Skip to main content
Abstract data governance regulatory reference grid

Data governance · maintained regulatory reference

China Data Privacy Regulatory Tracker.

Use this maintained source map to identify the instrument family that may affect a China data or personal-information workstream. Confirm the activity, data, parties, systems and current official text before drawing a compliance conclusion.

6 topic prompts5 official routes2026-08-21 source check
01 Current instrument set

Use a maintained source set, not one isolated rule

Start with the activity, data and parties, then identify the current instrument family.

China data work can involve the PIPL, network and data-security rules, cross-border transfer mechanisms, important-data or sector requirements and operational guidance. This tracker keeps those routes visible without treating a tag as a legal conclusion.

Source set checked 21 August 2026 by China Legal Portal Editorial. Draft consultation texts are not shown as effective law.

Maintained data-governance reference
Living referencePIPL, network data and cross-border transfer source set
Current through
21 August 2026
Primary authorities
National People’s Congress and Cyberspace Administration of China
Use boundary
Research orientation only; exact facts and current official texts require professional verification
Review the official source set ↓
02 Browse topics

Use prompts to locate the source family

Search the operational question, then verify the official text before drawing any conclusion.

Topic cards and tags are navigation aids. They do not determine whether data is personal or important, whether a transfer exists, or which mechanism applies.

6 sector prompts displayedOfficial-source verification required
01

Research prompt

Personal information protection

Start with the PIPL when the activity involves identifiable natural persons, processing roles, sensitive personal information, individual rights or overseas provision.

PIPLPersonal informationRights
Sources ↓
02

Research prompt

Network data security

Check the Network Data Security Management Regulations and adjacent cybersecurity or data-security rules for the system, operator and data activity.

Network dataSecurityGovernance
Sources ↓
03

Research prompt

Cross-border transfer route

Map whether the activity is an overseas provision of data, then test exemptions and the current security-assessment, standard-contract or certification route.

Data exportAssessmentSCC
Sources ↓
04

Research prompt

Important data and sector rules

Do not infer important-data status from volume alone. Check notifications, published catalogues, sector rules and applicable FTZ negative lists.

Important dataSectorFTZ
Sources ↓
05

Research prompt

Processor and recipient records

Map controllers or processors, entrusted processing, joint decisions, overseas recipients, contracts, impact assessments and change events.

RolesContractsRecords
Sources ↓
06

Research prompt

Operational change watch

Recheck new systems, SDKs, HRIS or CRM changes, new data fields, recipients, countries, vendors, mergers and incident response.

OperationsVendorsChange
Sources ↓
03 Official sources

Primary text before interpretation

Keep the instrument, activity and later updates in one research trail.

04 Additional checks

Data analysis is fact- and change-sensitive

Before selecting a route, preserve the facts that may change the regulatory analysis.

Processing activity

Describe collection, use, storage, access, sharing, transfer, deletion and automated decisions.

Data and people

Identify data fields, sensitivity, scale, affected individuals, important-data indicators and sector context.

Roles and systems

Map processors, entrusted parties, joint decisions, recipients, vendors, systems and access locations.

Mechanism and change

Verify exemptions or mechanisms, impact assessments, contracts, filings and operational change triggers.

05 Related routes

Continue from the source map

Move to the appropriate data decision or counsel resource.