On 18 June 2026, the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), and the Ministry of Public Security (MPS) jointly issued the Measures for Network Data Security Risk Assessment. The Measures, previously open for public comment in December 2025, will take effect on 20 August 2026. They operationalize obligations for key data processors stipulated in the Data Security Law and the Regulation on Network Data Security Management.
Under the new Measure, key data processors must conduct compulsory annual risk assessments and submit reports to the relevant authorities. The Measures set out two routes for conducting assessments: processors may carry out the assessment internally and appoint a Key Data Officer in Charge, or engage a qualified third-party assessment organization. Both internal teams and third-party organizations must meet the capacity requirements set out in GB/T 45389-2025 Data security technology - Capacity requirements for assessment organization of data security. Assessment reports must be submitted within 20 days after completing the assessment. The annual deadline is set at the end of January each year.
The Measures also apply to general and core data processors, though general data processors face a longer cycle, with assessments required at a maximum interval of three years. Data classification and grading follow the national standard GB/T 43697-2024 Data security technology - Rules for data classification and grading.
In general, key data processors are defined by three criteria:
classification under GB/T 43697-2024;
processing personal information of at least 10 million individuals, regardless of the sensitivity of personal information; or
inclusion in a Key Data Catalogue compiled by local, sectoral, or national competent authorities.
For foreign stakeholders operating in China or processing data from China, the Measures enter into force with limited lead time. The first step is to determine whether your entity qualifies as a key data processor under the three criteria, and more importantly to consult with cyberspace authorities at the national or regional level for confirmation. Completing the risk assessment ahead of the January deadline allows time for rectification and reduces compliance risk. Early preparation is strongly advised.
If you have any questions or need further assistance, please reach us at: info@bestao-consulting.com.
Top Read Articles
Switch articles-
2026.08.11China Releases 15th Five-Year Plan Action Plan to Peak Carbon by 2030 – JUL 2026
-
2026.08.10Automotive Testing and BEP Standards of China Calling for Comments – JUL, 2026
-
2026.08.07China Unveils New Measures to Boost Auto Aftermarket Consumption – JUN 2026
-
2026.08.05Road Vehicle TC Recruiting Experts for ISO Standard Revision – JUL, 2026
-
2026.08.03Fuel Consumption Limit Requirements Amended for Vehicles in China – JUL, 2026