Short answer
The Data Security Law classifies data by its importance to economic and social development and by the harm that alteration, destruction, disclosure, illegal acquisition, or illegal use could cause to national security, the public interest, or lawful individual and organizational interests. Regions and departments must identify important-data catalogues for their sectors and protect listed data more closely. is a separate, stricter category. A company's internal 'critical' or 'confidential' label can support screening, but it does not by itself establish either legal category.
For export screening, the 2024 Provisions say a processor does not need to declare data as unless a relevant department or region has notified the processor or publicly identified the data as important. This rule addresses the export filing decision; it does not remove the duty to monitor applicable catalogues and official notices.
An important-data processor must identify a data-security responsible person and management body: a named accountable lead and an organizational function responsible for implementing the data-security duties. The processor must periodically assess its data-processing activities and submit a report covering the types and quantities of , processing activities, risks, and response measures. The Data Security Law does not state one universal interval for every sector, so the processor must check applicable departmental and regional rules. General duties to monitor risk, remedy vulnerabilities, handle incidents, notify users where required, and report to the competent authority also apply.
A transfer outside China needs its own route. Under the 2024 Provisions, a exporting or , and a non-CII processor exporting important data, must apply for a through the provincial cyberspace authority, subject to the stated special provisions. Personal-information volume exemptions do not exempt important-data exports.
A successful assessment result is valid for three years from the result date. If the export will continue and no re-application trigger has occurred, the processor may apply for a three-year extension within 60 working days before expiry; the national cyberspace authority decides whether to approve it. Keep the validity period, extension decision, and any change requiring a new application separate from the periodic domestic important-data risk assessment.
Articles 21 and 27-31 establish important-data catalogues, enhanced governance, monitoring, incident response, periodic risk assessment and reporting, and separate export rules.
Use for the security-assessment procedure, pre-filing self-assessment, application materials, assessment factors, and re-application triggers where the current 2024 Provisions require an assessment.
Articles 2 and 7 state the official-identification rule and require CII operators exporting personal information or important data, and other processors exporting important data, to apply for a security assessment. Article 9 sets the assessment result's three-year validity and possible extension.