Release Date: 2022-12-08 (published online on 2022-12-13)
Effective Date: 2023-01-01
Source: Ministry of Industry and Information Technology
Original Title: 工业和信息化领域数据安全管理办法(试行)
Document No.: MIIT Cybersecurity [2022] No. 166 (工信部网安〔2022〕166号)
To the competent industry and information technology authorities of all provinces, autonomous regions, municipalities directly under the Central Government, cities specifically designated in the state plan, and the Xinjiang Production and Construction Corps; the communications administrations of all provinces, autonomous regions and municipalities directly under the Central Government; the radio regulatory authorities of Qinghai and Ningxia; all units and universities affiliated with the Ministry; and all relevant enterprises:
The Measures for Data Security Management in the Industry and Information Technology Sectors (for Trial Implementation) are hereby issued to you. Please conscientiously comply with and implement them.
Ministry of Industry and Information Technology
December 8, 2022
Article 1 These Measures are formulated in accordance with the Data Security Law of the People’s Republic of China, the Cybersecurity Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China, the National Security Law of the People’s Republic of China, the Civil Code of the People’s Republic of China and other laws and regulations to regulate data processing activities in the industry and information technology sectors, strengthen data security management, ensure data security, promote the development and use of data, protect the lawful rights and interests of individuals and organisations, and safeguard national security and development interests.
Article 2 Data processing activities in the industry and information technology sectors conducted within the territory of the People’s Republic of China, and the supervision and administration of their security, shall comply with the requirements of relevant laws, administrative regulations and these Measures.
Article 3 Data in the industry and information technology sectors includes industrial data, telecommunications data and radio data, among other types. Industrial data means data generated and collected across industrial sectors and fields in activities such as research and development, design, production and manufacturing, business management, operation and maintenance, and platform operation.
Telecommunications data means data generated and collected in the course of telecommunications business activities.
Radio data means data on radio wave parameters relating to radio frequencies, radio stations and similar matters that are generated and collected in the course of radio service activities.
Data processors in the industry and information technology sectors are entities in these sectors that independently determine the purposes and methods of processing in data processing activities. These include industrial enterprises, software and information technology service enterprises, telecommunications operators holding telecommunications business operating licences, and entities using radio frequencies and radio stations. According to their respective sectors, such processors may be divided into industrial data processors, telecommunications data processors, radio data processors and other categories. Data processing activities include, but are not limited to, data collection, storage, use, processing, transmission, provision and disclosure.
Article 4 Under the overall coordination of the national data security work coordination mechanism, the Ministry of Industry and Information Technology (MIIT) is responsible for supervising and guiding the competent industry and information technology authorities of provinces, autonomous regions, municipalities directly under the Central Government, cities specifically designated in the state plan, and the Xinjiang Production and Construction Corps, as well as the communications administrations and radio regulatory authorities of provinces, autonomous regions and municipalities directly under the Central Government (hereinafter collectively referred to as local industry regulators), in carrying out data security supervision and regulation. MIIT supervises and regulates data processing activities and security protection in the industry and information technology sectors.
Local industry regulators are respectively responsible for supervising and regulating the data processing activities and security protection of industrial, telecommunications and radio data processors within their jurisdictions.
MIIT and local industry regulators are collectively referred to as industry regulators.
Industry regulators shall, in accordance with relevant laws and administrative regulations, cooperate with the relevant departments in carrying out work relating to data security supervision and regulation.
Article 5 Industry regulators shall encourage the development and use of data and research into data security technologies, support the promotion of data security products and services, cultivate data security enterprises and research and service institutions, develop the data security industry, enhance data security assurance capabilities, and promote innovative applications of data.
The research, development and use of new data technologies, products and services by data processors in the industry and information technology sectors shall contribute to economic, social and industry development and comply with social morality and ethics.
Article 6 Industry regulators shall advance the development of systems of standards for data development and use and data security in the industry and information technology sectors, and organise the formulation, revision, promotion and application of relevant standards.
