DSL is data classification and national-security-grade data — not a second PIPL.
The Data Security Law applies to data handling in the PRC and, in defined cases, to overseas handling that harms PRC national security or public interest. It requires classification, protection by class, risk assessments for important data, and a gated story for export of important data. It is not PIPL (personal information) and not CSL (network security), though the three stack. This page is a scoped wiki definition, not a second Data Privacy L3 hub. Do not reprint sector catalogues here; they move.
4 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
Is the dataset PI, important data, or both?
PIPL and DSL can both apply.
ClassIs there a catalogue or CII overlay?
Sector and local identification.
CatalogueIs export on the table?
Important-data export is usually assessment-grade.
ExportWho is the regulator set?
CAC plus sector, not only a privacy officer.
RegulatorWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
Does DSL apply to ordinary customer names?
Those are primarily PIPL. They become a DSL story if they are also identified as important data or sit in a CII system.
Is this the L3 Data Privacy hub?
No. The national guide stays on its URL. This is the DSL definition layer.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.
