Processing Non-Important Data (General Data Processors) 

General data processors are encouraged to conduct a risk assessment at least once every three years. (Article 5 of the Assessment Measures)

Risk Assessment may be conducted internally or entrusted to an assessment institution.

This provision is advisory. General data processors may independently determine whether and how to establish a regular risk assessment mechanism, having regard to their data volume, business complexity, and risk level.

 

II. How to Structure an Assessment Programme?

i. Assessment Content

Article 6 of the Assessment Measures provides that risk assessment work shall be conducted in accordance with the requirements of the DSL and the Network Data Regulations, with reference to the relevant national standards on data security risk assessment. Where the competent authorities responsible for a particular industry or sector have issued separate provisions governing risk assessment work in that industry or sector, those provisions shall prevail.

In practice, enterprises may conduct assessments covering data processing activities, security management framework, technical measures, security incidents, and identified risks, having regard to the annual risk assessment report items listed under Article 33 of the Network Data Regulations and with reference to the recommended national standard Data Security TechnologyData Security Risk Assessment Methodology (GB/T 45577-2025).

Under Article 33 of the Network Data Regulations, the annual risk assessment report shall cover the following matters:

  • Basic information of the network data processor, information concerning the network data security management body, and the name and contact details of the person responsible for network data security;
  • The purpose, categories, volume, manner, scope, storage period, and storage location of important data processed, and a description of network data processing activities conducted, excluding the content of the network data itself;
  • Network data security management framework and their implementation, and the description and the effectiveness of technical measures such as encryption, backup, labelling and identification, access control, and security authentication, as well as other necessary measures;
  • Network data security risks identified, network data security incidents that have occurred and the corresponding handling measures;
  • Risk assessment in respect of the provision, entrusted processing, and joint processing of important data;
  • Cross-border transfer of network data;
  • Other reporting content as required by the competent authorities.
  • Risk assessment reports submitted by Large Internet Platform Service Providers that process important data shall, in addition to the content set out above, provide a comprehensive description of key business operations and supply chain network data security.

ii. Submission and Retention of Assessment Reports

Article 16 of the Assessment Measures requires important data processors to submit their annual risk assessment reports to the competent authorities in accordance with the requirements of those authorities within 20 working days of completing the annual risk assessment. Where the competent authority is not clearly identified, the report shall be submitted to the provincial-level CAC. 

In addition, article 15 of the assessment measures further requires that annual risk assessment reports of important data processors be retained for a minimum of 3 years.

Based on our experience, certain industriessuch as the automotive sectorhave already established annual submission mechanisms for data security risk assessment reports. It remains to be seen whether additional industry-specific competent authorities will establish dedicated submission mechanisms for data security risk assessment reports. 

Notably, the CAC issued an official notice on 20 August 2026 publicly releasing the dedicated enquiry hotline numbers for the national level CAC and each provincial-level CAC for data security risk assessment, and further industry regulators are expected to establish dedicated submission mechanisms in due course.

III. How Does It Differ from Other Assessments under Chinese Law?

The existing cybersecurity and data protection legal framework in China encompasses multiple assessment or audit mechanisms, which enterprises may find confusing in practice. The network data security risk assessment is fundamentally distinct from the following three commonly encountered assessment mechanisms:

i. Personal Information Protection Impact Assessment 

Article 55 of the Personal Information Protection Law (the “PIPL”) requires personal information processors to conduct a personal information protection impact assessment (the “PIPIA”) in specified circumstances, including the processing of sensitive personal information, the use of personal information for automated decision-making, entrusted processing, provision or disclosure of personal information to other personal information processors, and the cross-border transfer of personal information to recipients outside China.

By contrast, a PIPIA focuses on the impact of specific personal information processing activities on the rights and interests of data subjects. A network data security risk assessment, on the other hand, addresses the overall security risks of network data and network data processing activities, and its scope is not limited to personal information.

ii. Personal Information Protection Compliance Audit 

Article 54 of the PIPL requires personal information processors to conduct regular audits of the compliance of their personal information processing activities. The Measures for the Administration of Personal Information Protection Compliance Audits further elaborate upon this requirement: personal information processors that process the personal information of more than 10 million individuals are required to conduct a compliance audit at least once every 2 years. For a detailed introduction to the application of personal information protection compliance audits, please refer to our earlier article .

