Article 31 The State shall, based on the classified protection system for cybersecurity, focus on protecting both the critical information infrastructure used for public communications and information service, energy, transport, water conservancy, finance, public services, e-government affairs and other important industries and fields and other critical information infrastructure that will result in serious damage to the national security, national economy and people's livelihood and public interests if they are destroyed, there are lost functions or they are subject to data leakage. The specific scope and measures for security protection for critical information infrastructure shall be formulated by the State Council. The State encourages network operators other than critical information infrastructure to participate in the protective system of critical information infrastructure on a voluntary basis. Article 32 The departments in charge of protecting the security of critical information infrastructure, in accordance with the responsibilities stipulated by the State Council, shall respectively compile and organize the implementation of critical information infrastructure security plans for their own industry and field, and guide and supervise the work related to the protection of operation security of critical information infrastructure. Article 33 To construct the critical information infrastructure, it shall be ensured that the critical information infrastructure has properties for supporting the stable and continuous operation of the business, and that technical security measures are planned, established and used concurrently. Article 34 In addition to the provisions of Article 21 herein, critical information infrastructure operators shall also fulfill the following obligations of security protection, 1. Set up independent security management institutions and designate persons responsible for security management, and review the security background of the said responsible persons and personnel in key positions; 2. Periodically conduct cybersecurity education, technical training and skill assessment for practitioners; 3. Make disaster recovery backups of important systems and databases; 4. Formulate contingency plans for cybersecurity incidents, and carry out drills periodically; and 5. Other obligations stipulated by laws and administrative regulations. Article 35 Where critical information infrastructure operators purchase network products and services, which may influence national security, they shall go through a security review organized by the national cyberspace administration authority in concert with the relevant departments under the State Council. Article 36 To purchase network products and services, critical information infrastructure operators shall enter into security confidentiality agreements with the providers in accordance with the provisions, in which obligations and responsibilities in terms of security and confidentiality shall be clarified. Article 37 Critical information infrastructure operators shall store personal information and important data gathered and produced during operations within the territory of the People's Republic of China. Where it is really necessary to provide such information and data to overseas parties due to business requirements, a security assessment shall be conducted in accordance with the measures formulated by the national cyberspace administration authority in concert with the relevant departments under the State Council. Where the laws and administration regulations have other provisions, those provisions shall prevail. Article 38 Critical information infrastructure operators shall conduct by themselves, or entrust cybersecurity service institutions to conduct, the detection and assessment of their cybersecurity and any potential risk at least once a year; and submit the detection and assessment situations as well as improvement measures to the relevant departments responsible for the security protection of critical information infrastructure. Article 39 The national cyberspace administration authority shall coordinate with the relevant departments 6

Sélectionner le paragraphe cible3