Article 7 MIIT shall organise the formulation of standards and specifications for data classification and grading, the identification and determination of important data and core data, and data protection according to grade in the industry and information technology sectors. It shall guide data classification and grading management, establish specific industry catalogues of important data and core data, and keep those catalogues under ongoing review and updating.
Local industry regulators shall respectively organise data classification and grading management and the identification of important data and core data in the industry and information technology sectors within their jurisdictions. They shall determine specific local catalogues of important data and core data and submit them to MIIT. Changes to the catalogues shall be promptly reported through updated submissions.
Data processors in the industry and information technology sectors shall regularly review and organise their data, identify important data and core data in accordance with relevant standards and specifications, and compile specific catalogues for their organisations.
Article 8 Based on factors such as industry requirements and characteristics, business needs, data sources and purposes of use, data categories in the industry and information technology sectors include, but are not limited to, research and development data, production and operational data, management data, operation and maintenance data, and business service data.
Data in the industry and information technology sectors is divided into three grades: general data, important data and core data. The grade is determined by the degree of harm that tampering, destruction, leakage, illegal acquisition or illegal use of the data would cause to national security, public interests, or the lawful rights and interests of individuals or organisations, among other considerations.
Data processors in the industry and information technology sectors may further subdivide data categories and grades on this basis.
Article 9 Data shall be classified as general data where the degree of harm falls within any of the following circumstances:
(I) it has a relatively minor impact on public interests or the lawful rights and interests of individuals or organisations, with limited adverse effects on society;
(II) it affects relatively few users and enterprises, covers a relatively small area of production and daily life, lasts for a relatively short period, and has a relatively minor impact on business operations, industry development, technological progress and the industrial ecosystem; or
(III) the data is otherwise not included in the catalogues of important data or core data.
Article 10 Data shall be classified as important data where the degree of harm falls within any of the following circumstances:
(I) it poses threats to security in areas such as politics, territory, military affairs, the economy, culture, society, science and technology, the electromagnetic spectrum, cyberspace, ecology, resources and nuclear matters, and affects key areas relating to national security, such as overseas interests, biology, outer space, polar regions, the deep sea and artificial intelligence;
(II) it seriously affects development, production, operations, economic interests or other aspects of the industry and information technology sectors;
(III) it causes major data security incidents or production safety accidents, seriously affects public interests or the lawful rights and interests of individuals or organisations, and has substantial adverse effects on society;
(IV) it produces pronounced cascading effects, affects multiple industries or regions or multiple enterprises within an industry, or continues for a prolonged period, seriously affecting industry development, technological progress and the industrial ecosystem; or
(V) the data is otherwise determined by MIIT, following assessment, to be important data.
Article 11 Data shall be classified as core data where the degree of harm falls within any of the following circumstances:
(I) it poses serious threats to security in areas such as politics, territory, military affairs, the economy, culture, society, science and technology, the electromagnetic spectrum, cyberspace, ecology, resources and nuclear matters, and seriously affects key areas relating to national security, such as overseas interests, biology, outer space, polar regions, the deep sea and artificial intelligence;
(II) it has a major impact on the industry and information technology sectors and their key enterprises, critical information infrastructure, important resources or other essential elements;
(III) it causes major harm to industrial production and operations, telecommunications network and Internet operations and services, or radio service activities, resulting in widespread suspension of work and production, extensive interruption of radio services, large-scale paralysis of networks and services, substantial loss of business processing capacity or similar consequences; or
(IV) the data is otherwise determined by MIIT, following assessment, to be core data.
Article 12 Data processors in the industry and information technology sectors shall file their organisations’ catalogues of important data and core data with their local industry regulators. The filing shall include, but is not limited to, basic information on data sources, categories, grades, volume, media, processing purposes and methods, scope of use, responsible entities, external sharing, cross-border transfers and security protection measures. It shall not include the data content itself.
Local industry regulators shall complete their review within twenty working days after a data processor in the industry and information technology sectors submits a filing application. Where the filing information meets the requirements, the filing shall be accepted and its details shall be reported to MIIT at the same time. Where a filing is not accepted, the applicant shall be promptly informed and given the reasons. The applicant shall resubmit the filing application within fifteen working days after receiving that feedback.