By contrast, a personal information protection compliance audit focuses principally on verifying whether personal information processing activities comply with the applicable laws and regulations. A network data security risk assessment, on the other hand, centres on the identification, analysis, and evaluation of network data security risks.

iii. Data Export Security Assessment

Data export security assessment constitutes a specialised regulatory mechanism applicable to specific cross-border data transfer activities. Under the current data export rules, operators of critical information infrastructure that provide personal information or important data to overseas recipients, as well as non-critical information infrastructure operators that provide important data overseas or that meet the prescribed volume thresholds for cross-border transfer of personal information, are required by law to apply for a data export security assessment, unless certain exemptions under the Provisions on Promoting and Regulating Cross-border Data Flows is satisfied. For a detailed introduction to the application of data export security assessments, please refer to our earlier article.

By contrast, a data export security assessment is a specialised ex ante assessment of cross-border data transfer activities, focused on the impact of such transfers on national security, the public interest, and the rights and interests of data subjects; a network data security risk assessment, on the other hand, is a periodic or special assessment of the overall security of network data processing activities, focused on the identification, analysis, and evaluation of network data security risks.

In summary, fulfillment of the foregoing assessment or audit obligations does not automatically discharge the obligation to conduct a network data security risk assessment. Nonetheless, Article 52 of the Network Data Regulations expressly provides that personal information protection compliance audits, important data risk assessments, and important data export security assessments shall be better coordinated to avoid duplicative assessments and audits. We understand that as the various assessment and audit regimes are progressively implemented, the degree of coordination and coherence among them will continue to improve.

IV. What Are the Legal Consequences of Non-compliance?

Article 22 of the Assessment Measures provides that where a network data processor fails to conduct a risk assessment in accordance with the prescribed requirements, it shall be dealt with pursuant to the relevant requirements of the applicable higher-level legislation. The Assessment Measures therefore do not themselves establish an independent set of penalty tiers. Rather, they operate by reference to the existing liability framework under the higher-level legislation:

Read together with Article 45 of the DSL and Article 57 of the Network Data Regulations, important data processors that fail to conduct regular risk assessments and fulfil their obligations to submit risk assessment reports, or that fail to conduct a risk assessment prior to providing, entrusting the processing of, or jointly processing important data, shall be subject to the following liability:

  • The competent authorities shall order rectification and issue a warning; a fine of not less than CNY 50,000 and not more than CNY 500,000 may also be imposed, and persons directly responsible in a managerial capacity and other directly responsible individuals may be subject to a fine of not less than CNY 10,000 and not more than CNY 100,000;
  • Where rectification is refused or serious consequences result, such as large-scale data leakage, a fine of not less than CNY 500,000 and not more than CNY 2,000,000 shall be imposed, and the authorities may order the suspension of relevant business operations, require business suspension for rectification, or revoke relevant business licences or the business licence altogether; persons directly responsible in a managerial capacity and other directly responsible individuals may be subject to a fine of not less than CNY 50,000 and not more than CNY 200,000.

Furthermore, Article 19 of the Assessment Measures provides that, in respect of important data processing activities that may endanger national security or the public interest, the authorities may order rectification. Where rectification is refused or the rectification requirements are not met, the authorities may require the cessation of important data processing.

OUR RECOMMENDATIONS

Enterprises may consider taking action in the following areas to ensure compliance with the requirements of the Assessment Measures:

  1. Determine whether the enterprise falls within the scope of application, and if so, identify the specific category of applicable entity: Having regard to important data catalogues published or communicated by the competent authorities, industry-specific rules, and the enterprises own data classification and grading results, assess whether important data is being processed, and accordingly determine whether the annual risk assessment obligation applies. Processing the personal information of 10 million or more individuals may equally trigger the annual assessment obligation. 
  2. Integrate the network data security risk assessment into the enterprises annual compliance calendar: Important data processors should schedule annual assessments well in advance and allow sufficient time for report preparation and internal approval, so as to ensure that regulatory submission is completed within 20 working days of the conclusion of the assessment.
  3. Review and coordinate existing assessment and audit results: Different assessment and audit regimes may overlap in respect of data mapping, risk identification, and security measures. The Network Data Regulations expressly require that personal information protection compliance audits, important data risk assessments, and important data export security assessments be better coordinated to avoid duplication. Subject to satisfying the independent statutory requirements of each regime, enterprises may reasonably reuse existing factual materials and assessment findings.
  4. Establish robust documentation and record-keeping mechanisms to respond to regulatory inspection: Annual risk assessment reports of important data processors shall be retained for a minimum of 3 years. enterprises may also simultaneously retain records of risk identification, rectification materials, internal approval records, and third-party assessment documents to support subsequent regulatory review.

 

 

* With thanks to Jingyu Zhang (Intern, Beijing) and Sisheng Peng (Intern, Beijing) for their contributions to the article.

 



Source link

Leave A Reply

Your email address will not be published.