Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ TAG · NATIONAL-STANDARD

Filed under national-standard

Every brief tagged "national-standard".

  • § 01 · DATA-ASSETS

    Two Registrations, One Word: China's New Data-Asset Standards and the Line Between 登记 and 登记

    On 2 July 2026 China issued two national standards for data as an asset — GB/T 47949-2026 (classification and codes) and GB/T 47950-2026 (registration guidance) — both effective 1 September 2026. They give data assets a fixed place in the asset-classification code system (block A0806020000, including a first-ever asset code for AI-training multimodal data measured in tokens) and a step-by-step model for putting data on an organization's own books. The trap for overseas counsel is the word 登记 (registration): these MOF/SAC standards register data as an asset internally, while the National Data Administration's Data Property Rights Registration Work Guide (Trial), finalized 1 July 2026, registers rights in data externally through a certificated institution. Same word, two regimes, two artifacts, two purposes. This DCC brief separates them, reads the two standards for what they require, and explains why the 入表 (balance-sheet entry) vs 确权 (rights confirmation) distinction keeps tripping up data-asset deals.

    data-assets · data-property-rights · data-registration
  • § 02 · SENSITIVE-PERSONAL-INFORMATION

    Seven Highlights of China's New Sensitive Personal Information Processing Standard — and What They Mean in Practice

    GB/T 45574-2025 《数据安全技术 敏感个人信息处理安全要求》 (Data Security Technology — Security Requirements for Processing Sensitive Personal Information) is China's first dedicated national standard on sensitive personal information (敏感个人信息), effective 1 November 2025. Authored by Wang Yi, Zhao Yanming, and Zeng Lingwei of the Shenzhen Data Exchange DEXC+ program, this brief walks through the seven highlights the standard introduces: a recalibrated scope of what counts as sensitive personal information under PIPL, dynamic classification logic, a new linkage between sensitive-PI volume and the important data threshold, industry-specific and group-specific protections, data-security-maturity requirements, a model written-consent template, and tightened lifecycle obligations covering collection, storage, display, and audit. The operational takeaway for overseas counsel: the standard converts PIPL's high-level sensitive-PI obligations into testable, auditable requirements — compliance teams should treat it as the primary implementation guide for PIPL Article 28 and beyond.

    sensitive-personal-information · pipl · national-standard
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →