Those handling important data shall clearly specify responsible personnel and management bodies for data
security and fully implement data security protection responsibilities.
Article 28 Any data handling activity as well as the research and development of new data technologies shall
benefit the advancement of economic and social development, enhance the people's welfare, and conform
to social morals and ethics.
Article 29 Those conducting data handling activities shall strengthen risk monitoring, and where they
discover risks such as data security flaws and vulnerabilities, immediately adopt remedial measures; when
data security incidents occur, they shall immediately take disposal measures, notify the users as required and
report the matter to the relevant competent department.
Article 30 Those handling important data shall, in accordance with relevant provisions, periodically conduct
risk assessments for their data handling activities, and submit a risk assessment report to the relevant
competent department.
The risk assessment report shall include the categories and quantities of important data handled by the said
organization, how data are handled, the data security risks faced and their countermeasures.
Article 31 The security administration of the cross-border transfer of important data collected and generated
by operators of critical information infrastructure during their operation in China shall be subject to the
provisions of the Cybersecurity Law of the People's Republic of China; the administrative measures for the
cross-border transfer of important data collected and generated by other data handlers during their
operation in the People's Republic of China shall be formulated by the national cyberspace administration
authority in collaboration with relevant departments of the State Council.
Article 32 Any organization or individual collecting data shall adopt lawful and proper methods and shall not
steal data or obtain them by other illegal means.
Where any law and administrative regulation contains provisions on the purpose or scope of data collection
or use, data shall be collected and used for the purpose and within the scope prescribed by such law and
administrative regulation.
Article 33 Institutions engaging in data transaction intermediary services shall, when providing their services,
require the data providers to explain the source of data, examine and verify the identity of both parties to
the transaction, and retain examination, verification, and transaction records.
Article 34 Where any law and administrative regulation stipulates that administrative license shall be
obtained before providing any service related to data handling, the service providers shall obtain such license
in accordance with the law.
Article 35 Where public security organs and national security organs need to consult any data in order to
safeguard national security or investigate a crime in accordance with the law, they shall, in accordance with
the relevant provisions of the State, undergo strict approval procedures and proceed with the matter in
accordance with the law; and the relevant organizations and individuals shall render cooperation.
Article 36 The competent authority of the People's Republic of China shall handle the request for providing
any data from a foreign judicial body and law enforcement body in accordance with relevant laws and the
international treaty or agreement which the People's Republic of China has concluded or acceded to, or
under the principle of equality and mutual benefit. Any organization or individual within the territory of the
People's Republic of China shall not provide any foreign judicial body and law enforcement body with any
data stored within the territory of the People's Republic of China without the approval of the competent
authority of the People's Republic of China.
5