China Data Security Law (DSL)
The Data Security Law of the People's Republic of China (effective September 2021) establishes a comprehensive framework for data security governance. It introduces a data classification and grading system, cross-border data transfer restrictions, government data security obligations, and a national data security review mechanism. Applies to data processing activities within China and extra-territorially where national security is affected.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
Assurance
| Code | Title |
|---|---|
| CN-DSL-V2-AUDIT | Data Security Compliance Audit |
Chapter II — Data Security and Development
Data security systems, industry self-regulation, and data security standards
| Code | Title |
|---|---|
| DSL-II-01 | Data Classification and Grading System |
| DSL-II-02 | National Core Data Protection |
| DSL-II-03 | Important Data Catalogue |
| DSL-II-04 | Data Security Standards |
Chapter III — Data Security System
Risk assessment, monitoring, emergency response, and national security review
| Code | Title |
|---|---|
| DSL-III-01 | Data Security Risk Assessment |
| DSL-III-02 | Data Security Emergency Response |
| DSL-III-03 | National Data Security Review |
| DSL-III-04 | Data Export Controls |
Chapter IV — Data Security Obligations
Data processor obligations for security management and protection
| Code | Title |
|---|---|
| DSL-IV-01 | Data Security Management System |
| DSL-IV-02 | Risk Monitoring and Incident Response |
| DSL-IV-03 | Important Data Risk Assessment |
| DSL-IV-04 | Data Transaction Security |
| DSL-IV-05 | Cross-Border Data Transfer |
Chapter V-VII — Government Data and Legal Liability
Government data security, international cooperation, and penalties
| Code | Title |
|---|---|
| DSL-V-01 | Government Data Security Responsibility |
| DSL-V-02 | Government Data Openness |
| DSL-VI-01 | International Cooperation Principles |
| DSL-VII-01 | Penalties for Non-Compliance |
| DSL-VII-02 | National Security Violations |
Cross-Border
| Code | Title |
|---|---|
| CN-DSL-V2-XBORDER-REVIEW | Cross-Border Security Assessment for Important Data |
Data Governance
| Code | Title |
|---|---|
| CN-DSL-V2-CLASSIFICATION | Hierarchical Data Classification |
| CN-DSL-V2-CORE-DATA | Core Data Stringent Protection |
| CN-DSL-V2-IMPORTANT-CATALOG | Important Data Catalog Compliance |
| CN-DSL-V2-OPEN-DATA | Open Data and Reuse Rules |
| CN-DSL-V2-PUBLIC-DATA | Government and Public Data Handling |
Governance
| Code | Title |
|---|---|
| CN-DSL-V2-LICENSING | Service Licensing for Data Brokers |
| CN-DSL-V2-NS-REVIEW | National Security Review |
| CN-DSL-V2-ROLES-DPO | Data Security Responsibility System |
| CN-DSL-V2-SCOPE | Scope and Extraterritorial Application |
| CN-DSL-V2-TRAINING | Data Security Training and Awareness |
Legal
| Code | Title |
|---|---|
| CN-DSL-V2-FOREIGN-REQUEST | Foreign Authority Data Requests |
| CN-DSL-V2-PENALTIES | Penalties for Violations |
Operational
| Code | Title |
|---|---|
| CN-DSL-V2-GOV-COOPERATION | Cooperation with Authorities |
| CN-DSL-V2-INCIDENT-NOTIFY | Incident Notification |
| CN-DSL-V2-MARKET-CONDUCT | Data Market and Trading Rules |
| CN-DSL-V2-MONITORING | Monitoring and Risk Disposal |
Risk
| Code | Title |
|---|---|
| CN-DSL-V2-RISK-ASSESSMENT | Important Data Risk Assessment |
Technical
| Code | Title |
|---|---|
| CN-DSL-V2-LIFECYCLE | Whole-Lifecycle Security Measures |
Your Compliance Coverage
If you comply with China Data Security Law (DSL), you already cover:
NIS2 Directive
21%
8 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
21%
8 controls mapped
Compare →EU AI Act
21%
8 controls mapped
Compare →+ 557 more: Chile Personal Data Protection Law (Law No. 21.719) (21%), ASEAN Data Management Framework (21%)
See all 560 mapped frameworks ↓Maps to 560 other frameworks
Frequently Asked Questions
What is China Data Security Law (DSL)?
China Data Security Law (DSL) is a compliance framework from China with 12 domains and 38 controls. The Data Security Law of the People's Republic of China (effective September 2021) establishes a comprehensive framework for data security governance. It introduces a data classification and grading system, cross-border data transfer restrictions, government data security obligations, and a national data security review mechanism. Applies to data processing activities within China and extra-territorially where national security is affected. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does China Data Security Law (DSL) have?
China Data Security Law (DSL) has 38 controls organised across 12 domains. The largest domains are Chapter IV — Data Security Obligations (5 controls), Chapter V-VII — Government Data and Legal Liability (5 controls), Data Governance (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does China Data Security Law (DSL) map to?
China Data Security Law (DSL) maps to 560 other compliance frameworks. The top mapping partners are NIS2 Directive (21% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (21% coverage), EU AI Act (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with China Data Security Law (DSL) compliance?
Start your China Data Security Law (DSL) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about China Data Security Law (DSL) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required