{"id":147656,"date":"2026-08-17T09:23:01","date_gmt":"2026-08-17T09:23:01","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=147656"},"modified":"2026-08-17T09:23:01","modified_gmt":"2026-08-17T09:23:01","slug":"china-tmt","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/china-tmt\/","title":{"rendered":"China: TMT"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-147656","comparative_guide","type-comparative_guide","status-publish","hentry","guides-tmt","jurisdictions-china"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Han Kun Law Offices<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2022\/03\/Firms-LOGO-1.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Han Kun Law Offices<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2022\/03\/Firms-LOGO-1.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of TMT laws and regulations applicable in China<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 How are proprietary rights in software and associated materials protected?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Proprietary rights in software and associated materials mainly include copyright and patent rights. Software copyright is mainly protected through the Copyright Law and the Regulation on Computer Software Protection. Software patent rights are mainly protected under the Patent Law, as the Patent Examination Guidelines explicitly state that computer program products are included in product claims. Additionally, if the software is not publicly disclosed, it can be protected as a trade secret under Article 10 of the Anti-Unfair Competition Law (as revised in 2025 and effective from 15 October 2025), provided that it meets the required criteria for confidentiality, value, and protective measures.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In the absence of a contractual agreement, the developer retains the proprietary rights related to both the patent and the copyright of the software. According to Article 859 of the Civil Code, unless otherwise specified by law or agreed upon by the parties, the right to apply for a patent for an invention or creation developed under a commissioned development agreement belongs to the developer or researcher. Regarding copyright, Article 19 of the Copyright Law and Article 11 of the Regulation on Computer Software Protection specify that, in the absence of a written contract or when the contract does not specify ownership, the copyright is vested in the developer.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 Are there any specific laws that govern the harm \/ liability caused by Software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Several laws govern the harm or liability caused by software or computer systems. Chapter 6 of the Cybersecurity Law sets responsibilities and penalties for network service providers whose products, including software and computer systems, cause harm \u2014 primarily in the form of fines. In severe cases that constitute a crime, liability may be pursued under Article 286 of the Criminal Law. While there are no specific laws covering all types of harm caused by software, broader legal frameworks offer fallback protection. The Tort Liability section of the Civil Code, the Product Quality Law, and the Law of the People&#8217;s Republic of China on the Protection of Consumer Rights and Interests ensure that users are safeguarded from damages caused by defective software or systems.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Article 22 of the Cybersecurity Law establishes requirements for network products and services, including software and computer systems, mandating adherence to national standards, the implementation of immediate corrective actions for security vulnerabilities, and the maintenance of continuous security. The Regulation on the Management of Security Vulnerabilities in Network Products provides additional guidance on handling such issues. Additionally, Articles 285 and 286 of the Criminal Law specify crimes related to unlawful conduct involving software or computer systems, including illegal access, data theft, and system disruption, along with penalties for those found guilty of such offenses. These laws ensure both security and accountability in the use of software and computer systems.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (Licence and SaaS) \u2013 Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>China does not have a dedicated technology-specific law governing software provision or cloud services. Instead, relevant rules are spread across multiple laws. Software licensing is mainly governed by the Civil Code, Copyright Law, and Regulation on Computer Software Protection. The provision of software-related services, including cloud-based services, falls under the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law (\u201cPIPL\u201d), which impose data protection and cybersecurity obligations on service providers. The Network Data Security Regulations, effective from 1 January 2025, further refine the regulatory requirements for network data security.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If \u2018yes\u2019, what would be considered a market standard level of cap?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, software vendors commonly seek to cap their maximum financial liability. There is no uniform PRC market-standard cap. In negotiated enterprise software and SaaS transactions, the cap is often linked to fees paid or payable over an agreed period, with the level depending on the deal value, bargaining position and risk profile; specified risks may be subject to a separate higher cap. Consumer-facing terms and free software often contain narrower remedies or broader disclaimers, subject to mandatory PRC law.