Research across the library

Search laws, regulations, standards and guides

Suggested searches

Current priorities

2026-07-03Revised Internet Information Service Measures draft2026-06-18Network data risk assessment: draft versus final
effectiveVerified 2026-07-22

Anthropomorphic AI Interaction Services: Consultation Draft vs. Final Measures

The final measures convert the CAC consultation proposal into a joint five-authority rule, retain the core focus on dependency, minors, personal information and security assessment, and add a fixed effective date and a more developed lifecycle-governance structure.

  • The final rule is jointly issued by five authorities rather than presented as a CAC consultation proposal.
  • The final text expressly frames safety duties across deployment, operation, upgrade and termination.
  • The final text adds a fixed effective date of 15 July 2026 and operative penalty provisions.
Open comparison
effectiveVerified 2026-07-22

Automotive Data Rules: 2021 Provisions and the 2026 Export Security Guideline

The 2026 guideline does not repeal or replace the 2021 trial provisions. It operationalizes the national data-export framework for automotive scenarios by setting out route selection, exemptions, important-data identification, filing steps and security controls.

  • The 2021 provisions establish baseline automotive-data processing and export duties; the 2026 guideline adds an operational export workflow.
  • The 2026 guideline aligns automotive exports with security assessment, standard contract and certification routes.
  • The 2026 guideline adds nine stated exemption scenarios and scenario-based important-data identification.
Open comparison
effectiveVerified 2026-07-19

2016 Cybersecurity Law vs. 2025 Amendment

The amendment adds national-policy and artificial-intelligence provisions, links personal-information handling to the PIPL and Civil Code, restructures liability provisions, increases consequence-based penalties, and broadens the extraterritorial provision.

  • New provisions address national cybersecurity policy and artificial-intelligence development and security.
  • Personal-information handling is expressly linked to the PIPL, Civil Code, and other laws and administrative regulations.
  • Liability provisions are reorganized with higher penalties for serious consequences and new mitigation language.
Open comparison
draftVerified 2026-07-30

GB/T 35273-2020 and the 2026 Draft Revision: Status and Version Watch

A source-controlled comparison of publication status and implementation use. It does not reproduce either standard and does not claim that the consultation draft has replaced GB/T 35273-2020.

  • The 2026 document is a consultation draft, not an effective national standard.
  • GB/T 35273-2020 remains the published edition until an official successor is recorded.
  • Draft-only controls should be separated from current-state implementation requirements.
Open comparison
effectiveVerified 2026-07-22

Online Information Affecting Minors: Draft vs. Final Classification Measures

The final measures turn the consultation framework into an effective eight-authority instrument, preserve the four-category approach, and add a fixed commencement date and express presentation, recommendation and prominent-placement controls.

  • The consultation proposal became a jointly issued eight-authority instrument.
  • The final text organizes covered information into four operational categories.
  • The final rule took effect on 1 March 2026 and includes express prominent-position and recommendation controls.
Open comparison
upcomingVerified 2026-07-19

Network Data Security Risk Assessment Measures: Draft vs. Final

The final measures retain annual assessment for important-data processors and the three-year encouragement for general-data processors, but change report preparation and submission mechanics, remove the draft report template, and revise institutional and enforcement language.

  • The final reporting deadline is 20 working days after the annual assessment, rather than 10 working days in the draft.
  • The draft's prescribed report-template annex is not included in the final measures.
  • The final text uses a coordinated inter-agency mechanism and less prescriptive wording on named standards and certified assessors.
Open comparison
effectiveVerified 2026-07-19

Personal Information Export Certification: 2022 Framework vs. 2025 Measures

The 2022 rules established the certification process and certificate lifecycle for personal-information protection, including cross-border processing. The 2025 measures add a dedicated departmental-rule basis for the export-certification route, define route eligibility, regulate overseas recipients and certification institutions, and connect the route to current cross-border data rules.

  • The 2025 measures expressly define who may use export certification and exclude important data.
  • The newer measures add dedicated obligations for processors, overseas recipients, certification bodies, and oversight authorities.
  • The existing three-year certificate term and six-month renewal window remain part of the certification framework rather than being newly created in 2025.
Open comparison
upcomingVerified 2026-07-26

Simplified Measures for Small Personal Information Processors: Draft vs. Final Provisions

The final provisions preserve the proportionate-compliance model for eligible small processors, confirm the fewer-than-100,000-person threshold, add the Ministry of Public Security as a joint issuer, and establish a fixed commencement date.

  • The consultation proposal became a joint CAC and Ministry of Public Security departmental rule.
  • The final text confirms that the threshold is fewer than 100,000 persons, not 100,000 or fewer.
  • The final provisions establish an effective date of 1 September 2026 and confirm simplified audit, impact-assessment and selected cross-border arrangements.
Open comparison