Where a material change occurs in the filing information, the data processor in the industry and information technology sectors shall complete the procedures for amending the filing within three months of the change. A material change means a change of 30% or more in the volume of any category of important data or core data, measured by the number of data entries, total storage volume or similar measures, or a change in any other filing information.
Article 13 Data processors in the industry and information technology sectors shall bear primary responsibility for the security of their data processing activities and apply protection to each category of data according to its grade. Where data of different grades is processed simultaneously and separate protection measures are difficult to implement, protection shall meet the requirements applicable to the highest grade involved, ensuring that the data remains effectively protected and lawfully used at all times. They shall:
(I) establish a security management system covering the entire data lifecycle and formulate specific protection requirements and operating procedures for different data grades at stages including collection, storage, use, processing, transmission, provision and disclosure;
(II) appoint data security management personnel as needed to take overall responsibility for security supervision and management of data processing activities and assist industry regulators in their work;
(III) reasonably determine operational permissions for data processing activities and strictly manage personnel access rights;
(IV) formulate emergency response plans and conduct emergency drills as required for responding to data security incidents;
(V) regularly provide data security education and training to personnel; and
(VI) take other measures prescribed by laws, administrative regulations and other applicable provisions.
Processors of important data or core data in the industry and information technology sectors shall also:
(I) establish a data security organisational system covering the relevant departments of their organisations, designate the person responsible for data security and the management body, and establish mechanisms for regular communication and cooperation. The organisation’s legal representative or principal person in charge bears primary responsibility for data security, while the member of the leadership team in charge of data security bears direct responsibility;
(II) identify key data processing positions and their responsibilities, and require personnel in those positions to sign data security responsibility statements covering, among other matters, their data security duties, obligations, disciplinary measures and precautions; and
(III) establish internal registration, approval and other working mechanisms to strictly manage the processing of important data and core data and retain records.
Article 14 Data processors in the industry and information technology sectors shall collect data in accordance with the principles of lawfulness and legitimacy and shall not steal data or collect it by other illegal means.
During data collection, they shall take security measures appropriate to the data security grade, strengthen the management of personnel and equipment involved in collecting important data and core data, and record collection sources, times, types, quantities, frequency, data flows and other relevant information.
Where important data or core data is obtained indirectly, data processors in the industry and information technology sectors shall clarify the legal responsibilities of both parties with the data provider by signing relevant agreements, letters of undertaking or similar documents.
Article 15 Data processors in the industry and information technology sectors shall store data using the methods and for the periods prescribed by laws and administrative regulations and agreed with users. When storing important data or core data, they shall ensure secure storage through measures such as data verification technologies and cryptographic technologies, implement disaster recovery backups and security management of storage media, and regularly conduct data recovery tests.
Article 16 Where data processors in the industry and information technology sectors use data for automated decision-making, they shall ensure the transparency of the decision-making and the fairness and reasonableness of the results. When using or processing important data or core data, they shall also strengthen access controls.
Where data processing services provided by data processors in the industry and information technology sectors involve the operation of telecommunications businesses, they shall obtain a telecommunications business operating licence in accordance with relevant laws and administrative regulations.
Article 17 Data processors in the industry and information technology sectors shall formulate security policies and take protection measures based on the types and grades of data transmitted and the application scenarios. When transmitting important data or core data, they shall adopt measures such as data verification technologies, cryptographic technologies, secure transmission channels or secure transmission protocols.
Article 18 When providing data to external parties, data processors in the industry and information technology sectors shall specify the scope, categories, conditions, procedures and other relevant matters concerning the provision. When providing important data or core data, they shall enter into data security agreements with the recipients, verify the recipients’ data security protection capabilities, and take necessary security protection measures.
Article 19 Before publicly disclosing data, data processors in the industry and information technology sectors shall analyse and assess the potential impact on national security and public interests. Where there would be a major impact, the data shall not be publicly disclosed.
