Skip to content

Evidence request lists

China Data Security Law (DSL)

Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

China DSL: Data Security Protection Obligations (Chapter IV)

DSL-Art27
Data Security Management System and Whole-Lifecycle Measures (Art. 27)

Data processors must establish a sound data-security management system across the whole process, organise data-security education and training, and adopt appropriate technical and other measures; processing of important data requires a designated person and management body responsible for data security.

Artefacts an auditor will ask for
  • documented whole-lifecycle data-security management system
  • data-security training records
  • for important data: designated responsible person and management body
  • technical and organisational measures
Where this commonly fails
  • no data-security management system
  • no responsible person for important data
  • staff untrained
DSL-Art28
Lawful and Legitimate Data Processing (Art. 28)

Data processing must comply with laws and regulations, respect social morality and ethics, observe commercial and professional ethics, be honest and trustworthy, and must not endanger national security or the public interest.

Artefacts an auditor will ask for
  • evidence processing complies with law and does not harm national/public interest
Where this commonly fails
  • processing not assessed against legality/public-interest requirements
DSL-Art29
Risk Monitoring, Remediation and Incident Notification (Art. 29)

Data processors must strengthen risk monitoring; on discovering data-security defects/vulnerabilities, immediately take remedial measures; on a data-security incident, immediately take disposal measures and promptly notify users and report to the relevant authority.

Artefacts an auditor will ask for
  • risk monitoring and vulnerability remediation process
  • incident disposal, user notification and regulator reporting records
Where this commonly fails
  • vulnerabilities not remediated
  • incidents not notified to users/authorities
DSL-Art30
Important Data Risk Assessment and Reporting (Art. 30)

Processors of important data must periodically conduct a risk assessment of their data-processing activities and submit the risk-assessment report to the relevant authority.

Artefacts an auditor will ask for
  • periodic risk assessments of important-data processing
  • risk-assessment reports submitted to the relevant authority
Where this commonly fails
  • important data processed without periodic risk assessment/reporting
DSL-Art31
Cross-Border Transfer of Important Data (Art. 31)

Cross-border transfer of important data collected/generated by CII operators follows the CSL; for other data processors, cross-border transfer of important data follows measures formulated by the Cyberspace Administration with relevant departments.

Artefacts an auditor will ask for
  • security assessment / approved mechanism for cross-border transfer of important data
Where this commonly fails
  • important data transferred abroad without the required assessment/mechanism
DSL-Art32
Lawful and Proper Collection of Data (Art. 32)

Any organisation or individual collecting data must use lawful and proper methods and must not steal or otherwise illegally obtain data; collection must stay within any purpose/scope set by law.

Artefacts an auditor will ask for
  • evidence data is collected by lawful and proper means within legal purpose/scope
Where this commonly fails
  • data obtained by illegal/improper means
DSL-Art33
Data Trading Intermediary Obligations (Art. 33)

Institutions providing data-trading intermediary services must require providers to explain the source of the data, verify the identities of both parties, and keep transaction records.

Artefacts an auditor will ask for
  • source verification and identity checks for traded data
  • retention of transaction records
Where this commonly fails
  • traded data source not verified
  • no transaction records

China DSL: Data Security System (Chapter III)

DSL-Art21
Hierarchical Data Classification, Core Data and Important Data Catalogue (Art. 21)

A categorical and hierarchical data-protection system: data is classified and graded by importance to economy/society and the impact if compromised; national core data receives the strictest protection; regions/departments determine important-data catalogues.

Artefacts an auditor will ask for
  • data classification/grading scheme by importance and impact
  • identification of national core data and important data against the applicable catalogue
Where this commonly fails
  • data not classified/graded
  • important data / core data not identified against the catalogue
DSL-Art22
National Data Security Risk Assessment, Monitoring and Early Warning (Art. 22)

The State establishes a centralised, unified, efficient and authoritative data-security risk assessment, reporting, information-sharing, monitoring and early-warning mechanism.

Artefacts an auditor will ask for
  • participation in / alignment with risk monitoring and early-warning where required
Where this commonly fails
  • no data-security risk monitoring capability
DSL-Art23
Data Security Emergency Response (Art. 23)

The State establishes a data-security emergency response mechanism; on a data-security incident, the responsible department activates the emergency plan, takes mitigation measures and releases warnings to the public.

