Skip to main content

Cybersecurity · 02

Cybersecurity & MLPS

MLPS is a network-security grade, not a personal-information export clearance.

First job Separate cybersecurity grading from personal-information export questions.

Start here

Key considerations

  1. Is the question about networks and grading, or about personal information leaving China?
  2. Has an MLPS grade already been assigned?
  3. Who owns the security file versus the privacy file?

Decision map

Keep the question bounded.

  1. Separate the filesCSL/MLPS versus PIPL transfers.
  2. Locate the gradeIf grading is live, it has its own evidence.
  3. Hand off incidentsA live incident belongs on the incident route.

Curated resources

Open the asset that matches this job.

Helpful to prepare

Facts that make the next conversation clearer.

These items are orientation aids, not a legal requirement list.

  1. Whether MLPS is in scope for the systems at issue
  2. Security versus privacy owner
  3. Any parallel export question

Local context

Add the city when regulator practice changes.

CAC and industry-regulator practice can differ after the national transfer or cybersecurity question is identified.

Open city and province guides

Counsel hand-off

Need data-privacy counsel?

This hub organises PIPL, cybersecurity and export questions. It does not decide whether a transfer is lawful or whether notice is required on your facts.

Find data-privacy counsel

Request a free consultation

Directory and legal information only — not legal advice. Confirm current rules with qualified counsel.

Editorial policy · Last reviewed August 2026 · Data Privacy & Cybersecurity