Article 20 Data processors in the industry and information technology sectors shall establish a data destruction system, specifying the data subject to destruction and the applicable rules, procedures, technologies and other requirements, and shall create and retain records of destruction activities. Where individuals or organisations request destruction in accordance with legal provisions, contractual agreements or other applicable requirements, the data processors shall destroy the corresponding data.
After destroying important data or core data, data processors in the industry and information technology sectors shall not restore the destroyed data for any reason or by any means. Where the destruction changes the filing information, the procedures for amending the filing shall be completed.
Article 21 Where laws or administrative regulations require domestic storage, important data and core data collected and generated by data processors in the industry and information technology sectors within the territory of the People’s Republic of China shall be stored within that territory. Where it is truly necessary to provide such data overseas, a security assessment of the cross-border transfer shall be conducted in accordance with applicable laws and regulations.
MIIT shall handle requests from foreign law enforcement authorities responsible for industry, telecommunications or radio matters for the provision of data in the industry and information technology sectors in accordance with relevant laws and international treaties or agreements concluded or acceded to by the People’s Republic of China, or on the basis of equality and reciprocity. Without MIIT’s approval, data processors in the industry and information technology sectors shall not provide data in these sectors that is stored within the territory of the People’s Republic of China to such foreign law enforcement authorities.
Article 22 Where data processors in the industry and information technology sectors need to transfer data due to mergers, restructuring, bankruptcy or other reasons, they shall specify a data transfer plan and notify affected users by telephone, text message, email, public announcement or other means. Where the transfer changes the filing information for important data or core data, the procedures for amending the filing shall be completed.
Article 23 Where data processors in the industry and information technology sectors entrust others to conduct data processing activities, they shall specify the data security responsibilities and obligations of the entrusting and entrusted parties through contracts, agreements or other means. Where the processing of important data or core data is entrusted to others, the entrusted party’s data security protection capabilities and qualifications shall be verified.
Unless otherwise provided by laws, administrative regulations or other applicable provisions, the entrusted party shall not provide the data to a third party without the entrusting party’s consent.
Article 24 Where core data is provided or transferred between entities, or its processing is entrusted to another entity, data processors in the industry and information technology sectors shall assess security risks and take necessary security protection measures. The matter shall be reviewed by the local industry regulator and then submitted to MIIT. MIIT shall conduct a review in accordance with relevant provisions.
Article 25 Data processors in the industry and information technology sectors shall record logs of data processing, permission management, personnel operations and other relevant activities throughout the data processing lifecycle. Logs shall be retained for at least six months.
Article 26 MIIT shall establish a mechanism for monitoring data security risks, organise the formulation of interfaces and standards for data security monitoring and early warning, coordinate the development of technical means for data security monitoring and early warning, build capabilities for monitoring, early warning, response and source tracing, and strengthen information sharing with relevant departments.
Local industry regulators shall respectively establish mechanisms for monitoring and providing early warning of data security risks within their jurisdictions, organise data security risk monitoring, promptly issue early warning information in accordance with relevant provisions, and notify data processors in the industry and information technology sectors within their jurisdictions to take timely response measures.
Data processors in the industry and information technology sectors shall monitor data security risks, promptly investigate and identify security vulnerabilities and hazards, and take necessary measures to prevent data security risks.
Article 27 MIIT shall establish mechanisms for reporting and sharing data security risk information, centrally collect, analyse, assess and circulate such information, and encourage security service providers, industry organisations, research institutions and other bodies to report and share data security risk information.
Local industry regulators shall respectively consolidate and analyse data security risks within their jurisdictions and promptly report to MIIT any risks that may cause security incidents classified as major or above.
Data processors in the industry and information technology sectors shall promptly report to their local industry regulators any risks that may cause security incidents classified as relatively major or above.
Article 28 MIIT shall formulate emergency response plans for data security incidents in the industry and information technology sectors and organise and coordinate emergency responses to security incidents involving important data and core data.