Artefacts an auditor will ask for
  • data-security incident emergency response plan
  • coordination with the relevant department
Where this commonly fails
  • no data-security incident response plan
DSL-Art24
National Security Review of Data Activities (Art. 24)

The State establishes a data-security review system to conduct national security reviews of data-processing activities that affect or may affect national security.

Artefacts an auditor will ask for
  • assessment of whether data activities trigger a national security review
Where this commonly fails
  • data activities affecting national security not assessed for review
DSL-Art25
Export Controls on Controlled Data (Art. 25)

Data that is a controlled item relevant to safeguarding national security and interests, or to fulfilling international obligations, is subject to export-control law.

Artefacts an auditor will ask for
  • classification of any data subject to export controls and compliance with export-control law
Where this commonly fails
  • controlled-item data exported without export-control compliance

China DSL: Data Security and Development (Chapter II)

DSL-Art17
Data Security Standards (Art. 17)

The State establishes and improves a data-security standards system; relevant bodies organise the development of data-security standards.

Artefacts an auditor will ask for
  • alignment of data-security practices to applicable national/industry standards
Where this commonly fails
  • practices not aligned to data-security standards
DSL-Art19
Data Trading Market Rules (Art. 19)

The State establishes a sound data-transaction management system, regulates data-trading conduct, and cultivates a data-trading market.

Artefacts an auditor will ask for
  • compliance with data-transaction rules where the organisation trades data
Where this commonly fails
  • data trading without regard to the transaction management regime
DSL-Art7
Data Security and Development (Art. 7)

The State protects data-related rights and interests, encourages lawful and rational data use, and promotes data-driven economic and social development with security.

Artefacts an auditor will ask for
  • data governance framework balancing security and development
Where this commonly fails
  • no overarching data governance posture

China DSL: General Provisions (Chapter I)

DSL-Art2
Scope and Extraterritorial Application (Art. 2)

The DSL governs data processing activities and their security within the PRC, and applies extraterritorially to data activities outside the PRC that harm national security, the public interest, or the rights of PRC citizens/organisations.

Artefacts an auditor will ask for
  • assessment of whether the organisation conducts data-processing activities in scope (incl. extraterritorial trigger)
Where this commonly fails
  • DSL applicability/extraterritorial reach not assessed
DSL-Art3
Definitions of Data and Data Processing (Art. 3)

Defines data (any record of information in electronic or other form), data processing (collection, storage, use, processing, transmission, provision, disclosure, etc.) and data security.

Artefacts an auditor will ask for
  • inventory of data-processing activities mapped to the DSL definitions
Where this commonly fails
  • data-processing activities not mapped to the law

China DSL: Government Data and Legal Liability (Chapters V-VII)

DSL-Art35
Data Access by Public/National Security Organs (Art. 35)

Where public-security or national-security organs need to access data for safeguarding national security or investigating crimes, they must follow strict approval procedures and the organisation must cooperate.

Artefacts an auditor will ask for
  • procedure for handling lawful data-access requests from PRC organs with proper approval
Where this commonly fails
  • no process for lawful access requests
DSL-Art36
Foreign Authority Data Requests (Art. 36)

PRC competent authorities handle foreign requests for data under international treaties/agreements or the principle of reciprocity; organisations must not provide data stored in the PRC to foreign judicial or law-enforcement bodies without approval of the competent PRC authority.

Artefacts an auditor will ask for
  • process to refuse/escalate foreign judicial/law-enforcement data requests pending PRC authority approval
Where this commonly fails
  • data provided to foreign authorities without PRC approval
DSL-Art37
Government Affairs Data Security (Art. 37-42)

State organs must establish sound data-security management systems for government affairs data, fulfil data-security protection obligations, and (where entrusting processing) require the trustee to fulfil obligations; government data should be made open per law.

Artefacts an auditor will ask for
  • data-security management for government-affairs data (where applicable)
  • controls over entrusted processing
Where this commonly fails
  • government-affairs data inadequately protected
DSL-Art45
Legal Liability and Penalties (Art. 45-52)

Administrative penalties (rectification orders, warnings, fines on the entity and responsible persons, suspension of business, revocation of permits/licences) for failing to perform data-security obligations, with heavier penalties for core/important data violations and illegal cross-border transfer.

Artefacts an auditor will ask for
  • awareness of DSL penalty exposure (incl. core/important data and cross-border)
  • process for responding to rectification orders
Where this commonly fails
  • no process for regulatory enforcement response
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the China Data Security Law (DSL) framework page.