DSL-Art17 | Data Security Standards (Art. 17) | 0 |
DSL-Art19 | Data Trading Market Rules (Art. 19) | 0 |
DSL-Art2 | Scope and Extraterritorial Application (Art. 2) | 1 |
DSL-Art21 | Hierarchical Data Classification, Core Data and Important Data Catalogue (Art. 21) | 1 |
DSL-Art22 | National Data Security Risk Assessment, Monitoring and Early Warning (Art. 22) | 1 |
DSL-Art23 | Data Security Emergency Response (Art. 23) | 1 |
DSL-Art24 | National Security Review of Data Activities (Art. 24) | 1 |
DSL-Art25 | Export Controls on Controlled Data (Art. 25) | 0 |
DSL-Art27 | Data Security Management System and Whole-Lifecycle Measures (Art. 27) | 1 |
DSL-Art28 | Lawful and Legitimate Data Processing (Art. 28) | 0 |
DSL-Art29 | Risk Monitoring, Remediation and Incident Notification (Art. 29) | 1 |
DSL-Art3 | Definitions of Data and Data Processing (Art. 3) | 0 |
DSL-Art30 | Important Data Risk Assessment and Reporting (Art. 30) | 1 |
DSL-Art31 | Cross-Border Transfer of Important Data (Art. 31) | 3 |
DSL-Art32 | Lawful and Proper Collection of Data (Art. 32) | 0 |
DSL-Art33 | Data Trading Intermediary Obligations (Art. 33) | 0 |
DSL-Art35 | Data Access by Public/National Security Organs (Art. 35) | 0 |
DSL-Art36 | Foreign Authority Data Requests (Art. 36) | 1 |
DSL-Art37 | Government Affairs Data Security (Art. 37-42) | 0 |
DSL-Art45 | Legal Liability and Penalties (Art. 45-52) | 0 |
DSL-Art7 | Data Security and Development (Art. 7) | 0 |
21 | Art. 21 Classify and grade data, identify important data by the catalogues, and apply the stricter regime to national core data | 0 |
24-25 | Art. 24-25 Submit to national security review of data processing that affects national security; observe export control on controlled data | 0 |
27 | Art. 27 Whole-process data security management system, training, technical measures, the classified protection baseline, and named responsibility for important data | 0 |
28 | Art. 28 Processing and new data technologies conducive to development, welfare and ethics | 0 |
29 | Art. 29 Closer risk monitoring, immediate remediation of defects, immediate incident handling with user notification and reporting | 0 |
30 | Art. 30 Important data processors: regular risk assessments reported to the competent departments with the prescribed content | 0 |
31 | Art. 31 Outbound transfer of important data: CIIOs under the Cybersecurity Law, others under the CAC's measures | 0 |
32 | Art. 32 Lawful and proper collection; purposes and scope as the law provides | 0 |
33-34 | Art. 33-34 Data transaction intermediaries verify sources and identities and keep records; data services obtain the required administrative permits | 0 |
35 | Art. 35 Cooperate with public security and national security organs' lawful data requests | 0 |
36 | Art. 36 No provision of data stored in China to foreign judicial or law enforcement bodies without competent-authority approval | 0 |
38-39 | Art. 38-39 State organs collect and use data within their statutory duties, keep it confidential, and run data security management systems | 0 |
40 | Art. 40 Entrusting e-government systems or government data: strict approval, supervision, and the entrusted party's duties | 0 |
41 | Art. 41 Disclose government data timely and accurately except where non-disclosure is required | 0 |
GOV | Chapter V: Security and openness of government data (Articles 38 to 41) | 0 |
LAW | The Data Security Law: what it is, what is held and its implementing instruments | 0 |
OBL | Chapter IV: Data security protection obligations (Articles 27 to 36) | 0 |
PEN | Legal liability (Articles 44 to 52) | 0 |
STATE | The state's role: security governance, development, standards, the regulators and complaints (Articles 4 to 26 in part) | 0 |
SYS | Chapter III: Data security systems that bind processors (classification, review, export control) | 0 |