Local industry regulators shall respectively organise emergency responses to data security incidents within their jurisdictions. Security incidents involving important data or core data shall be reported to MIIT immediately, and developments in the incidents and their handling shall be reported promptly.
Following a data security incident, data processors in the industry and information technology sectors shall promptly undertake emergency response measures in accordance with their emergency response plans. Security incidents involving important data or core data shall be reported immediately to their local industry regulators. After incident handling is completed, a summary report shall be prepared within the prescribed time limit. Data processors shall report annually to their local industry regulators on their handling of data security incidents.
Where a data security incident occurs that may harm users’ lawful rights and interests, data processors in the industry and information technology sectors shall promptly notify users and provide measures to mitigate the harm.
Article 29 MIIT shall entrust relevant industry organisations to establish channels for complaints and reports concerning data security violations in the industry and information technology sectors. Local industry regulators shall respectively establish mechanisms or channels for complaints and reports concerning data security violations within their jurisdictions, receive and handle complaints and reports in accordance with the law, and conduct enforcement investigations as needed. Data processors in the industry and information technology sectors are encouraged to establish mechanisms for handling user complaints.
Article 30 MIIT shall guide and encourage appropriately qualified institutions to conduct industry data security testing and certification in accordance with relevant standards.
Article 31 MIIT shall establish a management system for industry data security assessments and manage assessment institutions. It shall formulate specifications for industry data security assessments and guide assessment institutions in conducting data security risk assessments, security assessments of cross-border data transfers and other relevant work.
Local industry regulators shall respectively be responsible for organising data security assessments within their jurisdictions.
Processors of important data or core data in the industry and information technology sectors shall conduct a risk assessment of their data processing activities at least once each year, either themselves or through an entrusted third-party assessment institution. They shall promptly remedy identified risks and problems and submit risk assessment reports to their local industry regulators.
Article 32 Industry regulators shall supervise and inspect compliance by data processors in the industry and information technology sectors with the requirements of these Measures.
Data processors in the industry and information technology sectors shall cooperate with supervision and inspections conducted by industry regulators.
Article 33 Under the guidance of the national data security work coordination mechanism, MIIT shall carry out work relating to data security reviews in the industry and information technology sectors.
Article 34 Personnel of industry regulators and data security assessment institutions entrusted by them shall strictly maintain the confidentiality of personal information, trade secrets and other such information learned in the course of performing their duties, and shall not disclose it or illegally provide it to others.
Article 35 Where industry regulators discover significant security risks in data processing activities while performing their data security supervision and management duties, they may conduct regulatory interviews with data processors in the industry and information technology sectors in accordance with the prescribed powers and procedures, and require them to take corrective measures and eliminate security hazards.
Article 36 Where these Measures are violated, industry regulators shall, in accordance with relevant laws and regulations and having regard to the seriousness of the circumstances, impose administrative penalties such as confiscation of unlawful gains, fines, suspension of business activities, suspension of operations for rectification, or revocation of operating licences. Where a violation constitutes a crime, criminal liability shall be pursued in accordance with the law.
Article 37 Central state-owned enterprises shall supervise and guide their affiliated enterprises in complying with local regulatory administration requirements when filing catalogues of important data and core data, assessing risks in the processing of core data across entities, reporting risk information, submitting annual reports on the handling of data security incidents, conducting risk assessments of important data and core data, and carrying out other relevant work. They shall also comprehensively review and consolidate information relating to data security at their group headquarters and affiliated companies and promptly submit it to MIIT.
Article 38 Data processing activities involving personal information shall also comply with relevant laws and administrative regulations.
Article 39 Data processing activities involving military information, State secrets and similar matters shall be governed by the relevant provisions of the State.
Article 40 Specific measures for the processing of government affairs data in the industry and information technology sectors shall be separately prescribed by MIIT.
Article 41 The State Administration of Science, Technology and Industry for National Defence and the State Tobacco Monopoly Administration shall be responsible for data security management in the defence science, technology and industry sector and the tobacco sector, respectively. Specific rules shall be formulated separately with reference to these Measures.
Article 42 These Measures shall enter into force on January 1, 2023.
