Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

China Expands the Scope of the Data Localisation Requirement under its Cybersecurity Law

By Gabriela Kennedy on April 21, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

On 11 April 2017, the Cybersecurity Administration of China (CAC) released the draft Security Assessment Measures for Cross-Border Transfer of Personal Information and Important Data (“Draft Measures”). Draft measures and guidelines relating to the Cybersecurity Law (CSL) which was released in November last year, have been expected for a while. The hope has been that such guidelines and measures would shed light on the more opaque terms in the CSL and offer some clarity on the interpretation of broad definitions and concepts. The Draft Measures address the data localisation requirement but instead of narrowing down the concept, they appear to have further expanded the scope of this requirement, thus creating more uncertainty. The data localisation requirement was originally applicable to critical information infrastructures (CIIs) only. The Draft Measures indicate that it should cover both CIIs and network operators. If adopted, the Draft Measures will impose data localisation requirements on multinational companies (MNCs) which previously believed they were not CIIs thus not subject to these rules. The consultation period for the Draft Measures will end on 11 May, shortly before the 1 June effective date of the CSL.

Continue reading.

Photo of Gabriela Kennedy Gabriela Kennedy

Gabriela Kennedy is a partner of Mayer Brown and head of the Asia IP and TMT group. She is also co-leader of Mayer Brown’s global Intellectual Property practice and a member of the firm’s global Cybersecurity & Data Privacy and Technology & IP…

Gabriela Kennedy is a partner of Mayer Brown and head of the Asia IP and TMT group. She is also co-leader of Mayer Brown’s global Intellectual Property practice and a member of the firm’s global Cybersecurity & Data Privacy and Technology & IP Transactions practices. She is based in Hong Kong, practising intellectual property, media, information technology and telecommunications law. She handles the full spectrum of intellectual property work from litigation to licensing, strategic advice and portfolio management. Gabriela advises extensively on technology and data protection issues in Hong Kong and throughout Asia, particularly in relation to business processing outsourcing, the cross-border transfer of data, data compliance, data breaches and cybersecurity issues. She has handled a number of data breach complaints filed with the Privacy Commissioner in Hong Kong and has conducted in-depth data audits and drafted/devised privacy manuals and procedures for the Asia operations of a number of multi-national companies. On the information technology side, Gabriela’s particular expertise includes advising on complex IT transactions and projects, IT outsourcing, cloud-computing, mobile payments, smart card projects, the regulation of encryption technology, software licensing, and disputes stemming from failed IT projects. She has been involved with a number of international organisations in discussions involving standard setting for the cross-border transfer of data and the formulation of strategies to deal with cyber-security.

Read Gabriela’s full bio.

Read more about Gabriela KennedyEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Inside Cybersecurity & Privacy Law
  • Organization:
    Mayer Brown

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo