Skip to main content

China Cybersecurity Law — Multi-Level Protection Scheme

China's Cybersecurity Law (effective 2017) establishes cybersecurity requirements for network operators, including the Multi-Level Protection Scheme (MLPS 2.0), data localization mandates, and incident reporting obligations.

  • Type Definition-first explainer
  • Read 1 min
  • Updated

Applicability

The law applies to all \"network operators\" � any entity operating or providing network services in China, including websites, mobile apps, cloud services, and internal corporate networks.

Multi-Level Protection Scheme (MLPS 2.0)

Information systems are classified into five security levels based on the impact of a breach. Level 2 and above require filing with the public security bureau and passing a security assessment by a qualified third party. Level 3 and above require annual audits.

Data Localization

Critical information infrastructure (CII) operators must store personal information and?? data within China. Data exported must undergo a security assessment. CII sectors include finance, energy, transportation, healthcare, and telecommunications.

Go deeper

Related guides & counsel

Move from this definition into full practice guidance, city markets, or a verified lawyer directory.

Educational information only — not legal advice. Laws and practice change; consult qualified counsel for your situation. No attorney–client relationship is formed by using this site.

China Legal Wiki

More plain-English China law explainers

Browse definition-first pages on WFOE, visas, trademarks, courts, tax, and more — then open full practice and city guides.