China EditionArticle 7 · China Edition

Data Security, CII Compliance & Cross-Border Data Flows

Data Security, CII Compliance & Cross-Border Data Flows


In an era where data has become a factor of production, security compliance is not the opposite of innovation — it is the prerequisite for sustainable operations.

China's Data Security Legal Framework

Community data centers operating in China must comply with a three-tier data security legal system:

Legal TierCore RegulationData Center Applicability
Foundational LawCybersecurity Law (2017)MLPS 2.0 mandatory baseline · Data localization · Personal information protection
Specialized LawData Security Law (2021)Data classification & grading · CII designation · Important data catalogs
Supporting LawPersonal Information Protection Law (2021)Personal information processing rules · Cross-border transfer mechanisms · Individual rights protection
Administrative RegulationRegulations on the Security Protection of Critical Information Infrastructure (2021)CII designation criteria · Security review · Annual inspection & assessment
Cross-Border RulesProvisions on Promoting and Regulating Cross-Border Data Flows (2024)Exemption scenarios · Security assessment · Standard contract · Protection certification
📅 Policy as of: June 2026. Cross-border data flow rules are in a period of rapid evolution. Readers are advised to establish quarterly internal compliance review mechanisms and track the latest regulations from the Cyberspace Administration of China (CAC).

CII Designation & Differentiated Disclosure

What is Critical Information Infrastructure (CII)?

CII refers to network facilities and information systems whose destruction, loss of function, or data leakage could seriously endanger national security, the national economy, people's livelihoods, or the public interest. Data centers — particularly large-scale or hub-level data centers carrying data from critical sectors such as government, finance, energy, and transportation — may be designated as CII.

Differentiated Disclosure Arrangement

This framework applies different information disclosure requirements for CII and non-CII data centers:

Disclosure RequirementNon-CII Data CenterCII Data Center
Real-time operational dashboardPublic ✓❌ Replaced by periodic regulatory reports
Annual community impact reportPublic ✓Public (after desensitization) ✓
Energy / Water dataReal-time public ✓Aggregated historical data public ✓
Independent audit reportFull public disclosure ✓Public after security review
Regulatory reportingPer MLPS requirementsPer MLPS + CII requirements, higher frequency
⚙️ Compliance Basis: The above differentiated arrangements are based on Article 21 of the Data Security Law (data classification & grading) and relevant provisions of the Regulations on the Security Protection of Critical Information Infrastructure. Information disclosure in any scenario shall satisfy the principles of "lawful, legitimate, and necessary."

Data Classification & Grading

The Data Security Law classifies data into three levels, with different processing and disclosure rules for each:

LevelDefinitionProcessing RequirementsThis Framework's Disclosure Rule
Core DataRelated to national security, lifelines of the national economyStrictest controlsNot disclosed
Important DataMay endanger national security or public interestStrict controls + security assessmentDisclosed after desensitization & aggregation
General DataNot involving the above two categoriesProcessed in accordance with lawMay be disclosed (per law)

Most environmental and social data generated by community data centers in daily operations (PUE, WUE, renewable energy ratio, community employment headcount, etc.) falls under General Data and may be publicly disclosed in accordance with law. Data involving specific customer information, network topology, security configurations, etc. falls under Important Data or Core Data and must be strictly controlled.


Cross-Border Data Flows

Three Compliance Pathways

Under Article 38 of the Personal Information Protection Law and the 2024 Provisions on Promoting and Regulating Cross-Border Data Flows, there are three compliance pathways for data export:

PathwayApplicable ScenariosRegulatory Body
Data export security assessmentImportant data export · CII operator personal information export · Large-scale personal information exportCAC
Personal information export standard contractNon-CII · Non-important data · Small-to-medium scale personal information exportProvincial CAC (filing)
Personal information protection certificationIntra-group cross-border data transfers within multinational corporations, etc.Certification bodies

Exemption Scenarios under the 2024 Rules

The 2024 Provisions on Promoting and Regulating Cross-Border Data Flows relaxed regulatory requirements for certain scenarios:

- Personal information export necessary for international trade, cross-border transportation, academic cooperation, etc.

- Personal information collected and processed overseas then transmitted back into China

- Personal information export necessary for contract performance

Recommendation: Community data center operators should establish data classification inventories, clearly identify which data may involve export scenarios, and pre-assess applicable compliance pathways. For the vast majority of community DCs, localized data processing is the more pragmatic choice.

The Role of the National Data Administration (NDA)

The National Data Administration (NDA, established 2023) is the specialized agency coordinating the establishment of basic data systems and the integrated sharing, development, and utilization of data resources. In terms of data security compliance:

- Data classification & grading guidelines — NDA is coordinating with relevant departments to develop industry-specific Important Data catalogs

- Data factor marketization — NDA promotes data trading market development (implementation of the "Data Twenty Measures")

- Computing infrastructure — NDA participates in nationally integrated computing power network planning

This framework recommends that community data center operators monitor industry guidance documents published by NDA to ensure data management practices remain aligned with the latest policies.


Eternal Harmony is an AI research and development company. This is part of our public-interest research on technology infrastructure and community impact.

This framework is an independent initiative, not approved or endorsed by any government agency.