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor\u2019s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under Chinese law, clauses excluding liability for personal injury, or for property loss caused by wilful misconduct or gross negligence, are invalid. For confidentiality breaches, data protection or data security violations (including data loss), IPR infringement, breaches of applicable law, regulatory fines and AI-related claims, there is no single market position. Depending on bargaining leverage and risk profile, these liabilities may be uncapped, subject to a separate higher cap, or included within the general cap. Regulatory fines and other liabilities that cannot lawfully be transferred or limited remain subject to applicable law.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Source code escrow is occasionally used in on-premises licence transactions, particularly where the vendor is responsible for ongoing maintenance, updates or custom development. It is intended to protect the licensee if the vendor becomes insolvent, materially breaches the agreement or ceases to support the software. The practical protection depends on the licence and release terms. Under Article 18 of the Enterprise Bankruptcy Law, after a bankruptcy application is accepted, the administrator may decide whether to terminate or continue a pre-existing contract where both the debtor and the counterparty have not completed performance. Bankruptcy therefore does not automatically terminate every software licence, and the licensee&#8217;s continued right to use released code should be assessed under the specific licence and the status of performance. For SaaS, source code is generally not escrowed; some parties instead consider escrowing system images or deployment materials for business continuity, although this remains relatively uncommon.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>For banking and insurance institutions, compliance regarding IT outsourcing with these sector-specific rules is mandatory, irrespective of general technology laws. IT outsourcing in other regulated sectors (e.g., healthcare, critical infrastructure) may also face additional constraints under China&#8217;s overarching data security, cybersecurity, and personal information protection regimes.<\/p>\n<p>Notably, the Measures for the Regulation of Information Technology Outsourcing Risks of Banking and Insurance Institutions mandate key principles for IT outsourcing, including: institutions may not outsource their information technology management responsibilities or primary cybersecurity accountability; outsourcing must not undermine core capability development and institutions must retain control of critical technologies; institutions must balance outsourcing risks, costs and benefits; network and information security and personal information protection must be safeguarded; ex-ante controls and ongoing supervision should be emphasized; and outsourcing strategies and risk-management measures should be reviewed and improved on a continuing basis.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>China does not have a TUPE-style regime under which employees automatically transfer to an IT outsourcing provider solely because a function is outsourced. The existing employer remains bound by its employment contracts unless the employees agree to transfer or the employment relationships are otherwise lawfully changed or terminated under the Labor Contract Law. By contrast, where the employer itself undergoes a merger or division, Article 34 of the Labor Contract Law provides that existing employment contracts remain effective and are continued by the successor employer. Any workforce restructuring associated with outsourcing must therefore be implemented in accordance with the applicable requirements on consultation, amendment, termination and severance.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and\/or services, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal regulations on telecommunications in China include the Telecommunications Regulations of the People\u2019s Republic of China (the \u201cTelecom Regulations\u201d), the Administrative Measures for the Licensing of Telecommunications Business (the \u201cLicensing Measures\u201d), the Classification Catalogue of Telecommunications Services (the \u201cCatalog\u201d), and the Administrative Provisions for Foreign-funded Telecommunications Enterprises (the \u201cFITE Provisions\u201d).<\/p>\n<p>The Telecom Regulations provide the principal framework governing telecommunications services in China. They categorize telecommunications businesses into basic telecommunications businesses (the \u201cBTS\u201d) and value-added telecommunications businesses (the \u201cVAT\u201d) and require different licences for each category. The Catalog defines the different types of telecommunications businesses in further detail.<\/p>\n<p>In addition, the Licensing Measures set out the requirements and procedures for applying for, approving, using and managing telecommunications business licences, while the FITE Provisions set out the rules applicable to foreign-invested telecommunications enterprises operating in China.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Catalog sets out specific features and descriptions of each type of telecommunication services, and telecommunication service providers shall obtain the corresponding license before operating business. The application and approval requirements for different types of licenses may vary, for example, compared to VAT, BTS requires the telecommunication operator to have a state-owned equity or shareholding of not less than 51%.