---
title: "How does important data change China cybersecurity obligations?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations"
author: "Sorena AI"
description: "Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# How does important data change China cybersecurity obligations?

Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.

*Question* *China*

## How does important data change China cybersecurity obligations? Direct answer

Once data is identified as important data, the processor must name a data-security responsible person and management body, conduct periodic risk assessments, submit reports, and apply monitoring and incident controls.

Important-data status depends on an applicable catalogue, government notice, or public identification. Any transfer outside China needs a separate export assessment route.

Important data is not simply a synonym for confidential or personal information: each category has a different legal test. Once data is identified as important data, the processor has added governance, risk-assessment, reporting, incident, and export obligations.

## Definitions

### Important data

Important data is a legal data category identified through China's classified and graded data-protection system and applicable sector or regional catalogues, notices, or public identifications. The category turns on the importance of the data and the harm that alteration, destruction, disclosure, illegal acquisition, or illegal use could cause; it is not created by a company's internal confidential or critical label.

**Why it matters here:** Once data is identified as important data, the processor has added governance, periodic risk-assessment and reporting duties. Exporting it also triggers a separate data export security-assessment analysis.

Sources:

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io)

### National core data

**Term:** core data

Core data is data related to national security, the lifelines of the national economy, important aspects of people's livelihoods, or major public interests. The Data Security Law subjects it to a stricter management system than important data.

**Why it matters here:** Do not use important data and core data as interchangeable labels. If a catalogue or authority identifies core data, apply the stricter rules and record that classification separately.

Sources:

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)

### Critical information infrastructure operator

**Term:** CII operator

A CII operator operates critical information infrastructure identified under the applicable protected-sector and serious-harm framework. Ordinary data processing, network operation, or possession of important data does not by itself prove CII status.

**Why it matters here:** CII status changes the export route: a CII operator exporting personal information or important data must apply for a data export security assessment under the 2024 Provisions, subject to any applicable special provisions.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io)

### CAC data export security assessment

**Term:** data export security assessment

A data export security assessment is the state-administered review route for data exports that meet the current triggers. The processor applies through the provincial cyberspace authority to the national cyberspace authority and supplies a pre-filing self-assessment and the required export materials.

**Why it matters here:** Important-data exports by non-CII processors and exports of personal information or important data by CII operators enter this route under the 2024 Provisions. Personal-information volume exemptions do not remove the important-data trigger.

Sources:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io)
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io)

### Personal information

Personal information is information, recorded electronically or otherwise, that relates to an identified or identifiable natural person, excluding anonymized information. It is a separate legal category from important data, although the same dataset can contain personal information and also be identified as important data.

**Why it matters here:** Export-route rules use different triggers for personal information and important data. Do not apply personal-information volume exemptions to data that is also important data.

Sources:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io)

## Short answer

The Data Security Law classifies data by its importance to economic and social development and by the harm that alteration, destruction, disclosure, illegal acquisition, or illegal use could cause to national security, the public interest, or lawful individual and organizational interests. Regions and departments must identify important-data catalogues for their sectors and protect listed data more closely. Core data is a separate, stricter category. A company's internal 'critical' or 'confidential' label can support screening, but it does not by itself establish either legal category.

For export screening, the 2024 Provisions say a processor does not need to declare data as important data unless a relevant department or region has notified the processor or publicly identified the data as important. This rule addresses the export filing decision; it does not remove the duty to monitor applicable catalogues and official notices.

An important-data processor must identify a data-security responsible person and management body: a named accountable lead and an organizational function responsible for implementing the data-security duties. The processor must periodically assess its data-processing activities and submit a report covering the types and quantities of important data, processing activities, risks, and response measures. The Data Security Law does not state one universal interval for every sector, so the processor must check applicable departmental and regional rules. General duties to monitor risk, remedy vulnerabilities, handle incidents, notify users where required, and report to the competent authority also apply.

A transfer outside China needs its own route. Under the 2024 Provisions, a CII operator exporting personal information or important data, and a non-CII processor exporting important data, must apply for a data export security assessment through the provincial cyberspace authority, subject to the stated special provisions. Personal-information volume exemptions do not exempt important-data exports.

A successful assessment result is valid for three years from the result date. If the export will continue and no re-application trigger has occurred, the processor may apply for a three-year extension within 60 working days before expiry; the national cyberspace authority decides whether to approve it. Keep the validity period, extension decision, and any change requiring a new application separate from the periodic domestic important-data risk assessment.

Sources for this answer:

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Articles 21 and 27-31 establish important-data catalogues, enhanced governance, monitoring, incident response, periodic risk assessment and reporting, and separate export rules.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use for the security-assessment procedure, pre-filing self-assessment, application materials, assessment factors, and re-application triggers where the current 2024 Provisions require an assessment.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Articles 2 and 7 state the official-identification rule and require CII operators exporting personal information or important data, and other processors exporting important data, to apply for a security assessment. Article 9 sets the assessment result's three-year validity and possible extension.

## What to keep as evidence

Preserve the source and date behind the classification. A self-created label alone does not show that the legal category applies.

- Data inventory: source, type, quantity, purpose, processing operations, systems, storage location, recipients, retention, and business and system owners.
- Identification record: each applicable sector or regional catalogue, direct authority notice, or public identification, including version, date, matching data fields, and unresolved classification questions.
- Harm analysis tied to the statutory classification factors, without inventing a universal volume or sensitivity threshold.
- Governance evidence: named data-security responsible person and management body, decision rights, policies, training, access, monitoring, incident, supplier, and remediation records.
- Periodic risk-assessment report and submission evidence covering the important-data types and quantities, processing activities, risks, and response measures.
- For every transfer outside China, a documented CII-status and export-route decision, self-assessment where required, filing materials, outcome, validity period, and change triggers.

Sources for this answer:

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Articles 21 and 27-31 support the classification, governance, assessment, reporting, incident, and export evidence listed here.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Supports the self-assessment, application materials, assessment factors, procedure, and change-trigger records where an export security assessment is required.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Supports the current official-identification rule, important-data export trigger, three-year validity period, and extension route.

## Primary sources

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use for data export security assessment triggers, self-assessment, application materials, review timing, re-review, validity, and re-application triggers.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current important-data identification rule, export-route thresholds and exemptions, assessment validity, and 22 March 2024 effective date.

## Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

*Operationalize the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Sorena AI helps turn the answer to "How does important data change China cybersecurity obligations?" into assigned controls and retained evidence.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md
