Overseas Koreans · Global Business Magazine 🇰🇷 KR🇨🇳 中🇺🇸 EN🇻🇳 VI
포커스기업소식FOCUS BUSINESS MAGAZINE
A business & lifestyle magazine connecting overseas Koreans and Korean businesses worldwide
Special · China Policy

China's Data Risk Assessment Rules Take Effect 20 August — Annual Assessment and Filing for Important Data Handlers

China's Measures for Network Data Security Risk Assessment take effect on 20 August 2026. Companies that handle “important data” must carry out a risk assessment every year and file the report with the competent authority within 20 working days of completion. Failure to conduct the assessment is handled under the Data Security Law and related regulations.

Graphic on the effective date of China's Measures for Network Data Security Risk Assessment
▲ Key dates for the Measures for Network Data Security Risk Assessment (Graphic: Focus Business Magazine · Source: CAC/MIIT/MPS Order No. 24, promulgated 18 June 2026)

Companies operating in China have one more rule to check themselves against. Order No. 24, the Measures for Network Data Security Risk Assessment, jointly issued by the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT) and the Ministry of Public Security (MPS), takes effect on 20 August 2026.

The Measures were approved at the CAC's 12th executive meeting of 2026 on 1 June, endorsed by MIIT and MPS, and promulgated on 18 June. They are grounded in the Data Security Law, the Cybersecurity Law and the Regulations on Network Data Security Management, which took effect on 1 January 2025. Rather than creating a new obligation, they pin down the frequency, procedure and filing mechanics of a risk assessment duty that already existed in the higher-level rules.

Who has to do it, and how often

Article 5 is the core. Handlers of important data must conduct a risk assessment every year. Where the security status of important data changes materially in a way that could adversely affect data security, an assessment must promptly be carried out on the changed parts and their effects. Handlers of ordinary data are not obliged but are encouraged to assess at least once every three years.

An assessment may be conducted in-house or outsourced to a third-party assessment body (Article 7). Where done in-house, the company must designate a person in charge; where outsourced, the rights and obligations of both sides must be set out in a contract or another legally effective document. The work follows the requirements of the Data Security Law and the Regulations on Network Data Security Management, with reference to the relevant national standards on data security risk assessment.

Key obligations at a glance

Instrument
Measures for Network Data Security Risk Assessment (CAC · MIIT · MPS Order No. 24)
Promulgated / effective
Promulgated 18 June 2026 · effective 20 August 2026
Frequency
Important data handlers = annually (plus prompt assessment on material change) / ordinary data handlers = once every three years, encouraged
Method
In-house (designated person in charge) or outsourced to a third-party assessment body
Filing deadline
Within 20 working days of completing the annual assessment. If no competent authority is clear, file with the provincial or national cyberspace administration
Retention
Reports kept for at least three years
Rectification report
Filed within 15 working days of completing required rectification
Non-compliance
Handled under the Data Security Law, the Regulations on Network Data Security Management and related rules

Filing and verification — a paper trail by design

Article 16 carries the heaviest practical burden. Important data handlers must file the risk assessment report with the competent authority within 20 working days of completing the annual assessment. Where the competent authority is unclear, the filing goes to the provincial-level or national cyberspace administration. The receiving authority must notify its counterpart cyberspace administration within 10 working days, and the national cyberspace administration consolidates the reports and shares them with telecoms, public security and state security authorities.

Filing is not the end of it. Cyberspace administrations at provincial level or above, telecoms authorities, public security organs, state security organs and other relevant departments may inspect and verify the authenticity and accuracy of the report, and the company must cooperate. Reports must be kept for at least three years (Article 15). A pro-forma submission is unlikely to hold up.

Where risk is judged significant, supervision escalates. Under Article 17, authorities may require a company to engage a certified assessment body where the data processing activity carries relatively high security risk that could endanger national security or the public interest, or where a data security incident has caused leakage or theft of important data or large volumes of personal information. Repeated demands for outsourced assessment over the same incident or risk are prohibited.

A company directed to use an external body must provide the necessary support, including access to data facilities, data, systems and operation logs, and complete the assessment within the set period (Article 18). The report filed must bear the signatures of the assessment body's principal officer and the assessment lead, plus the body's official seal. Problems identified must be rectified, with a rectification report filed within 15 working days of completion. Companies may not ask or hint that an assessment body issue a false or improper report.

For important data handlers that refuse to rectify or fall short of rectification requirements, authorities may order measures including suspension of important data processing (Article 19). Failure to carry out an assessment at all is handled under the Data Security Law and the Regulations on Network Data Security Management (Article 22).

Assessment bodies face rules too

Constraints also apply on the provider side. An assessment body may not sub-contract the assessment to another body (Article 11), and the same body and its affiliates may not conduct more than three consecutive annual assessments for the same data handler (Article 12). Companies that have long used a single provider should check their renewal timing.

Assessment bodies must promptly notify the company on finding a major data security risk (Article 13), and must keep confidential any data, trade secrets and confidential business information obtained, deleting it promptly after the assessment or handling it as agreed (Article 14). Certification is encouraged rather than mandatory (Article 8) — but the authority-directed assessments under Article 17 must go to a certified body.

Authorities are also constrained. Competent departments must submit their annual inspection plans to the national cyberspace administration by the end of January each year, which coordinates with telecoms, public security and state security authorities to avoid unnecessary and duplicated inspections. Charging companies fees for such inspections is prohibited (Article 4).

What Korean companies in Tianjin and north China should check now

The Measures do not weigh equally on every Korean firm. The dividing line is whether a company qualifies as an important data handler. Whether data counts as “important” is determined, under the framework of the Regulations on Network Data Security Management, by catalogues and notifications issued by regional and sectoral authorities — so the notices from the authority where the company is located are the reliable reference. Sectors that handle large volumes of industrial data — auto parts, chemicals, healthcare, logistics, telecoms — should check especially carefully.

A practical sequence:

First, build a data inventory. Map what the China entity collects, stores and uses by business line, noting storage location, access rights and whether anything is transferred abroad. This material is a prerequisite for judging important-data status in any case.

Second, name the person before anything else. If you choose in-house assessment, designating a responsible person is an express requirement. Even if it is an administration or IT staffer wearing a second hat, put it in writing.

Third, confirm the filing channel in advance. Twenty working days is not generous; starting to look for the right authority after the assessment is finished is too late. Where the sector authority is unclear, identify the provincial cyberspace administration route ahead of time.

Fourth, set up report archiving. Given the three-year retention rule and authenticity checks, keep the supporting evidence alongside the report.

The full text is published through the CAC's official channels. Whether the Measures apply to a given company, and the exact scope of compliance, varies case by case — local Chinese legal and compliance advice is the safe route.

Sources

Full text
Measures for Network Data Security Risk Assessment, full text (China News Service, reprinted from the “Wangxin China” WeChat account, 18 June 2026)
Issuing bodies
Cyberspace Administration of China · MIIT · Ministry of Public Security (Order No. 24)
Governing laws
Data Security Law · Cybersecurity Law · Regulations on Network Data Security Management (effective 1 January 2025)
Regulator
Cyberspace Administration of China (cac.gov.cn)

※ This article was auto-drafted from the full text of Order No. 24, the Measures for Network Data Security Risk Assessment, issued by three Chinese ministries (reprinted by China News Service, 18 June 2026). Editorial review is required before publication.

← Back to list