<\/p>\n<p>China also maintains foreign-investment restrictions for many value-added telecommunications services, with foreign equity generally capped at 50% unless otherwise provided. Under the MIIT pilot launched in 2024 in specified areas of Beijing, Shanghai, Hainan and Shenzhen, foreign equity caps have been removed for specified categories, including Internet Data Center (IDC), Content Delivery Network (CDN), Internet Access Service (ISP), online data processing and transaction processing, certain information publishing platform and delivery services, and information protection and processing services. Foreign-invested enterprises must obtain an MIIT pilot approval and comply with the applicable licensing and regulatory requirements. As of June 2026, 166 foreign-invested enterprises had received pilot approvals, while the number of foreign-invested telecommunications enterprises in China exceeded 3,100. This marks a significant step in China&#8217;s gradual easing of restrictions on telecommunications business.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>China does not have a consolidated law governing the access to communications data by competent agencies. Instead, the relevant provisions are scattered in different laws and regulations, and they do not specify detailed data types. For example, Article 65 of the Telecom Regulations provides that for reasons of national security or the investigation of criminal offenses, public security organs, national security organs, or people&#8217;s procuratorates may inspect telecommunications content in accordance with the procedures prescribed by law. Article 35 of the Data Security Law also sets out that the security organs may obtain data for the purpose of protecting national security or investigating crimes according to law.<\/p>\n<p>Laws and regulations also set restrictions on such access by authorities. For example, according to Article 35 of the Data Security Law, the authority must follow strict procedures for approval and access data in accordance with the law. In addition, Article 28 of the Provisions on Procedures for Administrative Law Enforcement by Cyberspace Authorities provides that only in the event that the evidence may be destroyed or lost, or difficult to obtain in the future, and upon the approval of the person in charge of the cyberspace authority, law enforcement officers may register and retain in advance the data storage devices involved in the suspected violation.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that impose cyber security and\/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and\/or provision of telecommunications services.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Cybersecurity Law, the Data Security Law, and the PIPL collectively impose cybersecurity and operational resiliency obligations on telecommunications infrastructure operators and service providers. The Cybersecurity Law establishes baseline security protection requirements, including the Multiple Level Protection Scheme, and imposes enhanced obligations on operators of Critical Information Infrastructure. The Data Security Law requires data classification and protection measures. The Network Data Security Regulations, effective from 1 January 2025, further refines the regulatory requirements for network data security. In addition, the National Cybersecurity Incident Reporting Management Measures, issued in September 2025 and effective from 1 November 2025, set out detailed requirements for the reporting of cybersecurity incidents, including reporting procedures, timelines, and content.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The main competent authorities are the Ministry of Industry and Information Technology (MIIT) and the State Administration for Market Regulation (SAMR).<\/p>\n<p>For example, the Department of Science and Technology of MIIT and the Standardization Administration of China (SAC) under SAMR usually work with research institutes such as the China Academy of Information and Communications Technology (CAICT) and the China Electronics Standardization Institute (CESI), and join hands with other industry associations, technology enterprises and research institutions to issue cutting-edge technical standards related to mobile communications and connected technologies. These include mandatory national standards, recommended national standards, and guiding technical documents.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Technical interoperability standards, developed through the integration of authoritative guidance from regulators, technical expertise from research institutes (e.g., CAICT, CESI), and practical feedback from industry, are fundamental to the advancement of connected technologies. By ensuring compatibility across diverse devices and systems, these standards eliminate fragmentation, enabling seamless collaboration between 5G networks, IoT sensors, smart devices, and emerging domains like connected vehicles and digital health tools. This interoperability is crucial for accelerating the large-scale deployment and adoption of these technologies across industries and in daily life.<\/p>\n<p>Mandatory national standards establish baseline requirements for safety, security, and quality, thereby safeguarding public interests and maintaining market order. Meanwhile, recommended standards and guiding documents offer flexibility, encouraging technological innovation by allowing enterprises to explore new solutions within a standardized framework. The development of such standards also involves careful consideration of intellectual property rights, often governed by principles like Fair, Reasonable, and Non-Discriminatory (FRAND) licensing, to ensure widespread adoption and innovation.<\/p>\n<p>Overall, such a standardized system balances regulation and innovation, fosters industry collaboration, reduces technical barriers, mitigates R&amp;D risks by providing clear technical pathways and development costs, and ultimately drives the healthy and sustainable growth of connected technologies.