Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ DOMAIN · ENERGY, AVIATION & RESOURCES

Energy, Aviation & Resources.

能源·航空·自然资源

The sector-specific data regimes for energy, civil aviation, and natural resources — the National Energy Administration's energy-industry data-security measures, the Ministry of Natural Resources' data-security measures, and the CAAC's civil-aviation data-security monitoring requirements — built on the Data Security Law.

This domain gathers the resource- and infrastructure-sector data regimes that sit on top of the general Data Security Law and Cybersecurity Law framework. It collects the instruments that energy companies, civil-aviation operators, and natural-resources data holders must observe in addition to the economy-wide rules: the National Energy Administration’s Measures for Data Security Management in the Energy Industry, the Ministry of Natural Resources’ Measures for Data Security Management in the Natural-Resources Field, and the Civil Aviation Administration of China’s technical requirements for civil-aviation data-security monitoring and early warning.

Each of these sectors handles data that bears directly on national and economic security — grid and generation data, surveying-and-mapping and geographic data, and aviation-operations data — so the sector rules emphasize “important data” cataloguing, classified-grading protection, supply-chain and outsourcing controls, and monitoring-and-early-warning duties calibrated to critical-infrastructure risk.

§ LAWS IN THIS DOMAIN

The legal corpus.

6 laws.

§ BRIEFS

In this domain.

1 brief.

  • § 01 · TRANSPORT

    Five Grades of Data, One Reporting Spine: The Ministry of Transport's Data Security Measures

    On June 18, 2026 the Ministry of Transport issued the Measures for Data Security Management in Transport (交科技规〔2026〕3号), effective July 1, 2026 — 41 articles that complete the sector build-out of the Data Security Law for highways, waterways and comprehensive transport. The full text reached the public record in July through an academic-society WeChat repost rather than the ministry's own site. DCC reads the Measures around four load-bearing features: a five-grade classification ladder that splits general data into Grades 3/2/1 and pulls Grade-3 general data into the hard transmission-protection net alongside important and core data; an annual risk-assessment duty that extends beyond important-data handlers to any processor holding personal information on 10 million or more people, dated the same day as the national Network Data Security Risk Assessment Measures but effective 50 days earlier; an AI clause requiring pre-deployment evaluation of corpora, training data and algorithm explainability, plus a default ban on training on entrusted data; and a single reporting spine that routes filings through provincial transport authorities to MOT, with a direct line for central transport SOEs. Storage follows the sector pattern: localization for transport-authority personal information and CIIO-collected data, MLPS Level 3 for important-data systems, Level 4 or CII protection for core data, and security-assessed cloud services only.

    transport · mot · important-data
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →