China Data Security Law (DSL)
Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
China DSL: Data Security Protection Obligations (Chapter IV)
Data processors must establish a sound data-security management system across the whole process, organise data-security education and training, and adopt appropriate technical and other measures; processing of important data requires a designated person and management body responsible for data security.
- documented whole-lifecycle data-security management system
- data-security training records
- for important data: designated responsible person and management body
- technical and organisational measures
- no data-security management system
- no responsible person for important data
- staff untrained
Data processing must comply with laws and regulations, respect social morality and ethics, observe commercial and professional ethics, be honest and trustworthy, and must not endanger national security or the public interest.
- evidence processing complies with law and does not harm national/public interest
- processing not assessed against legality/public-interest requirements
Data processors must strengthen risk monitoring; on discovering data-security defects/vulnerabilities, immediately take remedial measures; on a data-security incident, immediately take disposal measures and promptly notify users and report to the relevant authority.
- risk monitoring and vulnerability remediation process
- incident disposal, user notification and regulator reporting records
- vulnerabilities not remediated
- incidents not notified to users/authorities
Processors of important data must periodically conduct a risk assessment of their data-processing activities and submit the risk-assessment report to the relevant authority.
- periodic risk assessments of important-data processing
- risk-assessment reports submitted to the relevant authority
- important data processed without periodic risk assessment/reporting
Cross-border transfer of important data collected/generated by CII operators follows the CSL; for other data processors, cross-border transfer of important data follows measures formulated by the Cyberspace Administration with relevant departments.
- security assessment / approved mechanism for cross-border transfer of important data
- important data transferred abroad without the required assessment/mechanism
Any organisation or individual collecting data must use lawful and proper methods and must not steal or otherwise illegally obtain data; collection must stay within any purpose/scope set by law.
- evidence data is collected by lawful and proper means within legal purpose/scope
- data obtained by illegal/improper means
Institutions providing data-trading intermediary services must require providers to explain the source of the data, verify the identities of both parties, and keep transaction records.
- source verification and identity checks for traded data
- retention of transaction records
- traded data source not verified
- no transaction records
China DSL: Data Security System (Chapter III)
A categorical and hierarchical data-protection system: data is classified and graded by importance to economy/society and the impact if compromised; national core data receives the strictest protection; regions/departments determine important-data catalogues.
- data classification/grading scheme by importance and impact
- identification of national core data and important data against the applicable catalogue
- data not classified/graded
- important data / core data not identified against the catalogue
The State establishes a centralised, unified, efficient and authoritative data-security risk assessment, reporting, information-sharing, monitoring and early-warning mechanism.
- participation in / alignment with risk monitoring and early-warning where required
- no data-security risk monitoring capability
The State establishes a data-security emergency response mechanism; on a data-security incident, the responsible department activates the emergency plan, takes mitigation measures and releases warnings to the public.
- data-security incident emergency response plan
- coordination with the relevant department
- no data-security incident response plan
The State establishes a data-security review system to conduct national security reviews of data-processing activities that affect or may affect national security.
- assessment of whether data activities trigger a national security review
- data activities affecting national security not assessed for review
Data that is a controlled item relevant to safeguarding national security and interests, or to fulfilling international obligations, is subject to export-control law.
- classification of any data subject to export controls and compliance with export-control law
- controlled-item data exported without export-control compliance
China DSL: Data Security and Development (Chapter II)
The State establishes and improves a data-security standards system; relevant bodies organise the development of data-security standards.
- alignment of data-security practices to applicable national/industry standards
- practices not aligned to data-security standards
The State establishes a sound data-transaction management system, regulates data-trading conduct, and cultivates a data-trading market.
- compliance with data-transaction rules where the organisation trades data
- data trading without regard to the transaction management regime
The State protects data-related rights and interests, encourages lawful and rational data use, and promotes data-driven economic and social development with security.
- data governance framework balancing security and development
- no overarching data governance posture
China DSL: General Provisions (Chapter I)
The DSL governs data processing activities and their security within the PRC, and applies extraterritorially to data activities outside the PRC that harm national security, the public interest, or the rights of PRC citizens/organisations.
- assessment of whether the organisation conducts data-processing activities in scope (incl. extraterritorial trigger)
- DSL applicability/extraterritorial reach not assessed
Defines data (any record of information in electronic or other form), data processing (collection, storage, use, processing, transmission, provision, disclosure, etc.) and data security.
- inventory of data-processing activities mapped to the DSL definitions
- data-processing activities not mapped to the law
China DSL: Government Data and Legal Liability (Chapters V-VII)
Where public-security or national-security organs need to access data for safeguarding national security or investigating crimes, they must follow strict approval procedures and the organisation must cooperate.
- procedure for handling lawful data-access requests from PRC organs with proper approval
- no process for lawful access requests
PRC competent authorities handle foreign requests for data under international treaties/agreements or the principle of reciprocity; organisations must not provide data stored in the PRC to foreign judicial or law-enforcement bodies without approval of the competent PRC authority.
- process to refuse/escalate foreign judicial/law-enforcement data requests pending PRC authority approval
- data provided to foreign authorities without PRC approval
State organs must establish sound data-security management systems for government affairs data, fulfil data-security protection obligations, and (where entrusting processing) require the trustee to fulfil obligations; government data should be made open per law.
- data-security management for government-affairs data (where applicable)
- controls over entrusted processing
- government-affairs data inadequately protected
Administrative penalties (rectification orders, warnings, fines on the entity and responsible persons, suspension of business, revocation of permits/licences) for failing to perform data-security obligations, with heavier penalties for core/important data violations and illegal cross-border transfer.
- awareness of DSL penalty exposure (incl. core/important data and cross-border)
- process for responding to rectification orders
- no process for regulatory enforcement response
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the China Data Security Law (DSL) framework page.