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Cybersecurity Law (&#8220;CSL&#8221;), as amended in 2025 and effective in its revised form from 1 January 2026, the Data Security Law (&#8220;DSL&#8221;), effective from 1 September 2021, and the Personal Information Protection Law (&#8220;PIPL&#8221;), effective from 1 November 2021, constitute the three foundational laws in China&#8217;s data protection and cybersecurity framework. The Network Data Security Regulations (&#8220;NDSR&#8221;), effective from 1 January 2025, further specify requirements for network data security and personal information protection.<\/p>\n<p>The CSL provides the foundational cybersecurity architecture, while the DSL establishes a classification-based data security regime applicable to data processing activities. The PIPL is China&#8217;s comprehensive personal information protection law and focuses on processing rules and individual rights. The NDSR complements this framework with more detailed network data security and personal information protection requirements. The Personal Information Protection Compliance Audit Measures, effective from 1 May 2025, require processors handling more than 10 million individuals&#8217; personal information to conduct a compliance audit at least once every two years and also provide for regulator-initiated audits in specified circumstances. In August 2026, the CAC also released draft Regulations on Personal Information Protection by Large Personal Information Processors, which would establish an identification and enhanced compliance regime for processors meeting specified scale, service and systemic-impact criteria.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under the DSL, failure to comply with data protection obligations can result in fines ranging from RMB 50,000 to RMB 2,000,000. The highest penalty for illegal cross-border transfer of important data can be up to RMB 10,000,000. In cases where core data protection is violated and national sovereignty, security, and development are at risk, the fine may reach RMB 10,000,000, and criminal liability may also be imposed.<\/p>\n<p>Under the PIPL, the maximum penalty for violating personal information protection laws can be RMB 50,000,000 or 5% of the data handler&#8217;s annual turnover from the previous year. Infringements related to personal information protection can also lead to criminal liability under the Criminal Law.<\/p>\n<p>Apart from sanctions imposed on the data handlers, the person directly in charge and other directly liable persons may face fines of up to RMB 1,000,000. In the case of severe personal information infringement, a decision may be made to prohibit the said persons from acting as directors, supervisors, senior executives and persons-in-charge of personal information protection of relevant enterprises within a certain period of time.<\/p>\n<p>Under the NDSR, violations of network data security requirements may result in fines of up to RMB 10,000,000. In addition to monetary penalties, regulatory authorities may order the suspension of relevant business activities, require suspension of operations for rectification, or revoke relevant permits or business licenses. The directly responsible persons in charge and other directly liable persons may also face fines of up to RMB 1,000,000.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What data protection rules are relevant to technology contracts in your country?  Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>PRC technology contracts commonly address the CSL, DSL, PIPL and NDSR where the parties process personal information or other regulated data. Depending on the arrangement, provisions may address processing purpose and scope, roles and instructions for entrusted processing, security measures, incident notification and cooperation, handling of individual rights requests, retention and deletion or return, onward provision or sharing, audit rights, and cross-border transfer requirements. Contracts with no international nexus do not typically incorporate the EU GDPR or CCPA merely as a matter of course. Those regimes are generally addressed where they apply territorially, where a party&#8217;s global compliance framework requires them, or where the parties or data flows create a relevant international connection.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The CSL, as the fundamental legislation in the field of cybersecurity, systematically establishes legal requirements for several core issues, including without limitation: protection obligations for operators of critical information infrastructure (CIIOs), the Multiple Level Protection Scheme of cybersecurity, compliance management requirements for critical network equipment and special-purpose cybersecurity products, emergency response to cybersecurity incidents, the governance of network information contents, etc.<\/p>\n<p>The specific requirements for these issues are stipulated in the corresponding administrative regulations, departmental rules, and national standards, such as Security Protection Regulations for Critical Information Infrastructure, GB\/T 22239-2019 Information security technology &#8211; Baseline for classified protection of cybersecurity, GB 42250-2022 Information security technology &#8211; Security technical requirements of specialized cybersecurity products, Provisions on the Ecological Governance of Network Information Contents, etc.<\/p>\n<p>On 28 October 2025, the revised version of the Cybersecurity Law was promulgated and took effect on 1 January 2026. The amendment mainly introduces guiding provisions, including provisions on AI governance to address the evolving needs in the AI era, and revises the relevant penalty provisions.