China Data Security Law (DSL)
The Data Security Law of the People's Republic of China (effective September 2021) establishes a comprehensive framework for data security governance. It introduces a data classification and grading system, cross-border data transfer restrictions, government data security obligations, and a national data security review mechanism. Applies to data processing activities within China and extra-territorially where national security is affected.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Chapter II — Data Security and Development
Data security systems, industry self-regulation, and data security standards
| Code | Title |
|---|---|
| DSL-II-01 | Data Classification and Grading System |
| DSL-II-02 | National Core Data Protection |
| DSL-II-03 | Important Data Catalogue |
| DSL-II-04 | Data Security Standards |
Chapter III — Data Security System
Risk assessment, monitoring, emergency response, and national security review
| Code | Title |
|---|---|
| DSL-III-01 | Data Security Risk Assessment |
| DSL-III-02 | Data Security Emergency Response |
| DSL-III-03 | National Data Security Review |
| DSL-III-04 | Data Export Controls |
Chapter IV — Data Security Obligations
Data processor obligations for security management and protection
| Code | Title |
|---|---|
| DSL-IV-01 | Data Security Management System |
| DSL-IV-02 | Risk Monitoring and Incident Response |
| DSL-IV-03 | Important Data Risk Assessment |
| DSL-IV-04 | Data Transaction Security |
| DSL-IV-05 | Cross-Border Data Transfer |
Chapter V-VII — Government Data and Legal Liability
Government data security, international cooperation, and penalties
| Code | Title |
|---|---|
| DSL-V-01 | Government Data Security Responsibility |
| DSL-V-02 | Government Data Openness |
| DSL-VI-01 | International Cooperation Principles |
| DSL-VII-01 | Penalties for Non-Compliance |
| DSL-VII-02 | National Security Violations |
Maps to 546 other frameworks
Frequently Asked Questions
What is China Data Security Law (DSL)?
China Data Security Law (DSL) is a compliance framework from China with 4 domains and 18 controls. The Data Security Law of the People's Republic of China (effective September 2021) establishes a comprehensive framework for data security governance. It introduces a data classification and grading system, cross-border data transfer restrictions, government data security obligations, and a national data security review mechanism. Applies to data processing activities within China and extra-territorially where national security is affected. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does China Data Security Law (DSL) have?
China Data Security Law (DSL) has 18 controls organised across 4 domains. The largest domains are Chapter IV — Data Security Obligations (5 controls), Chapter V-VII — Government Data and Legal Liability (5 controls), Chapter II — Data Security and Development (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does China Data Security Law (DSL) map to?
China Data Security Law (DSL) maps to 546 other compliance frameworks. The top mapping partners are Chile Personal Data Protection Law (Law No. 21.719) (44% coverage), ASEAN Data Management Framework (44% coverage), US Gramm-Leach-Bliley Act (GLBA) — Higher Education Safeguards Rule (39% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with China Data Security Law (DSL) compliance?
Start your China Data Security Law (DSL) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about China Data Security Law (DSL) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 18 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required