Skip to main content

China Cybersecurity Law — Multi-Level Protection Scheme

Authored by: Peter Zhu
30. July 2026
Overview (draft). This page is published for navigation and internal linking while we expand the full guide. For advice on a specific matter, browse verified lawyers.

China's Cybersecurity Law (effective 2017) establishes cybersecurity requirements for network operators, including the Multi-Level Protection Scheme (MLPS 2.0), data localization mandates, and incident reporting obligations.

Applicability

The law applies to all \"network operators\" � any entity operating or providing network services in China, including websites, mobile apps, cloud services, and internal corporate networks.

Multi-Level Protection Scheme (MLPS 2.0)

Information systems are classified into five security levels based on the impact of a breach. Level 2 and above require filing with the public security bureau and passing a security assessment by a qualified third party. Level 3 and above require annual audits.

Data Localization

Critical information infrastructure (CII) operators must store personal information and?? data within China. Data exported must undergo a security assessment. CII sectors include finance, energy, transportation, healthcare, and telecommunications.

About the Author

Peter Zhu

READER DISCUSSION

Discussion

Share experience or questions about this topic. This is a public discussion — not legal advice. Do not post confidential case details.

Have a question after reading? Leave it here, or Ask a Lawyer for a free initial consultation.

Comments are moderated. China Law List is a directory and information resource; no attorney–client relationship is formed by posting here.

Related Legal Topics