Data Security, CII Compliance & Cross-Border Data Flows
In an era where data has become a factor of production, security compliance is not the opposite of innovation — it is the prerequisite for sustainable operations.
China's Data Security Legal Framework
Community data centers operating in China must comply with a three-tier data security legal system:
| Legal Tier | Core Regulation | Data Center Applicability |
| Foundational Law | Cybersecurity Law (2017) | MLPS 2.0 mandatory baseline · Data localization · Personal information protection |
| Specialized Law | Data Security Law (2021) | Data classification & grading · CII designation · Important data catalogs |
| Supporting Law | Personal Information Protection Law (2021) | Personal information processing rules · Cross-border transfer mechanisms · Individual rights protection |
| Administrative Regulation | Regulations on the Security Protection of Critical Information Infrastructure (2021) | CII designation criteria · Security review · Annual inspection & assessment |
| Cross-Border Rules | Provisions on Promoting and Regulating Cross-Border Data Flows (2024) | Exemption scenarios · Security assessment · Standard contract · Protection certification |
📅 Policy as of: June 2026. Cross-border data flow rules are in a period of rapid evolution. Readers are advised to establish quarterly internal compliance review mechanisms and track the latest regulations from the Cyberspace Administration of China (CAC).
CII Designation & Differentiated Disclosure
What is Critical Information Infrastructure (CII)?
CII refers to network facilities and information systems whose destruction, loss of function, or data leakage could seriously endanger national security, the national economy, people's livelihoods, or the public interest. Data centers — particularly large-scale or hub-level data centers carrying data from critical sectors such as government, finance, energy, and transportation — may be designated as CII.
Differentiated Disclosure Arrangement
This framework applies different information disclosure requirements for CII and non-CII data centers:
| Disclosure Requirement | Non-CII Data Center | CII Data Center |
| Real-time operational dashboard | Public ✓ | ❌ Replaced by periodic regulatory reports |
| Annual community impact report | Public ✓ | Public (after desensitization) ✓ |
| Energy / Water data | Real-time public ✓ | Aggregated historical data public ✓ |
| Independent audit report | Full public disclosure ✓ | Public after security review |
| Regulatory reporting | Per MLPS requirements | Per MLPS + CII requirements, higher frequency |
⚙️ Compliance Basis: The above differentiated arrangements are based on Article 21 of the Data Security Law (data classification & grading) and relevant provisions of the Regulations on the Security Protection of Critical Information Infrastructure. Information disclosure in any scenario shall satisfy the principles of "lawful, legitimate, and necessary."
Data Classification & Grading
The Data Security Law classifies data into three levels, with different processing and disclosure rules for each:
| Level | Definition | Processing Requirements | This Framework's Disclosure Rule |
| Core Data | Related to national security, lifelines of the national economy | Strictest controls | Not disclosed |
| Important Data | May endanger national security or public interest | Strict controls + security assessment | Disclosed after desensitization & aggregation |
| General Data | Not involving the above two categories | Processed in accordance with law | May be disclosed (per law) |
Most environmental and social data generated by community data centers in daily operations (PUE, WUE, renewable energy ratio, community employment headcount, etc.) falls under General Data and may be publicly disclosed in accordance with law. Data involving specific customer information, network topology, security configurations, etc. falls under Important Data or Core Data and must be strictly controlled.
Cross-Border Data Flows
Three Compliance Pathways
Under Article 38 of the Personal Information Protection Law and the 2024 Provisions on Promoting and Regulating Cross-Border Data Flows, there are three compliance pathways for data export:
| Pathway | Applicable Scenarios | Regulatory Body |
| Data export security assessment | Important data export · CII operator personal information export · Large-scale personal information export | CAC |
| Personal information export standard contract | Non-CII · Non-important data · Small-to-medium scale personal information export | Provincial CAC (filing) |
| Personal information protection certification | Intra-group cross-border data transfers within multinational corporations, etc. | Certification bodies |
Exemption Scenarios under the 2024 Rules
The 2024 Provisions on Promoting and Regulating Cross-Border Data Flows relaxed regulatory requirements for certain scenarios:
- Personal information export necessary for international trade, cross-border transportation, academic cooperation, etc.
- Personal information collected and processed overseas then transmitted back into China
- Personal information export necessary for contract performance
Recommendation: Community data center operators should establish data classification inventories, clearly identify which data may involve export scenarios, and pre-assess applicable compliance pathways. For the vast majority of community DCs, localized data processing is the more pragmatic choice.The Role of the National Data Administration (NDA)
The National Data Administration (NDA, established 2023) is the specialized agency coordinating the establishment of basic data systems and the integrated sharing, development, and utilization of data resources. In terms of data security compliance:
- Data classification & grading guidelines — NDA is coordinating with relevant departments to develop industry-specific Important Data catalogs
- Data factor marketization — NDA promotes data trading market development (implementation of the "Data Twenty Measures")
- Computing infrastructure — NDA participates in nationally integrated computing power network planning
This framework recommends that community data center operators monitor industry guidance documents published by NDA to ensure data management practices remain aligned with the latest policies.
Eternal Harmony is an AI research and development company. This is part of our public-interest research on technology infrastructure and community impact.
This framework is an independent initiative, not approved or endorsed by any government agency.