China
5 regulators · 6 instruments · 1 upcoming deadline
| Instrument | Type | Year | Regulator | Summary | Source |
|---|---|---|---|---|---|
| Cybersecurity Law | Act | 2025 | CAC | The Cybersecurity Law (CSL) of the People’s Republic of China is in full force and effect… | official |
The Cybersecurity Law (CSL) of the People’s Republic of China is in full force and effect, operating through an extensive reform process that was fully implemented on January 1, 2026. As the oldest structural element of China's data governance structure, the CSL governs activities of domestic networks, provides cybersecurity protection for Critical Information Infrastructure (CII), and enforces stringent data localization requirements for critical network infrastructure. Operated by a joint agency management structure consisting of the Cyberspace Administration of China (CAC) together with the Ministry of Public Security (MPS), the recent 2026 framework has done away with prior notice periods in favor of imposing direct financial fines, extended its jurisdictional reach to foreign cyber threats, and required stringent security compliance for artificial intelligence infrastructure. | |||||
| Data Security Law | Act | 2021 | CAC | The Data Security Law of the People's Republic of China that came into force on September… | official |
The Data Security Law of the People's Republic of China that came into force on September 1, 2021, is an all-encompassing legal regulation that views data as a valuable resource linked to the national security and sovereignty of the country. As opposed to privacy regulations concentrated only on protecting the rights of consumers, the DSL adopts a hierarchical structure that classifies data depending on the level of its influence on the public interest and stability of the state as General, Important, and Core Data. The law places restrictions on the cross-border transfer of data, demanding the prior consent of the government before any domestic entities transfer the data to foreign governmental, judicial, or law enforcement agencies. At the same time, the DSL declares extraterritorial jurisdiction over the processing of data abroad that may cause harm to the national interests of China. Under the threat of harsh penalties, such as fines of up to 10 million RMB and even license revocation, the DSL obliges companies to have secure architecture and perform regular risk assessments. | |||||
| Personal Information Protection Law (PIPL) | Act | 2021 | CAC | Personal Information Protection Law (PIPL) is currently operative and strictly enforced, … | official |
Personal Information Protection Law (PIPL) is currently operative and strictly enforced, serving as the bedrock on which China's data governance policy of China is built. Following the initial enforcement of the two in late 2021, the regulatory environment has since grown into one that sees extensive enforcement under the auspices of the Cyberspace Administration of China (CAC) and other sector-specific ministries, including the MIIT and MPS. The compliance framework takes into consideration the scale of operations of an organization with regard to how data is processed; mandatory audits are required for large-scale organizations handling data for more than 10 million individuals, whereas small-scale organizations follow a simpler reporting process. Cross-border data transfer activities are strictly regulated using formal mechanisms such as mandatory certifications for outbound transfers of data. Moreover, the legal framework continues to evolve, bolstered by ongoing legislative alignment efforts, such as amendments to the Cybersecurity Law to ensure that penalties have been harmonized and extended extraterritorially. | |||||
| Anti-Money Laundering Law of the PRC | Act | 2006 | PBOC | The Anti-Money Laundering (AML) Law of the People's Republic of China is now fully operat… | official |
The Anti-Money Laundering (AML) Law of the People's Republic of China is now fully operational based on an extensive revision that officially came into effect on January 1, 2025. Passed by the Standing Committee of the National People's Congress and regulated mainly by the People's Bank of China (PBOC), the new structure steers China towards a risk-based compliance system in line with international standards. In addition to covering areas beyond conventional banks, the law extends regulatory coverage to designated non-financial businesses and professions (DNFBPs) such as real estate, accounting, and law firms while enforcing tight regulations on virtual assets and cryptocurrencies. With joint enforcement powers with the Ministry of Public Security (MPS), the system asserts extraterritorial jurisdiction against financial threats from abroad, real-time asset freezes under “Special Preventive Measures,” and tough fines combined with a safe harbor clause for executives. | |||||
| Securities Law of the PRC | Act | 1998 | CSRC | The Securities Law of the People's Republic of China is in full swing as it operates in t… | official |
The Securities Law of the People's Republic of China is in full swing as it operates in the aftermath of a groundbreaking revision implemented on March 1, 2020, and tightened through a cross-border corrective action plan initiated on May 22, 2026. The law was formulated by the Standing Committee of the National People's Congress and implemented by the China Securities Regulatory Commission (CSRC). It updates the Chinese securities market through the permanent implementation of a registration-based IPO regime, which transforms market access away from government approval to disclosure-based accountability. In an effort to address financial misbehavior and to safeguard retail investors, the framework provides harsh penalties (up to 100% of illegal profits from fraudulent issuance as fines on companies) and a representative class-action mechanism for stockholders. With global enforcement provisions, the law exercises extraterritorial jurisdiction over cross-border operations that interfere with the domestic market order, and the CSRC collaborates extensively with cybersecurity and policing agencies to shut down illegal cross-border brokers. | |||||
| Commercial Banking Law of the PRC | Act | 1995 | NFRA | The Commercial Banking Law of the People's Republic of China is an entirely functional me… | official |
The Commercial Banking Law of the People's Republic of China is an entirely functional mechanism that regulates the licensing, operations, and risk management practices of all banking establishments in Mainland China. The system was first created back in 1995 and operates on the basis of a very aggressive and modern restructuring carried out by the National Financial Regulatory Administration (NFRA) and the People's Bank of China (PBOC) – integrating old banking laws directly into the cross-sector Financial Law system [globallawexperts.com]. In order to protect the interests of general depositors and to prevent any financial breakdowns from taking place, the law imposes very strict segregation between commercial banking and speculative securities business, requires compulsory approval of any equity transfers that exceed 5%, and operates on a very tough "look-through" criterion. With the help of tough monetary punishments and an explicit institutional resolution hierarchy, the current system exercises substantial extraterritorial powers over illegal cross-border financing transactions targeting the Chinese domestic capital market. | |||||
| No instruments match these filters. | |||||