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under the revised CSL, effective from 1 January 2026, sanctions are tiered according to the severity of the consequences and are substantially higher than under the previous regime. Network operators that fail to perform their cybersecurity protection obligations may be fined up to RMB 500,000 where they refuse to rectify or the breach harms cybersecurity; up to RMB 2,000,000 where the breach causes serious consequences, such as a large-scale data leak or the loss of partial functionality of critical information infrastructure; and up to RMB 10,000,000 where it causes particularly serious consequences, such as the loss of principal functionality of critical information infrastructure. CIIOs that fail to perform their enhanced obligations are subject to a higher band on the same tiered basis. Persons directly in charge and other directly liable persons may be fined up to RMB 1,000,000. Regulators may also order the suspension of the relevant business and the closure of the relevant website or mobile application, and criminal liability may be pursued in severe cases.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. The Multiple Level Protection Scheme (MLPS) requires network operators to classify their information systems by security level and undergo corresponding security protection assessments. CIIOs are subject to enhanced cybersecurity obligations under the Security Protection Regulations for Critical Information Infrastructure. Additionally, providers of algorithmic recommendation services, deep synthesis services, and generative AI services are required to complete algorithm filings with the Cyberspace Administration of China (&#8220;CAC&#8221;). Blockchain information service providers must complete regulatory filings under the Provisions on Blockchain Information Services.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the regulatory framework for the reporting of cybersecurity incidents.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The National Cybersecurity Incident Reporting Management Measures, issued by the CAC in September 2025 and effective from 1 November 2025, establish a comprehensive framework for cybersecurity incident reporting. The Measures apply to network operators that construct, operate or provide services through networks within China. They require reporting of &#8220;relatively serious or above&#8221; cybersecurity incidents, with differentiated reporting timelines based on the type of network operator: CII operators must report to the protection department and public security authorities within 1 hour at the latest; other network operators must report to the local provincial cyberspace authority within 4 hours at the latest. The Measures also establish the &#8220;12387&#8221; cybersecurity incident reporting hotline and other channels. The annex, the Cybersecurity Incident Classification Guide, provides indicators for classifying incidents as &#8220;particularly serious,&#8221; &#8220;serious,&#8221; &#8220;relatively serious,&#8221; or &#8220;general.&#8221; For incidents involving leakage of personal information, the Guide includes quantitative indicators of 100 million, 10 million and 1 million individuals for the first three categories respectively; these are among several alternative indicators used to classify incidents.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Which body(ies), if any, is\/are responsible for the regulation of artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Multiple regulatory bodies share responsibility for AI regulation in China. The Cyberspace Administration of China (CAC) is the primary regulator for algorithmic recommendation services, deep synthesis services, and generative AI services, overseeing algorithm filings, content moderation, and security assessments. The Ministry of Industry and Information Technology (MIIT) regulates the technology and industry development aspects of AI. The Ministry of Science and Technology plays a role in AI research and development policies. Other sector-specific regulators (e.g., the People&#8217;s Bank of China for fintech AI applications) also exercise regulatory authority within their respective domains.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal laws governing AI in China include the Interim Measures for the Management of Generative Artificial Intelligence Services (the &#8220;Generative AI Measures&#8221;), which impose obligations on generative AI service providers regarding content security, algorithm filing, and security assessments. The Provisions on the Administration of Algorithm Recommendations, the Provisions on Deep Synthesis in Internet Information Services, and the Provisions on the Ecological Governance of Network Information Contents also impose relevant obligations.<\/p>\n<p>On 28 February 2025, the mandatory national standard GB 45438-2025 &#8220;Cybersecurity Technology \u2014 Labeling Methods for Artificial Intelligence Generated and Synthetic Content&#8221; was issued. Subsequently, in March 2025, the CAC and three other departments jointly issued the Artificial Intelligence Generated and Synthetic Content Labeling Measures. Both the Measures and the national standard took effect on 1 September 2025. These measures establish a \u201cvisible + invisible\u201d dual labeling system for AI-generated content, requiring service providers to add visible labels that can be perceived by users and invisible labels embedded in file metadata.<\/p>\n<p>In September 2025, the AI Security Governance Framework 2.0, a non-binding technical and governance framework, was officially released, upgrading the 2024 version and expanding the categories of security risks. The revised CSL adds Article 20 as the first framework provision on AI in a national law, covering support for AI research and infrastructure, the improvement of AI ethical norms, and the strengthening of risk monitoring, assessment and security supervision.