China Data Security Law (DSL)
What is China Data Security Law (DSL)?
The Data Security Law of the People's Republic of China (effective September 1, 2021) establishes a comprehensive framework for data security governance. It introduces a data classification and grading system, cross‑border data transfer restrictions, security assessment mechanisms, government data security obligations, and a national security assessment system for data handling.. It comprises 21 controls organised across 5 domains, and applies in China.
How China Data Security Law (DSL) maps to other frameworks
All 21 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 5 domains China Data Security Law (DSL) groups its controls into
Where China Data Security Law (DSL) overlaps with the standards you already hold
What China Data Security Law (DSL) means in your sector
What China Data Security Law (DSL) means for your job
Questions people ask about China Data Security Law (DSL)
What is China Data Security Law?
How many controls does China Data Security Law have?
Where does China Data Security Law apply?
What frameworks does China Data Security Law map to?
How do I get started with China Data Security Law compliance?
Query China Data Security Law (DSL) programmatically
China Data Security Law (DSL), its 21 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
China Data Security Law (DSL) API reference and MCP config →What China Data Security Law (DSL) requires, control by control
Each page carries the requirement text for one China Data Security Law (DSL) control and what an assessor expects to see as evidence.
- DSL-ART2 Scope and Extraterritorial Application (Art. 2)
- DSL-ART21 Hierarchical Data Classification, Core Data and Important Data Catalogue (Art. 21)
- DSL-ART22 National Data Security Risk Assessment, Monitoring and Early Warning (Art. 22)
- DSL-ART23 Data Security Emergency Response (Art. 23)
- DSL-ART24 National Security Review of Data Activities (Art. 24)
- DSL-ART27 Data Security Management System and Whole-Lifecycle Measures (Art. 27)
- DSL-ART29 Risk Monitoring, Remediation and Incident Notification (Art. 29)
- DSL-ART30 Important Data Risk Assessment and Reporting (Art. 30)
- DSL-ART31 Cross-Border Transfer of Important Data (Art. 31)
- DSL-ART36 Foreign Authority Data Requests (Art. 36)
How ready are you for China Data Security Law (DSL)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.