and in adopting a variety of methods to cultivate talent in data development and use technology and data
security, and to promote talent exchange.
Chapter III Data Security Systems
Article 21 The State shall establish a classified and graded data protection system, and carry out classified
and graded data protection in accordance with the degree of importance of data to economic and social
development, and the damage to national security, public interests, or the legitimate rights and interests of
individuals or organizations in the event that data are tampered with, destroyed, leaked, or illegally obtained
or used. The national data security coordination mechanism shall make overall planning for and coordinate
relevant departments in formulating the catalogues for important data and strengthening the protection of
important data.
Data that have a bearing on national security, the lifelines of national economy, umportant aspects of
people's livelihood and major public interests shall constitute the core data of the State and shall be subject
to stricter management system.
Each region and department shall, in accordance with the classified and graded data protection system,
determine the specific catalogue for important data for the respective region and department, and in
relevant industries and areas, and undertake special protection for the data included in the catalogue.
Article 22 The State shall establish a centralized, efficient, and authoritative mechanism for data security risk
assessment, reporting, information sharing, supervision, and early warning. The national data security
coordination mechanism shall make overall planning for and coordinate relevant departments in
strengthening their work in the collection, analysis, determination, and early warning of the data security risk
information.
Article 23 The State shall establish a data security emergency response mechanism. In the event of a data
security incident, the relevant competent department shall, in accordance with the law, activate a
contingency plan, adopt appropriate emergency response measures, prevent expansion of harms, eliminate
security hazards, and promptly publish the warning information related to the public.
Article 24 The State shall establish a data security review system, where data handling activities that affect or
may affect the national security will undergo national security review.
Security review decisions issued in accordance with the law are final decisions.
Article 25 The State shall implement export controls in accordance with the law on data belonging to
controlled categories and those relevant to safeguarding national security and interests and fulfilling
international obligations.
Article 26 For any country or region that adopts discriminatory prohibitions, limitations, or other similar
measures related to data and data development and use technology, against the People's Republic of China,
in investment, trade and other areas, the People's Republic of China may, depending on the actual
circumstances, adopt the equivalent measures against such country or region.
Chapter IV Data Security Protection Obligations
Article 27 Those conducting data handling activities shall, in accordance with laws and regulations, establish
and perfect a data security management system across the entire workflow, organize and conduct data
security education and training, and adopt the corresponding technical measures and other necessary
measures to ensure data security. Those conducting data handling activities by using the internet or other
information networks shall, based on the graded cybersecurity protection system, perform the aforesaid data
security protection obligations.
4