<\/p>\n<p>In April 2026, the CAC and four other departments issued the AI Anthropomorphic Interaction Service Management Interim Measures, which took effect on 15 July 2026. The Measures apply to services that use AI to provide continuous emotional interaction by simulating natural-person personality traits, thinking patterns and communication styles. Ordinary customer service, knowledge Q&amp;A, work-assistant, education and research services that do not involve continuous emotional interaction fall outside their scope.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and\/or generative AI (including agentic AI)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. The Generative AI Measures impose specific requirements on providers of generative AI services to the public in China. For services with public-opinion attributes or social-mobilisation capability, the Measures require security assessment in accordance with applicable rules and algorithm filing under the algorithm-recommendation regime. Separately, current CAC practice distinguishes between filing of generative AI services and registration of applications or functions that directly call the capabilities of already-filed models through APIs or other means. These procedures should therefore be distinguished rather than treated as a single security-assessment process.<\/p>\n<p>The AI Content Labeling Measures, issued in March 2025 and effective from 1 September 2025, further specify the labeling requirements for AI-generated content. The Measures introduce differentiated visible labeling obligations for various types of AI-generated content, and require service providers to embed invisible labels containing prescribed information into the metadata of the AI-generated files.<\/p>\n<p>The AI Anthropomorphic Interaction Service Management Interim Measures, issued by the CAC in April 2026 and effective from 15 July 2026, introduce additional compliance requirements for services providing anthropomorphic AI interaction, including protection of minors and elderly users, controls on emotional boundaries, and anti-addiction measures.<\/p>\n<p>As regards agentic AI, there is not yet a dedicated binding regulation. On 8 May 2026, the CAC, the National Development and Reform Commission and MIIT jointly issued the Implementing Opinions on the Regulated Application and Innovative Development of AI Agents, indicating the intended regulatory direction: permission management and behaviour control for agents, a classification-and-grading governance framework calibrated to the application scenario and potential impact, full-lifecycle security management, and the development of agent interconnection standards.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Generative AI Measures require providers of generative AI services to establish service terms with users, clarifying the rights and obligations of both parties. The AI Content Labeling Measures further stipulate that service providers should clearly specify provisions related to AI-generated content labeling in their service terms, in order to enhance transparency.<\/p>\n<p>Although current regulations do not mandate other specific provisions that must be included in service terms, providers of generative AI services commonly incorporate the following provisions into their service terms to fulfill their legal obligations:<\/p>\n<p>Content Safety Management: Users are prohibited from inputting or inducing the output of content that is illegal or harmful under PRC law. The provider reserves the right to take appropriate actions and to report the incident to the relevant regulatory authorities in the event of unlawful conduct.<\/p>\n<p>Disclosure of Technological Limitations: Providers typically include statements explaining the limitations of generative AI technologies and guide users toward a rational and lawful understanding and use of such technologies, particularly to prevent minors from becoming overly reliant on or addicted to generative AI services.<\/p>\n<p>Complaint and Reporting Mechanism: Service terms typically outline the procedures and response timelines for handling complaints and reports related to generative AI services, ensuring that user feedback is received and addressed in accordance with AI-related regulations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, the ownership and intellectual property rights (particularly copyright) in AI-generated outputs are typically governed by contract terms. Whether AI-generated content qualifies for copyright protection depends on the degree of human creative contribution involved in its production. Chinese courts have, in a number of cases, recognized such content as a protected work, with copyright vesting in the user, if the user demonstrates sufficient originality through actions such as inputting specific prompts or adjusting parameters. The Hangzhou Internet Court, in a virtual digital avatar case, held that the developer&#8217;s aesthetic choices regarding AI-generated content constituted creation, affirming that copyright belonged to the developer.<\/p>\n<p>Conversely, content generated without substantial human involvement currently receives no copyright protection under Chinese law (e.g., automatically generated statistical data). Contracts typically stipulate that such outputs constitute the subject of &#8220;property interests&#8221; belonging to the client or platform, with corresponding usage rights granted accordingly.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Blockchain \u2013 What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Blockchain is primarily regulated through the Provisions on Blockchain Information Services, which require service providers to complete regulatory filings, authenticate users (using real names), and implement content controls. The CAC has been publishing batches of blockchain information service filing numbers on an ongoing basis.<\/p>\n<p>Digital assets are highly regulated. According to the Notice on Further Preventing and Dealing with Speculation Risks in Virtual Currency Trading, virtual currencies such as Bitcoin and ETH are not legal tender and cannot be used for circulation or as a means of payment. All cryptocurrency-related business activities \u2014 including trading, exchanges, and overseas platforms serving domestic users \u2014 are prohibited. In 2025, regulatory authorities further strengthened oversight of virtual currencies and Real World Assets (RWA)-related activities, with multiple financial industry associations issuing risk warnings. Financial institutions are prohibited from providing services for the issuance and trading of virtual currencies and RWA tokens.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Search Engines and Marketplaces \u2013 Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under PRC law, search engines are primarily regulated by the Administrative Provisions on Internet Information Search Services and the Telecommunications Regulations. The Administrative Provisions on Internet Information Search Services impose obligations on search engine operators to implement content security management measures, protect personal information, clearly label paid search results, and ensure advertising compliance, etc. Search engine operators should also obtain the necessary licenses, such as the B25 value-added telecommunications license for &#8220;information search and query services,&#8221; where foreign ownership in entities operating such value-added telecommunications services may not exceed 50% (subject to the ongoing pilot program in Beijing, Shanghai, Hainan, and Shenzhen relaxing such restrictions for certain VAT businesses).<\/p>\n<p>Online marketplaces are subject to regulations, including the E-Commerce Law and the Consumer Protection Law. These platforms must obtain any required administrative licenses, safeguard consumers&#8217; rights to be informed and to make choices, fulfil personal information protection obligations, retain records of products, services, and transactions for no less than 3 years, provide consumers with options that are not based on personal profiling, and ensure advertising compliance.<\/p>\n<p>In addition, both search engine and marketplace operators are required to comply with competition laws, including the Anti-Unfair Competition Law and the Interim Provisions on Preventing Unfair Competition in the Online Market.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The operation of social media and online platforms shall be in line with the Administrative Measures for Internet Information Services and the Provisions on the Ecological Governance of Network Information Contents, which mandate content moderation, user identity verification, and the governance of unlawful and harmful information in accordance with applicable PRC requirements. The operators should also obtain the necessary licenses, such as the B25 value-added telecommunications license for information services.<\/p>\n<p>Platform operators shall also abide by the CSL and PIPL to fulfill their obligations of personal information and cybersecurity protection.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The fines for operating social media platforms without a proper license may be up to RMB 1,000,000. The maximum penalty for violating personal information protection laws can be RMB 50,000,000 or 5% of the data handler&#8217;s annual turnover from the previous year.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Spatial Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No specific laws tailored exclusively to spatial computing have been established yet. It is mainly regulated by existing legal frameworks.<\/p>\n<p>For example, the PIPL governs the collection, storage, transmission, and sharing of sensitive personal data \u2014 such as iris scans, fingerprints, and physiological indicators \u2014 collected through spatial computing technologies.<\/p>\n<p>In addition, intellectual property is regulated by relevant laws. The Patent Law, Copyright Law, and Trademark Law protect patents related to spatial computing (such as 3D engines and VR\/AR technologies), copyrights (like software and algorithms), and trademarks (such as virtual IPs). These laws prevent unauthorized use of such intellectual property, maintaining an innovative environment and market order.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Quantum Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern quantum computing and\/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is currently no PRC law dedicated exclusively to quantum computing. Depending on the relevant application, existing regimes &#8211; including cybersecurity, data protection, export control, intellectual property and sector-specific rules &#8211; may apply.<\/p>\n<p>Quantum cryptography is principally governed by the Cryptography Law and the Regulation on the Administration of Commercial Cryptography. The Cryptography Law classifies cryptography as core cryptography, ordinary cryptography and commercial cryptography, with different regulatory regimes. Commercial cryptographic products and services may also be subject to applicable standards, testing or certification, import and export controls, and requirements applicable to critical information infrastructure.<\/p>\n<p>Post-quantum cryptography remains an evolving technical and standard-setting area in China. Businesses should therefore monitor relevant national and industry standards and cryptography requirements rather than assume that a separate quantum-specific statutory regime has already been established.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Datacentres \u2013 Does your jurisdiction have any specific regulations that apply to data centres?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under PRC legal framework, Internet Data Centre (IDC) business refers to the use of corresponding computer room facilities to provide users with placement, maintenance on behalf of the user, system configuration, and management services for their servers and other internet or network-related equipment through outsourcing and leasing. IDC businesses also include Internet Resource Collaboration Service (IRCS) business. Typical IRCS business includes providing data storage, internet application development environments, deployment of internet applications, operation, and management services.<\/p>\n<p>IDC businesses are primarily regulated by the Telecom Regulations. Operators of data centres must obtain a B11 IDC license. A pilot program has been launched in Beijing, Shanghai, Hainan, and Shenzhen to remove the 50% foreign equity ratio restriction for data centre businesses and certain other VAT businesses. As of June 2026, 166 foreign-invested enterprises have received pilot approvals to carry out IDC and other VAT businesses.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 What are your top 3 predictions for significant developments in technology law in the next 3 years?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p><strong>Consolidation of AI Regulation into a Comprehensive Statute<\/strong><\/p>\n<p>China has developed its AI regulatory framework mainly through a series of rules targeting specific services, including algorithm recommendation (2022), deep synthesis (2023), generative AI (2023), AI-generated content labelling (effective September 2025) and, most recently, the Interim Measures for the Administration of AI Anthropomorphic Interactive Services (effective 15 July 2026). The regulatory approach is now likely to move towards a more consolidated framework. The revised CSL added Article 20, the first framework-level AI provision in a national law. In addition, the State Council\u2019s 2026 Legislative Work Plan, issued in May 2026, calls for accelerating comprehensive legislation on the healthy development of AI, as well as legislation addressing common elements of AI, including data, computing power, algorithms, property rights, cybersecurity and supply chain security, and key application scenarios. Against this background, we expect a comprehensive AI law to be proposed within the next three years.<\/p>\n<p><strong>Agentic AI as the Next Regulatory Frontier<\/strong><\/p>\n<p>Agentic AI is likely to become the next focus of AI regulation in China as AI systems move beyond generating content to making decisions, using external tools and taking actions with limited human intervention. China has not yet adopted binding rules specifically addressing these systems. Existing rules on cybersecurity, data protection, product safety, tort liability and sector-specific safety will continue to apply, but may not fully address risks arising from autonomous actions or physical interaction. We therefore expect future rules and standards to focus on human oversight, the scope of user authorisation, testing and incident reporting, allocation of responsibility across developers, deployers and users, and additional safeguards for high-risk applications capable of causing financial, physical or other material harm.<\/p>\n<p><strong>Embodied AI and the Emerging Market for Training Data<\/strong><\/p>\n<p>The development of embodied AI will create growing demand for high-quality real-world data, including visual, audio, tactile, spatial, motion-control and environmental data. Unlike data collected from online services, these datasets are often generated in homes, workplaces, factories and public spaces, and may capture personal information, information relating to incidental third parties, trade secrets or other protected content. Data sourcing and transaction compliance will therefore become a key part of embodied AI development. China is already encouraging the construction and circulation of high-quality datasets. The June 2026 Implementation Plan for Advancing the Development of High-Quality Industry Datasets specifically calls for the development of real-machine interaction datasets for key scenarios, covering physical interaction, environmental perception and motion control, to support embodied AI development. As this market develops, parties will need to look beyond contractual claims of data \u201cownership\u201d and verify how the data was collected, what rights were obtained from individuals, venue operators and other participants, and whether the proposed training, commercialisation, onward transfer and cross-border use are permitted. We expect future rules and market practice to place greater emphasis on data provenance, quality standards, labelling consistency, permitted-use restrictions and traceability throughout the data transaction chain.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 Do technology contracts in your country commonly include provisions to address sustainability \/ net-zero obligations or similar environmental commitments?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Technology contracts in China increasingly include sustainability, EHS and carbon-related provisions, particularly in multinational supply chains, data-centre or cloud projects, large enterprise procurements and projects involving state-owned enterprises. The level of contractualisation varies. Some contracts use measurable obligations, such as energy-efficiency, renewable-energy or reporting requirements, and link non-compliance to contractual remedies; others retain higher-level policy commitments. Such provisions are not yet a uniform feature of PRC technology contracts, and their content is generally driven by the parties&#8217; industry, supply-chain requirements, procurement policies and applicable environmental regulation rather than a technology-specific statutory mandate.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">6854<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/147656","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=147656"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}